English

In-context learning for the classification of manipulation techniques in phishing emails

Cryptography and Security 2025-07-01 v1 Artificial Intelligence

Abstract

Traditional phishing detection often overlooks psychological manipulation. This study investigates using Large Language Model (LLM) In-Context Learning (ICL) for fine-grained classification of phishing emails based on a taxonomy of 40 manipulation techniques. Using few-shot examples with GPT-4o-mini on real-world French phishing emails (SignalSpam), we evaluated performance against a human-annotated test set (100 emails). The approach effectively identifies prevalent techniques (e.g., Baiting, Curiosity Appeal, Request For Minor Favor) with a promising accuracy of 0.76. This work demonstrates ICL's potential for nuanced phishing analysis and provides insights into attacker strategies.

Keywords

Cite

@article{arxiv.2506.22515,
  title  = {In-context learning for the classification of manipulation techniques in phishing emails},
  author = {Antony Dalmiere and Guillaume Auriol and Vincent Nicomette and Pascal Marchand},
  journal= {arXiv preprint arXiv:2506.22515},
  year   = {2025}
}
R2 v1 2026-07-01T03:37:06.371Z