← Studies

Supports · 2024

Devising and Detecting Phishing Emails Using Large Language Models

Fredrik Heiding, Bruce Schneier, Arun Vishwanath, Jeremy Bernstein, Peter S. Park

Key finding

Click-through was 19-28% for generic control phishing, 30-44% for GPT-4 generated emails, 69-79% for emails designed by hand using the V-Triad cognitive-bias rules, and 43-81% for GPT-4 combined with the V-Triad. Large language models were also fairly good at detecting phishing intent, sometimes beating humans, and cut attacker costs.

Why it matters

Shows AI lowers the cost of psychologically tuned emails, raising the stakes for tactic-level recognition rather than spotting typos.

Informs Cite
Heiding, F., Schneier, B., Vishwanath, A., Bernstein, J., & Park, P. S. (2024). Devising and Detecting Phishing Emails Using Large Language Models. IEEE Access, 12. https://doi.org/10.1109/ACCESS.2024.3375882