| 講演抄録/キーワード |
| 講演名 |
2026-03-03 14:45
LLMワークフローを用いたウェブホスティングサービス上のフィッシング検知 ○犬塚 祥(早大)・戸田宇亮(早大/理研AIP)・千葉大紀(NTTセキュリティホールディングス)・森 達哉(早大/理研AIP/NICT) ICSS2025-99 |
| 抄録 |
(和) |
フリーウェブホスティングサービス(FWHs)を悪用したフィッシング攻撃が増加している.FWHs上では良性・悪性サイトが同一ドメイン配下で運用されるため,従来の特徴量による判別が困難である.本研究は,この問題を解決する方法としてLLMワークフロー型検知手法を提案する.提案手法は,ブランドの知名度と機密性の高い行動への誘導を推定し,両者の組合せを文脈の不自然さの手掛かりとして判定する.また,判定根拠も出力し説明可能性を向上させる.10種類のFWHsで評価した結果,提案手法はF1スコア0.94を達成し,従来手法の0.41を大きく上回った.また,ケーススタディを通じて,提案手法が文脈の不自然さに基づく判定過程を説明可能な形で提示できていることを確認した. |
| (英) |
Phishing attacks exploiting free web hosting services (FWHs) are increasing. On FWHs, both benign and malicious sites operate under the same domain, making detection using conventional features difficult. We propose an LLM workflow-based detection method. The proposed method estimates brand popularity and inducement toward sensitive actions, using their combination as indicators of contextual unnaturalness for classification. It also outputs the rationale behind its judgment to improve explainability. Evaluation on 10 FWHs showed that the proposed method achieved an F1 score of 0.94 under out-of-training-data conditions, significantly outperforming the baseline method's 0.41. Case studies confirmed that the method can present its judgment process based on contextual unnaturalness in an explainable manner. |
| キーワード |
(和) |
フィッシング検知 / フリーウェブホスティングサービス / 大規模言語モデル / 説明可能性 / / / / |
| (英) |
Phishing Detection / Free Web Hosting Services / Large Language Models / Explainability / / / / |
| 文献情報 |
信学技報, vol. 125, no. 381, ICSS2025-99, pp. 99-106, 2026年3月. |
| 資料番号 |
ICSS2025-99 |
| 発行日 |
2026-02-24 (ICSS) |
| ISSN |
Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
ICSS2025-99 |