用大模型少样本学习识别钓鱼邮件中的40种心理操纵手法
In-context learning for the classification of manipulation techniques in phishing emails
- 基于40种操纵手法的分类体系,利用大模型少样本学习进行细粒度分析
- 在100封真实法语钓鱼邮件上达到0.76准确率,有效识别常见手法
- 适合安全研究者和反钓鱼系统开发者参考,助力理解攻击者策略
传统钓鱼邮件检测常忽视心理操纵因素。本研究探索使用大语言模型(LLM)的上下文学习(ICL)方法,基于40种操纵手法的分类体系,对钓鱼邮件进行细粒度分类。在真实世界法语钓鱼邮件数据集SignalSpam上,采用GPT-4o-mini模型,通过少样本示例进行评估,测试集为人工标注的100封邮件。结果表明,该方法能有效识别主流操纵手法(如诱饵、好奇心吸引、请求微小帮助),准确率达到0.76。研究展示了ICL在细致钓鱼分析中的潜力,并为理解攻击者策略提供了新视角。
原文摘要 · Abstract (English)
Traditional phishing detection often overlooks psychological manipulation. This study investigates using Large Language Model (LLM) In-Context Learning (ICL) for fine-grained classification of phishing emails based on a taxonomy of 40 manipulation techniques. Using few-shot examples with GPT-4o-mini on real-world French phishing emails (SignalSpam), we evaluated performance against a human-annotated test set (100 emails). The approach effectively identifies prevalent techniques (e.g., Baiting, Curiosity Appeal, Request For Minor Favor) with a promising accuracy of 0.76. This work demonstrates ICL's potential for nuanced phishing analysis and provides insights into attacker strategies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。