Detection Of AI: Generated Phishing Emails Using Cross Model Generalization

  • Unique Paper ID: 208482
  • PageNo: 259-271
  • Abstract:
  • Large language models (LLMs) have changed the practical characteristics of phishing email. A message that once required deliberate manual drafting can now be produced in seconds, adapted to a target role, and rewritten repeatedly while maintaining fluent grammar and a credible business tone. This development weakens the assumption behind many older filters: that phishing is recognizable because it is poorly written, repetitive, or linguistically unusual. The central question of this paper is therefore not whether artificial intelligence can detect phishing, but whether current AI-assisted detection approaches remain reliable when the generator, wording, context, and delivery conditions change. This paper presents a structured gap analysis of recent approaches to detecting AI- and LLM-generated phishing emails. The review focuses on four recurring dimensions: detection capability, cross-model generalization, operational latency, and interpretability. Recent evidence shows that stylometric systems can perform strongly when the evaluation distribution is close to the training distribution, while broader reviews identify over-reliance on manually assembled datasets and disproportionate attention to GPT-family models. A 2026 cross-model study further demonstrates that a detector trained on one generator can lose substantial transfer performance when evaluated on another, although threshold recalibration and multi-generator training can reduce the observed gap [1], [2], [3]. The analysis argues that the strongest and most defensible research gap is cross-model robustness under distribution shift. Latency and explainability remain important engineering constraints, but generalization is the issue that most directly challenges the scientific validity of a detector if its benchmark assumes a single or narrow generator family. The paper therefore treats generalization as the primary gap and positions latency, false-positive control, privacy, and explanation quality as secondary deployment requirements. Rather than claiming completed experimental results, the paper proposes an evaluation framework that can test detectors against known generators, held-out generators, paraphrased variants, human-written phishing, and legitimate business email. The intended contribution is a human-readable research map: what existing approaches actually detect, where their evidence is strong, where their conclusions are narrow, and what a future lightweight detector should prove before being considered robust. This distinction is important because high accuracy on an internal test split is not equivalent to operational reliability. The paper concludes with a research direction based on multi-generator training, explicit held-out-generator testing, compact feature extraction, selective escalation, and structured explanations.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{208482,
        author = {Alokananda Ghosh and Shamsher Singh Hada and Shruti Dhotre and Guna Dhondwad},
        title = {Detection Of AI: Generated Phishing Emails Using Cross Model Generalization},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {13},
        number = {no},
        pages = {259-271},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=208482},
        abstract = {Large language models (LLMs) have changed the practical characteristics of phishing email. A message that once required deliberate manual drafting can now be produced in seconds, adapted to a target role, and rewritten repeatedly while maintaining fluent grammar and a credible business tone. This development weakens the assumption behind many older filters: that phishing is recognizable because it is poorly written, repetitive, or linguistically unusual. The central question of this paper is therefore not whether artificial intelligence can detect phishing, but whether current AI-assisted detection approaches remain reliable when the generator, wording, context, and delivery conditions change.
This paper presents a structured gap analysis of recent approaches to detecting AI- and LLM-generated phishing emails. The review focuses on four recurring dimensions: detection capability, cross-model generalization, operational latency, and interpretability. Recent evidence shows that stylometric systems can perform strongly when the evaluation distribution is close to the training distribution, while broader reviews identify over-reliance on manually assembled datasets and disproportionate attention to GPT-family models. A 2026 cross-model study further demonstrates that a detector trained on one generator can lose substantial transfer performance when evaluated on another, although threshold recalibration and multi-generator training can reduce the observed gap [1], [2], [3].
The analysis argues that the strongest and most defensible research gap is cross-model robustness under distribution shift. Latency and explainability remain important engineering constraints, but generalization is the issue that most directly challenges the scientific validity of a detector if its benchmark assumes a single or narrow generator family. The paper therefore treats generalization as the primary gap and positions latency, false-positive control, privacy, and explanation quality as secondary deployment requirements. Rather than claiming completed experimental results, the paper proposes an evaluation framework that can test detectors against known generators, held-out generators, paraphrased variants, human-written phishing, and legitimate business email.
The intended contribution is a human-readable research map: what existing approaches actually detect, where their evidence is strong, where their conclusions are narrow, and what a future lightweight detector should prove before being considered robust. This distinction is important because high accuracy on an internal test split is not equivalent to operational reliability. The paper concludes with a research direction based on multi-generator training, explicit held-out-generator testing, compact feature extraction, selective escalation, and structured explanations.},
        keywords = {AI-generated phishing; LLM-generated email; phishing detection; stylometry; cross-model generalization; robustness; distribution shift; explainable cybersecurity; email security.},
        month = {September},
        }

Cite This Article

Ghosh, A., & Hada, S. S., & Dhotre, S., & Dhondwad, G. (2026). Detection Of AI: Generated Phishing Emails Using Cross Model Generalization. International Journal of Innovative Research in Technology (IJIRT), 259–271.

Related Articles