iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Commercial LPG Prices Cut by Over Rs 200; Delhi, Kolkata 19-kg Cylinder Rates Published US Stock Markets Rally as Chip Stock Gains Lift Nasdaq, S&P 500 and Dow SEBI Clarifies Unlisted Share Sale Rules: 200-Buyer Private Deal Limit GeM completes 10 years as India's trusted digital public procurement platform Moody's Assigns First-Time Baa2 Rating to RBL Bank, One Notch Above India's Sovereign Sebi Bars Zee's Subhash Chandra, Punit Goenka From Market for One Year Zepto Defers IPO by Two to Three Quarters After Tepid Investor Response Tim Cook: India Among Apple's Best Global Markets as June Quarter Records Revenue Domestic funds reach record 21% stake in Indian companies as FPI ownership drops to 17% Cybercriminals widen net as assessees rush to meet I-T return filing deadline Commercial LPG Prices Cut by Over Rs 200; Delhi, Kolkata 19-kg Cylinder Rates Published US Stock Markets Rally as Chip Stock Gains Lift Nasdaq, S&P 500 and Dow SEBI Clarifies Unlisted Share Sale Rules: 200-Buyer Private Deal Limit GeM completes 10 years as India's trusted digital public procurement platform Moody's Assigns First-Time Baa2 Rating to RBL Bank, One Notch Above India's Sovereign Sebi Bars Zee's Subhash Chandra, Punit Goenka From Market for One Year Zepto Defers IPO by Two to Three Quarters After Tepid Investor Response Tim Cook: India Among Apple's Best Global Markets as June Quarter Records Revenue Domestic funds reach record 21% stake in Indian companies as FPI ownership drops to 17% Cybercriminals widen net as assessees rush to meet I-T return filing deadline
Home ›› Technology ›› Ai ›› Llms ›› New LLM Framework Detects Phishing Emails with Over 90% Accuracy

New LLM Framework Detects Phishing Emails with Over 90% Accuracy

A paper on arXiv introduces LLMPEA, a framework using GPT-4o, Claude Sonnet 4, and Grok-3 to detect phishing emails with over 90% accuracy. The study also reveals vulnerabilities to adversarial attacks, prompt injection, and multilingual attacks, emphasizing the need for hardening before deployment.

iG
iGEN Editorial
June 16, 2026
New LLM Framework Detects Phishing Emails with Over 90% Accuracy

Phishing remains one of the most prevalent and globally consequential vectors of cyber intrusion, affecting organizations worldwide. Researchers have proposed a new framework, LLMPEA, that leverages large language models (LLMs) to detect phishing emails with over 90% accuracy, according to a paper published on arXiv. The framework is designed to counter evolving attacks that exploit the fundamental architectures of LLMs.

The LLMPEA Framework

The LLMPEA (LLM-based Phishing Email Attack detection) framework evaluates three frontier LLMs: GPT-4o (OpenAI), Claude Sonnet 4 (Anthropic), and Grok-3 (xAI). The researchers employed comprehensive prompting design to assess the feasibility, robustness, and limitations of these models against phishing email attacks. According to the paper, the empirical analysis reveals that LLMs can detect phishing emails with over 90% accuracy.

Performance Across Models

All three models demonstrated strong performance on standard phishing detection tasks. However, the paper highlights significant weaknesses: LLM-based phishing detection systems could be exploited by adversarial attacks, prompt injection, and multilingual attacks. These attack vectors are specifically designed to exploit architectural vulnerabilities inherent in current LLMs. The authors note that current LLMs require substantial hardening before deployment in email security systems, particularly against coordinated multi-vector attacks.

Attack Vector Description
Prompt Injection Maliciously crafted inputs to alter model behavior
Text Refinement Subtle rewording to evade detection
Multilingual Attacks Using non-English languages to bypass filters

Vulnerabilities and Challenges

The paper explicitly identifies the attack vectors tested: prompt injection, text refinement, and multilingual attacks. These are coordinated multi-vector attacks that exploit architectural vulnerabilities. The findings provide critical insights for LLM-based phishing detection in real-world settings, where attackers exploit multiple vulnerabilities in combination. The researchers emphasize that hardening measures—such as adversarial training and input sanitization—are necessary before these systems can be reliably deployed.

Implications for Enterprise Email Security

For enterprise technology leaders, the results underscore both the promise and the risks of adopting LLM-based phishing detection. Achieving over 90% accuracy is encouraging, but the identified vulnerabilities mean that organizations cannot rely solely on LLMs without additional safeguards. As phishing grows more sophisticated—especially against systems that deploy LLM applications—enterprises should consider layered security approaches. These combine LLM detection with traditional rule-based systems, user training, and continuous monitoring. The paper, authored by Hasan, Najmul, BusiReddyGari, Prashanth, Zhao, Haitao, Ren, Yihao, Xu, Jinsheng, Zhang, and Shaohu, provides a foundation for hardening LLMs against coordinated attacks. Decision-makers should weigh the accuracy gains against the need for robust defensive postures.


Sources:

Keep Reading

Recommended Stories

New Method LUCID Detects Hallucinations in LLM-Based Knowledge Graph Reasoning Technology

New Method LUCID Detects Hallucinations in LLM-Based Knowledge Graph Reasoning

Researchers introduce LUCID, the first hallucination detection method designed for large language model-based knowledge graph reasoning. By jointly leveraging attention scores, KG semantics, and structural information via a graph neural network, LUCID achieves state-of-the-art performance across nine datasets compared to 15 baselines. The method addresses a critical gap where existing detection techniques overlook structural information in knowledge graphs.

June 20, 2026
Apple's Hide My Email Vulnerability Exposes User Addresses for Over a Year Technology

Apple's Hide My Email Vulnerability Exposes User Addresses for Over a Year

A vulnerability in Apple's Hide My Email service has been leaking users' real email addresses for at least a year, according to security researcher Tyler Murphy. In tests, all Hide My Email addresses were exploitable. Apple has acknowledged the issue but it remains unpatched. This story is part of a broader security roundup covering Pegasus spyware, Google's EU warnings, Meta chatbot testing, and the arrest of a Scattered Spider hacker.

July 4, 2026
Beyond Reasoning Gains: Mitigating General-Capability Forgetting in Large Reasoning Models Technology

Beyond Reasoning Gains: Mitigating General-Capability Forgetting in Large Reasoning Models

A new research paper from arXiv shows that reinforcement learning with verifiable rewards (RLVR) can cause large reasoning models to forget foundational capabilities like perception and faithfulness. The authors propose RECAP, a replay strategy with dynamic objective reweighting that preserves general knowledge while maintaining reasoning gains.

June 21, 2026
Fine-Tuning LLMs for Vulnerability Detection Fails to Improve Security Reasoning, Study Finds Technology

Fine-Tuning LLMs for Vulnerability Detection Fails to Improve Security Reasoning, Study Finds

A new study introduces CWE-Trace, a framework for evaluating LLM vulnerability detection using Linux kernel samples. It finds that fine-tuning and data contamination do not improve security reasoning; detection accuracy remains near chance, and models lack genuine comprehension.

June 21, 2026