The paper introduces a prompt‑injection detection framework for email assistants that models attacks as a chain of stages. It combines a text detector, stage‑specific verifiers, rule‑based risk signals, user intent consistency checks, and a logistic decision policy. Experiments on five benchmarks show the framework outperforms pretrained detectors, achieving a mean F1 of 0.406 versus 0.216, and demonstrate that training on benign emails resembling attacks reduces false alarms.
By Ahmad Hashmi, Dhyey Patel, Yunting Yin
arXiv:2606. 11471v1 Announce Type: cross Abstract: The expansion of the digital domain has resulted in a substantial increase in digital communication, with email emerging as one of the most prominent channels.
By Warren Fernando, Nikos Komninos
arXiv:2507.15393v2 Announce Type: replace-cross
Abstract: Phishing email is a critical step in the cybercrime kill chain due to the high reachability of victims' email accounts and the low cost of la...
By Ruofan Liu, Yun Lin, Yuxin Wang, Xiwen Teoh, Zhenkai Liang, Gongshen Liu, Haojin Zhu, Jin Song Dong
arXiv:2606. 21690v2 Announce Type: replace-cross Abstract: Phishing is a multi-modal threat.
By Saifelden M. Ismail, Aser O. Ibrahim, Omar A. Mahmoud
arXiv:2602. 09222v2 Announce Type: replace-cross Abstract: Large language model (LLM) based web agents are increasingly deployed to automate complex online tasks by directly interacting with web sites and performing actions on users' behalf.
By Georgios Syros, Evan Rose, Brian Grinstead, Christoph Kerschbaumer, William Robertson, Cristina Nita-Rotaru, Alina Oprea
arXiv:2608. 15893v1 Announce Type: new Abstract: The rise of social media bots poses a persistent threat, enabling misinformation, opinion manipulation, and the erosion of trust in online platforms.
By Nof Orenstein, Yoni Birman