arXiv:2509.21129cs.LGcs.CR2025-09被引 1

用自演化智能体对抗新型垃圾邮件和钓鱼攻击

EvoMail: Self-Evolving Cognitive Agents for Adaptive Spam and Phishing Email Defense

  • 构建融合文本、元数据与嵌入资源的异构邮件图,结合大模型进行上下文推理
  • 红蓝对抗中自动学习失败经验,内存模块持续优化检测能力
  • 在真实数据集上显著提升准确率与适应性,适合安全防御研究者使用

现代垃圾邮件和钓鱼攻击已远超关键词黑名单或简单启发式规则。攻击者如今采用多模态策略,结合自然语言文本、混淆链接、伪造头信息与恶意附件,并在数日内调整战术以绕过过滤系统。传统检测系统依赖静态规则或单模态模型,难以整合异构信号或持续适应,导致性能快速下降。我们提出EvoMail,一种用于鲁棒检测垃圾邮件与钓鱼邮件的自演化认知代理框架。EvoMail首先构建统一的异构邮件图,融合文本内容、元数据(头信息、发件人、域名)及嵌入资源(链接、附件)。基于大语言模型增强的认知图神经网络,在多源信息间执行上下文感知推理,识别协同攻击行为。最关键的是,EvoMail引入对抗式自我演化循环:红队代理生成新型规避策略(如字符混淆或AI生成钓鱼文本),蓝队检测器从失败中学习,将经验压缩至记忆模块并复用于未来推理。在真实世界数据集(Enron-Spam、Ling-Spam、SpamAssassin、TREC)及合成对抗变体上的大量实验表明,EvoMail在检测准确率、对演进攻击的适应性以及推理过程可解释性方面均持续优于现有最先进基线。结果凸显其作为下一代抗垃圾邮件与钓鱼威胁的韧性且可解释防御框架的潜力。

原文摘要 · Abstract (English)

Modern email spam and phishing attacks have evolved far beyond keyword blacklists or simple heuristics. Adversaries now craft multi-modal campaigns that combine natural-language text with obfuscated URLs, forged headers, and malicious attachments, adapting their strategies within days to bypass filters. Traditional spam detection systems, which rely on static rules or single-modality models, struggle to integrate heterogeneous signals or to continuously adapt, leading to rapid performance degradation. We propose EvoMail, a self-evolving cognitive agent framework for robust detection of spam and phishing. EvoMail first constructs a unified heterogeneous email graph that fuses textual content, metadata (headers, senders, domains), and embedded resources (URLs, attachments). A Cognitive Graph Neural Network enhanced by a Large Language Model (LLM) performs context-aware reasoning across these sources to identify coordinated spam campaigns. Most critically, EvoMail engages in an adversarial self-evolution loop: a ''red-team'' agent generates novel evasion tactics -- such as character obfuscation or AI-generated phishing text -- while the ''blue-team'' detector learns from failures, compresses experiences into a memory module, and reuses them for future reasoning. Extensive experiments on real-world datasets (Enron-Spam, Ling-Spam, SpamAssassin, and TREC) and synthetic adversarial variants demonstrate that EvoMail consistently outperforms state-of-the-art baselines in detection accuracy, adaptability to evolving spam tactics, and interpretability of reasoning traces. These results highlight EvoMail's potential as a resilient and explainable defense framework against next-generation spam and phishing threats.

邮件安全对抗学习自演化大模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。