Hive-AI: a defended multi-service honeypot framework for generative AI APIs
Unknown authors
Sep 2026· International Journal of Information Security· Vol 25· 0 citations· 70 references
TL;DR
HIVE-AI, a 47,578-LoC honeypot framework deployed continuously on a single 4-vCPU/4-GB Virtual Private Server since 6 April 2026, is presented, a promising low-cost alternative rather than a full substitute for open-source honeypot frameworks.
Abstract
Public Large Language Model (LLM) APIs draw attacker traffic that defenders cannot see. Probes hit at the semantic layer—past TLS, past Web Application Firewall rules—and conventional intrusion detection picks up almost none of it. No open-source honeypot framework today captures this traffic at scale, and the few LLM-honeypot prototypes that exist push captured logs straight into a downstream LLM analyzer, exposing the analysis pipeline to indirect prompt injection through attacker-controlled inputs. We address both gaps with HIVE-AI, a 47,578-LoC honeypot framework deployed continuously on a single 4-vCPU/4-GB Virtual Private Server since 6 April 2026. Five protocol-faithful facades feed an eight-stage classification cascade with sub-5-ms p99 synchronous latency. The LLM threat-hunter is protected by a five-layer defense-in-depth architecture against indirect prompt injection, characterized theoretically and through operational field evidence; controlled per-layer validation is deferred to a follow-up deployment. We report these findings as a single-site, single-window case study: twenty days of operation captured 16,683 attacks from 1229 unique source IPs across 50 countries. The triangulation defense reduces mean adversarial evasion from 54.8 to 9.3% (paired test, p<0.001\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$p<0.001$$\end{document}). Blind human validation on 100 events yields Cohen’s κ=0.74\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\kappa = 0.74$$\end{document} between the LLM and analyst majority—statistically indistinguishable from human-on-human κ=0.71\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\kappa = 0.71$$\end{document}. A local Ollama+Qwen2.5–1.5B backend reproduces the cloud severity verdict on 71% of events (κ=0.59\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\kappa = 0.59$$\end{document}, moderate agreement), a promising low-cost alternative rather than a full substitute. Code and dataset are released under MIT License and CC BY 4.0; the source code is archived at Zenodo HIVE-AI: A Honeypot Source Code (https://doi.org/10.5281/zenodo.19853664) and the live attack map at https://honeypot.ttpsec.cl:4443/livemap.
The method, ECCOLA, is presented, which aims at making the high-level AI ethics principles more practical, making it possible for developers to more easily implement them in practice.
Ville Vakkuri, Kai-Kristian Kemell, P. Abrahamsson· EUROMICRO Conference on Soft...· 64 citations· ⚡6
The goal is to not only refine the accuracy of the LLM-based tool but also to underscore its potential in streamlining the software development lifecycle through proactive code improvement and education.
Z. Rasheed, Malik Abdul Sami, Muhammad Waseem et al.· arXiv.org· 62 citations· ⚡3
A comprehensive overview of how enhanced sampling methods are reshaping the field, with a particular focus on the data-driven construction of collective variables, is provided.
Kai Zhu, Enrico Trizio, Jintu Zhang et al.· Chemical Reviews· 58 citations
The use of large language models to automatically improve the user story quality in Austrian Post Group IT agile teams is explored, with a reference model for an Autonomous LLM-based Agent System developed and implemented at the company.
Zheying Zhang, M. Rayhan, Tomas Herda et al.· International Conference on...· 48 citations· ⚡4
This paper introduces a novel multi-AI-agent system designed to fully automate SLRs, and demonstrates how it substantially reduces the time and effort traditionally required for SLRs while maintaining comprehensiveness and precision.
Abdul Malik Sami, Z. Rasheed, Kai-Kristian Kemell et al.· arXiv.org· 44 citations· ⚡2
The proposed LLM-based multi-agent system automates qualitative data analysis process, creating opportunities for researchers and practitioners, and future improvements focus on enhancing multilingual performance and integrating continuous expert feedback.
Z. Rasheed, Muhammad Waseem, Aakash Ahmad et al.· arXiv.org· 41 citations
AI is making software generation faster, but speed does not remove the need for expertise. As more work is delegated to AI, tacit knowledge may become one of the most important human advantages in software engineering. The post Beyond Prompt Engineering: The Role of Tacit Knowledge in Software Engineering appeared first on GPT-Lab.
MIT News · Artificial Intelligence· news.mit.eduSep 16, 2026