NLP and Deep Learning for Phishing and Social Engineering Detection: A Systematic Review (2018–2026)

  • Ovan Sunarto Pulu
  • Muhammad Fadly
N/ACitations
Citations of this article
6Readers
Mendeley users who have this article in their library.

Abstract

Phishing and social engineering continue to escalate as digital public services and online commerce expand, with attackers exploiting linguistic deception, impersonation cues, and routine “click-and-comply” behavior across email, SMS, and voice channels. Objective: This study aims to systematically synthesize research on phishing and social engineering detection using natural language processing (NLP) and deep learning (2018–2026) to address fragmented evidence across channels and inconsistent terminology that limits robust comparison and practical translation. Method: A systematic literature review was conducted through structured database searches and snowballing, followed by deduplication, staged screening, and eligibility assessment. Studies were analyzed using a standardized extraction form, then synthesized via descriptive mapping and thematic analysis to develop a method taxonomy and examine evaluation rigor and operational readiness. Findings: The evidence base is dominated by email/BEC detection, while smishing and vishing remain comparatively underrepresented. Methods increasingly rely on contextual language representations and hybrid architectures to capture semantic and local deception patterns; however, evaluation practices are heterogeneous and often provide limited evidence on cross-dataset generalization, temporal robustness, and deploy ability. Socio-technical findings also indicate that human susceptibility and system/client workflow vulnerabilities can moderate the real-world effectiveness of technical defenses. Implications: The proposed taxonomy supports method selection by channel and highlights actionable priorities for practice and policy, including standardized reporting, cross-dataset and temporal validation, robustness testing, and integration with operational security workflows. Originality: This review adds value by consolidating detection and deception-centric strands through explicit inclusion of impersonation, fraud email, and scam terminology, and by linking methodological choices to evaluation rigor and deployment constraints across email, SMS, and voice contexts.

Cite

CITATION STYLE

APA

Ovan Sunarto Pulu, & Muhammad Fadly. (2025). NLP and Deep Learning for Phishing and Social Engineering Detection: A Systematic Review (2018–2026). JITAR : Journal of Information Technology and Applications Research, 1(2), 62–77. https://doi.org/10.63956/jitar.v1i2.39

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free