SearcharxivSearch

arXiv subjects

Hiroki Nakano

Publications and source records attributed to Hiroki Nakano.

At least 19 recordsLinked to original sources

Designing electronic magnetoelectric matter with organic quantum spin trimers

Magnetoelectric (ME) phenomena are commonly driven by spin-lattice coupling. Here we demonstrate a different route based on frustrated quantum spin trimers that intrinsically intertwine magnetic moments and electric dipoles. Using molecular design principles, we realize a weakly coupled lattice of equilateral $S=1/2$ spin trimers in the organic radical crystal TNN$\cdot$CH$_3$CN. In this material, correlated electronic fluctuations within each trimer generate electric dipoles, while geometrically frustrated intertrimer interactions organize them into collective ME states. Magnetization, thermodynamic, and dielectric measurements reveal multiple magnetic-field-induced phases, including the $1/3$-magnetization plateau marked by pronounced dielectric anomalies. Effective low-energy theories and numerical simulations show that these phenomena are driven by electronically generated trimer dipoles whose collective order is stabilized by frustration relief of the intertrimer interactions, establishing a direct connection between geometric frustration and emergent magnetoelectricity. Our results identify quantum spin trimers as multifunctional building blocks, providing a bottom-up route for designing correlated ME materials from electronically active quantum spin clusters.

cond-mat.str-el

TIBlender: Early-Warning Threat Intelligence from Cross-Platform Social Media Evidence

Cyber threat signals are fragmented across multiple social media platforms, yet no existing approach has fully automated their integration into actionable threat intelligence (TI) reports. We present TIBlender, a multi-agent system that monitors four platforms (X, Reddit, Telegram, and Discord) and produces structured TI reports via role-specialized LLM agents. These agents conduct multi-perspective investigations, tracing chains of evidence to uncover related Indicators of Compromise (IoCs) via collaborative, evidence-backed analysis. In a real-world deployment, TIBlender detected emerging threats across all four threat categories ahead of public feeds, including in-the-wild exploitation ahead of public vulnerability registries; the majority of its IoCs were absent from each evaluated feed. Quantitative evaluation confirms that each platform contributes unique threat information unavailable from the others, and that excluding any single platform results in substantial loss of reports in specific threat categories. Under identical single-platform input conditions, TIBlender's IoC extraction meets or exceeds each baseline; the full pipeline surfaces substantially more IoCs, most of which are absent from any single-platform baseline. These results establish cross-platform social media monitoring as an effective and scalable early-warning layer for operational TI pipelines.

cs.CR

PhishLumos: An Adaptive Multi-Agent System for Proactive Phishing Campaign Mitigation

Phishing attacks are a significant societal threat, disproportionately harming vulnerable populations and eroding trust in essential digital services. Current defenses are often reactive, failing against modern evasive tactics like cloaking that conceal malicious content. To address this, we introduce PhishLumos, an adaptive multi-agent system that proactively mitigates entire attack campaigns. It confronts a core cybersecurity imbalance: attackers can easily scale operations, while defense remains an intensive expert task. Instead of being blocked by evasion, PhishLumos treats it as a critical signal to investigate the underlying infrastructure. Its Large Language Model (LLM)-powered agents uncover shared hosting, certificates, and domain registration patterns. On real-world data, our system identified 100% of campaigns in the median case, over a week before their confirmation by cybersecurity experts. PhishLumos demonstrates a practical shift from reactive URL blocking to proactive campaign mitigation, protecting users before they are harmed and making the digital world safer for all.

cs.CR

Spin excitation of the Heisenberg antiferromagnet with frustration: from the bounce-lattice antiferromagnet through the maple-leaf-lattice antiferromagnet to the exact-dimer system

The spin-S Heisenberg antiferromagnet on the two-dimensional lattice is investigated for S=1/2 and S=1. We consider interaction at isolated dimers ($J_{\rm d}$) and interaction bonds that form the bounce lattice ($J_{\rm b}$). For $J_{\rm d}=J_{\rm b}$, the system is reduced to the maple-leaf-lattice antiferromagnet. We primarily conduct highly parallelized numerical diagonalization to examine the spin excitation gap above the ground state for various $J_{\rm b}/J_{\rm d}$ cases. For S=1/2, we report calculations for a 42-site cluster that has not been previously treated. The S=1 case is examined for the first time for clusters up to 24 sites. Regardless of whether S=1/2 or 1, we find that the system has a gapped nature for small $J_{\rm d}/J_{\rm b}$ and becomes gapless at $J_{\rm d}/J_{\rm b}\sim 1.4$. For S=1, we also find that another gapped region appears between the gapless case at $J_{\rm d}/J_{\rm b}\sim 1.4$ and the boundary of the exact-dimer phase.

cond-mat.mtrl-sci

Clouding the Mirror: Stealthy Prompt Injection Attacks Targeting LLM-based Phishing Detection

