{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,5]],"date-time":"2026-02-05T09:12:03Z","timestamp":1770282723899,"version":"3.49.0"},"reference-count":43,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:00:00Z","timestamp":1750204800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:00:00Z","timestamp":1750204800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,6,18]]},"DOI":"10.1109\/ntms65597.2025.11076905","type":"proceedings-article","created":{"date-parts":[[2025,7,18]],"date-time":"2025-07-18T17:42:27Z","timestamp":1752860547000},"page":"196-204","source":"Crossref","is-referenced-by-count":1,"title":["A Survey on Large Language Models in Phishing Detection"],"prefix":"10.1109","author":[{"given":"Muharrem Atakan","family":"\u015eent\u00fcrk","sequence":"first","affiliation":[{"name":"Istanbul University Fatih,Department of Computer Engineering,Istanbul,T&#x00FC;rkiye,34452"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"\u015eerif","family":"Bahtiyar","sequence":"additional","affiliation":[{"name":"Istanbul Technical University Maslak,Cyber Security and Privacy Research Lab SPFLab,Department of Computer Engineering,Istanbul,T&#x00FC;rkiye,34469"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/1290958.1290968"},{"key":"ref2","article-title":"large language model","year":"2024"},{"key":"ref3","article-title":"Language models are few-shot learners","author":"Brown","year":"2020","journal-title":"arXiv preprint arXiv:2005.14165"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2017.8004877"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.4018\/IJSPPC.320225"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00182"},{"key":"ref7","article-title":"A comprehensive overview of large language models (llms) for cyber defences: Opportunities and directions","author":"Hassanin","year":"2024","journal-title":"arXiv preprint arXiv:2405.14487"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3505983"},{"key":"ref9","article-title":"Detecting phishing sites using chatgpt","author":"Koide","year":"2023","journal-title":"arXiv preprint arXiv:2306.05816"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3292171"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10095719"},{"key":"ref12","article-title":"Generating phishing attacks using chatgpt","author":"Roy","year":"2023","journal-title":"arXiv preprint arXiv:2305.05133"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3605764.3623985"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627111"},{"key":"ref15","article-title":"From ml to 1 lm: Evaluating the robustness of phishing webpage detection models against adversarial attacks","author":"Kulkarni","year":"2024","journal-title":"arXiv preprint arXiv:2407.20361"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3483905"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/eCrime66200.2024.00007"},{"key":"ref18","article-title":"It\u2019s scary easy to use chatgpt to write phishing emails","author":"Fowler","year":"2023"},{"key":"ref19","article-title":"Devising and detecting phishing: Large language models vs. smaller human models","author":"Heiding","year":"2023","journal-title":"arXiv preprint arXiv:2308.12287"},{"key":"ref20","article-title":"Spear phishing with large language models","author":"Hazell","year":"2023","journal-title":"arXiv preprint arXiv:2305.06972"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC57700.2023.00198"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/BigData55660.2022.10020452"},{"key":"ref23","article-title":"Targeted phishing campaigns using large scale language models","author":"Karanjai","year":"2022","journal-title":"arXiv preprint arXiv:2301.00665"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/WI-IAT55865.2022.00028"},{"key":"ref25","article-title":"Large language model lateral spear phishing: A comparative study in large-scale organizational settings","author":"Bethany","year":"2024","journal-title":"arXiv preprint arXiv:2401.09727"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1002\/spy2.402"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3665451.3665531"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/BigData62323.2024.10825018"},{"key":"ref29","article-title":"Large language models spot phishing emails with surprising accuracy: A comparative analysis of performance","author":"Patel","year":"2024","journal-title":"arXiv preprint arXiv:2404.15485"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/BDAI62182.2024.10692765"},{"key":"ref31","article-title":"An explainable transformer-based model for phishing email detection: A large language model approach","author":"Uddin","year":"2024","journal-title":"arXiv preprint arXiv:2402.13871"},{"key":"ref32","article-title":"Adapting to cyber threats: A phishing evolution network (pen) framework for phishing generation and analyzing evolution patterns using large language models","author":"Chen","year":"2024","journal-title":"arXiv preprint arXiv:2411.11389"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/DSC63325.2024.00017"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/eIT53891.2022.9813922"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3538491"},{"key":"ref36","article-title":"Assessing ai vs human-authored spear phishing sms attacks: An empirical study using the trapd method","author":"Francia","year":"2024","journal-title":"arXiv preprint arXiv:2406.13049"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ISDFS60797.2024.10527300"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00182"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3300381"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TPS-ISA58951.2023.00045"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-99-7969-1_18"},{"key":"ref42","article-title":"Large language models in cybersecurity: State-of-the-art","author":"Motlagh","year":"2024","journal-title":"arXiv preprint arXiv:2402.00891"},{"key":"ref43","article-title":"Large language models for cyber security: A systematic literature review","author":"Xu","year":"2024","journal-title":"arXiv preprint arXiv:2405.04760"}],"event":{"name":"2025 12th IFIP International Conference on New Technologies, Mobility and Security (NTMS)","location":"Paris, France","start":{"date-parts":[[2025,6,18]]},"end":{"date-parts":[[2025,6,20]]}},"container-title":["2025 12th IFIP International Conference on New Technologies, Mobility and Security (NTMS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11076604\/11076612\/11076905.pdf?arnumber=11076905","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,19]],"date-time":"2025-07-19T04:50:54Z","timestamp":1752900654000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11076905\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,18]]},"references-count":43,"URL":"https:\/\/doi.org\/10.1109\/ntms65597.2025.11076905","relation":{},"subject":[],"published":{"date-parts":[[2025,6,18]]}}}