Defending Against AI‑Driven Phishing and Malicious URLs

Artificial intelligence has transformed phishing from opportunistic deception into automated, adaptive social engineering on a scale. Contemporary campaigns leverage generative content synthesis, adversary-in-the-middle credential relay, QR-code mobile pivots, and infrastructure churn to evade traditional signature-based and reputation-driven defenses. As identity systems increasingly underpin cloud services and critical infrastructure, phishing mitigation becomes a resilience challenge rather than a purely technical filtering problem. This study introduces the AID-PDR Framework (AI-Driven Phishing Defense & Resilience), a multi-layer socio-technical architecture integrating phishing-resistant authentication (FIDO2/WebAuthn), standards-based email authentication (SPF, DKIM, DMARC with MTA-STS and TLS-RPT), browser-level enforcement, adversarially robust machine learning detection pipelines, and adaptive AI-driven phishing simulation. A quantitative resilience model illustrates how layered controls produce multiplicative risk reduction across independent defensive mechanisms. Grounded in breach investigations, threat intelligence reporting, applied ML design patterns, and alignment with NIST and Zero Trust frameworks, this work advances a unified approach to mitigating AI-driven phishing risk at enterprise and national scale.

Paper

Full text

PDF

Defending Against AI‑Driven Phishing and Malicious URLs

Semantic Scholar · 2026

Abstract

Artificial intelligence has transformed phishing from opportunistic deception into automated, adaptive social engineering on a scale. Contemporary campaigns leverage generative content synthesis, adversary-in-the-middle credential relay, QR-code mobile pivots, and infrastructure churn to evade traditional signature-based and reputation-driven defenses. As identity systems increasingly underpin cloud services and critical infrastructure, phishing mitigation becomes a resilience challenge rather than a purely technical filtering problem. This study introduces the AID-PDR Framework (AI-Driven Phishing Defense & Resilience), a multi-layer socio-technical architecture integrating phishing-resistant authentication (FIDO2/WebAuthn), standards-based email authentication (SPF, DKIM, DMARC with MTA-STS and TLS-RPT), browser-level enforcement, adversarially robust machine learning detection pipelines, and adaptive AI-driven phishing simulation. A quantitative resilience model illustrates how layered controls produce multiplicative risk reduction across independent defensive mechanisms. Grounded in breach investigations, threat intelligence reporting, applied ML design patterns, and alignment with NIST and Zero Trust frameworks, this work advances a unified approach to mitigating AI-driven phishing risk at enterprise and national scale.

Similar papers

© 2026 NYSGPT2525 LLC