Phishing sites continue to grow in volume and sophistication. Recent work leverages large language models (LLMs) to analyze URLs, HTML, and rendered content to decide whether a website is a phishing site. While these approaches are promising, LLMs are inherently vulnerable to prompt injection (PI). Because attackers can fully control various elements of phishing sites, this creates the potential for PI that exploits the perceptual asymmetry between LLMs and humans: instructions imperceptible to end users can still be parsed by the LLM and can stealthily manipulate its judgment. The specific risks of PI in phishing detection and effective mitigation strategies remain largely unexplored. This paper presents the first comprehensive evaluation of PI against multimodal LLM-based phishing detection. We introduce a two-dimensional taxonomy, defined by Attack Techniques and Attack Surfaces, that captures realistic PI strategies. Using this taxonomy, we implement diverse attacks and empirically study several representative LLM-based detection systems. The results show that phishing detection with state-of-the-art models such as GPT-5 remains vulnerable to PI. We then propose InjectDefuser, a defense framework that combines prompt hardening, allowlist-based retrieval augmentation, and output validation. Across multiple models, InjectDefuser significantly reduces attack success rates. Our findings clarify the PI risk landscape and offer practical defenses that improve the reliability of next-generation phishing countermeasures.

cs.CR

Numerical Diagonalization Study of the Phase Boundaries of the S=2 Heisenberg Antiferromagnet on the Orthogonal Dimer Lattice

The S=2 Heisenberg antiferromagnet on the orthogonal dimer lattice is studied. The edges of the exact dimer and Neel-ordered phases in the ground state of the system are examined by the numerical diagonalization method. Our present results are discussed by combining them with previously obtained estimates for smaller-S cases. We find that an intermediate region between the exact dimer and Neel-ordered phases gradually widens as spin S is increased up to S=2.

cond-mat.mtrl-sci

Understanding Reader Perception Shifts upon Disclosure of AI Authorship

As AI writing support becomes ubiquitous, how disclosing its use affects reader perception remains a critical, underexplored question. We conducted a study with 261 participants to examine how revealing varying levels of AI involvement shifts author impressions across six distinct communicative acts. Our analysis of 990 responses shows that disclosure generally erodes perceptions of trustworthiness, caring, competence, and likability, with the sharpest declines in social and interpersonal writing. A thematic analysis of participants' feedback links these negative shifts to a perceived loss of human sincerity, diminished author effort, and the contextual inappropriateness of AI. Conversely, we find that higher AI literacy mitigates these negative perceptions, leading to greater tolerance or even appreciation for AI use. Our results highlight the nuanced social dynamics of AI-mediated authorship and inform design implications for creating transparent, context-sensitive writing systems that better preserve trust and authenticity.

cs.HC

PhishParrot: LLM-Driven Adaptive Crawling to Unveil Cloaked Phishing Sites

Phishing attacks continue to evolve, with cloaking techniques posing a significant challenge to detection efforts. Cloaking allows attackers to display phishing sites only to specific users while presenting legitimate pages to security crawlers, rendering traditional detection systems ineffective. This research proposes PhishParrot, a novel crawling environment optimization system designed to counter cloaking techniques. PhishParrot leverages the contextual analysis capabilities of Large Language Models (LLMs) to identify potential patterns in crawling information, enabling the construction of optimal user profiles capable of bypassing cloaking mechanisms. The system accumulates information on phishing sites collected from diverse environments. It then adapts browser settings and network configurations to match the attacker's target user conditions based on information extracted from similar cases. A 21-day evaluation showed that PhishParrot improved detection accuracy by up to 33.8% over standard analysis systems, yielding 91 distinct crawling environments for diverse conditions targeted by attackers. The findings confirm that the combination of similar-case extraction and LLM-based context analysis is an effective approach for detecting cloaked phishing attacks.

cs.CR

Translational Symmetry Broken Magnetization Plateau of the $S={{1}\over{2}}$ Anisotropic Spin Ladder with Ferromagnetic Rung Interaction

The magnetization process of the $S=1/2$ anisotropic spin ladder with the ferromagnetic rung interaction is investigated using the numerical diagonalization of finite-size clusters. It is found that the translational symmetry broken magnetization plateau would appear at half the saturation magnetization, when the competing anisotropies are sufficiently large. The phase diagram with respect to the anisotropies and several magnetization curves are presented.

cond-mat.str-el

Magnetization Plateau of the $S={1 \over 2}$ Distorted Diamond Spin Chain with Ferromagnetic Interaction

The magnetization process of the $S=1/2$ distorted diamond spin chain with ferromagnetic interactions is investigated using the numerical diagonalization of finite-size clusters. The level spectroscopy analysis applied for the model with the spin anisotropy indicates that two different magnetization plateau phases appear at 1/3 of the saturation magnetization. The phase diagrams for some typical interaction parameters are presented. In addition the magnetization curves for several typical parameters are obtained.

cond-mat.str-el

Translational-Symmetry-Broken Magnetization Plateaux of the $S=3/2$ Anisotropic Antiferromagnetic Chain

