VelLMes: A High-Interaction AI-Based Deception Framework
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F68407700%3A21230%2F25%3A00384976" target="_blank" >RIV/68407700:21230/25:00384976 - isvavai.cz</a>
Result on the web
<a href="https://doi.org/10.1109/EuroSPW67616.2025.00082" target="_blank" >https://doi.org/10.1109/EuroSPW67616.2025.00082</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/EuroSPW67616.2025.00082" target="_blank" >10.1109/EuroSPW67616.2025.00082</a>
Alternative languages
Result language
angličtina
Original language name
VelLMes: A High-Interaction AI-Based Deception Framework
Original language description
There are very few SotA deception systems based on Large Language Models. The existing ones are limited only to simulating one type of service, mainly SSH shells. These systems - but also the deception technologies not based on LLMs - lack an extensive evaluation that includes human attackers. Generative AI has recently become a valuable asset for cybersecurity researchers and practitioners, and the field of cyber-deception is no exception. Researchers have demonstrated how LLMs can be leveraged to create realistic-looking honeytokens, fake users, and even simulated systems that can be used as honeypots. This paper presents an AI-based deception framework called VelLMes, which can simulate multiple protocols and services such as SSH Linux shell, MySQL, POP3, and HTTP. All of these can be deployed and used as honeypots, thus VelLMes offers a variety of choices for deception design based on the users' needs. VelLMes is designed to be attacked by humans, so interactivity and realism are key for its performance. We evaluate the generative capabilities and the deception capabilities. Generative capabilities were evaluated using unit tests for LLMs. The results of the unit tests show that, with careful prompting, LLMs can produce realistic-looking responses, with some LLMs having a 100% passing rate. In the case of the SSH Linux shell, we evaluated deception capabilities with 89 human attackers. The attackers interacted with a randomly assigned shell (either honeypot or real) and had to decide if it was a real Ubuntu system or a honeypot. The results showed that about 30% of the attackers thought that they were interacting with a real system when they were assigned an LLM-based honeypot. Lastly, we deployed 10 instances of the SSH Linux shell honeypot on the Internet to capture real-life attacks. Analysis of these attacks showed us that LLM honeypots simulating Linux shells can perform well against unstructured and unexpected attacks on the Internet, responding corr...
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
—
Continuities
I - Institucionalni podpora na dlouhodoby koncepcni rozvoj vyzkumne organizace
Others
Publication year
2025
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings of the 10th IEEE European Symposium on Security and Privacy Workshops
ISBN
979-8-3315-9546-3
ISSN
2768-0649
e-ISSN
2768-0657
Number of pages
9
Pages from-to
671-679
Publisher name
IEEE Computer Society
Place of publication
Cannes
Event location
Venice
Event date
Jun 30, 2025
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
001576286100076