Skip to content
Open access

GenPot: A generative honeypot architecture for adaptive web and API interaction

Sep 2026 · Applied intelligence (Boston) · Vol 56 · 0 citations · 30 references

Abstract

Honeypots are widely used as cyber-deception tools to study adversarial behaviour, yet their effectiveness is limited by a trade-off between realism and security risk. Low-interaction honeypots are easily detected, while high-interaction honeypots provide realistic data at the cost of network exposure. Recent advances suggest that Large Language Models (LLMs) can mitigate this trade-off by dynamically generating convincing outputs without requiring a vulnerable backend. In this paper, we present GenPot, a fine-tuned LLM-powered honeypot that integrates command-line, API, and dynamic web interaction to deliver realistic yet non-compromisable environments. Our approach combines supervised fine-tuning with prompt engineering, cybersecurity safeguards, and state management to simulate consistent and realistic system responses. As a proof-of-concept use case, we implement the system on top of an OpenCanary baseline simulating a Synology NAS device. To rigorously assess the framework, we conducted an exhaustive multi-dimensional evaluation encompassing deep semantic fidelity, inference latency, high-concurrency scalability, and operational energy efficiency (RPS/W). Technical results demonstrate that the optimized architecture sustains over 1,000 requests per second with near-perfect structural validity, while token-level guardrails ensure high resilience against prompt injection attacks. Crucially, we validate the system’s practical deception efficacy through a 14-day in-the-wild deployment and a human-in-the-loop credibility assessment, where experts were unable to distinguish the honeypot from a physical device (45% accuracy). Furthermore, the framework’s generalizability is proven via a rapid adaptation to a medical Fast Healthcare Interoperability Resources (FHIR) API. This work advances the current state of LLM-powered honeypots by demonstrating a reproducible, highly scalable, energy-aware, and credible approach for adaptive cyber deception.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.