CFP last date
20 October 2026
Reseach Article

Detection of Artificial Intelligence-Generated Phishing Attacks using Transformer Models

by Samuel Okechukwu Nnaji, Anyalebechi Felicia Nneamaka, Christabel Linda Uchenwa, Abigail Eberechi Nwoka
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Number 142
Year of Publication: 2026
Authors: Samuel Okechukwu Nnaji, Anyalebechi Felicia Nneamaka, Christabel Linda Uchenwa, Abigail Eberechi Nwoka
10.5120/ijca209cd5833714

Samuel Okechukwu Nnaji, Anyalebechi Felicia Nneamaka, Christabel Linda Uchenwa, Abigail Eberechi Nwoka . Detection of Artificial Intelligence-Generated Phishing Attacks using Transformer Models. International Journal of Computer Applications. 187, 142 ( Sep 2026), 34-44. DOI=10.5120/ijca209cd5833714

@article{ 10.5120/ijca209cd5833714,
author = { Samuel Okechukwu Nnaji, Anyalebechi Felicia Nneamaka, Christabel Linda Uchenwa, Abigail Eberechi Nwoka },
title = { Detection of Artificial Intelligence-Generated Phishing Attacks using Transformer Models },
journal = { International Journal of Computer Applications },
issue_date = { Sep 2026 },
volume = { 187 },
number = { 142 },
month = { Sep },
year = { 2026 },
issn = { 0975-8887 },
pages = { 34-44 },
numpages = {9},
url = { https://ijcaonline.org/archives/volume187/number142/detection-of-artificial-intelligence-generated-phishing-attacks-using-transformer-models/ },
doi = { 10.5120/ijca209cd5833714 },
publisher = {Foundation of Computer Science (FCS), NY, USA},
address = {New York, USA}
}
%0 Journal Article
%1 2026-09-19T02:57:29.511761+05:30
%A Samuel Okechukwu Nnaji
%A Anyalebechi Felicia Nneamaka
%A Christabel Linda Uchenwa
%A Abigail Eberechi Nwoka
%T Detection of Artificial Intelligence-Generated Phishing Attacks using Transformer Models
%J International Journal of Computer Applications
%@ 0975-8887
%V 187
%N 142
%P 34-44
%D 2026
%I Foundation of Computer Science (FCS), NY, USA
Abstract

The proliferation of large language models (LLMs) such as GPT-4, Claude, and Llama has fundamentally altered the phishing threat landscape by enabling attackers to generate grammatically fluent, contextually convincing, and highly personalized phishing content at scale. Unlike traditional phishing emails, which often exhibit tell-tale linguistic errors and generic phrasing, artificial intelligence (AI)-generated phishing messages closely mimic legitimate human correspondence, substantially reducing the effectiveness of conventional rule-based and keyword-driven detection systems. This study proposes and evaluates a transformer-based framework for detecting AI-generated phishing attacks in enterprise email environments. A composite corpus of 15,000 labelled messages comprising legitimate correspondence, human-crafted phishing emails, and LLM-generated phishing emails synthesized from multiple generator models was constructed and used to fine-tune four transformer variants (BERT-base, DistilBERT, RoBERTa, and a proposed attention-fusion hybrid) alongside classical machine learning and recurrent baselines. The proposed hybrid model, which combines domain-adaptively pre-trained RoBERTa and DistilBERT encoders through an attention-weighted fusion layer, achieved the strongest performance, recording 97.8% accuracy, an F1-score of 97.5%, and an area under the receiver operating characteristic curve (AUC) of 0.991, outperforming all baseline models and the best-performing single transformer (RoBERTa, 96.1% accuracy) by a statistically meaningful margin. Explainability analysis using attention visualization further showed that the model consistently attended to psychological-pressure cues, spoofed-domain indicators, and stylistic hallmarks characteristic of machine-generated text. These findings demonstrate that transformer architectures, when combined with a purpose-built AI-generated phishing corpus, can meaningfully close the detection gap created by generative AI misuse and offer a viable foundation for next-generation, explainable email security systems.

