arXiv ScienceSearch

arXiv · 2508.21457

SoK: Systematizing Generation, Characteristics, and Defenses in LLM-Generated Phishing

Abstract

The rapid advancement of Large Language Models (LLMs), with their growing abuse in phishing, has enabled phishing content, including deceptive pretexts and other persuasive elements, to be generated at a scale difficult to achieve manually. This growing misuse of LLMs in phishing raises questions about potential LLM-driven changes in phishing characteristics, associated security implications for users, and the resulting challenges to existing defenses. While prior research has examined individual dimensions, including threats of LLM abuse, LLM-driven phishing, user susceptibility to phishing, and phishing defenses, these efforts remain fragmented and have not been consolidated into a comprehensive understanding of how these dimensions interrelate. To address this research gap, we provide a systematic examination of the LLM-generated phishing landscape, including a taxonomy of LLM manipulation methods, characteristics associated with LLM-generated phishing threats, and a taxonomy of defenses aligned with these manipulation methods. We also benchmark five academic and five industrial phishing detectors across datasets associated with different LLM-based generation methods. We further extract insights and research gaps that suggest promising directions for future research in this growing area. Our findings underscore the need for countermeasures that are evaluated across LLM generators and manipulation strategies. Our work provides a systematic foundation for studying LLM-generated phishing, enabling more consistent comparison and evaluation across the community.

Explore related subjects

Keep this discovery

BibTeXRIS

Fengchao Chen, Tingmin Wu, Van Nguyen, Carsten Rudolph. 2026-08-29. SoK: Systematizing Generation, Characteristics, and Defenses in LLM-Generated Phishing. https://arxiv.org/abs/2508.21457

Cite the original work for its findings. Save a collection to share your selection of sources.

Discover connections

Connections use source metadata and explicit phrase matches, not verified experimental comparisons.

KEEP EXPLORING

Related papers

The Impact of Magma: A Ground-Truth Fuzzing Benchmark

Magma is an open-source and ground-truth fuzzing benchmark that enables uniform fuzzer evaluation and comparison. Magma was originally released with a research paper published at ACM SIGMETRICS 2021. This short paper explains the motivation, the design, and the impact of Magma, with a description of extensions to the original benchmark.

cs.CR

Permutation polynomials over finite fields from low-degree rational functions

This paper considers permutation polynomials over the finite field $F_{q^2}$ in even characteristic by utilizing low-degree permutation rational functions over $F_q$. As a result, we obtain two classes of permutation binomials and six classes of permutation pentanomials over $F_{q^2}$. Additionally, we show that the obtained binomials and pentanomials are quasi-multiplicative inequivalent to the known ones in the literature.

cs.CR

Using Hyper-V Sockets for Real-time Data Extraction from a Malware Analysis Sandbox

We present how Hyper-V sockets can be used as a real-time communication channel for a malware analysis sandbox. We show that, compared to WinSock TCP sockets, Hyper-V sockets are not subject to TCP/IP-layer blocking and are not enumerated by common TCP connection listing tools. We compare the throughput of the two communication channels as a function of buffer size.

cs.CR