{"id":"https://openalex.org/W4416998073","doi":"https://doi.org/10.3390/computers14120523","title":"A Two-Stage Deep Learning Framework for AI-Driven Phishing Email Detection Based on Persuasion Principles","display_name":"A Two-Stage Deep Learning Framework for AI-Driven Phishing Email Detection Based on Persuasion Principles","publication_year":2025,"publication_date":"2025-12-01","ids":{"openalex":"https://openalex.org/W4416998073","doi":"https://doi.org/10.3390/computers14120523"},"language":"en","primary_location":{"id":"doi:10.3390/computers14120523","is_oa":true,"landing_page_url":"https://doi.org/10.3390/computers14120523","pdf_url":"https://www.mdpi.com/2073-431X/14/12/523/pdf?version=1764583136","source":{"id":"https://openalex.org/S4210228075","display_name":"Computers","issn_l":"2073-431X","issn":["2073-431X"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Computers","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://www.mdpi.com/2073-431X/14/12/523/pdf?version=1764583136","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5120586237","display_name":"Peter Tooher","orcid":null},"institutions":[{"id":"https://openalex.org/I39555362","display_name":"University of Warwick","ror":"https://ror.org/01a77tt86","country_code":"GB","type":"education","lineage":["https://openalex.org/I39555362"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Peter Tooher","raw_affiliation_strings":["WMG, Cyber Security Centre, University of Warwick, Coventry CV4 7AL, UK"],"affiliations":[{"raw_affiliation_string":"WMG, Cyber Security Centre, University of Warwick, Coventry CV4 7AL, UK","institution_ids":["https://openalex.org/I39555362"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5003182879","display_name":"Harjinder Singh Lallie","orcid":"https://orcid.org/0000-0002-1558-5115"},"institutions":[{"id":"https://openalex.org/I39555362","display_name":"University of Warwick","ror":"https://ror.org/01a77tt86","country_code":"GB","type":"education","lineage":["https://openalex.org/I39555362"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Harjinder Singh Lallie","raw_affiliation_strings":["WMG, Cyber Security Centre, University of Warwick, Coventry CV4 7AL, UK"],"affiliations":[{"raw_affiliation_string":"WMG, Cyber Security Centre, University of Warwick, Coventry CV4 7AL, UK","institution_ids":["https://openalex.org/I39555362"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5003182879"],"corresponding_institution_ids":["https://openalex.org/I39555362"],"apc_list":{"value":1600,"currency":"CHF","value_usd":1732},"apc_paid":{"value":1600,"currency":"CHF","value_usd":1732},"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.52128646,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"14","issue":"12","first_page":"523","last_page":"523"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.910099983215332,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.910099983215332,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12268","display_name":"Deception detection and forensic psychology","score":0.022199999541044235,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11147","display_name":"Misinformation and Its Impacts","score":0.020400000736117363,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/persuasion","display_name":"Persuasion","score":0.9491000175476074},{"id":"https://openalex.org/keywords/phishing","display_name":"Phishing","score":0.8877999782562256},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5688999891281128},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.37790000438690186},{"id":"https://openalex.org/keywords/binary-number","display_name":"Binary number","score":0.3693000078201294},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.29820001125335693},{"id":"https://openalex.org/keywords/construct","display_name":"Construct (python library)","score":0.2919999957084656}],"concepts":[{"id":"https://openalex.org/C2781310500","wikidata":"https://www.wikidata.org/wiki/Q1231428","display_name":"Persuasion","level":2,"score":0.9491000175476074},{"id":"https://openalex.org/C83860907","wikidata":"https://www.wikidata.org/wiki/Q135005","display_name":"Phishing","level":3,"score":0.8877999782562256},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7319999933242798},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5777000188827515},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5688999891281128},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.39410001039505005},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.37790000438690186},{"id":"https://openalex.org/C48372109","wikidata":"https://www.wikidata.org/wiki/Q3913","display_name":"Binary number","level":2,"score":0.3693000078201294},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.30550000071525574},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.29820001125335693},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.29249998927116394},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.2919999957084656},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.28049999475479126},{"id":"https://openalex.org/C3020028006","wikidata":"https://www.wikidata.org/wiki/Q9158","display_name":"Electronic mail","level":2,"score":0.27570000290870667},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2752000093460083},{"id":"https://openalex.org/C175154964","wikidata":"https://www.wikidata.org/wiki/Q380077","display_name":"Task