Just Testing, Move Along: Evasion of LLM-based System Log Interpretation by Prompt Injection
Max Landauer, Florian Skopik, Markus Wurzenberger, Franciszek Górski, Mateusz Krzysztoń
cs.CR
Submitted: 2026-07-27
Code: https://github.com/ait-aecid/log-interpretation-prompt-injection
License: http://creativecommons.org/licenses/by-nc-sa/4.0/
The gist: Large Language Models (LLMs) are increasingly integrated into Security Operations Center (SOC) workflows, where they support analysts in tasks such as the interpretation of system logs.
Terminology
Abstract
Large Language Models (LLMs) are increasingly integrated into Security Operations Center (SOC) workflows, where they support analysts in tasks such as the interpretation of system logs. However, the ability of LLMs to directly process untrusted textual input also introduces new attack surfaces. In particular, attackers can inject contextual information or explicit instructions into log entries in order to influence how malicious activity is interpreted by the model. Despite the growing adoption of LLMs for log analytics, the robustness of such systems against adversarial log injection remains largely unexplored. To address this gap, this paper presents a framework for evaluating prompt injection attacks against LLM-based log interpretation. Using log traces generated during real cyber attacks, our approach creates adversarial examples through generic injection generation, refinement, and attack-specific optimization. Our evaluation across multiple state-of-the-art LLMs shows that these injections can cause malicious log traces to be classified as benign despite containing clear indicators of compromise. As a potential remedy, we show that the explanations generated by the LLMs alongside their classifications frequently contain indicators of adversarial manipulation that can be leveraged to detect such attacks.
Sources
- System Log Parsing with Large Language Models: A Review
- On Evaluating Adversarial Robustness
- A Systematic Literature Review on LLM Defenses Against Prompt Injection and Jailbreaking: Expanding NIST Taxonomy
- OntoLogX: Ontology-Guided Knowledge Graph Extraction from Cybersecurity Logs with Large Language Models
- Large Language Models for Security Operations Centers: A Comprehensive Survey
- CAM-LDS: Cyber Attack Manifestations for Automatic Interpretation of System Logs and Security Alerts
- Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks
- LLMs in the SOC: An Empirical Study of Human-AI Collaboration in Security Operations Centres
- Adversarial Robustness for Machine Learning Cyber Defenses Using Log Data
- Evaluating Language Models For Threat Detection in IoT Security Logs
- The Landscape of Prompt Injection Threats in LLM Agents: From Taxonomy to Analysis
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs