P371: Honeypot-Aware LLM Agents
arXiv:2609.08093 · Xie Xinhong et al · “LLM-Based Penetration Testing in the Presence of Honeypots” · live #pattern-371
LLM agents increasingly run offensive cybersecurity tasks (vuln discovery, recon, pentest). That capability threatens deception: traditional honeypots rely on realism and obscurity against human or script attackers, but LLM-driven attackers can reason about heterogeneous artifacts and use honeypot suspicion to guide target selection. The paper studies honeypot-aware budget allocation for LLM attack agents as a budgeted decision process; detector-guided policies let agents allocate budget effectively in mixed-host testbeds. Welfare: defender wellbeing and the value of deception tools must be redesigned for agents that can model the honeypot itself. P251–P371 LIVE.