Sep 2026· International Journal of Information Security· Vol 25· 1 citation· 70 references
TL;DR
HIVE-AI, a 47,578-LoC honeypot framework deployed continuously on a single 4-vCPU/4-GB Virtual Private Server since 6 April 2026, is presented, a promising low-cost alternative rather than a full substitute for open-source honeypot frameworks.
Abstract
Public Large Language Model (LLM) APIs draw attacker traffic that defenders cannot see. Probes hit at the semantic layer—past TLS, past Web Application Firewall rules—and conventional intrusion detection picks up almost none of it. No open-source honeypot framework today captures this traffic at scale, and the few LLM-honeypot prototypes that exist push captured logs straight into a downstream LLM analyzer, exposing the analysis pipeline to indirect prompt injection through attacker-controlled inputs. We address both gaps with HIVE-AI, a 47,578-LoC honeypot framework deployed continuously on a single 4-vCPU/4-GB Virtual Private Server since 6 April 2026. Five protocol-faithful facades feed an eight-stage classification cascade with sub-5-ms p99 synchronous latency. The LLM threat-hunter is protected by a five-layer defense-in-depth architecture against indirect prompt injection, characterized theoretically and through operational field evidence; controlled per-layer validation is deferred to a follow-up deployment. We report these findings as a single-site, single-window case study: twenty days of operation captured 16,683 attacks from 1229 unique source IPs across 50 countries. The triangulation defense reduces mean adversarial evasion from 54.8 to 9.3% (paired test, p<0.001\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$p<0.001$$\end{document}). Blind human validation on 100 events yields Cohen’s κ=0.74\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\kappa = 0.74$$\end{document} between the LLM and analyst majority—statistically indistinguishable from human-on-human κ=0.71\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\kappa = 0.71$$\end{document}. A local Ollama+Qwen2.5–1.5B backend reproduces the cloud severity verdict on 71% of events (κ=0.59\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\kappa = 0.59$$\end{document}, moderate agreement), a promising low-cost alternative rather than a full substitute. Code and dataset are released under MIT License and CC BY 4.0; the source code is archived at Zenodo HIVE-AI: A Honeypot Source Code (https://doi.org/10.5281/zenodo.19853664) and the live attack map at https://honeypot.ttpsec.cl:4443/livemap.
The method, ECCOLA, is presented, which aims at making the high-level AI ethics principles more practical, making it possible for developers to more easily implement them in practice.
Ville Vakkuri, Kai-Kristian Kemell, P. Abrahamsson· EUROMICRO Conference on Soft...· 64 citations· ⚡6
The goal is to not only refine the accuracy of the LLM-based tool but also to underscore its potential in streamlining the software development lifecycle through proactive code improvement and education.
Z. Rasheed, Malik Abdul Sami, Muhammad Waseem et al.· arXiv.org· 62 citations· ⚡3
A comprehensive overview of how enhanced sampling methods are reshaping the field, with a particular focus on the data-driven construction of collective variables, is provided.
Kai Zhu, Enrico Trizio, Jintu Zhang et al.· Chemical Reviews· 58 citations
The use of large language models to automatically improve the user story quality in Austrian Post Group IT agile teams is explored, with a reference model for an Autonomous LLM-based Agent System developed and implemented at the company.
Zheying Zhang, M. Rayhan, Tomas Herda et al.· International Conference on...· 48 citations· ⚡4
This paper introduces a novel multi-AI-agent system designed to fully automate SLRs, and demonstrates how it substantially reduces the time and effort traditionally required for SLRs while maintaining comprehensiveness and precision.
Abdul Malik Sami, Z. Rasheed, Kai-Kristian Kemell et al.· arXiv.org· 44 citations· ⚡2
The proposed LLM-based multi-agent system automates qualitative data analysis process, creating opportunities for researchers and practitioners, and future improvements focus on enhancing multilingual performance and integrating continuous expert feedback.
Z. Rasheed, Muhammad Waseem, Aakash Ahmad et al.· arXiv.org· 41 citations
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduOct 1, 2026
With $2.1 million funding from Google.org, the open-source Public Transit Intelligence Hub will unify public transit monitoring, operations, and passenger communication.
Able to defeat top-ranked human players and more efficient than other models, the new system could help decision-makers in military maneuvers or business negotiations.
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.