Automated WAF Rule Generation from Adversarial Prompt Pattern Mining for Perimeter-Level Protection of LLM Applications

This work proposes an adversarial prompt pattern mining methodology for the automated generation of Web Application Firewall (WAF) detection rules for the perimeter-level inspection of requests to Large Language Model (LLM) applications. The proposed methodology extracts linguistic patterns from an adversarial prompt corpus using sequential n-gram analysis, TF–IDF weighting, normalized frequency, and Interest Factor (IF) metrics. The resulting patterns are prioritized through a configurable scoring function and automatically transformed into ModSecurity-compatible rules capable of inspecting HTTP request bodies before prompts reach the protected LLM service. The generated rules are experimentally evaluated using 299,970 AI-generated adversarial test prompts and 10,000 benign user prompts across three symmetric weighting scenarios, each emphasizing one prioritization metric, and three rule-set sizes. The experimental results show that the proposed methodology achieves a maximum recall of 59.8% with 60k rules. No false positives are observed in the evaluated benign set. The best detection performance is obtained when a normalized frequency receives the highest weighting during pattern prioritization. The mean ModSecurity p2 processing time increased from 1.474 ms with 200 rules to 19.902 ms with 60k rules, indicating the expected trade-off between detection coverage and request-body inspection overhead as the rule base expands. Overall, recurrent adversarial prompt patterns can be automatically transformed into deployable WAF rules that operate as an additional perimeter-level security layer for LLM applications, complementing model-level safety mechanisms without requiring modifications to the underlying LLM.

Authors

Institutions

Publication Details

Journal
Electronics
Published
2026-09-25
DOI
https://doi.org/10.3390/electronics15194416
Primary Topic
Web Application Security Vulnerabilities
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Automated WAF Rule Generation from Adversarial Prompt Pattern Mining for Perimeter-Level Protection of LLM Applications

Hernán Barba Molina, Manuel L. B. Martinez, Aldrin Reyes Narváez, Jessica Bracero Puente
Electronics
Web Application Security Vulnerabilities
article

Automated WAF Rule Generation from Adversarial Prompt Pattern Mining for Perimeter-Level Protection of LLM Applications

Hernán Barba Molina, Manuel L. B. Martinez, Aldrin Reyes Narváez, Jessica Bracero Puente
article en

Abstract

This work proposes an adversarial prompt pattern mining methodology for the automated generation of Web Application Firewall (WAF) detection rules for the perimeter-level inspection of requests to Large Language Model (LLM) applications. The proposed methodology extracts linguistic patterns from an adversarial prompt corpus using sequential n-gram analysis, TF–IDF weighting, normalized frequency, and Interest Factor (IF) metrics. The resulting patterns are prioritized through a configurable scoring function and automatically transformed into ModSecurity-compatible rules capable of inspecting HTTP request bodies before prompts reach the protected LLM service. The generated rules are experimentally evaluated using 299,970 AI-generated adversarial test prompts and 10,000 benign user prompts across three symmetric weighting scenarios, each emphasizing one prioritization metric, and three rule-set sizes. The experimental results show that the proposed methodology achieves a maximum recall of 59.8% with 60k rules. No false positives are observed in the evaluated benign set. The best detection performance is obtained when a normalized frequency receives the highest weighting during pattern prioritization. The mean ModSecurity p2 processing time increased from 1.474 ms with 200 rules to 19.902 ms with 60k rules, indicating the expected trade-off between detection coverage and request-body inspection overhead as the rule base expands. Overall, recurrent adversarial prompt patterns can be automatically transformed into deployable WAF rules that operate as an additional perimeter-level security layer for LLM applications, complementing model-level safety mechanisms without requiring modifications to the underlying LLM.

ElectronicsVol. 15(19)
National Polytechnic School (EC)
Peace, Justice and strong institutions
Openalex Percentile: Top 4%
Web Application Security Vulnerabilities
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Automated WAF Rule Generation from Adversarial Prompt Pattern Mining for Perimeter-Level Protection of LLM Applications — Hernán Barba Molina, Manuel L. B. Martinez, et al. · Electronics (2026) | TGRS Research Map | TGRS