Personality-Driven Deception in Cybersecurity

Personality-Driven Deception in Cybersecurity

How LLMs can create more convincing honeypot agents

SANDMAN introduces personality-induced LLM agents as advanced cyber decoys that extend attacker observation periods through more believable human interactions.

  • Leverages the five-factor model of personality to systematically create distinct personalities in LLMs
  • Creates high-fidelity engagement with attackers by simulating human-like responses and behaviors
  • Serves as a new generation of honeypots that can maintain attacker engagement longer than traditional decoys

This research significantly advances cybersecurity defenses by enabling more sophisticated threat intelligence gathering through prolonged attacker interactions with seemingly human targets.

Inducing Personality in LLM-Based Honeypot Agents: Measuring the Effect on Human-Like Agenda Generation

3 | 4