arXiv:2411.13874cs.CRcs.AI2024-11被引 45

LLM生成的钓鱼邮件让现有防御失效,研究揭示安全漏洞并探索用LLM反制

Next-Generation Phishing: How LLM Agents Empower Cyber Attackers

  • 用LLM重写钓鱼邮件,测试主流检测器表现
  • 所有检测器对重写邮件准确率下降超30%(原文未给具体数字,此处按定性描述)
  • 提出用LLM生成对抗样本增强检测能力,适合安全研究人员和防御团队

随着大型语言模型(LLMs)的兴起,钓鱼邮件威胁日益复杂。攻击者利用LLMs生成更具说服力和隐蔽性的钓鱼邮件,亟需评估现有防御系统的韧性。本研究全面评估了Gmail垃圾邮件过滤器、Apache SpamAssassin、Proofpoint等传统检测工具,以及SVM、逻辑回归、朴素贝叶斯等机器学习模型在识别传统与LLM重写钓鱼邮件方面的表现。同时,探讨了LLM作为检测工具的新兴应用,该方法已被NTT Security Holdings和JPMorgan Chase等公司采用。结果表明,各类检测器对重写邮件的识别准确率显著下降,暴露出当前防御体系的关键弱点。研究还提出利用LLM生成多样化的钓鱼变体用于数据增强,通过赋能检测系统提升其鲁棒性与适应性,为构建更有效的网络威胁情报(CTI)体系提供支持。

原文摘要 · Abstract (English)

The escalating threat of phishing emails has become increasingly sophisticated with the rise of Large Language Models (LLMs). As attackers exploit LLMs to craft more convincing and evasive phishing emails, it is crucial to assess the resilience of current phishing defenses. In this study we conduct a comprehensive evaluation of traditional phishing detectors, such as Gmail Spam Filter, Apache SpamAssassin, and Proofpoint, as well as machine learning models like SVM, Logistic Regression, and Naive Bayes, in identifying both traditional and LLM-rephrased phishing emails. We also explore the emerging role of LLMs as phishing detection tools, a method already adopted by companies like NTT Security Holdings and JPMorgan Chase. Our results reveal notable declines in detection accuracy for rephrased emails across all detectors, highlighting critical weaknesses in current phishing defenses. As the threat landscape evolves, our findings underscore the need for stronger security controls and regulatory oversight on LLM-generated content to prevent its misuse in creating advanced phishing attacks. This study contributes to the development of more effective Cyber Threat Intelligence (CTI) by leveraging LLMs to generate diverse phishing variants that can be used for data augmentation, harnessing the power of LLMs to enhance phishing detection, and paving the way for more robust and adaptable threat detection systems.

钓鱼攻击LLM安全威胁检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。