Skip to content
#generative ai Open access

Hive-AI: a defended multi-service honeypot framework for generative AI APIs

Sep 2026 · International Journal of Information Security · Vol 25 · 1 citation · 70 references

TL;DR

HIVE-AI, a 47,578-LoC honeypot framework deployed continuously on a single 4-vCPU/4-GB Virtual Private Server since 6 April 2026, is presented, a promising low-cost alternative rather than a full substitute for open-source honeypot frameworks.

Abstract

Public Large Language Model (LLM) APIs draw attacker traffic that defenders cannot see. Probes hit at the semantic layer—past TLS, past Web Application Firewall rules—and conventional intrusion detection picks up almost none of it. No open-source honeypot framework today captures this traffic at scale, and the few LLM-honeypot prototypes that exist push captured logs straight into a downstream LLM analyzer, exposing the analysis pipeline to indirect prompt injection through attacker-controlled inputs. We address both gaps with HIVE-AI, a 47,578-LoC honeypot framework deployed continuously on a single 4-vCPU/4-GB Virtual Private Server since 6 April 2026. Five protocol-faithful facades feed an eight-stage classification cascade with sub-5-ms p99 synchronous latency. The LLM threat-hunter is protected by a five-layer defense-in-depth architecture against indirect prompt injection, characterized theoretically and through operational field evidence; controlled per-layer validation is deferred to a follow-up deployment. We report these findings as a single-site, single-window case study: twenty days of operation captured 16,683 attacks from 1229 unique source IPs across 50 countries. The triangulation defense reduces mean adversarial evasion from 54.8 to 9.3% (paired test, p<0.001\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$p<0.001$$\end{document}). Blind human validation on 100 events yields Cohen’s κ=0.74\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\kappa = 0.74$$\end{document} between the LLM and analyst majority—statistically indistinguishable from human-on-human κ=0.71\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\kappa = 0.71$$\end{document}. A local Ollama+Qwen2.5–1.5B backend reproduces the cloud severity verdict on 71% of events (κ=0.59\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\kappa = 0.59$$\end{document}, moderate agreement), a promising low-cost alternative rather than a full substitute. Code and dataset are released under MIT License and CC BY 4.0; the source code is archived at Zenodo HIVE-AI: A Honeypot Source Code (https://doi.org/10.5281/zenodo.19853664) and the live attack map at https://honeypot.ttpsec.cl:4443/livemap.

Read PDF

Similar papers

Preprint Sep 2026

OllamaDrama: Designing and Deploying a Honeypot to Measure Attacks on Exposed LLM Infrastructure

Publicly exposed large language model (LLM) infrastructure creates a growing attack surface, yet real-world targeting remains poorly understood. We present Ollure, a low- and medium-interaction honeypot that emulates the Ollama API without a backend LLM. Spanning four deployments across cloud and university networks, O...

Karina Elzer, Niklas Netterstrøm Johansen, Emmanouil Vasilomanolakis · 0 citations
Preprint Sep 2026

LLM-Based Penetration Testing in the Presence of Honeypots

This work presents a systematic study of honeypot-aware budget allocation for LLM attack agents and shows that with the proposed detector-guided policy, LLM agent attackers can effectively allocate budget to compromise hosts in a host pool, highlighting the importance of dynamically allocating budget in a controlled mi...

Xin-Hong Xie, Piyush Nagasubramaniam, Neeraj Karamchandani et al. · 0 citations
Open access Sep 2026

GenPot: A generative honeypot architecture for adaptive web and API interaction

GenPot is presented, a fine-tuned LLM-powered honeypot that integrates command-line, API, and dynamic web interaction to deliver realistic yet non-compromisable environments and is validated through a 14-day in-the-wild deployment and a human-in-the-loop credibility assessment.

Antonio Lara-Gutierrez, Juan Zamorano, J. A. Onieva · 0 citations
#machine learning Preprint Sep 2026

HoneyRoute: Honeypot-Model Routing for Adversarial LLM Serving

We introduce HoneyRoute, an inference-serving layer that detects whether an incoming request is malicious and, if so, routes it to a dedicated honeypot model, shielding production while the adversary's interaction is continuously harvested for intelligence. Existing defenses embed traps inside model memory or rebuild d...

Han Jin · 0 citations
Review Open access Aug 2026

An Integrated Honeypot and LLM-Based Framework for near Real-Time Detection and Behavioral Analysis of Malicious Activities

Integration of deterministic preprocessing with LLM-based reasoning enables the transformation of raw honeypot logs into structured and actionable cybersecurity intelligence, reducing analyst workload while improving the explainability and reliability of intrusion analysis in near-real-time environments.

Rúben Oliveira, Tiago Gomes, D. Pinho et al. · 0 citations
Review Open access Oct 2026

Prompt Injection Threats in Azure-Based Large Language Model Applications

Large language models (LLMs) hosted on Microsoft Azure, primarily through Azure OpenAI Service, are increasingly embedded in enterprise applications that combine user input, retrieved documents, web content, and tool-calling agents within a single prompt context. This architectural pattern, while powerful, collapses th...

Shekar Rao Lakavath · 0 citations

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.