
International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
![]()

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
B Rajani1 , B Poojitha2, G Rahul Reddy3, J Laxman4, D Ashok5
1Asst.ProfessorDepartment of Information Technology, TKR College of Engineering and Technology, Telangana, India
2345Department of Information Technology, TKR College of Engineering and Technology, Telangana, India
Abstract - Phishing attacks are being carried out in a sophisticated manner using various techniques, including social engineering attacks to extract critical information from users. The conventional approach to identify phishing emails uses rules, which are not sufficient to handle newly generated and semantically sophisticated phishing emails. The objective of the proposed project is to create a conversational AI service using Large Language Models (LLMs) to analyze emails based on semantic characteristics such as urgency, impersonation, authority, deception, etc.
The system can effectively classify in an intelligent manner, thus performing better for the identification of potential risks. Lastly, it can easily be incorporated into online applications, with privacy guaranteed at the time of analysis, ensuring effective phishing awareness and decision-making, as evident from the user assessment, while at the same time demonstrating the efficiency of implementing the system with interaction, as evident from the evaluation performed.
Key Words: Phishing Detection, Cybersecurity, Large Language Models, Conversational AI, Email Security, Semantic Analysis, Usable Security.
Ithasturnedouttobeoneofthemostprevalentaswellas detrimental varieties of cybercrime in recent times. AccordingtotheAnti-PhishingWorkingGroup,therewere over 1.2 million reported cases of phishing in the second quarterof2023alone.Itisestimatedthataround3.4billion phishingemailsaretransmittedeverydayacrosstheworld, whichtranslatesintomorethanatrillionemailseveryyear. Phishingmakesupfor91%ofallcyberattacksandtriggers 36%ofdatabreaches;therefore,itisoneofthemostsevere cybersecurityconcerns.
Thisgivesrisetosocialengineeringasthebasisforphishing attacks.Phishingattacksbasicallyexploithumanpsychology morethananythingelse.Theattackersplayonemotionslike urgency, power, fear, or curiosity to trick the users into clicking on certain web pages or giving away sensitive information.Duetothesetechniquesbasedonpsychology, phishingattacksarebasicallycasesofhumanerror.Human errorgivesriseto95%ofallsuccessfulcyberattacks.Lackof knowledge,tension,cognitiveoverload,orsecuritytraining
are some factors that minimize a user's ability to a great extent.
Although there is an existence of automated phishing detectiontools,theemphasisofmostofthesetoolsismainly technicalfeatures;nonetheless,thereisalackofexplanation whichiseasilyunderstandable,especiallyfornon-technical people,whoarethetargetofmostattackers.
Inordertoaddressthesechallenges,ithasbeenproposedto develop a system that can assist the user in the more efficient processing of phishing emails with the help of Artificial Intelligence. To achieve this objective, there is a plantoincorporateLargeLanguageModelstoidentifynot only textual phishing attacks but also semantic and psychologicalattacks.Additionally,sentence-levelinsights havebeenproposedtoofferdetailedexplanationtotheuser onwhyithasmarkedtheemailassuspicious.
Moreover,thereistheabilityfortheusertoqueryaswellas provideexplanationsinaconversationalmanner.Thiswill enhancetheawarenessofthesystem,thuseliminatingthe need to have knowledge of the technology, which can enhancetheeffectivenessofthesolutionbyincorporating the intelligent analysis, the ease of use, as well as the privacy-preservingabilityoflocalprocessing
Phishingisoneofthetechniquesofcyberattackswhere hackers try to fool a victim into revealing their sensitive information to the cyber attackers by pretending to be a trusted source. Phishing attacks differ from other kinds of attacks, such as exploitation attacks, which are successful based on the system's vulnerabilities, but in the case of a phishing attack, all its efforts are focused on soliciting a victim'spsychologicalresponseswiththehelpoffactorssuch as"urgency,""fear,""authority,"and"curiosity."
