Scholay

学术搜索 · AI 审稿 · LaTeX 协作

Phish-Master: Leveraging Large Language Models for Advanced Phishing Email Generation and Detection

作者:Weihong Han, Junyi Zhu, Chenhui Zhang, Zhiqiang Zhang, Yangyang Mei, Le Wang · 发表于:Applied Sciences · 年份:2025 · DOI:10.3390/app152212203 · 被引用次数:2 · 研究领域:Spam and Phishing Detection、Advanced Malware Detection Techniques、Misinformation and Its Impacts

Phishing emails present a significant and persistent cybersecurity threat to individuals and organizations globally due to the difficulty in detecting these malicious messages. Large Language Models (LLMs) have inadvertently intensified this challenge by facilitating the automated creation of high-quality, covert phishing emails that can evade traditional rule-based detection systems. In this study, we examine the offensive capabilities of LLMs in generating phishing emails and introduce Phish-Master, a novel algorithm that integrates Chain-of-Thought (COT) reasoning, MetaPrompt techniques, and domain-specific insights to produce phishing emails designed to bypass enterprise-level filters. Our experiment, involving 100 malicious emails, validates Phish-Master’s real-world effectiveness, achieving a 99% evasion rate within authentic campus networks, successfully bypassing filters and targeting recipients, a testament to its capability in navigating complex network environments. To counteract the threat posed by Phish-Master and similar LLM-generated phishing emails, we have developed a multi-machine learning model integration framework trained on Kaggle’s phishing email dataset. This framework achieved an impressive detection rate of 99.87% on a rigorous test set of LLM-generated phishing emails, highlighting the critical role of our specialized dataset in enabling the detection tool to effectively recognize sophisticated patterns in LLM-crafted phishing emails. This study hig...