Abracadabra Labs / resource directory

Intersections · 14 links

Where the three topics meet

The three topics on this site connect in interesting ways. This page collects the 14 links that make a real contribution to more than one of them. AI attackers and deception is where the most is happening. As attackers start using AI, defenders are asking whether their traps still work. Early research suggests AI attackers may fall for traps more easily than people do, and AI is also being used to build more convincing traps. Quantum cognition and deception meet in the question of how people make judgments when someone is trying to mislead them. Deception works by shaping what an attacker sees and in what order, and quantum cognition studies how that order changes decisions. Quantum cognition and AI attackers is the newest connection. One recent study tested whether AI models show the same decision patterns as people, and found this harder to measure than expected. Much is still unexplored. No one has yet used quantum cognition to model what an AI attacker believes, or tested whether traps built around human thinking habits work on AI. If you know of work that fills these gaps, let us know.

The three pairings

Attackers + Deception 11

11 entries that belong to both literatures, not just to one that mentions the other.

  • 0x4D31/galah

    LLM-powered web honeypot: generates a plausible HTTP response to whatever arrives instead of emulating fixed applications. Go, Apache-2.0.

    living
  • Adversary Village at DEF CON

    DEF CON community track on adversary simulation, emulation tactics and purple teaming. The programme page links no recordings at all, so it is hard to follow remotely.

    living
  • beelzebub-labs/beelzebub

    Low-code deception runtime, Go, GPL-3.0. The interesting part is the MCP bait tooling: decoys aimed at AI agents rather than human intruders. A commercial product sits on top.

    livingvendor-authoredopen version
  • Hacking Back the AI-Hacker: Prompt Injection as a Defense Against LLM-driven Cyberattacks

    Plants adversarial text in responses an attacking agent will read, disrupting it or compromising the attacker's own machine, with over 95% reported effectiveness. The cleanest statement of deception aimed at machines rather than people.

    preprintseminalopen version
  • Honeyquest for LLMs: Rethinking Cyber Deception for AI Attackers

    Twenty-one models against 174 reconnaissance queries, finding LLMs take deceptive bait far more often than humans, show no attention-diversion effect, and act on traps 73.4% of the time despite naming them in their reasoning.

    preprint
  • HoneyTrap: Deceiving Large Language Model Attackers to Honeypot Traps with Resilient Multi-Agent Defense

    Four cooperating agents divert jailbreak attempts into decoy responses, reporting a 68.77% average reduction in attack success while leaving legitimate queries intact. Preprint; the threat model is model-level, not network-level.

    preprint
  • Intelligent interactive honeypots: A systematization of AI-driven cyber deception

    Systematizes forty studies on AI-driven interactive honeypots, mapping interaction level to attack stage and calling out unstandardised datasets and evaluation as the field's main weaknesses. Carries a 2027 issue date.

  • LLM Honeypot: Leveraging Large Language Models as Advanced Interactive Honeypot Systems

    Fine-tunes an open-weights model on captured attacker sessions to generate honeypot responses, then evaluates realism and deploys it live. Preprint; evaluation is thinner than shelLM's.

    preprint
  • LLM in the Shell: Generative Honeypots

    shelLM, an LLM-backed Linux shell honeypot reporting a 0.90 true negative rate against security experts asked to tell it from a real host. The paper that started the generative-honeypot line.

  • pasquini-dario/project_mantis

    The Mantis decoys as running code: tarpitted FTP, deliberately vulnerable web apps, weak telnet, injection payloads, reverse-shell listeners.

    living
  • SoK: Honeypots & LLMs, More Than the Sum of Their Parts?

    Systematizes both directions at once: LLMs used to build honeypots, and honeypots built for LLM attackers. Includes a taxonomy of honeypot detection vectors and a critique of how the area evaluates itself.

    preprint

Attackers + Quantum cognition 2

2 entries that belong to both literatures, not just to one that mentions the other.

Deception + Quantum cognition 1

1 entry that belong to both literatures, not just to one that mentions the other.

  • A formulation of computational trust based on quantum decision theory

    Splits trust into objective and subjective components and uses interference terms to model how evaluations shift between isolated and comparative judgment. One of very few quantum-cognition papers aimed at a security-adjacent problem.

    paywalled