With several volumes of phishing messages reaching usersannually,ithasnowgrownintooneofthebiggestand most widespread cybersecurity challenges worldwide. Nowadays,manyphishingattacksareadequatelyintelligent; they use texts and brand names that bypassold-fashioned methodsofdetection.Moreover,theintroductionofQRcode phishing and multi-channel phishing attacks is a further reminder of the importance of developing intelligent, adaptive,anduser-centricsolutions.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Thephishingattacksarebecominghighlysophisticated, targetingthehumanbehaviorratherthantargetingsystem flaws. Most of the traditional phishing solutions, i.e., blacklist-based filtering and rule-based heuristics, have limitationsastheyareonlybasedonpreviousexperiences. SincetheattackersaredynamicallychangingURLs,emails, andsocialengineeringcampaigns,theconventionalphishing solutionsarenotcapableofdetectingnewphishingattacks andattacksbasedonsemanticattacks.Mostofthesolutions availableinthetraditionalapproachhavenofeedback,thus usersarenotabletotrustthesesolutions.
However,themainissueliesintheincapabilityofthese systems to grasp the semantic meaning as well as the underlying psychological manipulation used in phishing messages. Modern phishing messages look technically correct but, in reality, try to convey hidden meanings of urgency,impersonation,orconsequences.Anewdimension ofphishingriskshas alsoappeared, asQR-based phishing providescustomersnoopportunitytolookatanyembedded URLbeforeopeningit.Therefore,itisimportantthatausercentric,intelligent,andtransparentsolutionisdevised,not onlycapableoftacklingphishingrisksinemailsorQRcodes, but also potentially supportive in increasing user understanding
Theproposedsystemisanintelligentsystemintheform of an AI-based conversational assistant that is expected to detect and analyze phishing threats from emails and QR codes in a way that is easily understandable. The system brings together under one roof the facilities of Large LanguageModelsusingtheGoogleGeminiAPIwithaDjangobased web application to facilitate intelligent phishing detection.
In the architecture proposed, three main modules are foreseen to be implemented, notably Email Phishing Detection, QR Code Malicious URL Detection, and finally ConversationalAIAssistant.Fromthere,aftertheinputofthe mailmessagebytheuser,itisexpectedthatthesystemwill makeuseoftheGeminitoolincarryingoutsemanticanalysis. InordertodetectmaliciousfeatureswithintheQRcode,it will go through image scanning before being subjected to potentialmaliciousfeaturesusinganOpenCVlibrary.
Unlike traditional systems that output only two classification results, such as Phishing or Safe, with no explanation, the proposed method enables users to obtain contextualexplanationoftheirdecisions.Itdoessothrough theabilitytointeractwiththeinterface,askingquestionsand receivingresponsesinnaturallanguage.
Itisdesignedwithamodularandsecurearchitecture,using theauthenticationframeworkforusermanagementgivenby
theDjangoframework,forrole-basedaccess.Itisdesignedin suchawaythatallcomponentsaremadetoworktogetherin order to provide accurate detection, usability, and cybersecurityawareness.
The system architecture is built as a modular form of a Django-basedwebapplication,whichincorporatesAI-based phishing detection for email, analysis of QR codes, and a conversationalassistant,allunderasecureauthentication setup. It consists of four components: User Interface, Application Layer, AI Processing Layer, and Data Storage Layer.
Both users and administrators interact through the web interface,whereinuserscanregister,login,andinputemail content, upload images of QR codes, and retrieve results fromtheAImodule.TheDjangoapplicationlayerisusedto handlealltherequesthandlingandauthenticationofusers. The email content is sent to the Gemini API through LangChain for analysis of content, and the QR code is scannedusingOpenCVtodetectmaliciousURLs.Theuser detailsandresultsoftheanalysisarestoredinthedatabase tomaintainsystemreliability.

The workflow of the system would start with the registrationoftheuser,administrativeapproval,andthenan authenticatedlogin.Onceauthenticated,theuserwouldbe presentedwithtwochoices:oneforanalyzingemailsandthe otherforQRcodeanalysis.
Emailanalysispath:Thesystemreadsthecontentsfrom theemailsubmissionandperformsphishingdetectionwith theGeminiLLMthroughLangChain.Itclassifiesthecontent asphishingorlegitimateanddisplaystheresultalongwith thecontextualreasoning.Then,theconversationalassistant givesadviceoncybersecuritytoenhanceuserawareness.
