Skip to content
Open access

GenPot: A generative honeypot architecture for adaptive web and API interaction

Sep 2026 · Applied intelligence (Boston) · Vol 56 · 0 citations · 30 references

TL;DR

GenPot is presented, a fine-tuned LLM-powered honeypot that integrates command-line, API, and dynamic web interaction to deliver realistic yet non-compromisable environments and is validated through a 14-day in-the-wild deployment and a human-in-the-loop credibility assessment.

Abstract

Honeypots are widely used as cyber-deception tools to study adversarial behaviour, yet their effectiveness is limited by a trade-off between realism and security risk. Low-interaction honeypots are easily detected, while high-interaction honeypots provide realistic data at the cost of network exposure. Recent advances suggest that Large Language Models (LLMs) can mitigate this trade-off by dynamically generating convincing outputs without requiring a vulnerable backend. In this paper, we present GenPot, a fine-tuned LLM-powered honeypot that integrates command-line, API, and dynamic web interaction to deliver realistic yet non-compromisable environments. Our approach combines supervised fine-tuning with prompt engineering, cybersecurity safeguards, and state management to simulate consistent and realistic system responses. As a proof-of-concept use case, we implement the system on top of an OpenCanary baseline simulating a Synology NAS device. To rigorously assess the framework, we conducted an exhaustive multi-dimensional evaluation encompassing deep semantic fidelity, inference latency, high-concurrency scalability, and operational energy efficiency (RPS/W). Technical results demonstrate that the optimized architecture sustains over 1,000 requests per second with near-perfect structural validity, while token-level guardrails ensure high resilience against prompt injection attacks. Crucially, we validate the system’s practical deception efficacy through a 14-day in-the-wild deployment and a human-in-the-loop credibility assessment, where experts were unable to distinguish the honeypot from a physical device (45% accuracy). Furthermore, the framework’s generalizability is proven via a rapid adaptation to a medical Fast Healthcare Interoperability Resources (FHIR) API. This work advances the current state of LLM-powered honeypots by demonstrating a reproducible, highly scalable, energy-aware, and credible approach for adaptive cyber deception.

Read PDF

Similar papers

#generative ai Open access Sep 2026

Hive-AI: a defended multi-service honeypot framework for generative AI APIs

HIVE-AI, a 47,578-LoC honeypot framework deployed continuously on a single 4-vCPU/4-GB Virtual Private Server since 6 April 2026, is presented, a promising low-cost alternative rather than a full substitute for open-source honeypot frameworks.

Sebastián Vargas Yáñez, Sergio Tobón · 1 citation
Conference Aug 2026

Cloud-Deployed Adaptive SSH Honeypot with Reinforcement Learning and LLM-based Dynamic Response Generation

A honeypot is a decoy computer system that is intentionally deployed to attract cyber attackers and gather threat intelligence in a controlled environment. However, honeypot frameworks like the popularly used Cowrie SSH honeypot completely rely on static responses that do not change based on the attacker’s behavior. Th...

Dhikshanya K, S. Saravanan · 0 citations
Preprint Sep 2026

LLM-Based Penetration Testing in the Presence of Honeypots

This work presents a systematic study of honeypot-aware budget allocation for LLM attack agents and shows that with the proposed detector-guided policy, LLM agent attackers can effectively allocate budget to compromise hosts in a host pool, highlighting the importance of dynamically allocating budget in a controlled mi...

Xin-Hong Xie, Piyush Nagasubramaniam, Neeraj Karamchandani et al. · 0 citations
#machine learning Preprint Sep 2026

HoneyRoute: Honeypot-Model Routing for Adversarial LLM Serving

We introduce HoneyRoute, an inference-serving layer that detects whether an incoming request is malicious and, if so, routes it to a dedicated honeypot model, shielding production while the adversary's interaction is continuously harvested for intelligence. Existing defenses embed traps inside model memory or rebuild d...

Han Jin · 0 citations
Review Open access Aug 2026

An Integrated Honeypot and LLM-Based Framework for near Real-Time Detection and Behavioral Analysis of Malicious Activities

Integration of deterministic preprocessing with LLM-based reasoning enables the transformation of raw honeypot logs into structured and actionable cybersecurity intelligence, reducing analyst workload while improving the explainability and reliability of intrusion analysis in near-real-time environments.

Rúben Oliveira, Tiago Gomes, D. Pinho et al. · 0 citations
Preprint Sep 2026

OllamaDrama: Designing and Deploying a Honeypot to Measure Attacks on Exposed LLM Infrastructure

Publicly exposed large language model (LLM) infrastructure creates a growing attack surface, yet real-world targeting remains poorly understood. We present Ollure, a low- and medium-interaction honeypot that emulates the Ollama API without a backend LLM. Spanning four deployments across cloud and university networks, O...

Karina Elzer, Niklas Netterstrøm Johansen, Emmanouil Vasilomanolakis · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.