Full index · 136 links
Everything, in one table
Sortable and filterable with JavaScript on; a complete, readable table with it off. On narrow screens each row collapses into a stacked record. Every entry has a permalink here — the # at the end of its row.
A dash in the Year column is deliberate. Repositories, people, conference series and trackers have no publication year, so they carry none rather than being stamped with the year I happened to check them. They sort as undated.
Nothing matches those filters. Try clearing one of them.
| Title and annotation | Authors | Year | Type | Access | Topic | Citation |
|---|---|---|---|---|---|---|
| 0x4D31/deception-as-detection Crosswalk from deception-based detections to ATT&CK techniques across Windows, Linux and macOS, with a worked deception story for each. MIT. Dormant for years, and nothing has replaced the mapping. |
Karimi, A. | — | Tool | Open | Deception | # |
| 0x4D31/galah LLM-powered web honeypot: generates a plausible HTTP response to whatever arrives instead of emulating fixed applications. Go, Apache-2.0. |
Karimi, A. | — | Tool | Open | Deception, Attackers | # |
| 9.66J Computational Cognitive Science Background rather than quantum cognition: the Bayesian modelling tradition that quantum accounts define themselves against, without which the arguments are hard to follow. Notes, readings, projects. CC BY-NC-SA, and twenty years old. |
Tenenbaum, J. B. | 2004 | Course | Open | Quantum cognition | # |
| A 4-Month Dataset of SSH Botnet Interactions and Command Payloads 145,425 events from an SSH honeypot over four months. Command payloads, credential patterns, attack sequences. CC BY 4.0. |
Boiko, V.; Niiakyi, O. | 2026 | Dataset | Open | Deception | # |
| A comprehensive survey on cyber deception techniques to improve honeypot performance Open-access survey classifying techniques as advanced mimicking, fake cooperation and honeytoken bait, and proposing evaluation metrics plus a mathematical model for honeynet design. More current than Han et al. |
Javadpour, A. et al. | 2024 | Survey / SoK | Open | Deception | # |
| A formulation of computational trust based on quantum decision theory Splits trust into objective and subjective components and uses interference terms to model how evaluations shift between isolated and comparative judgment. One of very few quantum-cognition papers aimed at a security-adjacent problem. |
Ashtiani, M.; Azgomi, M. A. | 2016 | Paper | Paywalled | Quantum cognition, Deception | # |
| A Review of Honeypots: Fingerprinting Techniques, Detection, and Evasion Mechanisms The counter-deception side: how attackers fingerprint honeypots through behavioural and protocol tells, and how weak existing anti-fingerprinting defences are. The corrective to optimistic deployment literature. |
Chaudhry, A. et al. | 2026 | Survey / SoK | Open | Deception | # |
| A Survey of Agentic AI and Cybersecurity: Challenges, Opportunities and Use-case Prototypes Covers both directions of agentic AI in security and names systemic risks specific to agents: collusion between them, cascading failure, oversight evasion and memory poisoning. Preprint, with working prototypes included. |
Lazer, S. J. et al. | 2026 | Survey / SoK | Open | Attackers | # |
| A Virtual Honeypot Framework Honeyd: simulating whole virtual hosts at the network level so one machine can present thousands. The foundational low-interaction honeypot paper, and still the mental model most tooling inherits. |
Provos, N. | 2004 | Paper | Open | Deception | # |
| Advanced tools and concepts for quantum cognition: A tutorial The formal machinery worked through: POVMs, temporal Bell inequalities, model comparison. Free accepted version in City's repository. For building models, not reading about them. |
Yearsley, J. M. | 2017 | Course | Open | Quantum cognition | # |
| Adversarial Misuse of Generative AI GTIG's January 2025 baseline on APT and information-operations use of Gemini, concluding threat actors gained speed and volume but no novel capability. Useful as the deliberately deflationary counterweight to later autonomy claims. |
Google Threat Intelligence Group | 2025 | Report | Open | Attackers | # |
| Adversary Village at DEF CON DEF CON community track on adversary simulation, emulation tactics and purple teaming. The programme page links no recordings at all, so it is hard to follow remotely. |
Adversary Village | — | Venue | Open | Attackers, Deception | # |
| AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents Ninety-seven realistic agent tasks paired with 629 security test cases, built so attacks and defences can be swapped independently — which is what makes it reusable rather than a one-off result. The standard reference environment for agent hijacking work. |
Debenedetti, E. et al. | 2024 | Dataset | Open | Attackers | # |
| Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges Threat taxonomy for agents acting across digital and physical environments, with a review of evaluation methods and both technical and governance defences. Revised through April 2026; still a preprint. |
Chhabra, A. et al. | 2025 | Survey / SoK | Open | Attackers | # |
| AI as tradecraft: How threat actors operationalize AI Two years on from the 2024 baseline: AI embedded across phishing, malware development and post-compromise work, while humans keep targeting decisions. Notes DPRK use of fabricated identities for employment fraud. |
