Improving LLM-Based SSH Honeypots Through Prompting and Fine-Tuning

📅 2026-08-19
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
论文研究通过提示设计和监督微调改进本地LLM SSH蜜罐的壳模拟准确性,解决云模型部署问题及本地模型性能差的问题。
📝 Abstract
LLM-based SSH honeypots often use closed cloud LLMs because they give strong shell realism, but cloud models create deployment problems. These include no stable versioning, provider-side changes, attacker-driven cost, and model decommissioning. Local open-weight models avoid these problems, but they usually perform worse and make mistakes that reveal the honeypot. These mistakes include malformed outputs, command echoing, inconsistent filesystem state, and AI-style artifacts. This paper studies how to improve and evaluate the shell emulation accuracy of local LLM-based SSH honeypots using prompt design and supervised fine-tuning. We fine-tune and evaluate eight models in total: the original fine-tuned GPT-3.5 model used in shelLM and seven open-weight local models, each compared to its base model. We also test how prompt structure transfers across model families. Using 34 automated unit tests that measure shell emulation accuracy in single-session and fresh-session settings, we find that prompt design has a large effect and that fine-tuning depends on dataset coverage. Fine-tuning on the original 112-conversation dataset does not improve aggregate pass rate, while an expanded dataset built from honeypot logs produces clearly stronger local models. Taken together, the results suggest that prompting and fine-tuning can each improve local LLM honeypots on their own, but their effects do not combine straightforwardly, since strong rule-based prompting and supervised adaptation can also conflict by addressing overlapping shell-behavior constraints.
Problem

Research questions and friction points this paper is trying to address.

LLM-based SSH honeypots
shell emulation accuracy
local models
fine-tuning
prompt design
Innovation

Methods, ideas, or system contributions that make the work stand out.

prompt design
supervised fine-tuning
local LLM-based SSH honeypots
dataset coverage
shell emulation accuracy
💼 Related Jobs
No related jobs found.
M
Muris Sladić
Faculty of Electrical Engineering, Czech Technical University in Prague, Czechia
Veronica Valeros
Veronica Valeros
Czech Technical University in Prague
cybersecuritycyber deceptionintelligence analysishoneypotsagentic AI
E
Eman Alibalić
Faculty of Electrical Engineering, Czech Technical University in Prague, Czechia
Sebastian Garcia
Sebastian Garcia
Researcher in Czech Technical University in Prague [CTU, FEE]. PhD.
Network SecurityMachine LearningBotnetsAnomaly DetectionCyberSecurity