Aria AI · Project 03 / 25

Phish — Suspicious Email and Message Review

Review Persian and English messages with evidence-linked labels. Urgency alone is not phishing. Links are defanged, attachments are not opened, and the demo never returns a safe verdict.

Dataset Model Collection Organization
256 messagesPersian / English fixtures, seed 3
Campaign splitTrain and test lures do not overlap
Three labelsSuspicious, needs review, insufficient
CPURules + TF-IDF + LightGBM · no paid API

Organization Gradio hosting needs Team/Enterprise. Personal PRO has a daily Space-creation cap (20/day), so the interactive workstation is queued for alirezaaminzadeh/phish when that cap resets. Dataset, model, and this card already live under AriaAICompany.

Recorded sample · bank_otp_fa-00

Decision suspicious · severity high · confidence high · hash d9ff859335fe256e · 738 ms

KindFinding
ObservedReply-To domain does not match the From domain.
ObservedReturn-Path domain does not match the From domain.
ObservedVisible link text and actual href host do not match. Host defanged: hxxp://bmi-secure-login[.]example/otp/003
ObservedHost resembles the brand «bmi» but is not on the known-owner list.
ObservedMessage asks for a login or account update.
ObservedCopied Authentication-Results is not proof of SPF/DKIM/DMARC.
Inferencerule 1.00 · TF-IDF 0.86 · LightGBM 0.93 (calibrated lab scores, not a safe/unsafe certificate)

Held-out campaign test (96 messages)

MethodPR-AUCRecall @ FPR 0.10Brier
rule-structural1.001.000.10
tfidf-lr1.001.000.15
lightgbm-structural1.001.000.16

Hard-negative invoices and login notices were never labeled suspicious (0.00). Lab PR-AUC on synthetic fixtures is not operational accuracy.

فیش

ایمیل مشکوک را با شاهد قابل‌کلیک بررسی می‌کند. واژه «فوری» به‌تنهایی فیشینگ نیست. نتیجه «امن» وجود ندارد. لینک فقط تجزیه و خنثی می‌شود. دیتاست و مدل کوچک روی حساب سازمانی آریا ای آی منتشر شده‌اند.