← Latest papers
💬 NLP

FraudSMSWalker: Benchmarking Agentic Large Language Models for SMS-to-Webpage Fraud Detection

This paper introduces FraudSMSWalker, a controlled benchmark designed to evaluate the ability of agentic large language models to detect SMS-to-webpage fraud by forcing evidence-grounded judgments through URL masking and the inclusion of challenging benign cases that mimic scam flows.

Original authors: Y. H. Zhou, Z. M. Ma, Y. J. Zhou, Y. T. Li, H. X. Xiang, Y. M. Cheng, T. L. Chen, K. J. Zhang, Z. H. Nan, J. H. Ni, Z. Wu, Q. Y. Pan, S. Zhang, S. Cheng, M. Y. Luo

Published 2026-06-16
📖 4 min read☕ Coffee break read

Original authors: Y. H. Zhou, Z. M. Ma, Y. J. Zhou, Y. T. Li, H. X. Xiang, Y. M. Cheng, T. L. Chen, K. J. Zhang, Z. H. Nan, J. H. Ni, Z. Wu, Q. Y. Pan, S. Zhang, S. Cheng, M. Y. Luo

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you are a security guard at a very busy, high-stakes building. Your job is to decide who gets in and who is a scammer.

Usually, scammers send you a text message (the "SMS") that says, "Your package is delayed! Click here to fix it." The message includes a link. If you click it, you go to a webpage that looks like a delivery company's site.

The Problem with Current Security Guards (AI Models)
Right now, most AI security guards are a bit lazy. When they see a suspicious text, they don't actually look at the webpage the link leads to. Instead, they peek at the address bar (the URL) or check a "blacklist" of known bad websites. If the website is on the blacklist, they yell "FRAUD!" If it's a famous, trusted name, they say "All clear."

The paper argues this is cheating. Real scammers are getting smarter; they are using websites that look exactly like the real ones, but they are hosted on sneaky, unknown addresses. If your AI guard only checks the address, it misses the trick.

The New Test: FraudSMSWalker
The authors created a new training ground called FraudSMSWalker. Think of it as a "blindfolded" test for AI security guards.

  • The Setup: The AI gets a text message and a link.
  • The Twist: The AI is not allowed to see the actual website address, the domain name, or any reputation scores. It's like the guard is wearing a blindfold that covers the street sign.
  • The Task: The AI must look only at the text message and the actual content of the webpage (what it says, what buttons are there) to decide: "Is this a scam, or is this a legitimate service?"

The Dataset: The "Hard Benign" Trap
To make the test fair and tough, the researchers included a special group of "innocent" websites. These are real, legitimate sites (like a bank or a government portal) that look exactly like scam sites. They have login boxes, payment forms, and verification steps.

  • The Trap: A lazy AI sees a login box and immediately screams "SCAM!" because scammers love login boxes.
  • The Goal: A smart AI needs to realize, "Wait, this is a bank asking for a password. That's normal for a bank. This is safe."

What Happened When They Tested the AI?
The researchers tested nine different advanced AI "agents" (smart programs) on this blindfolded test. Here is what they found:

  1. The "Paranoid" Problem: The AI models were very good at spotting scams, but they were terrible at trusting innocent people. They were so scared of being tricked that they flagged almost everything as a scam.
    • Analogy: Imagine a security guard who stops everyone entering the building, even the CEO, because "everyone looks suspicious." They caught all the bad guys, but they also kicked out 70% of the good guys.
  2. The "Lucky Guess" Problem: Even when the AI got the answer right (saying "Yes, this is a scam"), they often couldn't explain why based on what they actually saw.
    • Analogy: It's like a student who gets a math problem right but didn't show their work. They might have just guessed. The researchers found that many AIs were making up reasons or relying on gut feelings rather than hard evidence from the webpage.
  3. The "Blindfold" Effect: When the researchers did let the AI see the website address (taking off the blindfold), the AI got much better at spotting scams, but it got even worse at trusting innocent sites. It relied too much on the address and ignored the actual content.

The Bottom Line
The paper concludes that current AI security guards are too aggressive. They are great at finding "bad" things but terrible at distinguishing between a "scam" and a "legitimate service that looks scary."

To fix this, we need to stop letting AI cheat by checking website addresses and start teaching them to look at the story the text and the webpage tell together. The new benchmark, FraudSMSWalker, is designed to force AI to learn this skill: making safe, evidence-based decisions without relying on shortcuts.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →