arXiv:2601.20270cs.CRcs.AI2026-01

用分步推理提升大模型识别钓鱼网址的准确率

Eliciting Least-to-Most Reasoning for Phishing URL Detection

  • 设计分步推理提示框架,逐步分析网址特征
  • 在三个数据集上优于单次提示基线,接近监督模型表现
  • 仅需少量数据,适合资源有限的场景

钓鱼攻击仍是主要威胁,精准分类钓鱼网址至关重要。近期大语言模型(LLMs)在该任务中表现优异,但其推理能力仍待深入探索。本文提出一种针对钓鱼网址检测的最少到最多提示框架,并引入“答案敏感性”机制,引导模型迭代推理以提升准确性。我们在三个网址数据集上,使用四种前沿LLM进行评估,对比单次提示和监督模型。结果表明,该框架优于单次提示基线,性能接近监督模型,且所需训练数据显著更少。深入分析显示,最少到最多框架结合答案敏感性机制,通过迭代推理带来性能提升。整体而言,这一简单而高效的提示策略在无需大量训练或少样本指导的情况下,持续优于单次提示与监督方法。

原文摘要 · Abstract (English)

Phishing continues to be one of the most prevalent attack vectors, making accurate classification of phishing URLs essential. Recently, large language models (LLMs) have demonstrated promising results in phishing URL detection. However, their reasoning capabilities that enabled such performance remain underexplored. To this end, in this paper, we propose a Least-to-Most prompting framework for phishing URL detection. In particular, we introduce an "answer sensitivity" mechanism that guides Least-to-Most's iterative approach to enhance reasoning and yield higher prediction accuracy. We evaluate our framework using three URL datasets and four state-of-the-art LLMs, comparing against a one-shot approach and a supervised model. We demonstrate that our framework outperforms the one-shot baseline while achieving performance comparable to that of the supervised model, despite requiring significantly less training data. Furthermore, our in-depth analysis highlights how the iterative reasoning enabled by Least-to-Most, and reinforced by our answer sensitivity mechanism, drives these performance gains. Overall, we show that this simple yet powerful prompting strategy consistently outperforms both one-shot and supervised approaches, despite requiring minimal training or few-shot guidance. Our experimental setup can be found in our Github repository github.sydney.edu.au/htri0928/least-to-most-phishing-detection.

钓鱼检测大模型提示工程推理增强

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。