Microsoft Threat Intelligence | 2026 | Report | Open | Attackers | # |
| AI Cyber Challenge marks pivotal inflection point for cyber defense DARPA's results announcement. Team Atlanta's system found 54 of 63 synthetic vulnerabilities and patched 43, across 54 million lines of code, and all seven finalist systems were released under OSI-approved licences — which is the part with lasting value, since the systems themselves are now inspectable. |
DARPA | 2025 | Programme | Open | Attackers | # |
| AIRT — AI Red Team Academy Eight free modules with Docker labs: prompt injection, RAG exploitation, multi-agent attacks, automated red teaming. |
Karimi, A. | — | Course | Open | Attackers | # |
| An overview of the quantum cognition research program The most current open-access survey, covering judgment fallacies, concept combination, order effects and memory, and engaging directly with replication failures such as Boyer-Kassem's order-effect results. |
Huang, J. et al. | 2025 | Survey / SoK | Open | Quantum cognition | # |
| Assessing AI-Generated vs. Human-Authored Spear Phishing SMS Attacks: An Empirical Study Pilot study of 25 participants comparing GPT-4 and student-written phishing SMS, finding 28% versus 21% click intention, a difference the authors themselves call statistically uncertain. Cite it carefully. |
Francia, J. et al. | 2024 | Paper | Open | Attackers | # |
| Auditing Question-Order Effects in Large Language Models with the QQ Equality: Mechanism Characterization and a Saturation Caveat Takes the parameter-free QQ equality from quantum cognition and applies it to model log-probabilities, finding most item pairs saturate into near-determinism and so cannot support a distribution-level test. The only direct link between these two literatures found. |
Kang, P. | 2026 | Paper | Open | Quantum cognition, Attackers | # |
| AutoAttacker: A Large Language Model Guided System to Implement Automatic Cyber-attacks Targets post-breach hands-on-keyboard activity rather than initial access, which is the phase most later threat reporting says actually shifted. Written by Microsoft-affiliated authors and still an unreviewed preprint. |
Xu, J. et al. | 2024 | Paper | Open | Attackers | # |
| awesome-ai-agent-security Reading list built around the lethal trifecta framing: MCP CVEs, defensive tooling, documented incidents. A fork with almost no history, so treat the selection as one person's. |
Matiny, H. | — | Tool | Open | Attackers | # |
| beelzebub-labs/beelzebub Low-code deception runtime, Go, GPL-3.0. The interesting part is the MCP bait tooling: decoys aimed at AI agents rather than human intruders. A commercial product sits on top. |
Beelzebub Labs | — | Tool | Open | Deception, Attackers | # |
| Big Enough to Break Out: Tracking the Rising Capability of LLM Penetration-Testing Agents Compares a human-in-the-loop pentest harness against a newer autonomous one across three public targets, arguing that planning rather than memory is the current bottleneck. Small sample, September 2026 preprint. |
Lovelace, V. et al. | 2026 | Paper | Open | Attackers | # |
| Building Intrusion Detection Honeypots Training Twelve-plus hours on HTTP, SSH and RDP honeypots, honey tokens, and the monitoring around them. $497 with the companion book. Listed despite the price because free material at this depth does not appear to exist. |
Sanders, C. | — | Course | Paywalled | Deception | # |
| cage-challenge/CybORG The environment behind the multinational CAGE Challenges for autonomous cyber defence agents. MIT. Challenge 4 adds multi-agent RL. |
TTCP CAGE | — | Tool | Open | Attackers | # |
| Can quantum probability provide a new direction for cognitive modeling? The target article that put quantum probability in front of the wider cognitive science community, published with dozens of peer commentaries. The commentaries are where the strongest objections live. |
Pothos, E. M.; Busemeyer, J. R. | 2013 | Paper | Paywalled | Quantum cognition | # |
| Canarytokens Hosted honeytoken generator, free: files, URLs, credentials, cloud keys that alert when touched. |
Thinkst Applied Research | — | Tool | Open | Deception | # |
| Cheating and Deception The deception typology cyber work keeps reimporting, often without citing it: masking, repackaging, dazzling, mimicking, inventing, decoying. Predates the field. Strong on structure, thin on evidence. |
Bell, J. B.; Whaley, B. | 1991 | Book | Paywalled | Deception | # |
| Cognitive Bias in High-Stakes Decision-Making with LLMs BiasBuster, a 16,800-prompt framework for measuring and mitigating cognitive bias in model decisions. Relevant here because deception doctrine assumes exploitable biases; this is the closest thing to an inventory of them in machines. |
Echterhoff, J. M. | 2024 | Paper | Open | Quantum cognition, Attackers | # |
| Concepts and Their Dynamics: A Quantum-Theoretic Modeling of Human Thought Treats contextuality, interference, entanglement and emergence in concept combination and ties them back to conventional psychological theories of concepts. Author list confirmed from the repository listing, not the arXiv header. |
Aerts, D. et al. | 2013 | Paper | Open | Quantum cognition | # |
| Conference on Applied Machine Learning in Information Security (CAMLIS) Practitioner venue for applied ML in security; 2024 proceedings open through CEUR-WS. The main site was serving stale cached content when I checked, so use the proceedings link. |