analysis","level":3,"score":0.26420000195503235},{"id":"https://openalex.org/C70118762","wikidata":"https://www.wikidata.org/wiki/Q376934","display_name":"Social engineering (security)","level":2,"score":0.260699987411499},{"id":"https://openalex.org/C2778827112","wikidata":"https://www.wikidata.org/wiki/Q22245680","display_name":"Feature engineering","level":3,"score":0.25589999556541443},{"id":"https://openalex.org/C2780402292","wikidata":"https://www.wikidata.org/wiki/Q282853","display_name":"Elaboration likelihood model","level":3,"score":0.25459998846054077},{"id":"https://openalex.org/C66905080","wikidata":"https://www.wikidata.org/wiki/Q17005494","display_name":"Binary classification","level":3,"score":0.25440001487731934}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.3390/computers14120523","is_oa":true,"landing_page_url":"https://doi.org/10.3390/computers14120523","pdf_url":"https://www.mdpi.com/2073-431X/14/12/523/pdf?version=1764583136","source":{"id":"https://openalex.org/S4210228075","display_name":"Computers","issn_l":"2073-431X","issn":["2073-431X"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Computers","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:238b7c56dbd240c18a410ae6d5d139fe","is_oa":true,"landing_page_url":"https://doaj.org/article/238b7c56dbd240c18a410ae6d5d139fe","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Computers, Vol 14, Iss 12, p 523 (2025)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.3390/computers14120523","is_oa":true,"landing_page_url":"https://doi.org/10.3390/computers14120523","pdf_url":"https://www.mdpi.com/2073-431X/14/12/523/pdf?version=1764583136","source":{"id":"https://openalex.org/S4210228075","display_name":"Computers","issn_l":"2073-431X","issn":["2073-431X"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Computers","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4416998073.pdf"},"referenced_works_count":17,"referenced_works":["https://openalex.org/W1970794815","https://openalex.org/W2049023511","https://openalex.org/W2134750673","https://openalex.org/W2470673105","https://openalex.org/W2905450671","https://openalex.org/W2921573932","https://openalex.org/W2982605177","https://openalex.org/W3021946193","https://openalex.org/W4213145421","https://openalex.org/W4320024060","https://openalex.org/W4386076580","https://openalex.org/W4389935952","https://openalex.org/W4396760408","https://openalex.org/W4400976635","https://openalex.org/W4401815860","https://openalex.org/W4405654320","https://openalex.org/W4408288399"],"related_works":[],"abstract_inverted_index":{"AI-generated":[0,195],"phishing":[1,40,167,186],"emails":[2],"present":[3],"a":[4,18,71,91,128,170],"growing":[5],"cybersecurity":[6],"threat,":[7],"exploiting":[8],"human":[9],"psychology":[10],"with":[11,27,44,109],"high-quality,":[12],"context-aware":[13],"language.":[14],"This":[15,104,159],"paper":[16],"introduces":[17],"novel":[19],"two-stage":[20],"detection":[21],"framework":[22,165],"that":[23,136],"combines":[24],"deep":[25],"learning":[26],"psychological":[28],"analysis":[29],"to":[30,75],"address":[31],"this":[32],"challenge.":[33],"A":[34],"new":[35],"dataset":[36,172],"containing":[37],"2995":[38],"GPT-o1-generated":[39],"emails,":[41],"each":[42,83],"labelled":[43],"Cialdini\u2019s":[45],"six":[46],"persuasion":[47,80],"principles,":[48],"is":[49],"created":[50],"across":[51],"five":[52],"organisational":[53],"sectors\u2014forming":[54],"one":[55],"of":[56,79,131,147,180],"the":[57,65,77,97,178],"largest":[58],"and":[59,120,141,151,188],"most":[60],"behaviourally":[61],"annotated":[62],"corpora":[63],"in":[64,82,156,183,192],"field.":[66],"The":[67,114],"first":[68],"stage":[69,99],"employs":[70],"fine-tuned":[72],"DistilBERT":[73],"model":[74,132],"predict":[76],"presence":[78],"principles":[81,137],"email.":[84],"These":[85],"confidence":[86],"scores":[87],"then":[88],"feed":[89],"into":[90,111],"lightweight":[92],"dense":[93],"neural":[94],"network":[95],"at":[96],"second":[98],"for":[100,166,173],"final":[101],"binary":[102],"classification.":[103],"interpretable":[105],"design":[106],"balances":[107],"performance":[108],"insight":[110],"attacker":[112],"strategies.":[113],"full":[115],"system":[116],"achieves":[117],"94%":[118],"accuracy":[119],"98%":[121],"AUC,":[122],"outperforming":[123],"comparable":[124],"methods":[125],"while":[126,149],"offering":[127],"clearer":[129],"explanation":[130],"decisions.":[133],"Analysis":[134],"shows":[135],"like":[138],"authority,":[139],"scarcity,":[140],"social":[142],"proof":[143],"are":[144],"highly":[145],"indicative":[146],"phishing,":[148],"reciprocation":[150],"likeability":[152],"occur":[153],"more":[154],"often":[155],"legitimate":[157],"emails.":[158],"research":[160],"contributes":[161],"an":[162],"interpretable,":[163],"psychology-informed":[164],"detection,":[168],"alongside":[169],"unique":[171],"future":[174],"study.":[175],"Results":[176],"demonstrate":[177],"value":[179],"behavioural":[181],"cues":[182],"identifying":[184],"sophisticated":[185],"attacks":[187],"suggest":[189],"broader":[190],"applications":[191],"detecting":[193],"malicious":[194],"content.":[196]},"counts_by_year":[],"updated_date":"2026-03-11T06:11:40.159057","created_date":"2025-12-04T00:00:00"}
