Skip to content

Reinforcement Learning Meets LLM Honeypots: A MITRE Engage-Aligned Approach

2026 · IEEE Transactions on Network and Service Management · Vol 23, pp. 7674-7689 · 0 citations · 21 references

Abstract

The growing sophistication of cyberattacks, accelerated by large language models (LLMs), highlights the limitations of traditional honeypots, which often lack realism, require heavy maintenance, and rely on static deception strategies. Recent LLM-based honeypots generate fluent, context-aware responses but cannot adapt to evolving attacker behavior, limiting long-term effectiveness. This work presents an adaptive honeypot that integrates reinforcement learning (RL) with LLM-generated deception, aligning state, reward, and action spaces with the MITRE ATT&CK and MITRE Engage frameworks. A fine-tuned LLM infers attacker tactics, techniques, and procedures (TTPs) from live command sequences, providing semantically rich states for the RL agent, which then selects context-sensitive actions from Engage’s Affect strategies to guide adversaries toward deeper and higher-value engagement. Evaluated on Linux and Windows testbeds, the system achieved a 23% increase in cumulative engagement reward on Windows over a non-RL baseline ( $p\lt 0.001$ ). Ablation over five random seeds shows that replacing the learned policy with random action selection over the same action space collapses attack depth from 9.52 to 4.25 on Linux ( $p\lt 0.001$ ), confirming that the learned policy, not the action space alone, drives engagement. Intent analysis accuracy improved by 55 percentage points relative to a rule-based baseline (Wazuh), and LLM-generated responses fell within 10 percentage points of a real system, a substantially smaller gap than Cowrie, an ordering confirmed by an independent cross-family judge. These results demonstrate that RL-driven adaptation, combined with LLM realism and standardized engagement frameworks, enables honeypots that sustain realistic, intelligence-rich interactions and enhance threat analysis without compromising system safety.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.