arXiv ScienceSearch

arXiv subjects

Carsten Rudolph

Publications and source records attributed to Carsten Rudolph.

1 recordsLinked to original sources

SoK: Systematizing Generation, Characteristics, and Defenses in LLM-Generated Phishing

The rapid advancement of Large Language Models (LLMs), with their growing abuse in phishing, has enabled phishing content, including deceptive pretexts and other persuasive elements, to be generated at a scale difficult to achieve manually. This growing misuse of LLMs in phishing raises questions about potential LLM-driven changes in phishing characteristics, associated security implications for users, and the resulting challenges to existing defenses. While prior research has examined individual dimensions, including threats of LLM abuse, LLM-driven phishing, user susceptibility to phishing, and phishing defenses, these efforts remain fragmented and have not been consolidated into a comprehensive understanding of how these dimensions interrelate. To address this research gap, we provide a systematic examination of the LLM-generated phishing landscape, including a taxonomy of LLM manipulation methods, characteristics associated with LLM-generated phishing threats, and a taxonomy of defenses aligned with these manipulation methods. We also benchmark five academic and five industrial phishing detectors across datasets associated with different LLM-based generation methods. We further extract insights and research gaps that suggest promising directions for future research in this growing area. Our findings underscore the need for countermeasures that are evaluated across LLM generators and manipulation strategies. Our work provides a systematic foundation for studying LLM-generated phishing, enabling more consistent comparison and evaluation across the community.

cs.CR