Research · curated 26 Sep 2026
OllamaDrama: Designing and Deploying a Honeypot to Measure Attacks on Exposed LLM Infrastructure
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
OllamaDrama provides empirical, real-world evidence that publicly exposed self-hosted LLM infrastructure like Ollama is actively targeted with prompt injection, RCE, and agent tool-use attacks, helping defenders understand and detect threats to their AI deployments.
OllamaDrama presents Ollure, a low- and medium-interaction honeypot emulating the Ollama API without a backend LLM, deployed across cloud and university networks for 84 days and recording 290,887 interactions from 2,793 unique source IPs. Beyond automated discovery and model enumeration, the researchers observed concrete exploitation attempts including model management abuse, path traversal and SSRF probes, RCE and cryptomining payloads, resource exhaustion, prompt injection, information extraction, and agent-oriented tool use against exposed self-hosted LLM services.