通过分析语音诈骗通话中的战术轨迹,提前预测其是否将导致信息窃取或金融诈骗。
Vishing-Tactics-Bench: Forecasting Exploitation Trajectories in Voice Phishing Calls

- 基于MITRE ATT&CK构建6类诈骗战术,标注3.5万条中文诈骗语音。
- 提出生存式预测框架,准确率(AP@k)和风险发散误差均优于基线模型。
- 可实时识别早期预警信号,适用于反诈系统中的干预时机选择。
语音诈骗(vishing)在实时中展开;等到通话结束后进行事后分类时,损失已不可挽回。更具行动价值的问题是:当前通话正朝着何种具体危害(信息收集或金融剥削)推进?我们提出Vishing-Tactics-Bench,一个基于Endsley情境意识框架的基准,将语音诈骗防御从事后欺诈分类转变为危害预测:在每一轮对话中预测通话是否会达到两类终态危害。我们为语音诈骗适配了MITRE ATT&CK的6战术分类体系(Vishing-Tactics),并标注了5,645个合成中文诈骗通话中的35,340条诈骗者语句。我们定义了“剥削轨迹预测”任务,采用生存式协议评估两种终态危害,使用三项指标:AP@k、C-index和发散误差。从马尔可夫启发式到微调大模型的基线实验表明,战术轨迹作为通话战术状态的可解释表示,支持针对特定危害的预测,并可用于下游干预策略选择;在严格误报预算下的分层提前量分析进一步揭示了轨迹信号何时提供早期预警。
原文摘要 · Abstract (English)
Voice phishing (vishing) unfolds in real time; by the time a call has ended and post-hoc classification is possible, the harm has already been done. The more actionable question is which concrete harm (Information Gathering or Financial Exploitation) an ongoing call is tactically progressing toward. We present Vishing-Tactics-Bench, a benchmark grounded in Endsley's situation-awareness (SA) framework that recasts vishing defense from after-the-fact fraud classification to harm projection: predicting at each turn whether the call will reach either terminal harm. We adapt MITRE ATT&CK to vishing as a 6-tactic taxonomy (Vishing-Tactics) and label 35,340 scammer utterances across 5,645 synthetic Chinese calls. We define Exploitation Trajectory Forecasting, a survival-style protocol over the two terminal harms with three metrics: AP@k, C-index, and divergence error. Baselines ranging from a Markov heuristic to fine-tuned LLMs show that the tactical trajectory serves as an interpretable representation of the call's tactical state, supporting harm-specific forecasting, which can then be used for the downstream application of intervention selection; a stratified lead-time analysis at a tight false-alarm budget further identifies at what point in a call the trajectory signal yields early warning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。