CAMLIS | — | Venue | Open | Attackers | # |
| Container Orchestration Honeypot: Observing Attacks in the Wild High-interaction honeypot for exposed Docker and Kubernetes endpoints that drew attackers within minutes and produced 94 days of attack data, shared with the community. Free PDF from the authors' lab. |
Spahn, N. et al. | 2023 | Paper | Open | Deception | # |
| cowrie/cowrie The default SSH and Telnet honeypot. Emulated shell, a proxy mode fronting a real host, an experimental LLM backend. Python, actively developed. |
Oosterhof, M. | — | Tool | Open | Deception | # |
| Curriculum Vitae for Neil C. Rowe Naval Postgraduate School; around 300 publications on deception in system defence, fake honeypots, and the ethics of deceptive operations. The CV links straight to full texts, which is why it is here rather than a departmental bio. |
Rowe, N. C. | — | Person | Open | Deception | # |
| CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application Vulnerabilities Sandboxed reproductions of critical-severity web CVEs with automated success checks. State-of-the-art agent frameworks resolved up to 13%. That figure is the most defensible number currently available for end-to-end autonomous exploitation, and it is a long way below what the threat reporting implies. |
Zhu, Y. et al. | 2025 | Dataset | Open | Attackers | # |
| Cybench Task descriptions across six CTF categories, run instructions, evaluation logs, a frontier-model leaderboard. Start here rather than the paper if you mean to run it. |
Zhang, A. K. | — | Dataset | Open | Attackers | # |
| Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models Forty professional CTF tasks from four competitions, each decomposed into subtasks so partial progress is measurable. The benchmark most frequently cited when labs and AI safety institutes report offensive cyber capability. |
Zhang, A. K. et al. | 2025 | Paper | Open | Attackers | # |
| Cyber deception trials: what we've learned so far NCSC's December 2025 interim findings, from trials across 121 UK organisations and 14 commercial providers. Deception does surface hidden compromise. It is also not plug-and-play, and needs deliberate configuration to produce anything — which is the finding most vendor material omits. |
National Cyber Security Centre | 2025 | Blog | Open | Deception | # |
| Cyber Deception: Building the Scientific Foundation Thirteen chapters — adversary modelling, honeypotting, anonymity, forum analysis — assembled as a graduate seminar text. The first serious attempt to give the area a scientific spine. |
Jajodia, S. et al. | 2016 | Book | Paywalled | Deception | # |
| Cyber Deception: Techniques, Strategies, and Human Aspects Ten chapters across game theory, AI and cognitive science — honeyfiles, ICS deception, breach detection. Two are open; the rest are behind Springer. |
Bao, T. et al. | 2023 | Book | Paywalled | Deception | # |
| Cyber expert feedback: Experiences, expectations, and opinions about cyber deception Questionnaire study of professional attackers finding they rarely expect deception, and that those who encounter it diverge sharply, some escalating effort and some abandoning it. Useful counterweight to averaged effect sizes. |
Ferguson-Walter, K. J. et al. | 2023 | Paper | Paywalled | Deception | # |
| Cyber Grand Challenge (CGC) The 2016 competition for machines that find, patch and exploit flaws unaided. It predates LLMs entirely — which is the reason to read it before treating agentic exploitation as new. |
DARPA | 2016 | Programme | Open | Attackers | # |
| Cyber threat actors: AI-assisted intrusion research Account of terminated DPRK-linked accounts researching intrusion tooling, phishing and malware, noting the requests mostly sought publicly available information. A useful deflationary data point against autonomy narratives. |
OpenAI | 2025 | Report | Open | Attackers | # |
| Cyber-Physical Deception Through Coordinated IoT Honeypots Coordinates multiple IoT honeypots so their simulated physical and network dependencies stay consistent under multi-source probing, closing a detection channel single decoys leave open. Free PDF and talk video. |
Guan, C.; Cao, G. | 2025 | Paper | Open | Deception | # |
| CyberLab honeynet dataset Cowrie captures from ~50 nodes at EU and US universities and companies, May 2019 to February 2020. |
Sedlar, U. et al. | 2020 | Dataset | Open | Deception | # |
| Deception Techniques in Computer Security: A Research Perspective Classifies deception along four orthogonal axes: goal, unit, layer, and deployment mode. The cleanest taxonomy in the literature; the ACM version is paywalled, so the authors' copy is linked first. |
Han, X. et al. | 2018 | Survey / SoK | Open | Deception | # |
| Deploying AI Systems Securely: Best Practices for Deploying Secure and Resilient AI Systems Seven-nation joint cybersecurity information sheet: governance, hardened deployment environments, access control, continuous monitoring. Written for operators. Nothing in it addresses offensive agent capability, which is worth knowing before citing it in that context. |
NSA Artificial Intelligence Security Center et al. | 2024 | Standard | Open | Attackers | # |
