Adaptive system improves email spam and phishing detection accuracy

AURA: Adaptive Uncertainty-Routed Analysis for Email Threat Detection

Machine Learning

Summary

Spam and phishing emails are dangerous because they try to trick people and can be hard to spot. The authors created a new system called AURA that looks closely at both the message and any links inside it. AURA first checks if the link is suspicious and only digs deeper into the email if it’s unsure. This two-step method helps the system better spot tricky emails, even ones it hasn't seen before, making email safer for everyone.

What this means in practice

  • For email security teams: Enhance email filtering systems by selectively analyzing suspicious URLs to improve detection of evolving spam and phishing attacks.
  • For cybersecurity service providers: Develop more robust managed email security services that adapt to novel and shifting phishing strategies using uncertainty-based message routing.$Commercial implications: Enables creation of advanced email threat detection products that maintain high accuracy against new phishing tactics for enterprise customers.

Authors

Omran Berjawi, Walid fahs, Rida Khatoun

Abstract

Email spam and phishing attacks remain a critical security threat. Adversaries increasingly exploit large language models to craft contextually convincing malicious messages, and existing spam detection systems often struggle to keep pace. Generalization across diverse and evolving attack scenarios is limited, which reduces effectiveness once these systems are deployed in practice. This paper introduces Adaptive Uncertainty-Routed Analysis (AURA), a multimodal email threat detection system that analyzes both the content of an email and its embedded URLs. AURA is built around two layers: the first quantifies prediction uncertainty from a URL classifier, and only ambiguous messages are escalated to a fine-tuned transformer encoder for semantic analysis. The system is evaluated on eight heterogeneous training corpora together with two held-out real-world corpora spanning a decade of adversarial campaigns. AURA reaches a macro F1-score of 0.9858 in-distribution, and on NazPhish-Eval and GuenterTrap-Eval it maintains 0.9502 and 0.9436, respectively, which is evidence of robust generalization under genuine distribution shift.