September 2026UnreviewedOpen access
Hive-AI: a defended multi-service honeypot framework for generative AI APIs
Sebastián Vargas Yáñez, Sergio Tobón
International Journal of Information Security
Abstract
Public Large Language Model (LLM) APIs draw attacker traffic that defenders cannot see. Probes hit at the semantic layer—past TLS, past Web Application Firewall rules—and conventional intrusion detection picks up almost none of it. No open-source honeypot framework today captures this traffic at scale, and the few LLM-honeypot prototypes that exist push captured logs straight into a downstream LLM analyzer, exposing the analysis pipeline to indirect prompt injection through attacker-controlled i
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@article{yanez2026hiveai,
title = {{Hive-AI: a defended multi-service honeypot framework for generative AI APIs}},
author = {Sebastián Vargas Yáñez and Sergio Tobón},
year = {2026},
month = sep,
journal = {International Journal of Information Security},
doi = {10.1007/s10207-026-01307-0},
url = {https://www.semanticscholar.org/paper/33566699ae6da88b8b15e737037575861d87045c}
}