Paper

HoneyGPT: Breaking the Trilemma in Terminal Honeypots with Large Language Model

Presents a language-model terminal honeypot architecture and describes a field evaluation.

HoneypotNetwork

Critical reading · Sep 15, 2026

What the source supports

The abstract describes an architecture and evaluation of a language-model terminal honeypot.

Question for evaluation

What was the baseline, and how was decoy realism measured?

This note is bounded by the material shown under “Review depth”. It is not an independent test.

Evidence limits

Metrics, field conditions and negative outcomes were not extracted from the full text.

Reviewed: full text.

Full-text review · 2026-09-16

Design and scope

LLM terminal architecture evaluated with response, session-length and interaction metrics.

Main finding

In the reported tests, GPT variants respond to more commands and sessions than Cowrie.

Evidence limits

Metrics favor response coverage; they do not prove credibility against human adversaries or sustained cost.

Sources and provenance

  1. HoneyGPT: Breaking the Trilemma in Terminal Honeypots with Large Language Model
    full-text · 2026-09-16

Reviewed: 2026-09-16. This record may change when new evidence is found.

RIS · BibTeX

Related resources

Open software

Cowrie

Review: RepositoryCritical reading

SSH and Telnet honeypot that records login attempts and attacker sessions.

NetworkHoneypot
Open software

Galah

Review: RepositoryCritical reading

Web honeypot using a language model to generate interactions.

ApplicationHoneypot