arXiv:2606. 00889v1 Announce Type: cross Abstract: Phishing attacks remain a major cybersecurity threat, exploiting deceptive URLs to steal sensitive user information.
By Uche Unoke Emmanuel, Gideon Francis Oghie
arXiv:2512. 10104v2 Announce Type: cross Abstract: Email phishing is one of the most prevalent and globally consequential vectors of cyber intrusion.
By Najmul Hasan, Prashanth BusiReddyGari, Haitao Zhao, Yihao Ren, Jinsheng Xu, Shaohu Zhang
AURA: Adaptive Uncertainty-Routed Analysis for Email Threat Detection is a multimodal system that evaluates both email content and embedded URLs to detect spam and phishing. It uses a two-layer approach: first, a URL classifier estimates prediction uncertainty, and only messages with high uncertainty are passed to a fine-tuned transformer encoder for deeper semantic analysis. Evaluated on eight diverse training corpora and two real-world datasets covering a decade of attacks, AURA achieves a macro F1-score of 0.9858 in-distribution and maintains scores above 0.94 on the NazPhish-Eval and GuenterTrap-Eval datasets, demonstrating strong generalization to new attack scenarios.
By Omran Berjawi, Walid fahs, Rida Khatoun
arXiv:2507.15393v2 Announce Type: replace-cross
Abstract: Phishing email is a critical step in the cybercrime kill chain due to the high reachability of victims' email accounts and the low cost of la...
By Ruofan Liu, Yun Lin, Yuxin Wang, Xiwen Teoh, Zhenkai Liang, Gongshen Liu, Haojin Zhu, Jin Song Dong
arXiv:2607. 18429v1 Announce Type: cross Abstract: Phishing emails remain one of the most persistent cybersecurity threats, and machine-learning classifiers are widely used to detect them.
By Tanveer Ahmed, Seyedali Pourmoafil
arXiv:2511. 12085v3 Announce Type: replace-cross Abstract: Phishing and related cyber threats are becoming increasingly sophisticated, with email-based phishing remaining the most persistent attack vector.
By Sajad U P
CoGReV is a hybrid framework that enhances machine‑learning phishing classifiers with a post‑hoc, non‑monotonic reasoning layer written in Answer Set Programming. It uses a confidence‑gated defeasible rule to revise low‑confidence phishing predictions toward legitimate only when website metadata is available, thereby allocating uncertain decisions to the reasoning layer while leaving confident ones to the classifier. The gated rule reduces false positives by 0.27 % of decisions and maintains recall within 0.7 % of the baseline, operating in linear time.
By Mainak Sen, Kumar Sankar Ray, Amlan Chakrabarti
arXiv:2608. 19901v1 Announce Type: cross Abstract: Agent Skills extend LLM agents with reusable instruction packages that may also include scripts, resources, and service configuration.
By Yue Wang, Yi Liu, Gelei Deng, Ying Zhang, Yuekang Li, Zhenyu Chen, Leo Zhang
The paper introduces a prompt‑injection detection framework for email assistants that models attacks as a chain of stages. It combines a text detector, stage‑specific verifiers, rule‑based risk signals, user intent consistency checks, and a logistic decision policy. Experiments on five benchmarks show the framework outperforms pretrained detectors, achieving a mean F1 of 0.406 versus 0.216, and demonstrate that training on benign emails resembling attacks reduces false alarms.
By Ahmad Hashmi, Dhyey Patel, Yunting Yin
arXiv:2606. 11471v1 Announce Type: cross Abstract: The expansion of the digital domain has resulted in a substantial increase in digital communication, with email emerging as one of the most prominent channels.
By Warren Fernando, Nikos Komninos
arXiv:2607. 02072v1 Announce Type: cross Abstract: Large language models (LLMs) are increasingly deployed in domains requiring guardrails to detect unsafe, off-topic, or adversarial prompts.
By Mahmoud Abdelfattah, Hamid Nasiri, Peter Garraghan
arXiv:2606. 18190v1 Announce Type: cross Abstract: Multi-stage cyberattacks span system, network, and browser logs.
By Abir Ashab Niloy, Ahmed Ryan, Imamul Hossain Rafi, Md Erfan, Md Rayhanur Rahman