Autonomous long-running realistic user simulation with embedded attacks #704
Replies: 1 comment
|
Great question! This is close to the primary use case we build for, so let me say what ships today, and where you will have to write/configure because we don't — yet! We ship in three layers that you can config/compose:
The most important piece of advice up front: you probably should not put the LLM in the per-action loop for every NPC. That's the design most people want first, and it gets expensive, drifty, and unstable over a multi-day run. Think: Tier 1 — baseline behavior is already autonomousYour "operates continuously with no manual prompting" requirement is mostly satisfied by the client itself. A timeline handler with
Build 3–5 role archetypes this way, push them to machine groups, and you have a week of plausible activity with zero LLM calls. Get this right and you have ~80% of what makes the telemetry. If you're running many NPCs and the audience won't be looking at the desktop/host directly, then Tier 2 — n8n + Ollama for content and decisionsn8n is the intended orchestration layer as of v9.0 — the old in-process animation jobs were reimplemented as workflows (that you can edit if you like). Templates ship in
Bootstrap/provisioning lives in What you'll need to write (small, hopefully)None of the shipped workflows push a timeline down to a client. They animate NPC cognitive/social state and post to the local Pandora/chat services at the API level. If you want clients to actually do something, add one HTTP node to the end of your workflow: or That is essentially the difference between narratives at the API level and clients actually doing activity. Tier 3 — embedded attacks on a scheduleFor "insert offensive techniques at chosen intervals," the Scenario/Execution model is what you want (
There's also For the actual malicious activity, use the real handlers — they already do everything on your list:
Also, every Where we still have workYou asked whether ready-made generators and templates exist. Partly...
If I were building your setup this week
Steps 1–2 work out of the box. Step 3 is one HTTP node beyond what ships. Step 4 is where you're writing the most net-new content. HTH. Anything specific, we can enter an issue and try to get it rectified as quickly as possible. |
Uh oh!
There was an error while loading. Please reload this page.
Hi!
I'm working with the GHOSTS API and would like to implement an autonomous system that simulates realistic user activity on NPCs over extended periods (1 day to 1 week).
Goal:
Build an autonomous agent that:
Generates realistic daily user behavior - indistinguishable from actual human activity
Periodically injects attack techniques (visiting malicious domains, downloading suspicious files, lateral movement attempts) at configurable intervals
Maintains consistent "user personas" across the simulation period
Runs continuously without requiring manual prompts
Current setup:
GHOSTS API is up and running
I can send JSON instructions to NPCs to trigger specific actions
I have a local LLM (Ollama with mistral) that can plan sequences of actions
n8n is available as a workflow engine
Questions:
Are there any built-in capabilities or reference implementations for autonomous long-running user simulation?
Is there a recommended architecture for a loop where an LLM continuously plans the next action and dispatches it to GHOSTS?
Is n8n the intended orchestration layer for such a loop - e.g., a workflow that asks the LLM for the next action and forwards it to GHOSTS? Are there any example workflows or templates for this?
Are there existing activity generators / scenario templates that produce realistic multi-day user behavior out of the box?
Has anyone implemented similar "autonomous NPC" setups, and what was the approach?
Any pointers to relevant documentation, examples, or architectural advice would be greatly appreciated.
Thanks!
All reactions