In the QR code analysis pathway, a user is allowed to uploadanimageofaQRcode.First,bymeansofOpenCV,the embeddedURLisdecoded.AfterextractingtheURL,it'sfed

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
tothe Gemini model forclassifyingit asmaliciousorsafe. Finally,theclassificationresultwillbeshowntotheuser.
Theprocessinbothcasesendswitheducatingtheuserby giving explanatory feedback that will eventually enhance better cybersecurity awareness to assure secure user protection.

The proposed system is achieved by using a secure and modular web-based application, and as such, the base platformwillbeDjango.Also,thelayeredarchitecturestyle is adopted, as it meets the needs of being scalable, maintainable, and incorporates AI-based phishing mechanisms.
ThebackendframeworkoftheapplicationisDjango,andit offerstheModelViewTemplate(MVT)pattern.InDjango, theprocessingoftherequest,alongwithsessionhandling andvalidation,isdoneonthebackend.Djangoisahigh-level frameworkandoffersacleanabstractionofbusinesslogic, view,anddatamodel.
The user management system is based on the user authentication system provided by Django. The authenticationofuserscanbeachievedbyregisteringusers, approving accounts by administrators, logging in, and session usage. Role-based access control is used for restrictingaccessofcertainphishingdetectiontoolsbythe user.Theusercanbemanagedbyadministratorsusingthe dashboard.HashingofpasswordsandprotectionofCSRFare enabledtoavoidunauthorizedaccessofanyuser.

The mechanism of phishing detection is now integrated through Lang Chain with the Gemini API of Google. Lang Chainprovidesanorchestrationlayertonormalizeprompt structuringandstandardizesmanagingmodelinteractions, therebyprocessingAIresponsesinaconsistentformat.
This system receives user-supplied content in standardized form and requests Gemini LLM to perform semanticanalysis.Themodelsearchesformarkers,suchas urgency, impersonation, authority claims, suspicious requests, and misleading tone. This system classifies the content as phishing or legitimate and provides humanreadable reasoning for the same; hence, it builds transparencyandusertrust.
TheseQRcodeextractedURLsarethenfedintotheGemini model, which scores their malicious intent. The AI model furtheranalyzesthestructureoftheURL,domainpatterns, andothercontextualthreatindicatorsbeforethefinalresult oftheclassificationisreturned.
TheextractionoftheQRcodeimageisperformedthrough the library called OpenCV. This means that any QR code imageenteredintothesystemaspartoftheimageanalysis process allows for the extraction of the data within the image.ThisimpliesthatiftheextracteddatawasaURL,then theURLisusedastheclassifierfortheURLthroughtheAI system.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
Thisintegrationwillhelptoidentifymaliciouslinksthat areembeddedwithinaQRcode,thusattendingtosomeof theemergingattacks,suchasQRphishingor“quishing” As previously discussed, the pipeline shall ensure speed in decoding and integration with the proposed AI analysis module.
SQLiteservesasthebackenddatabasetostorecredentials oftheusers,authenticationdata,andactivities.Here,Object RelationalMappingofDjangoishelpfulindatamanagement inanorganizedandsecuredmanner.
TheimagesofuploadedQRcodesarestoredbyutilizing thefilehandlingfacilityofferedbyDjangoforatemporary periodoftime.Additionally,thesensitivedataisnotleaked to outsiders, but the AI component is processed within a specificenvironmentformaintaininguserprivacy.
The performance of a proposed Conversational AI Assistant will be analyzed in the context of detecting phishing emails and malicious QR-based URLs. Detection wascarriedoutusingastructureddatasetanduserinputto testtheperformanceofthesystemregardingcorrectnessof classification,dependability,andeaseofuse.
4.1
The system has been tested against different types of phishing emails, legitimate emails, phishing URLs, and legitimateURLsintheformofQRcodes.Therearedifferent typesofphishingschemesinthesystem,includingurgencybasedphishingschemes,impersonatingschemes,andURLbasedphishingschemes.
