arXiv:2506.14337cs.CRcs.AI2025-06被引 1

用大模型分析钓鱼邮件意图,自动分类并生成威胁情报。

LLM-Powered Intent-Based Categorization of Phishing Emails

  • 基于大模型分析邮件意图,而非仅依赖隐藏元数据。
  • 可准确识别钓鱼邮件,并按类型分类,支持威胁响应。
  • 适合安全团队和自动化防御系统快速响应新型钓鱼攻击。

钓鱼攻击仍是现代网络安全的重大威胁,因其能成功欺骗人类及防护机制。传统检测系统主要依赖用户无法在收件箱中看到的邮件元数据,且难以应对经验丰富的用户仅凭文本即可识别的钓鱼邮件。本文研究大型语言模型(LLMs)通过关注邮件意图来检测钓鱼邮件的实用潜力。除了二分类外,论文引入了一种意图类型分类体系,由LLMs操作化为具体类别,从而生成可操作的威胁信息。为支持研究,我们整理了公开数据集,构建了一个包含合法与钓鱼邮件的定制数据集。结果表明,现有大模型具备检测和分类钓鱼邮件的能力,凸显其在此领域的应用潜力。

原文摘要 · Abstract (English)

Phishing attacks remain a significant threat to modern cybersecurity, as they successfully deceive both humans and the defense mechanisms intended to protect them. Traditional detection systems primarily focus on email metadata that users cannot see in their inboxes. Additionally, these systems struggle with phishing emails, which experienced users can often identify empirically by the text alone. This paper investigates the practical potential of Large Language Models (LLMs) to detect these emails by focusing on their intent. In addition to the binary classification of phishing emails, the paper introduces an intent-type taxonomy, which is operationalized by the LLMs to classify emails into distinct categories and, therefore, generate actionable threat information. To facilitate our work, we have curated publicly available datasets into a custom dataset containing a mix of legitimate and phishing emails. Our results demonstrate that existing LLMs are capable of detecting and categorizing phishing emails, underscoring their potential in this domain.

钓鱼邮件大模型意图识别安全检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。