ShellBox: Adversarially Enhanced LLM-Interactive Honeypot Framework

Guan Yang, Zhengzheng Sun, Yu Wang · IEEE Access · 2025

Honeypot technology is an active defence strategy designed to mitigate the asymmetry inherent in network attacks and defence dynamics. In recent years, honeypot systems powered by large language models (LLMs) have become a focal point of research owing to their ability to simulate complex network environments and generate highly deceptive virtual assets. However, response inconsistency in multi-turn dialogues and prompt injection vulnerabilities inherent to LLMs significantly reduce the deceptive capability of honeypots. This study first defines the threat model, and then introduces a relevance-based interaction history pruning algorithm and dynamic error simulation strategy to mitigate these challenges. Considering practical issues such as response latency and network instability, our experiments were conducted using multiple locally deployed open-source LLMs. The experimental results demonstrated that the proposed dynamic error simulation mechanism achieved a maximum accuracy of 81.63% for the DeepSeek-R1 model. Furthermore, applying the interaction history pruning algorithm improved the turn-level coherence score (TCS) by 34.5% compared with the baseline. Finally, this paper outlines potential future research directions for LLM-based honeypot technologies in active multi-turn mechanisms.

Read the paper · More papers on PaperTik