NetInspector: Measuring and Improving LLM Capabilities for Reliable Intent-Based Networking Policy Generation

📅 2026-09-17
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
为解决IBN系统中LLM生成网络策略的可靠性问题,提出NetInspector框架,通过分离信息检索与推理提高准确性。
📝 Abstract
Modern networks are large in scale and heterogeneous in configuration, making manual policy management increasingly impractical. Intent-Based Networking (IBN) addresses this by automating the translation of high-level operator goals into low-level network configurations. Yet existing IBN systems rely on static heuristics and fixed-feature classifiers that generalize poorly to distribution shifts such as new service definitions or evolving phrasing in operator requests. Large Language Models (LLMs), with strong reasoning and translation capabilities demonstrated across many domains, are a natural candidate for IBN policy generation. However, it is unclear whether LLMs can be reliably applied to this task, nor whether their use mitigates or worsens the underlying security risk. In this work, we show that while fine-tuned LLMs excel at intent translation, they exhibit false negative rates when checking whether a proposed intent violates an existing security policy. The root cause is not a lack of logical reasoning capability, but LLMs lack of persistent grounding in network topology and group hierarchy. Motivated by this finding, we introduce NetInspector, a three-layer agentic framework that enforces a verify-then-act protocol, decoupling information retrieval from reasoning so that the LLM focuses on symbolic reasoning while every policy decision is grounded in verifiable network facts retrieved from a live Environment Layer before approval. On NetInspector-Bench, a 2,224-sample synthetic benchmark spanning campus, enterprise, and WAN topologies, NetInspector reduces FNR by over 30\% relative to ungrounded baselines and remains robust under linguistic distribution shifts.
Problem

Research questions and friction points this paper is trying to address.

Intent-Based Networking
Large Language Models
Security Policy
Network Topology
Symbolic Reasoning
Innovation

Methods, ideas, or system contributions that make the work stand out.

Intent-Based Networking
Large Language Models
Network Topology
Persistent Grounding
Verify-Then-Act Protocol
🔎 Similar Papers
No similar papers found.