Aziz, Farouk, Oláh, Norbert (2026) LLM-Augmented Machine Learning for Phishing Email Detection: Enhancing Classification, Explainability, and Multilingual Support In: Proceedings of the 13th International Conference on Applied Informatics. Eger, Eszterházy Károly Catholic University Líceum Publisher. pp. 21-33.
|
pdf
ICAI2026-pp21-33.pdf Download (2MB) [error in script] |
Absztrakt (kivonat)
Nowadays, email is the world’s primary communication channel, making it a dominant vector for phishing attacks that exploit urgency, authority, and trust. Advances in Large Language Models (LLMs) have intensified this threat by enabling attackers to generate persuasive, context-aware, and multilingual phishing emails at low cost. Traditional machine learning (ML) approaches are no longer sufficient, as phishing techniques have evolved with the widespread public use of AI. These systems also face the scarcity of datasets for non-English content and the lack of human-friendly explanations of model decisions. Large Language Models can address these limitations, but are costly and impractical for large-scale deployment given that billions of emails are sent daily. This paper proposes a selective hybrid framework combining ML with LLMs in a cost-aware architecture. LLMs are invoked selectively to correct ML mistakes, translate non-English emails for a single English-trained classifier, and generate on-demand human-readable explanations of model decisions. GPT-4, Claude, and DeepSeek were independently evaluated across these three tasks to identify which performs best and fastest. The ML mistakes were forwarded to each LLM using task-specific prompts, translation was assessed across 18 languages, and explainability was evaluated by converting Local Interpretable Model-agnostic Explanations (LIME) feature attributions into natural language and measuring readability. A Term Frequency–Inverse Document Frequency (TF-IDF) based Linear Support Vector Machine (SVM) trained on approximately 14.000 English emails serves as the baseline classifier. The results confirm improvements in classification robustness, multilingual coverage, and explainability, while keeping computational overhead well below universal LLM pipelines. The three LLMs showed distinct strengths across tasks, highlighting that model selection should be tailored to each role within the architecture.
| Mű típusa: | Könyvrészlet - Book section |
|---|---|
| Szerző: | Szerző neve Email MTMT azonosító ORCID azonosító Közreműködés Aziz, Farouk NEM RÉSZLETEZETT NEM RÉSZLETEZETT NEM RÉSZLETEZETT Szerző Oláh, Norbert NEM RÉSZLETEZETT NEM RÉSZLETEZETT NEM RÉSZLETEZETT Szerző |
| Megjegyzés: | This research was conducted for the 13th International Conference on Applied Informatics. |
| Kapcsolódó URL-ek: | |
| Kulcsszavak: | phishing detection, large language models, machine learning, selective hybrid architecture, explainability, multilingual classification |
| Nyelv: | angol |
| DOI azonosító: | 10.17048/icai.2026.21 |
| Felhasználó: | Tibor Gál |
| Dátum: | 22 Szep 2026 06:40 |
| Utolsó módosítás: | 22 Szep 2026 06:40 |
| URI: | http://publikacio.uni-eszterhazy.hu/id/eprint/9432 |
![]() |
Tétel nézet |
