Intersections · 14 links
Where the three topics meet
The three topics on this site connect in interesting ways. This page collects the 14 links that make a real contribution to more than one of them. AI attackers and deception is where the most is happening. As attackers start using AI, defenders are asking whether their traps still work. Early research suggests AI attackers may fall for traps more easily than people do, and AI is also being used to build more convincing traps. Quantum cognition and deception meet in the question of how people make judgments when someone is trying to mislead them. Deception works by shaping what an attacker sees and in what order, and quantum cognition studies how that order changes decisions. Quantum cognition and AI attackers is the newest connection. One recent study tested whether AI models show the same decision patterns as people, and found this harder to measure than expected. Much is still unexplored. No one has yet used quantum cognition to model what an AI attacker believes, or tested whether traps built around human thinking habits work on AI. If you know of work that fills these gaps, let us know.
The three pairings
Nothing matches those filters. Try clearing one of them.
Attackers + Deception 11
11 entries that belong to both literatures, not just to one that mentions the other.
-
LLM-powered web honeypot: generates a plausible HTTP response to whatever arrives instead of emulating fixed applications. Go, Apache-2.0.
living# -
DEF CON community track on adversary simulation, emulation tactics and purple teaming. The programme page links no recordings at all, so it is hard to follow remotely.
living# -
Low-code deception runtime, Go, GPL-3.0. The interesting part is the MCP bait tooling: decoys aimed at AI agents rather than human intruders. A commercial product sits on top.
-
Hacking Back the AI-Hacker: Prompt Injection as a Defense Against LLM-driven Cyberattacks
Plants adversarial text in responses an attacking agent will read, disrupting it or compromising the attacker's own machine, with over 95% reported effectiveness. The cleanest statement of deception aimed at machines rather than people.
-
Honeyquest for LLMs: Rethinking Cyber Deception for AI Attackers
Twenty-one models against 174 reconnaissance queries, finding LLMs take deceptive bait far more often than humans, show no attention-diversion effect, and act on traps 73.4% of the time despite naming them in their reasoning.
preprint# -
Four cooperating agents divert jailbreak attempts into decoy responses, reporting a 68.77% average reduction in attack success while leaving legitimate queries intact. Preprint; the threat model is model-level, not network-level.
preprint# -
Intelligent interactive honeypots: A systematization of AI-driven cyber deception
Systematizes forty studies on AI-driven interactive honeypots, mapping interaction level to attack stage and calling out unstandardised datasets and evaluation as the field's main weaknesses. Carries a 2027 issue date.
-
LLM Honeypot: Leveraging Large Language Models as Advanced Interactive Honeypot Systems
Fine-tunes an open-weights model on captured attacker sessions to generate honeypot responses, then evaluates realism and deploys it live. Preprint; evaluation is thinner than shelLM's.
preprint# -
LLM in the Shell: Generative Honeypots
shelLM, an LLM-backed Linux shell honeypot reporting a 0.90 true negative rate against security experts asked to tell it from a real host. The paper that started the generative-honeypot line.
-
The Mantis decoys as running code: tarpitted FTP, deliberately vulnerable web apps, weak telnet, injection payloads, reverse-shell listeners.
living# -
SoK: Honeypots & LLMs, More Than the Sum of Their Parts?
Systematizes both directions at once: LLMs used to build honeypots, and honeypots built for LLM attackers. Includes a taxonomy of honeypot detection vectors and a critique of how the area evaluates itself.
preprint#
Attackers + Quantum cognition 2
2 entries that belong to both literatures, not just to one that mentions the other.
-
Takes the parameter-free QQ equality from quantum cognition and applies it to model log-probabilities, finding most item pairs saturate into near-determinism and so cannot support a distribution-level test. The only direct link between these two literatures found.
preprint# -
Cognitive Bias in High-Stakes Decision-Making with LLMs
BiasBuster, a 16,800-prompt framework for measuring and mitigating cognitive bias in model decisions. Relevant here because deception doctrine assumes exploitable biases; this is the closest thing to an inventory of them in machines.
preprint#
Deception + Quantum cognition 1
1 entry that belong to both literatures, not just to one that mentions the other.
-
A formulation of computational trust based on quantum decision theory
Splits trust into objective and subjective components and uses interference terms to model how evaluations shift between isolated and comparative judgment. One of very few quantum-cognition papers aimed at a security-adjacent problem.
paywalled#