遇见数据集

Rouxii: Exploiting Honeypots with Deception-Aware AI Pentesters

收藏
Zenodo2026-08-17 更新2026-08-20 收录
官方服务:

资源简介:

What this dataset is about This dataset is the evaluation corpus behind Rouxii experiment, a testbed built to answer one question: can a local LLM-driven penetration-testing agent tell a honeypot apart from a real host, and does that recognition change what it does next? The experiment crosses language models, attacker frameworks, and network setups, and records a structured evaluation for every run. What composes the dataset The corpus spans 12 experiment repetitions (Repetition_1 through Repetition_12) plus 6 supplementary HackingBuddy batches (HB_extra_YYYYMMDD/), for a total of 1,544 runs. Models: three local reasoning models served via Ollama — deepseek-r1:32b, qwen3.6:27b, and gemma4:31b. Attacker frameworks: Rouxii (run in two cohorts — rouxii-vanilla, which scans blind, and rouxii-anti-deception, which scans with named honeypot fingerprints), PentestGPT, and HackingBuddy. Targets: the honeypots Cowrie (SSH), Conpot (Modbus/S7/HTTP), and GasPot (ATG), set against real-service decoys, across 11 network setups. Each run directory holds: - report.json — the structured record: metadata, attack plan, step-by-step transcript, exploitation record, and the evaluation answers. - session.md — the run's full human-readable transcript. - report.md — a readable markdown summary of the run (Rouxii runs only). How to read the dataset Runs are organized as Repetition_N/<model>/<Framework>/<cohort-or-setup>/. Rouxii adds a rouxii-vanilla / rouxii-anti-deception level; PentestGPT uses numbered setups; HackingBuddy uses real_ssh /cowrie_ssh. The HB_extra_*/ directories follow the same shape (their internal subfolders keep the Repetition_N name). Inside each run directory you get the report.json / session.md / report.md files described above. The measurement itself lives in each report's evaluation block, which holds six labelized answers: R_IDENTIFY: services the agent judged real D_IDENTIFY: per-port honeypot/deception verdict V_IDENTIFY: services judged vulnerable SIG_CHAIN: the fingerprint signal chain behind the verdict NEXT_BLIND / NEXT_AWARE: the agent's next-action choice, elicited blind and deception-aware

提供机构:
Zenodo
创建时间:
2026-08-17
二维码
社区交流群
二维码
科研交流群
商业服务