| Detecting and countering misuse of AI: September 2026 Case studies of actors disrupted between December 2025 and August 2026 across seven harm categories, including cyber espionage and influence operations. Vendor-authored, and covers only misuse of one company's models. |
Anthropic | 2026 | Report | Open | Attackers | # |
| Diederik Aerts Founding director of CLEA, and the originator of the conceptuality interpretation. The Brussels group puts nearly everything on arXiv. |
Aerts, D. | — | Person | Open | Quantum cognition | # |
| Disrupting the first reported AI-orchestrated cyber espionage campaign Anthropic's account of a campaign it attributes to a Chinese state-sponsored group that drove Claude Code through roughly 80-90% of an intrusion chain against about thirty targets. Vendor-authored and self-reported; no independent corroboration of the attribution. |
Anthropic | 2025 | Report | Open | Attackers | # |
| Effectiveness Evaluation Method for Hybrid Defense of Moving Target Defense and Cyber Deception Combines queuing theory and evolutionary game theory to price security against reliability and overhead when deception and MTD run together. Addresses the cost side that most efficacy work ignores; evaluation is analytical. |
Hou, F. et al. | 2025 | Paper | Open | Deception | # |
| Examining the Efficacy of Decoy-based and Psychological Cyber Deception The results paper from the Tularosa data: a four-condition design finding that decoys plus telling attackers deception is present changes behaviour most. The strongest peer-reviewed evidence that deception imposes real cost. |
Ferguson-Walter, K. J. et al. | 2021 | Paper | Open | Deception | # |
| Exploratory Analysis of Decision-Making Biases of Professional Red Teamers in a Cyber-Attack Dataset Re-analysis of red-team data for confirmation bias and framing effects, reporting that framing reduced attacker interaction with the network. Exploratory by the authors' own description, and behind a subscription. |
Gutzwiller, R. S. et al. | 2023 | Paper | Paywalled | Deception | # |
| First known AI-powered ransomware uncovered by ESET Research PromptLock generates Lua payloads at runtime using a local gpt-oss-20b model. ESET states plainly it was never seen in an attack and is believed to be a proof of concept, which most coverage omitted. |
Cherepanov, A.; Strýček, P. | 2025 | Report | Open | Attackers | # |
| Foundations of Cyber Deception: Modeling, Analysis, Design, Human Factors, and Their Convergence Twelve chapters across theory, human factors and application domains including ICS and UAV networks. Pitched at students entering the area. |
Zhu, Q. et al. | 2026 | Book | Paywalled | Deception | # |
| From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code Walks through an exploitable stack buffer underflow in SQLite that the agent found and existing fuzzing had missed. Vendor-authored, and a single case. The technical detail is unusually complete for this genre. |
Google Big Sleep Team | 2024 | Blog | Open | Attackers | # |
| GameSec: Conference on Game Theory and AI for Security Where the formal game-theoretic treatment of deception and signalling gets published. Proceedings as Springer LNCS. |
GameSec | — | Venue | Open | Deception | # |
| GTIG AI Threat Tracker: From Prompting to Autonomy - The Evolution of Adversarial AI September 2026 tracker documenting a shift from prompt-assisted work to agentic workflows, including a cloud compromise and mass credential harvesting completed in under six hours. Names specific actors and malware families. |
Google Threat Intelligence Group | 2026 | Report | Open | Attackers | # |
| Hacking Back the AI-Hacker: Prompt Injection as a Defense Against LLM-driven Cyberattacks Plants adversarial text in responses an attacking agent will read, disrupting it or compromising the attacker's own machine, with over 95% reported effectiveness. The cleanest statement of deception aimed at machines rather than people. |
Pasquini, D. et al. | 2024 | Paper | Open | Attackers, Deception | # |
| HADES creates alternate reality to mislead hackers Moves an intruder into an altered environment to induce doubt rather than ejecting them. A press release, not a paper, and dated. |
Sandia National Laboratories | 2017 | Programme | Open | Deception | # |
| Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications Self-replicating prompts that propagate between RAG-connected agents without a user clicking anything, plus a proposed guardrail. Demonstrated in a lab; no such worm has been observed operationally. |
Cohen, S. et al. | 2024 | Paper | Open | Attackers | # |
| HoneyFactory: Container-Based Comprehensive Cyber Deception Honeynet Architecture Container-based honeynet that deploys honeypots dynamically as an intrusion progresses, using a Gaussian hidden Markov model to estimate attack stage. Open access; evaluation is simulation-based. |
Yu, T. et al. | 2024 | Paper | Open | Deception | # |
| Honeyquest for LLMs: Rethinking Cyber Deception for AI Attackers Twenty-one models against 174 reconnaissance queries, finding LLMs take deceptive bait far more often than humans, show no attention-diversion effect, and act on traps 73.4% of the time despite naming them in their reasoning. |
Prinos, K. et al. | 2026 | Paper | Open | Attackers, Deception | # |
