跳到正文
arXiv:cs.AI· Yuelin Wang, Jiongchi Yu, Yanbang Sun·· 4 小时前AI 评分41

AgentTrap:面向自主渗透测试智能体的有状态反馈欺骗蜜罐

AgentTrap: Stateful Feedback Deception against Autonomous Penetration Testing Agents

AI 导读

AgentTrap 是首个面向自主渗透测试智能体的闭环蜜罐,通过哨兵端点、基于受保护应用的有状态欺骗和行为引导升级来维持交互。在部署的 Web 应用中测试八款自主渗透测试智能体,相比无防御,它将真实目标攻击成功率从 95.8% 降至 79.2%,并在 18.8% 的运行中成功套取攻击者 API key,优于静态欺骗与固定升级策略。

正文

View PDF HTML (experimental)

Abstract:Autonomous penetration testing agents conduct multi-step attacks by continuously adapting their plans and actions to target responses. As a common defense, honeypots can be deployed to divert these agents from real assets by presenting decoy services, while also supporting attack tracing and active counterattacks. However, conventional honeypots rely primarily on static artifacts and predefined responses, leaving them unable to adapt to the evolving attack strategies of autonomous penetration testing agents. To this end, we present AgentTrap, the first closed-loop honeypot tailored for autonomous penetration testing agents. AgentTrap uses sentinel endpoints to avoid benign interference, stateful deception grounded in the protected application, and behavior-guided escalation to sustain engagement and collect agent-side behavioral evidence with controlled disclosures.
We evaluate AgentTrap against eight autonomous penetration-testing agents in a deployed web application containing a real application endpoint and a separate honeypot endpoint configured under three defense strategies. Compared with no defense, AgentTrap reduces the aggregate real-target attack success rate from 95.8% to 79.2% and successfully elicits attacker API keys in 18.8% of the runs, outperforming static deception and fixed escalation. Furthermore, trace analysis shows that resistance to such counterattacks depends jointly on model-level recognition of deceptive requests and architecture-level isolation of sensitive resources.
Comments: 4 pages
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as: arXiv:2610.02869 [cs.CR]
  (or arXiv:2610.02869v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.02869

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Jiongchi Yu [view email]
[v1] Fri, 2 Oct 2026 06:07:37 UTC (174 KB)

来源:arXiv:cs.AI · arxiv.org