References
  1. A. Basit, M. Zafar, X. Liu, A. R. Javed, Z. Jalil, and K. Kifayat, "A comprehensive survey of AI-enabled phishing attacks detection techniques," Telecommunication Systems, vol. 76, pp. 139–154, 2021.
  2. A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser, and I. Polosukhin, "Attention is all you need," in Advances in Neural Information Processing Systems, vol. 30, 2017.
  3. J. Devlin, M.-W. Chang, K. Lee, and K. Toutanova, "BERT: Pre-training of deep bidirectional transformers for language understanding," in Proc. NAACL-HLT, 2019, pp. 4171–4186.
  4. K. Han, A. Xiao, E. Wu, J. Guo, C. Xu, and Y. Wang, "Transformer in transformer," in Advances in Neural Information Processing Systems, vol. 34, 2021, pp. 15908–15919.
  5. S. Jamal, H. Wimmer, and I. H. Sarker, "An improved transformer-based model for detecting phishing, spam and ham emails: A large language model approach," Security and Privacy, vol. 7, no. 5, Art. e402, 2024.
  6. I. H. Sarker, H. Wimmer, and S. Jamal, "An explainable transformer-based model for phishing email detection: A large language model approach," arXiv preprint arXiv: 2402.13871, 2024 (revised 2025).
  7. M. A. Uddin, M. N. Islam, L. Maglaras, H. Janicke, and I. H. Sarker, "ExplainableDetector: Exploring transformer-based language modeling approach for SMS spam detection with explainability analysis," Digital Communications and Networks, vol. 11, no. 5, pp. 1504–1518, 2025.
  8. R. Melendez, M. Ptaszynski, and F. Masui, "Comparative investigation of traditional machine-learning models and transformer models for phishing email detection," Electronics, vol. 13, Art. 4877, 2024.
  9. H. Asliyuksek, O. Tonkal, and R. Kocaoglu, "A comparative evaluation of a multimodal approach for spam email classification using DistilBERT and structural features," Electronics, vol. 14, Art. 3855, 2025.
  10. M. Hosseinzadeh, U. Ali, S. Ali, R. Abbaszadi, F. S. Gharehchopogh, P. Khoshvaght, T. Porntaveetus, and J. Lansky, "Improving phishing email detection performance through deep learning with adaptive optimization," Scientific Reports, 2025.
  11. M. Safran and A. Musleh, "PhishingGNN: Phishing email detection using graph attention networks and transformer-based feature extraction," IEEE Access, vol. 13, 2025.
  12. M. Bethany, A. Galiopoulos, E. Bethany, M. B. Karkevandi, N. Vishwamitra, and P. Najafirad, "Lateral phishing with large language models: A large organization comparative study," IEEE Access, 2025 (arXiv:2401.09727, 2024).
  13. F. Heiding, B. Schneier, A. Vishwanath, J. Bernstein, and P. S. Park, "Devising and detecting phishing: Large language models vs. smaller human models," arXiv preprint arXiv:2308.12287, 2024.
  14. S. S. Roy, P. Thota, K. V. Naragam, and S. Nilizadeh, "From chatbots to phishbots? Phishing scam generation in commercial large language models," in Proc. 2024 IEEE Symp. Security and Privacy Workshops (SPW), 2024, pp. 221–221.
  15. C. S. Eze and L. Shamir, "Analysis and prevention of AI-based phishing email attacks," Electronics, vol. 13, no. 10, Art. 1839, 2024.
  16. K. Afane, W. Wei, Y. Mao, J. Farooq, and J. Chen, "Next-generation phishing: How LLM agents empower cyber attackers," in Proc. 2024 IEEE Int. Conf. Big Data (BigData), 2024, pp. 2558–2567.
  17. X. Wu et al., "Phish-Master: Leveraging large language models for advanced phishing email generation and detection," Applied Sciences, vol. 15, no. 22, Art. 12203, 2025.
  18. S. Nilizadeh et al., "SoK: Exposing the generation and detection gaps in LLM-generated phishing," arXiv preprint arXiv:2508.21457, 2025.
  19. Anonymous, "A systematic literature review of large language models in phishing attack generation and detection," ScienceDirect (in press), 2025/2026.
  20. Federal Bureau of Investigation, Internet Crime Complaint Center (IC3), Internet Crime Report 2024, U.S. Department of Justice, 2025.
  21. V. Sanh, L. Debut, J. Chaumond, and T. Wolf, "DistilBERT, a distilled version of BERT: Smaller, faster, cheaper and lighter," arXiv preprint arXiv:1910.01108, 2019.
  22. Y. Liu, M. Ott, N. Goyal, J. Du, M. Joshi, D. Chen, O. Levy, M. Lewis, L. Zettlemoyer, and V. Stoyanov, "RoBERTa: A robustly optimized BERT pretraining approach," arXiv preprint arXiv:1907.11692, 2019.
Index Terms

Computer Science
Information Sciences

Keywords

Phishing Detection; Transformer Models; Large Language Models; Bert; Roberta; Artificial Intelligence-Generated Attacks; Natural Language Processing; Cybersecurity; Explainable AI