← Latest papers
🤖 AI

Benchmarking Large Language Models for Zero-shot and Few-shot Phishing URL Detection

This paper presents a comprehensive benchmark evaluating the efficacy of large language models in detecting sophisticated, AI-generated phishing URLs through zero-shot and few-shot learning, demonstrating that few-shot prompting significantly enhances performance across multiple models to address the rapid escalation of phishing threats and the scarcity of labeled data.

Original authors: Najmul Hasan, Prashanth BusiReddyGari

Published 2026-02-04
📖 4 min read☕ Coffee break read

Original authors: Najmul Hasan, Prashanth BusiReddyGari

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the internet as a giant, bustling city. For years, the security guards at the gates (traditional cybersecurity tools) have been using a simple rule: "If a person's name is on our 'Bad List,' don't let them in." This works great for known troublemakers. But recently, a new kind of criminal has arrived. These criminals are using "Generative AI" to forge perfect fake IDs and create entirely new, convincing disguises that have never been seen before. The old "Bad List" is useless against them because the guards have never seen these faces.

This paper is like a report card for a new type of security guard: Large Language Models (LLMs). These are super-smart AI systems that have read almost everything on the internet. The researchers wanted to see if these AI guards could spot a fake URL (a web address) just by looking at it, even if they had never seen that specific address before.

Here is how they tested them, using simple analogies:

The Two Ways to Test the Guards

The researchers tested the AI guards in two different "training" scenarios:

  1. Zero-Shot (The "Cold Read"): Imagine handing a guard a photo of a stranger and asking, "Is this person a criminal?" without giving them any prior examples or a manual. The guard has to rely entirely on their general knowledge and intuition.
  2. Few-Shot (The "Show-and-Tell"): Imagine handing the guard the same photo, but this time you also show them three photos of known criminals and three photos of innocent people first. You say, "See these bad guys? And see these good guys? Now, look at this new person. Are they like the bad guys or the good guys?"

The Contenders

The paper put three of the most famous AI guards against each other:

  • GPT-4o (from OpenAI)
  • Claude-3.7 (from Anthropic)
  • Grok-3 (from xAI)

They tested these guards on a massive list of 10,000 web addresses (half were real, half were phishing traps) to see who could tell the difference best.

What They Found

The results were like a surprise race:

  • The "Show-and-Tell" Won: In almost every case, the guards performed much better when they were given a few examples first (Few-Shot). It's like how a detective gets better at spotting a forgery after seeing a few real examples of what to look for.
  • The Winner: Grok-3 was the champion. When given a few examples, it got the job done with the highest accuracy (about 94%). It was the best at saying "No" to bad links without accidentally saying "No" to good ones.
  • The Trade-Off: There was a slight catch. When the guards switched from "Cold Read" to "Show-and-Tell," they became stricter. They started catching fewer "good" links by mistake (which is good), but they also missed a few more "bad" links than they did when they were just guessing on their own. However, the overall score went up significantly.
  • The "Bad Guy" Problem: The researchers also tested what happens when the city is mostly full of good people, and only 1% are bad guys (a realistic scenario). Even in this tricky situation, the AI guards held their ground, especially Grok-3, which was very good at spotting the bad guys even without any examples.

The Bottom Line

The paper concludes that we don't always need to retrain these AI guards with massive amounts of new data every time a new scam appears. Instead, we can just give them a few quick examples (Few-Shot prompting), and they can adapt instantly to catch new, sophisticated phishing links.

In short: If you want an AI to spot a new type of internet scam, don't just ask it to guess. Show it a few examples of what a scam looks like first, and it will become a much sharper detective.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →