PhishGuard: Integrating Fine-Tuned Large Language Models (LLMs) into Password Management
- 1 School of Cybersecurity & Privacy (SCP), Georgia Institute of Technology, Atlanta, Georgia, USA
- 2 School of Cybersecurity & Privacy (SCP), Georgia Institute of Technology, Atlanta, Georgia, USA
Abstract
In the digital age, phishing attacks have been a persistent security threat leveraged by traditional password management systems that are not able to verify the authenticity of websites. This paper presents an approach to embedding sophisticated phishing detection within a password manager’s framework, called PhishGuard. PhishGuard uses a Large Language Model (LLM), specifically a fine-tuned BERT algorithm that works in real time, where URLs fed by the user in the credentials are analyzed and authenticated. This approach enhances user security with its provision of real-time protection from phishing attempts. Through rigorous testing, this paper illustrates how PhishGuard has scored well in tests that measure accuracy, precision, recall, and false positive rates.
- Prakash, P., Kumar, M., Kompella, R.R. and Gupta, M. (2010) Phishnet: Predictive Blacklisting to Detect Phishing Attacks. 2010 Proceedings IEEE INFOCOM , San Diego, 14-19 March 2010, 1-5. https://doi.org/10.1109/infcom.2010.5462216
- Felegyhazi, M., Kreibich, C. and Paxson, V. (2010) On the Potential of Proactive Domain Blacklisting. Proceedings of the 3 rd USENIX Conference on Large - Scale Exploits and Emergent Threats : Botnets , Spyware , Worms , and More , California, 27 April 2010, 6.
- Sheng, S., Wardman, B., Warner, G., Cranor, L.F., Hong, J. and Zhang, C. (2010) An Empirical Analysis of Phishing Blacklists. Proceedings of the 6 th Conference on Email and Anti - Spam , California, 16-17 July 2009.
- Siganevich, S. (2024) Why 2FA Multi-Factor Authentication Is No Longer Sufficient to Stop Phishing. Seraphic Security. https://seraphicsecurity.com/resources/blog/2fa-multi-factor-authentication-is-not-sufficient-to-stop-phishing/
- Bhopen Singh, O. and Tahbildar, H. (2015) A Literature Survey on Anti-Phishing Browser Extensions. International Journal of Computer Science & Engineering Survey , 6, 21-37. https://doi.org/10.5121/ijcses.2015.6402
- Jain, A.K. and Gupta, B.B. (2018) Towards Detection of Phishing Websites on Client-Side Using AI Based Approach. Telecommunication System s , 68, 687-700.
- Jain, A.K. and Gupta, B.B. (2019) An AI-Based Approach for Phishing Detection Using Hyperlinks Information. Journal of Ambient Intelligence and Humanized Computing , 10, 2015-2028.
- Rao, R.S. and Pais, A.R. (2019) Two Level Filtering Mechanism to Detect Phishing Sites Using Lightweight Visual Similarity Approach. Journal of Ambient Intelligence and Humanized Computing , 9, 3853-3872.
- Jain, A.K. and Gupta, B.B. (2017) Two-Level Authentication Approach to Protect from Phishing Attacks in Real Time. Journal of Ambient Intelligence and Humanized Computing , 9, 1783-1796.
- Rao, R.S., Umarekar, A. and Pais, A.R. (2021) Application of Word Embedding and Machine Learning in Detecting Phishing Websites. Telecommunication Systems , 79, 33-45. https://doi.org/10.1007/s11235-021-00850-6
- Guo, B., Zhang, Y., Xu, C., Shi, F., Li, Y. and Zhang, M. (2021) Hinphish: An Effective Phishing Detection Approach Based on Heterogeneous Information Networks. Applied Sciences , 11, Article No. 9733. https://doi.org/10.3390/app11209733
- Sahingoz, O.K., Buber, E., Demir, O. and Diri, B. (2019) Machine Learning Based Phishing Detection from URLs. Expert Systems with Applications , 117, 345-357. https://doi.org/10.1016/j.eswa.2018.09.029