Send to which account? Evaluation of an LLM-based Scambaiting System -- 2025 APWG Symposium on Electronic Crime Research (eCrime)
Academic Article
Overview
Identity
Additional document info
View All
Overview
Abstract
Scammers are increasingly harnessing generative AI(GenAI) technologies to produce convincing phishing contentat scale, amplifying financial fraud and undermining publictrust. While conventional defenses, such as detection algorithms,user training, and reactive takedown efforts remain important,they often fall short in dismantling the infrastructure scammersdepend on, including mule bank accounts and cryptocurrencywallets. To bridge this gap, a proactive and emerging strategyinvolves using conversational honeypots to engage scammers andextract actionable threat intelligence.This paper presents the first large-scale, real-world evaluationof a scambaiting system powered by large language models(LLMs). Over a five-month deployment, the system initiatedover 2,600 engagements with actual scammers, resulting in adataset of more than 18,700 messages. It achieved an Informa-tion Disclosure Rate (IDR) of approximately 32%, successfullyextracting sensitive financial information such as mule accounts.Additionally, the system maintained a Human Acceptance Rate(HAR) of around 70%, indicating strong alignment betweenLLM-generated responses and human operator preferences.Alongside these successes, our analysis reveals key operationalchallenges. In particular, the system struggled with engagementtakeoff: only 48.7% of scammers responded to the initial seedmessage sent by defenders. These findings highlight the need forfurther refinement and provide actionable insights for advancingthe design of automated scambaiting systems.