AI RESEARCH

Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots

arXiv CS.AI

ArXi:2605.29963v1 Announce Type: cross Honeypots are decoy systems mimicking real system components designed to defend against cyber attacks. Recently, LLMs increasingly serve as simulation backbones for honeypots. They enable defenders to construct high-interaction honeypots with low system security risks. However, LLM-powered honeypot development lacks a unified evaluation framework. Most evaluations consist of measuring response similarity on fixed commands, manual testing, or real-world deployment.