Skip to content
Open access

AI-Driven Honeypot: An Innovative Approach to Adaptive Cyber Security Defense

Jul 2026 · Latin American Journal of Computing · 0 citations · 23 references

TL;DR

Overall, this study demonstrates that the integration of AI within traditional honeypot strategies can significantly enhance cyber defense systems.

Abstract

As cyber threats continue to grow in sophistication, the need for intelligent and adaptive defense mechanisms becomes increasingly more critical. This research investigates the integration of Artificial Intelligence (AI) into a honeypot system to distract, mislead through deception, and engage potential cyber attackers. The primary research question to answer was: “How can AI-driven adaptive deception improve the effectiveness of honeypots in cybersecurity?” To address this, a high-interaction honeypot was developed on a HTML website to be perceived as a reverse shell, with the implementation of OpenAI’s GPT-4o model to respond, impersonating a Linux terminal, while silently tracking and logging the attacker, and classifying all commands into three sub-categories – Safe, Suspicious and Malicious. The core methods included command logging, AI-driven risk classification, dynamic fake filesystem manipulation, and the escalation of behavior based on the attacker's actions. Attack simulations were performed by highly credible third-party cybersecurity experts to evaluate the honeypots effectiveness in engaging and tracking the attacker for as long as possible. The findings suggest that AI integration significantly improved the realism and engagement level of the honeypot, both in terms of enhancing intelligence gathering and the improvements from traditional static honeypots. However, full automation of behavioral escalation tuning remains an area to further explore. Overall, this study demonstrates that the integration of AI within traditional honeypot strategies can significantly enhance cyber defense systems.

Read PDF

Similar papers

Open access Aug 2026

Explainability-driven adaptive cyber deception control system for autonomous network defense

The presented framework manages to incorporate explainable scoring, convergence of behavior analysis, adaptive control, environment mutation, and reinforcement learning into one cyber deception framework and manages to incorporate all of these features while still preserving transparency and adaptability during the whole process of deception.

S. Roy, G. Khekare, Sejal Chhajed · 0 citations
Open access Aug 2026

AI-Driven Cybercrime and Autonomous Malware: Technological Threats, Legal Challenges and the Need for a New Cybersecurity Framework

rtificial intelligence (AI) is transforming the cyber threat landscape by enabling malware and cyber operations that are adaptive, autonomous and scalable in ways that traditional tools could not achieve. AI-driven cybercrime and autonomous malware can dynamically modify their behaviour, choose attack paths, and evade detection without continuous human supervision, thereby challenging existing technical defenses and legal frameworks that were designed around static code and human-controlled attacks. This paper argues that the convergence of AI and cybercrime requires a recalibration of international and domestic cybersecurity law, including clearer liability standards for AI-enabled offences, updated treaty frameworks, and the development of a risk-based, technology-neutral cybersecurity architecture capable of addressing autonomous threats.

M. Pandey, Madhawa Srivastava, Mahesh Choudhary et al. · 0 citations
Review Open access Aug 2026

Artificial Intelligence and Cyber Defense: Navigating Emerging Threats in an Interconnected World

Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat intelligence platforms, and automated incident response tools, enabling organizations to identify and neutralize threats with greater speed and precision. However, the same interconnectedness that drives digital transformation—spanning IoT ecosystems, cloud infrastructures, and 5G networks—has also expanded the attack surface available to malicious actors, giving rise to increasingly sophisticated, adaptive, and often AI-enabled threats such as adversarial machine learning attacks, deepfake-driven social engineering, and automated supply chain exploits. This paper examines the dual role of AI as both a defensive asset and a potential vector of risk within modern cybersecurity ecosystems. Drawing on a review of existing AI-driven security solutions, comparative analysis of AI-based versus traditional defense mechanisms, and case study evaluation, the study assesses the effectiveness, limitations, and ethical implications of AI integration in cyber defense. Findings indicate that while AI substantially improves threat detection accuracy and response times, challenges related to explainability, adversarial vulnerability, and regulatory oversight remain significant barriers to widespread adoption. The paper concludes with practical recommendations for organizations and policymakers seeking to harness AI's defensive potential while mitigating its associated risks, emphasizing the need for explainable AI frameworks, human-AI collaboration, and adaptive governance structures in an increasingly interconnected digital age.

Nicolas Guzman Camacho · 0 citations
Open access Jul 2026

A Deception-Based Intrusion Prevention Framework for Proactive Network Security Using Behavioral Threat Analysis

Experimental evaluation conducted in a controlled network environment demonstrates that the proposed Deceptive Intrusion Prevention System improves detection accuracy, reduces false positives, and enhances overall system resilience.

Priyanka Tuppad, Vinit Kumar Shukla · 0 citations
Conference Jul 2026

Chameleon: A Deception Defense Strategy Against LLM-Assisted Attacker in New Power Systems

As new power systems become increasingly dependent on cloud-supported cyber-physical systems, their openness and interconnectivity continue to increase, thereby exposing risk points for advanced persistent threats (APTs). Deception defense has been widely regarded as an effective proactive approach for mitigating APT threats. However, the remarkable reasoning capabilities of large language models (LLMs) have enabled APT attackers to leverage LLM-based semantic understanding and task-planning capabilities to conduct automated, intelligent penetration attacks, while also bringing new challenges for traditional deception defense mechanisms. To address this issue, we propose a Chameleon service mechanism that constructs multiple types of LLM-oriented deceptive services based on the shared characteristics that LLMs exhibit during environment reconnaissance and target screening, and further incorporates an attack-defense game model with Minimax Q-learning for deployment. In this way, the proposed method increases the likelihood of trapping attackers while minimizing interference with normal power operations. The experimental results show that the proposed Chameleon service mechanism can effectively enhance the trapping effect of deceptive services on LLM-assisted attackers and demonstrate good effectiveness and stability across different candidate scales and LLM evaluation conditions. Our method can provide a feasible solution for proactive deception defense against intelligent attackers in new power systems.

Ying Yao, Yiji Lin, Qinglin Yang et al. · 0 citations