Theinputwillthenbeprocessedbypassingitthroughthe Django application, followed by analysis using the Gemini language model. In addition, the URLs provided in the QR codewillbedecodedusingOpenCV.Thiswillalsoinvolvean assessmentofthemaliciousintention.Thiswillbeachieved throughconsiderationoftheaccuracy,stability,andquality ofexplanationbytheconversationalAI.
The performance of the proposed model has been validatedusingabalanceddatasetof420phishingemails andanothersetof420legitimateemails.Theperformanceof theclassificationhasalsobeenvalidatedbasedonAccuracy, Precision, Recall, and F1 Score metrics. Overall, the correctnessofthemodelisquitehighinclassifyingphishing andlegitimateemails,asindicatedbyanaccuracyof95.24%. In addition, the precision level, which reflects the ratio of correctclassificationoflegitimateemailsasphishingemails,
isashighas96.8%.Thisshowsthatmostoftheemailsthat are given higher priority as phishing emails are actually such,therebyreducingfalsepositives.Similarly,therecall level,whichreflectsthecapabilityofthemodelintermsof reducingfalsenegatives,isashighas93.56%,asillustrated by its high value. This is further validated by its score of 95.15%,therebyaffirmingtherobustnessofthemodelasa correctbalancebetweenprecisionandrecall.
Otherthanthis,thereliabilityandconsistencyoftheQRbasedclassificationofmaliciousURLsapproachwerealso ensured through the use of the actual correct QR code decodingachievedthrough theapplicationofOpenCVand thesemanticevaluationoftheidentifiedURLsthroughthe application of the Large Language Model. The semantic evaluationoftheURLsthroughtheapplicationofAImethods hasshown improvements in terms of the enhancement of theactualaccuracyofdetection,comparedtothetraditional methodsofdetection,whichallowthebestofthemtocome underthecategoryofpsychologicalattacks.
Thesystemreliabilityhasalsobeenvalidatedbyundergoing extensivefunctionaltestingonalltheintegratedmodulesin the system. This has validated the consistency of function interactionbetweentheDjangobackendandGeminiAPIfor the purpose of carrying out semantic analysis, devoid of failedresponses.TheoperationoftheQRcodemodulehas successfully decoded the uploaded image using OpenCV, ensuringeffectiveacquisitionofthedetailsoftheURLstobe processed. Also, the implementation of the authentication function has shown to be effective in ensuring user login, session operation, and admin functionality, devoid of unauthorized operation or session conflict. Further, the systemhassuccessfullyoperatedintheprocessofinvalid, incomplete, and empty inputs, devoid of crashes and instabilities. This has therefore validated the smooth navigation to the entire modules in the system, ensuring effectiveoperationundernormalcircumstances.
Theproposedsystemutilizesvarioussecurityfactorsthat include consideration of security factors related to access control and data security. For example, the Django authentication module provides clients with access to protection of password hashing, support of sessions, and protection against a variety of web-based attack patterns, such as Cross-Site Request Forgery Attacks. Role-based accesscontrolofphishingdetectionmodulesisrestrictedto authorized users, whereas inappropriate admin access is restricted to authorized personnel only. Inappropriate inputs,suchasemailsand QRcode entries,arecontrolled usingthesystemtoavoidsuperfluousdatastorage,which cancompromisetheserisks.Moreover,thepresentedsystem willbemoreeffectiveatphishingdetectionusingthehelpof AI,bypassingtheneedforrule-baseddetection.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
From the point of view of usability, it is seen that the systemhasbeendevelopedinsuchawaythatitcanbeused by any user, whether technical or nontechnical, due to its simpleandorganizedinterface.Thereisalsoclarityinterms of classification results and explanations provided by the systemtomakebetterdecisions.Aconversationalassistant has also been integrated, which would be extremely beneficialtopromotefurtherusercyberawareness.



Thehighprecisionvaluealsoimpliesthatthesystemisnot likelytoclassifylegitimateemailsasphishingemails,which isquiteuseful.Furthermore,thehighvaluefortherecalltest
shows the system is able to detect almost all phishing attempts,thusbeingeffective.
With the assistance of semantics analysis, the detection can be improved over traditional rule-based systems, especially when trying to filter more complex phishing scenariosthatarebasedonpsychologicalmanipulation.