| HoneyTrap: Deceiving Large Language Model Attackers to Honeypot Traps with Resilient Multi-Agent Defense Four cooperating agents divert jailbreak attempts into decoy responses, reporting a 68.77% average reduction in attack success while leaving legitimate queries intact. Preprint; the threat model is model-level, not network-level. |
Li, S. et al. | 2026 | Paper | Open | Attackers, Deception | # |
| Impact of AI on cyber threat from now to 2027 UK national assessment using calibrated probability language, judging that AI will almost certainly make intrusion operations more efficient and that a widening gap will separate defended from undefended estates. |
National Cyber Security Centre | 2025 | Report | Open | Attackers | # |
| Imposing a Cyber Penalty Against Attackers with Cyber Deception Readable summary of the Tularosa findings for practitioners: 52% of attacker commands targeted decoys, and exploit failures doubled under deception. Read this before the two formal papers. |
Ferguson-Walter, K. J. | 2022 | Blog | Open | Deception | # |
| Incalmo: An Autonomous LLM-assisted System for Red Teaming Multi-Host Networks Inserts a high-level attack abstraction layer between the model and the network, reaching critical assets in 37 of 40 benchmark environments where baseline agents managed 3. The clearest evidence that scaffolding, not model scale, is the constraint. |
Singer, B. et al. | 2025 | Paper | Open | Attackers | # |
| Intelligent interactive honeypots: A systematization of AI-driven cyber deception Systematizes forty studies on AI-driven interactive honeypots, mapping interaction level to attack stage and calling out unstandardised datasets and evaluation as the field's main weaknesses. Carries a 2027 issue date. |
Nyamwaya, S. et al. | 2027 | Survey / SoK | Open | Deception, Attackers | # |
| International Symposium on Quantum Interaction (QI) The dedicated venue for quantum-structure work across cognition, language and information retrieval. Nothing since QI 2018; the series looks dormant. |
Springer | — | Venue | Paywalled | Quantum cognition | # |
| Introducing Aardvark: OpenAI's agentic security researcher Announcement of a GPT-5-based agent that finds vulnerabilities, validates exploitability in a sandbox and proposes patches, claiming 92% detection on a seeded benchmark. Vendor announcement, not a paper; the benchmark is not independently reproducible. |
OpenAI | 2025 | Report | Open | Attackers | # |
| Introducing CodeMender: an AI agent for code security The defensive counterpart to the discovery agents: reports 72 security fixes upstreamed to open source over six months, including into a 4.5-million-line codebase. Vendor-authored, with no external audit of fix quality. |
Google DeepMind | 2025 | Report | Open | Attackers | # |
| Introduction to Cyberdeception The only general textbook on the subject. Impersonation, delays, fakes, camouflage, false excuses, on both offence and defence, with sustained attention to industrial control systems throughout rather than in one token chapter. |
Rowe, N. C.; Rrushi, J. | 2016 | Book | Paywalled | Deception | # |
| Jennifer Trueblood Indiana University; directs the Computational Decision Making Lab. Order effects in inference, Bayesian model comparison. |
Trueblood, J. S. | — | Person | Open | Quantum cognition | # |
| Jerome Busemeyer Indiana University. The field's most prolific author. |
Busemeyer, J. R. | — | Person | Open | Quantum cognition | # |
| Journal of Mathematical Psychology, Volume 53, Issue 5: Special Issue on Quantum Cognition The 2009 Bruza and Gabora special issue, where the field consolidated: Aerts on quantum structure, and the first empirical Markov-versus-quantum comparisons. Articles mostly paywalled. |
Bruza, P. D.; Gabora, L. | 2009 | Venue | Paywalled | Quantum cognition | # |
| Know Your Enemy: Learning about Security Threats, 2nd Edition The Honeynet Project's collective account of running honeynets and reading what walked in. Badly dated. Out of print, though two sample chapters and the CD contents are still free. |
The Honeynet Project | 2004 | Book | Free registration | Deception | # |
| Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies Synthesises over 70 academic and industry sources on offensive and defensive LLM use, including AI-generated malware. Preprint and broad rather than deep; useful mainly as a bibliography. |
Ahi, K.; Valizadeh, S. | 2026 | Survey / SoK | Open | Attackers | # |
| LLM Agents can Autonomously Exploit One-day Vulnerabilities Reports GPT-4 exploiting 87% of 15 one-day CVEs when handed the CVE description, dropping to 7% without it. The headline number is widely cited; the caveat that it needs the writeup is the part most citations omit. |
Fang, R. et al. | 2024 | Paper | Open | Attackers | # |
| LLM Honeypot: Leveraging Large Language Models as Advanced Interactive Honeypot Systems Fine-tunes an open-weights model on captured attacker sessions to generate honeypot responses, then evaluates realism and deploys it live. Preprint; evaluation is thinner than shelLM's. |
Otal, H. T.; Canbaz, M. A. | 2024 | Paper | Open | Deception, Attackers | # |
| LLM in the Shell: Generative Honeypots shelLM, an LLM-backed Linux shell honeypot reporting a 0.90 true negative rate against security experts asked to tell it from a real host. The paper that started the generative-honeypot line. |
Sladić, M. et al. | 2024 | Paper | Open | Deception, Attackers | # |
