From Trust to Compromise: Outcome-Verified LLM Phishing Simulation and Real-Time Defense
Tulika Tewari, Nalin Asanka Gamagedara Arachchilage, Jagat Sesh Challa, Dhruv Kumar
Abstract
Large Language Models (LLMs) excel as conversational agents. However, these capabilities can be weaponized to automate socialengineering attacks that gradually build rapport to compromise the online safety of users. To understand this, researchers have simulated LLMbased attacks in controlled settings. However, the existing simulators focus on just Personal Identifiable Information (PII) requests within the chat. Thus, to represent a complete attack scenario, we introduce PhishSim, an outcomedriven LLM-based phishing simulator that verifies compromise by simulating a victim completing an external action step, such as submitting credentials on a malicious platform. This enables the generation of diverse, multi-turn attack trajectories. Building on these trajectories, we position PhishGate as a practical mitigation baseline for outcome-grounded conversational phishing: a real-time multi-agent risk scorer that detects manipulation tactics and estimates the severity of ongoing chats. For ambiguous cases, it invokes RAG-supported consistency checks. Evaluating four state-of-the-art LLM backends in a real-time setting, we find that PhishGate improves dialogue-level detection over a real-time baseline. Our results highlight both the promise and brittleness of LLMbased real-time phishing defense, providing an outcome-grounded testbed for studying conversational compromise.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on2
- The Influence of Human Factors on the Intention to Report Phishing EmailsIoana Andreea Marin, Pavlo Burda, Nicola Zannone, Luca AllodiCHI 2023 · 30 citations
- Defending Against Social Engineering Attacks in the Age of LLMsLin Ai, Tharindu Kumarage, Amrita Bhattacharjee, Zizhou Liu et al.EMNLP 2024 · 12 citations
Related papers
- When LLMs Go Online: The Emerging Threat of Web-Enabled LLMsHanna Kim, Minkyoo Song, Seung Ho Na, Seungwon Shin et al.USENIX Security 2025
- From Chatbots to Phishbots?: Phishing Scam Generation in Commercial Large Language ModelsSayak Saha Roy, Poojitha Thota, Krishna Vamsi Naragam, Shirin NilizadehS&P 2024 · 57 citations
- Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based AgentsWenkai Yang, Xiaohan Bi, Yankai Lin, Sishuo Chen et al.NeurIPS 2024 · 195 citations
- OpenDeception: Learning Deception and Trust in Human–AI Interaction via Multi-Agent SimulationYichen Wu, Qianqian Gao, Xudong Pan, Geng Hong et al.ICML 2026 · 1 citation
- BotSim: LLM-Powered Malicious Social Botnet SimulationBoyu Qiao, Kun Li, Wei Zhou, Shilong Li et al.AAAI 2025 · 23 citations
