Devising and Detecting Phishing Emails Using Large Language Models

被引:9
|
作者
Heiding, Fredrik [1 ,2 ]
Schneier, Bruce [3 ]
Vishwanath, Arun [4 ]
Bernstein, Jeremy [5 ]
Park, Peter S. [5 ]
机构
[1] Harvard Univ, Harvard John A Paulson Sch Engn & Appl Sci, Cambridge, MA 02138 USA
[2] KTH Royal Inst Technol, S-11428 Stockholm, Sweden
[3] Harvard Univ, Harvard Kennedy Sch, Cambridge, MA 02138 USA
[4] Avant Res Grp, Buffalo, NY 14214 USA
[5] MIT, Cambridge, MA 02139 USA
关键词
Phishing; large language models; social engineering; artificial intelligence;
D O I
10.1109/ACCESS.2024.3375882
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
AI programs, built using large language models, make it possible to automatically create phishing emails based on a few data points about a user. The V-Triad is a set of rules for manually designing phishing emails to exploit our cognitive heuristics and biases. In this study, we compare the performance of phishing emails created automatically by GPT-4 and manually using the V-Triad. We also combine GPT-4 with the V-Triad to assess their combined potential. A fourth group, exposed to generic phishing emails, was our control group. We use a red teaming approach by simulating attackers and emailing 112 participants recruited for the study. The control group emails received a click-through rate between 19-28%, the GPT-generated emails 30-44%, emails generated by the V-Triad 69-79%, and emails generated by GPT and the V-Triad 43-81%. Each participant was asked to explain why they pressed or did not press a link in the email. These answers often contradict each other, highlighting the importance of personal differences. Next, we used four popular large language models (GPT, Claude, PaLM, and LLaMA) to detect the intention of phishing emails and compare the results to human detection. The language models demonstrated a strong ability to detect malicious intent, even in non-obvious phishing emails. They sometimes surpassed human detection, although often being slightly less accurate than humans. Finally, we analyze of the economic aspects of AI-enabled phishing attacks, showing how large language models increase the incentives of phishing and spear phishing by reducing their costs.
引用
收藏
页码:42131 / 42146
页数:16
相关论文
共 50 条
  • [21] Automation of Network Configuration Generation using Large Language Models
    Chakraborty, Supratim
    Chitta, Nithin
    Sundaresan, Rajesh
    2024 20TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT, CNSM 2024, 2024,
  • [22] Dual Adapter Tuning of Vision–Language Models Using Large Language Models
    Mohammad Reza Zarei
    Abbas Akkasi
    Majid Komeili
    International Journal of Computational Intelligence Systems, 18 (1)
  • [23] Detecting Ambiguous Phishing Certificates using Machine Learning
    Homayoun, Sajad
    Hageman, Kaspar
    Afzal-Houshmand, Sam
    36TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2022), 2022, : 1 - 6
  • [24] Using Large Language Models in Business Processes
    Grisold, Thomas
    vom Brocke, Jan
    Kratsch, Wolfgang
    Mendling, Jan
    Vidgof, Maxim
    BUSINESS PROCESS MANAGEMENT, BPM 2023, 2023, 14159 : XXIX - XXXI
  • [25] Prediction of tumor board procedural recommendations using large language models
    Aubreville, Marc
    Ganz, Jonathan
    Ammeling, Jonas
    Rosbach, Emely
    Gehrke, Thomas
    Scherzad, Agmal
    Hackenberg, Stephan
    Goncalves, Miguel
    EUROPEAN ARCHIVES OF OTO-RHINO-LARYNGOLOGY, 2025, 282 (03) : 1619 - 1629
  • [26] Assessing the possibility of using large language models in ocular surface diseases
    Ling, Qian
    Xu, Zi-Song
    Zeng, Yan-Mei
    Hong, Qi
    Qian, Xian-Zhe
    Hu, Jin-Yu
    Pei, Chong-Gang
    Wei, Hong
    Zou, Jie
    Chen, Cheng
    Wang, Xiao-Yu
    Chen, Xu
    Wu, Zhen-Kai
    Shao, Yi
    INTERNATIONAL JOURNAL OF OPHTHALMOLOGY, 2025, 18 (01) : 1 - 8
  • [27] Accelerating Pharmacovigilance using Large Language Models
    Prakash, Mukkamala Venkata Sai
    Parab, Ganesh
    Veeramalla, Meghana
    Reddy, Siddartha
    Varun, V.
    Gopalakrishnan, Saisubramaniam
    Pagidipally, Vishal
    Vaddina, Vishal
    PROCEEDINGS OF THE 17TH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, WSDM 2024, 2024, : 1182 - 1183
  • [28] Evolution and Prospects of Foundation Models: From Large Language Models to Large Multimodal Models
    Chen, Zheyi
    Xu, Liuchang
    Zheng, Hongting
    Chen, Luyao
    Tolba, Amr
    Zhao, Liang
    Yu, Keping
    Feng, Hailin
    CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 80 (02): : 1753 - 1808
  • [29] Application of Large Language Models in Cybersecurity: A Systematic Literature Review
    Hasanov, Ismayil
    Virtanen, Seppo
    Hakkala, Antti
    Isoaho, Jouni
    IEEE ACCESS, 2024, 12 : 176751 - 176778
  • [30] WHO RESPONDS TO PHISHING EMAILS? AN INTERNATIONAL INVESTIGATION OF 15-YEAR-OLDS USING PISA DATA
    Jerrim, John
    BRITISH JOURNAL OF EDUCATIONAL STUDIES, 2023, 71 (06) : 701 - 724