AURA:用于电子邮件威胁检测的自适应不确定性路由分析
AURA: Adaptive Uncertainty-Routed Analysis for Email Threat Detection
浏览论文内容
中文总结 AI 辅助
本文提出AURA,一种多模态电子邮件威胁检测系统,通过两层架构量化URL分类器不确定性并升级模糊消息至Transformer编码器,在多个语料库上实现高F1分数,展现强泛化能力。
中文摘要 AI 辅助
电子邮件垃圾邮件和钓鱼攻击仍然是一个严重的安全威胁。攻击者越来越多地利用大型语言模型来制作上下文上具有说服力的恶意消息,而现有的垃圾邮件检测系统往往难以跟上步伐。跨多样化和不断演变的攻击场景的泛化能力有限,这降低了这些系统在实际部署后的有效性。本文介绍了自适应不确定性路由分析(AURA),一种多模态电子邮件威胁检测系统,它分析电子邮件的内容及其嵌入的URL。AURA围绕两层构建:第一层量化来自URL分类器的预测不确定性,只有模糊的消息才会升级到微调的Transformer编码器进行语义分析。该系统在八个异构训练语料库以及两个跨越十年对抗性活动的留出真实世界语料库上进行了评估。AURA在分布内达到了0.9858的宏F1分数,在NazPhish-Eval和GuenterTrap-Eval上分别保持了0.9502和0.9436,这证明了在真实分布偏移下的强大泛化能力。
英文摘要
Email spam and phishing attacks remain a critical security threat. Adversaries increasingly exploit large language models to craft contextually convincing malicious messages, and existing spam detection systems often struggle to keep pace. Generalization across diverse and evolving attack scenarios is limited, which reduces effectiveness once these systems are deployed in practice. This paper introduces Adaptive Uncertainty-Routed Analysis (AURA), a multimodal email threat detection system that analyzes both the content of an email and its embedded URLs. AURA is built around two layers: the first quantifies prediction uncertainty from a URL classifier, and only ambiguous messages are escalated to a fine-tuned transformer encoder for semantic analysis. The system is evaluated on eight heterogeneous training corpora together with two held-out real-world corpora spanning a decade of adversarial campaigns. AURA reaches a macro F1-score of 0.9858 in-distribution, and on NazPhish-Eval and GuenterTrap-Eval it maintains 0.9502 and 0.9436, respectively, which is evidence of robust generalization under genuine distribution shift.
发表机构
- Institut Polytechnique de Paris(巴黎综合理工学院)
- Télécom Paris(巴黎电信学院)
- Islamic University of Lebanon(黎巴嫩伊斯兰大学)
机构由 AI 辅助整理,请以论文原文为准。