CORTEXA
← Browse
openalexZenodo (CERN European Organization for Nuclear Research)2026-07-25Cited by 0

Bridging LLM Reasoning and Classical Explainability in Phishing Email Classification: A Faithfulness and Robustness Comparison

Musa Khan

Large language models (LLMs) are increasingly proposed as reasoning engines for cyber threat intelligence (CTI) triage and threat hunting, promising to reduce the alert-fatigue burden long documented in security operations research. However, most reported evaluations emphasize raw classification accuracy and give little attention to whether an LLM’s stated reasoning is actually faithful to the signal that drives its decision, or whether it is more robust than classical machine learning to adversarial text obfuscation. In this work we study phishing email classification — a canonical, high-volume CTI task — using a combined corpus of 81,880 labeled emails (CEAS 08, Enron, Nazario, Nigerian Fraud, SpamAssassin, and Ling). We train a TF-IDF + Logistic Regression baseline (98.55% accuracy, ROC-AUC 0.999) and use SHAP to obtain token-level feature attributions. We then construct a stratified 90-email case-study subsample — including all of the baseline’s misclassifications in the sample — and have an LLM (Claude Sonnet 5) independently classify each email zero-shot with a natural-language rationale. We find that (i) SHAP attributions frequently key on short character fragments produced by spam authors’ filter-evasion obfuscation (mean 1.25 fragment tokens among the top-5 SHAP features for obfuscated-spam emails, vs. 0.99 for non-obfuscated emails), indicating a degree of shortcut learning rather than pure semantic understanding; (ii) the LLM recovers 12 of the classical model’s 20 errors in the subsample (60%), achieving 100% accuracy specifically on character-obfuscated spam that defeats the bag-of-words model; and (iii) the LLM shares several genuine failure modes with the classical model on conversationally-phrased phishing and at least one likely case of label noise, showing that LLM-based triage is a complement to, rather than a strict replacement for, classical explainable models. We discuss the implications for LLM-assisted threat hunting and alert-fatigue reduction in security operations centers (SOCs).

View free PDFSource page

Related papers

openalexZenodo (CERN European Organization for Nuclear Research)2026-07-26

Leakage-Controlled Seriousness Triage of FAERS Reports: A Temporal Validation Framework with LLM Comparison on Novel First-in-Class Drugs

Shakil Mahmud

Background. Post-marketing pharmacovigilance depends on the timely identification of serious individual case safety reports (ICSRs) from large spontaneous-reporting databases such as the FDA Adverse Event Reporting System (FAERS). Machine-learning triage has been proposed to prio…

View free PDFSource page
openalexZenodo (CERN European Organization for Nuclear Research)2026-07-23

Visual Explainability-Driven DL framework for Lung Nodule Classification

I. Tejaswini, T. Thanmai, M. Apphia, Dr Mohit MP, A. Sagar

The large number of images and the subtle characteristics of pulmonary nodules make it challenging to detect the lung cancer from CT scans. Complex and small nodules may provide a less accurate diagnosis, and manual examination is time-consuming and result to variation among obse…

View free PDFSource page
openalexZenodo (CERN European Organization for Nuclear Research)2026-07-25

How Stable Are SHAP Explanations for Network Intrusion Detection? A Perturbation-Based Faithfulness Study

Musa Khan

Explainable AI (XAI) methods such as SHAP are increasingly presented to security operations center (SOC) analysts as a way to justify machine-learning-based network intrusion detection system (NIDS) alerts, on the premise that a stated explanation increases trust and speeds triag…

View free PDFSource page
openalexZenodo (CERN European Organization for Nuclear Research)2026-07-24

A Multi-Agent Architecture for AI-Based Early Screening, Referral, and Prediction of Retinal Diseases

Poolasetti Vamshi Jahnavi Somaraju

Retinal diseases such as diabetic retinopathy (DR), glaucoma, and age-related macular degeneration (AMD) are leading causes of preventable blindness worldwide, yet population-scale screening remains constrained by the limited availability of trained ophthalmologists, particularly…

View free PDFSource page
openalexZenodo (CERN European Organization for Nuclear Research)2026-08-09

Multi-Model Comparative Study for Bark-Texture Based Tree Species Classification Using Custom Indian Tree Species Dataset

Shaila Doddamani, Apeksha Kule

Accurate wood species identification is crucial for biodiversity preservation and forest management. Because traditional identification methods are time-consuming and heavily rely on expert knowledge, automated image-based solutions have become more and more important. This resea…

Also available via: European Organization for Nuclear Research

View free PDFSource page
openalexZenodo (CERN European Organization for Nuclear Research)2026-07-26

Sketch2DES pilot - An evaluation of Generative AI for Building Discrete-Event Simulation Models from Diagrams

Thomas Monks, Amy Heather, Alison Harper

:seedling: v1.0.0 Release created to accompany paper submission. Added Applied examples and model comparison using Sketch2DES LLM workflow method in notebooks 01-08. Evaluation of LLM workflow steps 1, 2 and end2end in notebooks 09-12 Applied example using NVidia 5090 in notebook…

View free PDFSource page