arrow
Return

Evaluating large language models’ ability to automate spear phishing

delete2026-02-06
delete0
PRE
AI
F
Fred Heiding
S
Simon Lermen
A
Andrew Kao
C
Claudio Mayrink Verdun
B
Bruce Schneier
A
Arun Vishwanath
DOI:10.1016/j.eswa.2026.131546delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
• Examines fully automated AI spear-phishing attacks validated on 101 human subjects. • AI phishing emails achieved  ∼ 54–56% click-through, on par with human experts. • Economic analysis shows AI phishing automation can boost attacker ROI by up to 50 × . • Human-subject study approved by university IRB and ethically reviewed. • Priming models for suspicion improved detection accuracy while maintaining low FP.
Keywords:
AI spear-phishing
large language models
click-through rate
attacker ROI
human subject study

Journal

Expert Systems with Applications cover
Expert Systems with Applications
IF:
7.5
Papers:
2.9W
Citations:
10.2W

Organization

H
Harvard University
Scholars:
26.5W
Papers: 22.0W
Citations: 28.7W
I
independent researcher
Scholars:
732
Papers: 652
Citations: 0
A
avant research group
Scholars:
1
Papers: 1
Citations: 0
researcher View more organizations