Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

NetInspector: Measuring and Improving LLM Capabilities for Reliable Intent-Based Networking Policy Generation

A three-layer agentic framework that grounds LLM reasoning in verifiable network facts to reduce false negatives in intent-based policy verification
Yuxuan Zhang; Hongxin Hu; Guofei Guยท 2026ยท DOI 10.48550/arXiv.2609.21103

The core problem

Modern networks are characterized by large scale and heterogeneous configurations, rendering manual policy management increasingly impractical. Intent-Based Networking (IBN) emerges as a solution by automating the translation of high-level operator goals into low-level network configurations. However, existing IBN systems rely on static heuristics and fixed-feature classifiers that generalize poorly to distribution shifts such as new service definitions or evolving phrasing in operator requests. Large Language Models (LLMs), with strong reasoning and translation capabilities demonstrated across many domains, are a natural candidate for IBN policy generation. Yet, it remains unclear whether LLMs can be reliably applied to this task, nor whether their use mitigates or worsens underlying security risks. This work investigates these questions, revealing that while fine-tuned LLMs excel at intent translation, they exhibit false negative rates when checking whether a proposed intent violates an existing security policy. The root cause is not a lack of logical reasoning capability, but LLMs' lack of persistent grounding in network topology and group hierarchy. Motivated by this finding, t

Innovation

The authors evaluate NetInspector on NetInspector-Bench, a 2,224-sample synthetic benchmark spanning campus, enterprise, and WAN topologies. The benchmark includes diverse intents and security policies to test the framework's robustness. Key findings include:

- **False Negative Rate (FNR) Reduction**: NetInspector reduces FNR by over 30% relative to ungrounded baselines. This demonstrates the effectiveness of grounding LLM reasoning in verifiable network facts.
- **Robustness to Distribution Shifts**: The framework remains robust under linguistic distribution shifts, such as new service definitions or evolving phrasing in operator requests. This is critical for real-world deployment where intents may vary.
- **Comparison with Baselines**: Ungrounded LLMs, even when fine-tuned, exhibit higher FNRs due to lack of persistent grounding. NetInspector's decoupled architecture addresses this by ensuring every decision is based on live network facts.

Quantitatively, if the baseline FNR is , NetInspector achieves

. The reduction is consistent across different topologies and intent types.

Modern networks are characterized by large scale and heterogeneous configurations, rendering manual policy management increasingly impractical. Intent-Based Networking (IBN) emerges as a solution by automating the translation of high-level operator goals into low-level network configurations. However, existing IBN systems rely on static heuristics and fixed-feature classifiers that generalize poorly to distribution shifts such as new service definitions or evolving phrasing in operator requests. Large Language Models (LLMs), with strong reasoning and translation capabilities demonstrated across many domains, are a natural candidate for IBN policy generation. Yet, it remains unclear whether LLMs can be reliably applied to this task, nor whether their use mitigates or worsens underlying security risks. This work investigates these questions, revealing that while fine-tuned LLMs excel at intent translation, they exhibit false negative rates when checking whether a proposed intent violates an existing security policy. The root cause is not a lack of logical reasoning capability, but LLMs' lack of persistent grounding in network topology and group hierarchy. Motivated by this finding, the authors introduce NetInspector, a three-layer agentic framework that enforces a verify-then-act protocol, decoupling information retrieval from reasoning so that the LLM focuses on symbolic reasoning while every policy decision is grounded in verifiable network facts retrieved from a live Environment Layer before approval.
NetInspector is a three-layer agentic framework designed to enforce a verify-then-act protocol. The architecture comprises:

Why it matters

The root cause of LLM false negatives in intent-based policy verification is not a lack of logical reasoning capability, but rather a lack of persistent grounding in network topology and group hierarchy. LLMs, when fine-tuned, can translate intents effectively but fail to verify them against existing security policies because they lack access to up-to-date network facts. NetInspector addresses this by decoupling information retrieval from reasoning, allowing the LLM to focus on symbolic reasoning while the Retrieval Layer fetches relevant facts from the Environment Layer.

This approach has several implications:

- **Security**: By grounding decisions in verifiable facts, NetInspector mitigates the risk of policy violations that could arise from ungrounded LLM decisions. This is crucial for maintaining network security.
- **Scalability**: The framework can handle large-scale networks with heterogeneous configurations, as the Environment Layer maintains a live representation that can be queried efficiently.
- **Generalization**: The decoupled architecture generalizes better to distribution shifts, as the LLM's reasoning is not tied to specific phrasings or service definitions.

However, challenges remain, such as maintaining the Environment Layer's accuracy and ensuring low-latency retrieval. Future work could explore integrating real-time network monitoring and adaptive retrieval strategies.

In summary, NetInspector demonstrates that LLMs can be reliably applied to IBN policy generation when their reasoning is grounded in verifiable network facts, reducing false negatives and enhancing security.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