Generative AI SSH Honeypot With Reinforcement Learning

Pragna Prasad, Nikhil Girish, V Sarasvathi, Apoorva Vh, Prem Kumar S · 2025

In today's rapidly evolving cyber landscape, traditional honeypots face significant limitations in their ability to adapt to sophisticated attack patterns and maintain convincing interactions with attackers. We propose Generative AI SSH Honeypot (GASH): an innovative approach to this problem combining Deep Reinforcement Learning (DRL) with Large Language Models (LLMs) to create a dynamic, engaging honeypot system. GASH employs a Deep Q-Network (DQN) architecture for strategic decision-making and leverages OpenAI’s GPT-4o for generating contextually appropriate responses while maintaining robust security measures. Our experimental results demonstrate improvements in attacker engagement duration compared to traditional honeypot systems like Kippo and Cowrie.

Read the paper · More papers on PaperTik