| METR Nonprofit evaluating frontier models for autonomous capability. Not cyber-specific, but its time-horizon work underpins most autonomy forecasting. |
METR | — | Programme | Open | Attackers | # |
| microsoft/CyberBattleSim Abstract simulated network for agents moving laterally, built for reinforcement learning rather than realism. MIT. The abstraction is deliberate and it does limit transfer. |
Microsoft Research | — | Tool | Open | Attackers | # |
| MITRE Engage MITRE's adversary engagement framework: prepare, operate and understand phases over a goal/approach/activity matrix, with a starter kit. Successor to MITRE Shield, and the common vocabulary most deception programmes end up using. |
MITRE Corporation | 2022 | Framework | Open | Deception | # |
| mitre-atlas/atlas-data ATLAS tactics, techniques, mitigations and case studies as versioned YAML. Easier to cite than the client-side-rendered website. |
MITRE Corporation | — | Framework | Open | Attackers | # |
| mitre/engage The Engage matrix as machine-readable data, plus the site tooling. Apache-2.0. |
MITRE Corporation | — | Tool | Open | Deception | # |
| Moving Target Defense II: Application of Game Theory and Adversarial Modeling Game-theoretic and adversarial modelling of surface randomisation. Read it with the GameSec proceedings for the formal treatment. |
Jajodia, S. et al. | 2012 | Book | Paywalled | Deception | # |
| Moving Target Defense: Creating Asymmetric Uncertainty for Cyber Threats The volume that named moving target defence as a research area. Pre-cloud; read it as an origin document. |
Jajodia, S. et al. | 2011 | Book | Paywalled | Deception | # |
| mushorg/conpot ICS/SCADA honeypot emulating industrial protocol stacks. Python, GPL-2.0. The usual starting point for OT deception. |
MushMush Foundation | — | Tool | Open | Deception | # |
| NIST AI 100-2 E2023: Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations The reference vocabulary for adversarial ML: attacker goals, capabilities, mitigations. This page is the E2023 final, published January 2024. A later 2025 edition exists and I could not find a stable landing page for it. |
Vassilev, A. et al. | 2024 | Standard | Open | Attackers | # |
| NIST SP 800-160 Vol. 2 Rev. 1: Developing Cyber-Resilient Systems: A Systems Security Engineering Approach The cyber resiliency engineering framework. Cite this when a deception programme has to map to recognised controls. |
Ross, R. et al. | 2021 | Standard | Open | Deception | # |
| NVIDIA/garak NVIDIA's LLM vulnerability scanner. Prompt injection, jailbreaks, training-data leakage, glitch tokens. Apache-2.0. |
NVIDIA | — | Tool | Open | Attackers | # |
| Open Quantum Systems in Biology, Cognitive and Social Sciences Extends the framework to open-system dynamics, with the decision maker coupled to an environment rather than isolated. The most current book-length treatment from this school. |
Khrennikov, A. Y. | 2023 | Book | Paywalled | Quantum cognition | # |
| OWASP Top 10 for Agentic Applications for 2026 Community risk list for autonomous agent systems. Practitioner-oriented, not empirical. The download page asks for your details. |
OWASP Gen AI Security Project | 2026 | Framework | Free registration | Attackers | # |
| paralax/awesome-honeypots The long-running index of honeypot software by protocol and environment, with a section on anti-honeypot detection tools. Breadth over curation. |
paralax | — | Tool | Open | Deception | # |
| pasquini-dario/project_mantis The Mantis decoys as running code: tarpitted FTP, deliberately vulnerable web apps, weak telnet, injection payloads, reverse-shell listeners. |
Pasquini, D. | — | Tool | Open | Attackers, Deception | # |
| PentestGPT: Evaluating and Harnessing Large Language Models for Automated Penetration Testing The peer-reviewed version of PentestGPT, splitting reasoning, generation and parsing into separate modules to survive context loss over long engagements. USENIX hosts the PDF and talk video free. |
Deng, G. et al. | 2024 | Paper | Open | Attackers | # |
| PHANTOM: polymorphic honeytoken adaptation with narrative-tailored organisational mimicry contextually convincing cyber deception at scale Generates honeytokens carrying organisation-specific naming and technology conventions, scoring 0.778 believability against 0.576 for templates. The authors concede the evaluation is 32 tokens scored by rules, not humans. |
Weinberg, A. I. | 2026 | Paper | Open | Deception | # |
| Planning and Integrating Deception into Computer Security Defenses Three-phase model for planning deception that makes attacker bias an explicit design input and carries Bell and Whaley's six techniques into computer security. Widely borrowed from, rarely credited. |
Almeshekah, M. H.; Spafford, E. H. | 2014 | Paper | Open | Deception | # |
| Professor Emmanuel Pothos Co-author of the BBS target article and the Annual Review survey. The free full texts are in City Research Online, not on this page. |
Pothos, E. M. | — | Person | Open | Quantum cognition | # |
| Project Naptime: Evaluating Offensive Security Capabilities of Large Language Models Argues that poor benchmark scores reflect bad scaffolding rather than model limits, and shows CyberSecEval 2 buffer-overflow scores moving from 0.05 to 1.00 once the tooling improved. The methodology post behind Big Sleep. |
Glazunov, S.; Brand, M. | 2024 | Blog | Open | Attackers | # |
