LLM Attacker Behavior and Designing Adaptive Honeypot Defences
Julius Wilhelm Amorim, Karl Viktor Lundin · KTH Publication Database DiVA (KTH Royal Institute of Technology) · 2026
A fast developing category of cyber attacks is the emergence of multi stage offensive tactics enabled by autonomous LLM agents, which can challenge traditional signature based cyber defence systems. Building defensive AI systems that are resilient to such attacks is constrained by a lack of empirical interaction data. In this work, this challenge is addressed by leveraging Project Violet, an adversarial simulation environment based on the Beelzebub honeypot infrastructure, to evaluate deception strategies designed to safely simulate autonomous cyber attackers. Adaptive in-loop defensive reconfiguration strategies are evaluated against static baselines in live adversarial simulations. Empirical findings indicate that adaptive deception alone does not substantially improve attacker engagement duration, detection rates or intelligence collection in the final matched comparison. These findings suggest that practical limitations in orchestration and operational overhead may outweigh the theoretical benefits of algorithmic adaptation. Ultimately, the work highlights the trade-offs between intelligence gain, system complexity and computational cost in the design of resilient AI assisted cyber defence systems.