LLM-Based Penetration Testing in the Presence of Honeypots

๐Ÿ“… 2026-09-08
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
็ ”็ฉถ้€š่ฟ‡ๆž„ๅปบ้ข„็ฎ—ๅ†ณ็ญ–ๆจกๅž‹๏ผŒๆŒ‡ๅฏผLLMๆ”ปๅ‡ปไปฃ็†ๅœจๅญ˜ๅœจ่œœ็ฝ็š„ๆƒ…ๅ†ตไธ‹ๆœ‰ๆ•ˆๅˆ†้…่ต„ๆบไปฅ่ฟ›่กŒๆธ—้€ๆต‹่ฏ•ใ€‚
๐Ÿ“ Abstract
Large language model (LLM) agents are increasingly employed for offensive cybersecurity tasks such as automated vulnerability discovery, reconnaissance, and penetration testing. This new capability also threatens one of the defender's most valuable tools: deception. Traditional honeypots rely on realism and obscurity to lure human or script-driven attackers into revealing tactics, techniques, and procedures (TTPs), but LLM-driven attackers can reason about heterogeneous artifacts and use the honeypot suspicion to guide target-selection decisions. We present a systematic study of honeypot-aware budget allocation for LLM attack agents. We formalize the attacker's problem as a budgeted decision process: an agent interacts with potential targets, consuming LLM execution budget during reconnaissance and exploitation, and must decide whether to (continue exploitation) or (skip) when honeypot suspicion arises. Our findings show that with the proposed detector-guided policy, LLM agent attackers can effectively allocate budget to compromise hosts in a host pool, highlighting the importance of dynamically allocating budget in a controlled mixed-host testbed. While defenses are beyond our present scope, we discuss implications for future adversarially resilient and adaptive honeypot design.
Problem

Research questions and friction points this paper is trying to address.

LLM
Penetration Testing
Honeypots
Budget Allocation
Innovation

Methods, ideas, or system contributions that make the work stand out.

LLM-based penetration testing
honeypot-aware budget allocation
budgeted decision process
detector-guided policy
๐Ÿ”Ž Similar Papers
No similar papers found.
X
Xinhong Xie
The Pennsylvania State University
P
Piyush Nagasubramaniam
The Pennsylvania State University
N
Neeraj Karamchandani
The Pennsylvania State University
Sencun Zhu
Sencun Zhu
Pennsylvania State University
Security and Privacy