| Quantum Approaches to Consciousness Last revised May 2024. Section 4 separates quantum cognition from quantum-consciousness claims, making the case for quantum mind without quantum brain. The cleanest statement of what the field is not claiming. |
Atmanspacher, H. | 2024 | Survey / SoK | Open | Quantum cognition | # |
| Quantum Cognition Free-to-read review covering contextual inference, belief updating and interference effects, with an explicit section on limitations. The single best orientation piece if you read only one thing here. |
Pothos, E. M.; Busemeyer, J. R. | 2022 | Survey / SoK | Open | Quantum cognition | # |
| Quantum cognition (Wikipedia) Reasonably sourced overview, roughly 48 citations spanning 1953 to 2022. It is here as an orientation link despite the general exclusion of secondary coverage. It has no criticism section and reads as advocacy, so pair it with Boyer-Kassem. |
Wikipedia contributors | — | Blog | Open | Quantum cognition | # |
| Quantum Cognition and Decision Notes Busemeyer's own page: tutorial chapters, free preprints of most of his papers, Hilbert Space Model code. Plain HTML, no index, and the full texts really are here. |
Busemeyer, J. R. | — | Course | Open | Quantum cognition | # |
| Quantum cognition: a new theoretical approach to psychology Short, readable introduction aimed at psychologists rather than mathematicians. The author's copy is free; the Elsevier version is paywalled. Ten pages, and the fastest way into the vocabulary. |
Bruza, P. D. et al. | 2015 | Paper | Open | Quantum cognition | # |
| Quantum Models of Cognition Chapter 7 of Ron Sun's handbook, which places quantum cognition among the other modelling paradigms instead of defending it in isolation. The most useful framing available if you already know Bayesian cognitive modelling. |
Busemeyer, J. R.; Pothos, E. M. | 2023 | Book | Paywalled | Quantum cognition | # |
| Quantum Models of Cognition and Decision The field's standard monograph. Builds the Hilbert-space machinery from scratch, then applies it to judgment, decision and memory. Assumes linear algebra. A second edition exists — check which you are citing. |
Busemeyer, J. R.; Bruza, P. D. | 2012 | Book | Paywalled | Quantum cognition | # |
| Quantum principles in psychology: The debate, the evidence, and the future The authors' reply to the BBS commentaries, and the most concentrated place to see the objections stated and answered. Free full text via City's repository; read it immediately after the target article. |
Pothos, E. M.; Busemeyer, J. R. | 2013 | Paper | Open | Quantum cognition | # |
| Quantum Structure in Cognition Proves that classical models cannot reproduce measured membership weights for conceptual conjunctions and disjunctions, and derives superposition and interference from that failure. The founding paper of the Brussels line of work. |
Aerts, D. | 2009 | Paper | Open | Quantum cognition | # |
| Quantum Structure in Cognition: Fundamentals and Applications Compact statement of the Brussels position: quantum conceptual thought running alongside classical reasoning, with implications drawn for information retrieval and artificial intelligence. Shorter than the journal papers. |
Aerts, D. et al. | 2011 | Paper | Open | Quantum cognition | # |
| Quantum-Like Bayesian Networks for Modeling Decision Making Replaces classical probabilities with amplitudes inside a Bayesian network and adds a similarity heuristic so the quantum parameters are computed rather than fitted. Addresses the standard overfitting objection directly. |
Moreira, C.; Wichert, A. | 2016 | Paper | Open | Quantum cognition | # |
| Quantum-like models cannot account for the conjunction fallacy The strongest published attack on the programme: experiments on question-order effects produce results the quantum account of the conjunction fallacy predicts wrongly. Read it before citing any quantum explanation of Linda. |
Boyer-Kassem, T. et al. | 2016 | Paper | Open | Quantum cognition | # |
| ReSCIND: Reimagining Security with Cyberpsychology-Informed Network Defenses US intelligence-community programme funding defences that exploit attacker cognitive biases. Began 2023, three phases; solicitation closed. |
IARPA | 2023 | Programme | Open | Deception | # |
| Shadowkube: enhancing Kubernetes security with behavioral monitoring and honeypot integration Converts compromised Kubernetes nodes into shadow honeypots in place, reporting 97.7% true-positive detection over 43 CVEs and 635 real attack attempts during public deployment. Open access, with live-deployment numbers rather than simulation. |
Chen, Q. et al. | 2025 | Paper | Open | Deception | # |
| Simon Willison: Prompt injection Twenty-five posts, September 2022 to November 2025, by the person who named the attack class. Tracks it from first description through multi-modal variants to defensive design patterns. Has a feed. |
Willison, S. | — | Blog | Open | Attackers | # |
| SoK: DARPA's AI Cyber Challenge (AIxCC): Competition Design, Architectures, and Lessons Learned Camera-ready systematization of AIxCC by participants and organizers, covering competition design, the finalist architectures, and execution traces. The single best account of what autonomous cyber reasoning systems could and could not do by 2025. |
Zhang, C. et al. | 2026 | Survey / SoK | Open | Attackers | # |
