Skip to content
Conference

CGL-FED: A Continual Graph-Based Learning Framework for Fraudulent Email Detection

Aug 2026 · 2026 6th International Conference on Emerging Smart Technologies and Applications (eSmarTA) · pp. 1-8 · 0 citations · 30 references

Abstract

Email communication remains the primary vector for sophisticated cyber threats, including phishing and spam, resulting in billions of dollars in annual financial losses. While state-of-the-art deep learning (DL) models have demonstrated high precision in static environments, they frequently suffer from performance degradation when deployed in dynamic, streaming environments—a phenomenon known as concept drift. Furthermore, traditional approaches to model updating lead to catastrophic forgetting, where the model’s weights are overwritten, affecting the ability to identify historical threat patterns. This paper presents a novel continual graph-based learning framework for fraudulent email detection (CGL-FED) that integrates a domain-specific fine-tuned DistilBERT encoder with a graph neural network (GNN) architecture. Unlike traditional instance-based graphs, CGL-FED maps contextual embeddings into a fixed-topology feature graph, ensuring structural stability and computational efficiency. To mitigate the forgetting challenge, the framework employs a rehearsal-based replay memory enhanced by segment-based masking. The extensive evaluation conducted on a large-scale corpus utilizing five benchmark datasets (Trec07p, Enron, SpamAssassin, Ling-Spam, and Nazario), shows that CGL-FED achieves state-of-the-art accuracy, reaching up to 100%. Additionally, it maintains an average cumulative forgetting rate of less than 0.005%. The proposed framework offers a robust, scalable, and industrial-ready solution for maintaining high-fidelity persistent identification of fraudulent messages in real-time cybersecurity operations.

View source

Similar papers

Open access Jul 2026

DriftGuard-HCL: Concept-Drift-Aware Continual Heterogeneous Graph Contrastive Learning for Evolving Financial Fraud Detection

Financial fraud detectors are commonly trained as stationary classifiers even though transaction distributions, merchant populations, and attack typologies evolve. This paper presents DriftGuard-HCL, a continual heterogeneous graph-contrastive framework that combines a scalable typed graph-context encoder, semantic-group contrastive regularization, delayed-label replay, and a relation-support-aware drift gate. Each transaction is modeled on a temporal customer–category–merchant graph; causal customer and merchant neighborhood summaries are fused with a typed relation embedding through a bilinear interaction. A multi-signal detector combines Jensen–Shannon divergence over category and amount distributions, latent feature shift, and novel-relation mass. The detector switches a stability–plasticity ensemble from a frozen warm-up anchor toward a replay-regularized current model only after a calibrated shift. We evaluate the method with a strict prequential protocol on the public BankSim benchmark: 30 six-day snapshots, a one-snapshot label delay, five shared random seeds, and no future-label feature construction. In the native chronological stream, DriftGuard-HCL obtains 0.732 PR-AUC and 0.648 F1. In a controlled emergent-typology stress stream, it obtains 0.747 PR-AUC and 0.668 F1, improving over a continually updated heterogeneous contrastive model by 0.169 PR-AUC and 0.306 F1. The drift detector triggers once at typology restoration and never in the native stream. These results are reproducible from the accompanying code and raw result files; they support the value of drift-gated adaptation while not constituting evidence of production-bank performance.

Kevin Liu · 0 citations
Open access Aug 2026

Phishing GAT: Adversarial-Hardened Phishing Email Detection via Semantic-Structural Fusion and Graph Attention Networks

PhishingGAT, a detector that fuses word-level semantic features with structural ones and is hardened against adversarial perturbation, is presented, a detector that fuses word-level semantic features with structural ones and is hardened against adversarial perturbation.

R. Kodali, Siva Rama Krishna T Dr · 0 citations
Open access Jul 2026

Fraud learns too: continual graph learning under strategic adversarial drift in dynamic networks

Game Theoretic Anticipatory Continual Graph Learning (GT-ACGL), a framework that casts fraud detection as a continuous Stackelberg game between a defender and an adaptive adversary, and encourages decision boundaries that remain comparatively stable under strategic structural perturbation.

Hui-Jie Fan, Yanan Jiao, M. Wang et al. · 1 citation
Open access Aug 2026

Resilient Semantic Threat Detection at the Edge: A Knowledge Distillation Framework for SMS Spam Classification

A high-efficiency detection framework utilizing DistilBERT, a distilled knowledge representation of the BERT transformer is proposed, substantiate the viability of Knowledge Distillation as a mechanism to deploy state-of-the-art semantic security filters on edge infrastructure.

Mrinal Mrinal, Neeraj Kumar · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.