A Deception-Based Framework for Detecting Reconnaissance Against AI Agent Infrastructure

  • Unique Paper ID: 205669
  • Volume: 13
  • Issue: 1
  • PageNo: 7489-7497
  • Abstract:
  • The growing adoption of autonomous AI agents has introduced attack surfaces that conventional cybersecurity mechanisms are not designed to monitor. Before launching targeted attacks, adversaries routinely conduct reconnaissance to map deployed agent topologies, probe exposed tool capabilities, and discover service endpoints. Existing security solutions concentrate on vulnerability detection and offer limited coverage of reconnaissance-phase activity against AI infrastructures. This paper presents ReconShield, a deception-based security framework that deploys synthetic AI agents and decoy service endpoints to attract and capture adversarial interaction. The framework classifies reconnaissance attempts across four behavioural patterns using the ReconShield Correlation Engine, a lightweight algorithm that converts raw interaction logs into actionable threat intelligence events. Experimental evaluation conducted across 23 representative adversarial scenarios demonstrates 91.3% recall at a 2.4% false positive rate, with sub-millisecond per-event processing overhead, confirming that deception-based detection is both effective and practical for protecting modern agentic AI deployments.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{205669,
        author = {M. Vairamuthu and Lin Eby Chandra},
        title = {A Deception-Based Framework for Detecting Reconnaissance Against AI Agent Infrastructure},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {13},
        number = {1},
        pages = {7489-7497},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=205669},
        abstract = {The growing adoption of autonomous AI agents has introduced attack surfaces that conventional cybersecurity mechanisms are not designed to monitor. Before launching targeted attacks, adversaries routinely conduct reconnaissance to map deployed agent topologies, probe exposed tool capabilities, and discover service endpoints. Existing security solutions concentrate on vulnerability detection and offer limited coverage of reconnaissance-phase activity against AI infrastructures. This paper presents ReconShield, a deception-based security framework that deploys synthetic AI agents and decoy service endpoints to attract and capture adversarial interaction. The framework classifies reconnaissance attempts across four behavioural patterns using the ReconShield Correlation Engine, a lightweight algorithm that converts raw interaction logs into actionable threat intelligence events. Experimental evaluation conducted across 23 representative adversarial scenarios demonstrates 91.3% recall at a 2.4% false positive rate, with sub-millisecond per-event processing overhead, confirming that deception-based detection is both effective and practical for protecting modern agentic AI deployments.},
        keywords = {Agentic AI Security, Cyber Deception, Honeypots, Large Language Models, Reconnaissance Detection, Threat Intelligence, Tool Probing.},
        month = {June},
        }

Cite This Article

Vairamuthu, M., & Chandra, L. E. (2026). A Deception-Based Framework for Detecting Reconnaissance Against AI Agent Infrastructure. International Journal of Innovative Research in Technology (IJIRT), 13(1), 7489–7497.

Related Articles