arXiv Machine Learning

Evaluating and Combating the Impact of Concept Drift on the Performance of Machine Learning-Based Phishing Detection Systems

arXiv:2606. 11471v1 Announce Type: cross Abstract: The expansion of the digital domain has resulted in a substantial increase in digital communication, with email emerging as one of the most prominent channels.

arXiv Machine Learning
Sep 18

AURA: Adaptive Uncertainty-Routed Analysis for Email Threat Detection

AURA: Adaptive Uncertainty-Routed Analysis for Email Threat Detection is a multimodal system that evaluates both email content and embedded URLs to detect spam and phishing. It uses a two-layer approach: first, a URL classifier estimates prediction uncertainty, and only messages with high uncertainty are passed to a fine-tuned transformer encoder for deeper semantic analysis. Evaluated on eight diverse training corpora and two real-world datasets covering a decade of attacks, AURA achieves a macro F1-score of 0.9858 in-distribution and maintains scores above 0.94 on the NazPhish-Eval and GuenterTrap-Eval datasets, demonstrating strong generalization to new attack scenarios.

By Omran Berjawi, Walid fahs, Rida Khatoun
arXiv Computation and Language
6d ago

Prompt Injection Detection for Email Agents Through Attack Chain Modeling

The paper introduces a prompt‑injection detection framework for email assistants that models attacks as a chain of stages. It combines a text detector, stage‑specific verifiers, rule‑based risk signals, user intent consistency checks, and a logistic decision policy. Experiments on five benchmarks show the framework outperforms pretrained detectors, achieving a mean F1 of 0.406 versus 0.216, and demonstrate that training on benign emails resembling attacks reduces false alarms.

By Ahmad Hashmi, Dhyey Patel, Yunting Yin
arXiv AI
Sep 10

CoGReV: A Confidence-Gated Post-Hoc Non-Monotonic Belief Revision Framework for Phishing Website Classification

CoGReV is a hybrid framework that enhances machine‑learning phishing classifiers with a post‑hoc, non‑monotonic reasoning layer written in Answer Set Programming. It uses a confidence‑gated defeasible rule to revise low‑confidence phishing predictions toward legitimate only when website metadata is available, thereby allocating uncertain decisions to the reasoning layer while leaving confident ones to the classifier. The gated rule reduces false positives by 0.27 % of decisions and maintains recall within 0.7 % of the baseline, operating in linear time.

By Mainak Sen, Kumar Sankar Ray, Amlan Chakrabarti
arXiv Machine Learning
Sep 21

Identifying Security Platform Product Abuse with Machine Learning

arXiv:2609.21303v1 Announce Type: cross Abstract: Product abuse is an individually rare, but growing, problem across the SaaS industry. Highly sophisticated threat actors can misuse security platform...

By Shaefer Drew, Michael Brautbar, Paul Knight, Edward Raff, Lana Peric-McDermott, Simran Sarin, Nickolas Machado, Hanna Albright, Vitaly Zaytsev