Master's thesis program outcomes
Showcasing work from our Master Thesis Program students. Students write their thesis in a real-world environment, at organizations who receives direct support and new expertise to take their AI projects to the next level.
Cohort of 2026
Identifying LLM-Powered Cyber Attacks with Timing Analysis and Honeytoken-Based Deception
Our master's research investigated how LLM-powered attackers can be identified and distinguished from traditional bots and human attackers using behavioral analysis, timing analysis, and honeytokens. Our results identified distinct differences in timing, behavioral patterns, and honeytoken interaction, demonstrating that LLM-powered attackers can exhibit measurable characteristics that can be used for detection. As LLMs and agentic AI become increasingly capable of performing autonomous tasks in cybersecurity, our work provides organizations and researchers with practical approaches for detecting and analyzing this emerging class of cyber threats.
Full thesis: Identifying LLM-Powered Cyber Attacks with Timing Analysis and Honeytoken-Based Deception
Code repository: github.com/AI-Sweden-Honeypot-Thesis/AhSh/tree/working_branch
Framework/s: Cybersecurity AI (CAI) (aliasrobotics.github.io/cai, github.com/aliasrobotics/cai)
LLM Attacker Behavior and Designing Adaptive Honeypot Defences
As autonomous AI agents start automating multi-stage cyberattacks, security teams lack practical data on how these tools actually behave when probing systems. Building on research within Project Violet, this work explored how to map attacker intentions and tested whether making honeypots dynamically adapt in real time genuinely improves defense. Our findings show that extra algorithmic complexity doesn’t necessarily outperform simple, well-grounded setups, helping teams make pragmatic, cost-effective decisions when experimenting with AI-driven threat intelligence.
More master's thesis works to be presented.