Also, the application of the conversational interface promotesusabilitysinceuserscanobtainexplanationsfor betterunderstandingoftherationalebehindclassification. This way, there is an improvement in cybersecurity awareness.
ThispaperhasproposedanAI-basedphishingdetection system in order to enhance user awareness and security against modern phishing attacks. The proposed phishing detectionsystemiscomposedofseveraldifferentfunctional elements, including safe user and administrator authenticationsaswellasphishingemailanalysis,dialogue, andQRcodedetectionformaliciousactivities.Thisproposed system,basedontheGoogleGeminiAPIandLangChainand computer vision technology using OpenCV, is capable of classificationandeasyunderstandingaswellassafetytips.
This ensures controlled access to the system, authentication, and sufficient administration, further enhancing reliability and governance. Overall functional testing confirmed that the system was successful in identifying phishing content, analyzing sender content, handlinginvalidcontent,andgeneratingrelevantcontext.
In contrast, when considering conventional phishing detection system development, the primary focus is normallyondevelopingamechanismforsuchidentification at the binary level. However, more focus is placed on explainability and user interaction using the proposed method, which is extremely useful for developing cybersecurity awareness and informed decisions. The system appears to have promising features to develop an effectivemechanismagainstphishingemailsandmalicious QR code attacks using relevant attributes of AI-driven semanticanalysis.
Even though the proposed system features efficient phishing detection and user navigation, there are still improvementstobemadetoenrichthescopeofthissystem. Someoftheseimprovementsfortheproposedsystemmight includeadditionalsupportforthedetectionsystem,which can be used for various phishing attacks, including SMS phishing,voicephishing,andsocialmediaphishing.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056
Volume: 13 Issue: 03 | Mar 2026 www.irjet.net p-ISSN: 2395-0072
In addition to that, having support for multi-language phishingdetectioncanmaketheapplicationmorepalatable todifferentcategoriesofusers.Theapplicationcanalsobe extended to incorporate intelligence feeds from different sources, such as Phish Tank and Open Phish, which can enhance its detection capabilities using updated phishing data. The application also has the ability to be used by mobileusersviaamobileapplication.
Further enhancements could include the integration of automated incident response with Security Management Systems (SIEM/SOAR) as well as the implementation of interactive cybersecurity training modules to reduce the susceptibilityofhumanstophishingattempts.
[1] S. Hossain, D. Sarma, and R. J. Chakma, “Machine Learning-BasedPhishingAttackDetection,”International JournalofAdvancedComputerScienceandApplications (IJACSA),2020.[Online].Available:www.ijacsa.thesai.org
[2]M.N.Alam,D.Sarma,F.F.Lima,I.Saha,R.E.Ulfath, andS.Hossain,“Phishingattacksdetectionusingmachine learningapproach,”inProc.3rdInt.Conf.SmartSystems andInventiveTechnology(ICSSIT),IEEE,Aug.2020,pp. 1173–1179.doi:10.1109/ICSSIT48917.2020.9214225
[3]N.Chou,R.Ledesma,Y.Teraguchi,andJ.C.Mitchell, “Client-side defense against web-based identity theft.” [Online].Available:www.ebaymode.com
[4]D.Miyamoto,H.Hazeyama,andY.Kadobayashi,“An evaluation of machine learning-based methods for detection of phishing sites,” Proc. IEEE International Symposium on Applications and the Internet (SAINT), 2008.
[5]Anti-PhishingWorkingGroup(APWG),“PhishingEmailReportsandPhishingSiteTrends,”PhishingActivity Trends Report, 2022. [Online]. Available: http://www.apwg.org
[6] D. Stuttard and M. Pinto, The Web Application Hacker’s Handbook: Finding and Exploiting Security Flaws.Hoboken,NJ,USA:Wiley,2011.
[7] Fatima Salahdine, Zakaria El Mrabet, Naima Kaabouch, “Phishing Attacks Detection A Machine Learning-Based Approach”, Proc. IEEE, Dec. 2021. doi: 10.1109/UEMCON53757.2021.9666627