GenPot is presented, a fine-tuned LLM-powered honeypot that integrates command-line, API, and dynamic web interaction to deliver realistic yet non-compromisable environments and is validated through a 14-day in-the-wild deployment and a human-in-the-loop credibility assessment.
Abstract
Honeypots are widely used as cyber-deception tools to study adversarial behaviour, yet their effectiveness is limited by a trade-off between realism and security risk. Low-interaction honeypots are easily detected, while high-interaction honeypots provide realistic data at the cost of network exposure. Recent advances suggest that Large Language Models (LLMs) can mitigate this trade-off by dynamically generating convincing outputs without requiring a vulnerable backend. In this paper, we present GenPot, a fine-tuned LLM-powered honeypot that integrates command-line, API, and dynamic web interaction to deliver realistic yet non-compromisable environments. Our approach combines supervised fine-tuning with prompt engineering, cybersecurity safeguards, and state management to simulate consistent and realistic system responses. As a proof-of-concept use case, we implement the system on top of an OpenCanary baseline simulating a Synology NAS device. To rigorously assess the framework, we conducted an exhaustive multi-dimensional evaluation encompassing deep semantic fidelity, inference latency, high-concurrency scalability, and operational energy efficiency (RPS/W). Technical results demonstrate that the optimized architecture sustains over 1,000 requests per second with near-perfect structural validity, while token-level guardrails ensure high resilience against prompt injection attacks. Crucially, we validate the system’s practical deception efficacy through a 14-day in-the-wild deployment and a human-in-the-loop credibility assessment, where experts were unable to distinguish the honeypot from a physical device (45% accuracy). Furthermore, the framework’s generalizability is proven via a rapid adaptation to a medical Fast Healthcare Interoperability Resources (FHIR) API. This work advances the current state of LLM-powered honeypots by demonstrating a reproducible, highly scalable, energy-aware, and credible approach for adaptive cyber deception.
HIVE-AI, a 47,578-LoC honeypot framework deployed continuously on a single 4-vCPU/4-GB Virtual Private Server since 6 April 2026, is presented, a promising low-cost alternative rather than a full substitute for open-source honeypot frameworks.
Sebastián Vargas Yáñez, Sergio Tobón· International Journal of Inf...· 1 citation
A honeypot is a decoy computer system that is intentionally deployed to attract cyber attackers and gather threat intelligence in a controlled environment. However, honeypot frameworks like the popularly used Cowrie SSH honeypot completely rely on static responses that do not change based on the attacker’s behavior. Th...
Dhikshanya K, S. Saravanan· 2026 International Conferenc...· 0 citations
This work presents a systematic study of honeypot-aware budget allocation for LLM attack agents and shows that with the proposed detector-guided policy, LLM agent attackers can effectively allocate budget to compromise hosts in a host pool, highlighting the importance of dynamically allocating budget in a controlled mi...
Xin-Hong Xie, Piyush Nagasubramaniam, Neeraj Karamchandani et al.· 0 citations
We introduce HoneyRoute, an inference-serving layer that detects whether an incoming request is malicious and, if so, routes it to a dedicated honeypot model, shielding production while the adversary's interaction is continuously harvested for intelligence. Existing defenses embed traps inside model memory or rebuild d...
Integration of deterministic preprocessing with LLM-based reasoning enables the transformation of raw honeypot logs into structured and actionable cybersecurity intelligence, reducing analyst workload while improving the explainability and reliability of intrusion analysis in near-real-time environments.
Rúben Oliveira, Tiago Gomes, D. Pinho et al.· Journal of Cybersecurity and...· 0 citations
Publicly exposed large language model (LLM) infrastructure creates a growing attack surface, yet real-world targeting remains poorly understood. We present Ollure, a low- and medium-interaction honeypot that emulates the Ollama API without a backend LLM. Spanning four deployments across cloud and university networks, O...