| SoK: Honeypots & LLMs, More Than the Sum of Their Parts? Systematizes both directions at once: LLMs used to build honeypots, and honeypots built for LLM attackers. Includes a taxonomy of honeypot detection vectors and a critique of how the area evaluates itself. |
Bridges, R. A. et al. | 2025 | Survey / SoK | Open | Attackers, Deception | # |
| Staying ahead of threat actors in the age of AI The first joint Microsoft and OpenAI disclosure, naming five state-linked groups using models for reconnaissance, scripting and social engineering, and finding no novel AI-enabled attack. The baseline everything since is measured against. |
Microsoft Threat Intelligence | 2024 | Report | Open | Attackers | # |
| Technical Blog: Strengthening AI Agent Hijacking Evaluations Hijacking success against one model rose from 11% to 81% once the red team adapted its attacks. That gap is the methodological warning for anyone quoting a single injection-resistance number, including the good ones. |
NIST Center for AI Standards and Innovation | 2025 | Blog | Open | Attackers | # |
| telekom-security/tpotce Around thirty honeypot daemons bundled with Elasticsearch, Kibana and Suricata behind one installer. GPL-3.0. |
Deutsche Telekom Security | — | Tool | Open | Deception | # |
| The Honeynet Project 501(c)(3) running since 1999. Institutional home of most of the open honeypot software listed here. |
The Honeynet Project | — | Programme | Open | Deception | # |
| The Road to Top 1: How XBOW Did It Vendor account of reaching the top of HackerOne's US leaderboard with roughly 1,060 validated findings from an autonomous system. Marketing-adjacent and entirely self-reported. The discussion of deduplication and validation is the substantive part, and it is the part most coverage of this left out. |
XBOW | 2025 | Blog | Open | Attackers | # |
| The Tularosa Study: An Experimental Design and Implementation to Quantify the Effectiveness of Cyber Deception Over 130 red-team professionals in a two-day penetration task, with presence and disclosure of deception manipulated independently, plus questionnaires and physiological measures. The design paper that most later efficacy claims trace back to. |
Ferguson-Walter, K. J. et al. | 2019 | Paper | Open | Deception | # |
| thinkst/opencanary Multi-protocol honeypot daemon light enough for a Raspberry Pi. BSD-3-Clause. The open counterpart to Thinkst's commercial Canary. |
Thinkst Applied Research | — | Tool | Open | Deception | # |
| Threat Intelligence (Anthropic) Index of Anthropic's dated misuse reports, March 2025 onward. No feed, so it needs checking by hand. |
Anthropic | — | Newsletter | Open | Attackers | # |
| Threat-Actors-use-of-Artificial-Intelligence Documented threat-actor AI use mapped to ATT&CK, from Microsoft, OpenAI, Anthropic, GTIG and Kaspersky reporting. Narrower than it looks: attacks on AI systems and influence operations are excluded by design. |
cybershujin | — | Tool | Open | Attackers | # |
| tl;dr sec Weekly security newsletter, free, with steady AI-security coverage. The feed avoids the signup. |
Gibler, C. | — | Newsletter | Free registration | Attackers | # |
| Toward Proactive, Adaptive Defense: A Survey on Moving Target Defense The standard MTD survey: design principles, classifications, algorithms, evaluation metrics and applications in one place. Free on arXiv and thorough, though it predates the cloud-native and agentic work entirely. |
Cho, J.-H. et al. | 2019 | Survey / SoK | Open | Deception | # |
| tracebit-com/awesome-deception Curated list of deception articles, papers, talks and tools, CC0. Maintained by a deception vendor, so weigh the selection accordingly. Still the best jumping-off point. |
Tracebit | — | Blog | Open | Deception | # |
| Ubiquitous Quantum Structure: From Psychology to Finance Develops the Växjö contextual probability model, arguing non-Kolmogorov probability is the general case rather than a quantum peculiarity. Mathematically heavier than Busemeyer and Bruza and much less tied to experiments. |
Khrennikov, A. Y. | 2010 | Book | Paywalled | Quantum cognition | # |
| UKGovernmentBEIS/inspect_ai The UK AI Security Institute's evaluation framework. CVE-Bench and several other cyber evals are written against it. MIT. |
UK AI Security Institute | — | Tool | Open | Attackers | # |
| What Is Quantum Cognition, and How Is It Applied to Psychology? Seven pages built around two ideas, complementarity and superposition, and explicit that the claim is mathematical rather than a claim about quantum brains. That disclaimer is the most misquoted thing in the field. |
Busemeyer, J. R.; Wang, Z. | 2015 | Paper | Paywalled | Quantum cognition | # |
| What we learned mapping a year's worth of AI-enabled cyber threats Maps 832 banned accounts from March 2025 to March 2026 onto MITRE ATT&CK, concluding AI use concentrated in post-compromise operations and that ATT&CK lacks categories for agentic orchestration. |
Anthropic | 2026 | Report | Open | Attackers | # |
| Workshop on Active Defense and Deception (AD&D) Fifth edition, Rome, 18 September 2026, co-located with ESORICS. Note that it explicitly excludes offensive counter-attack work. |
AD&D Workshop | — | Venue | Open | Deception | # |
| Zheng (Joyce) Wang Ohio State, School of Communication. Co-authored the question-order studies; comes at the field from communication rather than mathematical psychology. |
Wang, Z. | — | Person | Open | Quantum cognition | # |