The magnetization process of the $S=3/2$ quantum spin chain with the $XXZ$ anisotropy and the single-ion anisotropy $D$ is investigated using the numerical diagonalization of finite-size clusters and the level spectroscopy analysis. We obtain the phase diagrams at 1/3 and 2/3 of the saturation magnetization to find that the translational-symmetry-broken magnetization plateau appears for the first time. The similarity and the difference between the phase diagrams of the present model and the related models are discussed by use of the discrete parameters of the models. In addition several typical magnetization curves are presented.

cond-mat.str-el

DomainDynamics: Lifecycle-Aware Risk Timeline Construction for Domain Names

The persistent threat posed by malicious domain names in cyber-attacks underscores the urgent need for effective detection mechanisms. Traditional machine learning methods, while capable of identifying such domains, often suffer from high false positive and false negative rates due to their extensive reliance on historical data. Conventional approaches often overlook the dynamic nature of domain names, the purposes and ownership of which may evolve, potentially rendering risk assessments outdated or irrelevant. To address these shortcomings, we introduce DomainDynamics, a novel system designed to predict domain name risks by considering their lifecycle stages. DomainDynamics constructs a timeline for each domain, evaluating the characteristics of each domain at various points in time to make informed, temporal risk determinations. In an evaluation experiment involving over 85,000 actual malicious domains from malware and phishing incidents, DomainDynamics demonstrated a significant improvement in detection rates, achieving an 82.58\% detection rate with a low false positive rate of 0.41\%. This performance surpasses that of previous studies and commercial services, improving detection capability substantially.

cs.CR

Detecting Phishing Sites Using ChatGPT

The emergence of Large Language Models (LLMs), including ChatGPT, is having a significant impact on a wide range of fields. While LLMs have been extensively researched for tasks such as code generation and text synthesis, their application in detecting malicious web content, particularly phishing sites, has been largely unexplored. To combat the rising tide of cyber attacks due to the misuse of LLMs, it is important to automate detection by leveraging the advanced capabilities of LLMs. In this paper, we propose a novel system called ChatPhishDetector that utilizes LLMs to detect phishing sites. Our system involves leveraging a web crawler to gather information from websites, generating prompts for LLMs based on the crawled data, and then retrieving the detection results from the responses generated by the LLMs. The system enables us to detect multilingual phishing sites with high accuracy by identifying impersonated brands and social engineering techniques in the context of the entire website, without the need to train machine learning models. To evaluate the performance of our system, we conducted experiments on our own dataset and compared it with baseline systems and several LLMs. The experimental results using GPT-4V demonstrated outstanding performance, with a precision of 98.7% and a recall of 99.6%, outperforming the detection results of other LLMs and existing systems. These findings highlight the potential of LLMs for protecting users from online fraudulent activities and have important implications for enhancing cybersecurity measures.

cs.CR

ScamFerret: Detecting Scam Websites Autonomously with Large Language Models

With the rise of sophisticated scam websites that exploit human psychological vulnerabilities, distinguishing between legitimate and scam websites has become increasingly challenging. This paper presents ScamFerret, an innovative agent system employing a large language model (LLM) to autonomously collect and analyze data from a given URL to determine whether it is a scam. Unlike traditional machine learning models that require large datasets and feature engineering, ScamFerret leverages LLMs' natural language understanding to accurately identify scam websites of various types and languages without requiring additional training or fine-tuning. Our evaluation demonstrated that ScamFerret achieves 0.972 accuracy in classifying four scam types in English and 0.993 accuracy in classifying online shopping websites across three different languages, particularly when using GPT-4. Furthermore, we confirmed that ScamFerret collects and analyzes external information such as web content, DNS records, and user reviews as necessary, providing a basis for identifying scam websites from multiple perspectives. These results suggest that LLMs have significant potential in enhancing cybersecurity measures against sophisticated scam websites.

cs.CR

DomainLynx: Leveraging Large Language Models for Enhanced Domain Squatting Detection

Domain squatting poses a significant threat to Internet security, with attackers employing increasingly sophisticated techniques. This study introduces DomainLynx, an innovative compound AI system leveraging Large Language Models (LLMs) for enhanced domain squatting detection. Unlike existing methods focusing on predefined patterns for top-ranked domains, DomainLynx excels in identifying novel squatting techniques and protecting less prominent brands. The system's architecture integrates advanced data processing, intelligent domain pairing, and LLM-powered threat assessment. Crucially, DomainLynx incorporates specialized components that mitigate LLM hallucinations, ensuring reliable and context-aware detection. This approach enables efficient analysis of vast security data from diverse sources, including Certificate Transparency logs, Passive DNS records, and zone files. Evaluated on a curated dataset of 1,649 squatting domains, DomainLynx achieved 94.7\% accuracy using Llama-3-70B. In a month-long real-world test, it detected 34,359 squatting domains from 2.09 million new domains, outperforming baseline methods by 2.5 times. This research advances Internet security by providing a versatile, accurate, and adaptable tool for combating evolving domain squatting threats. DomainLynx's approach paves the way for more robust, AI-driven cybersecurity solutions, enhancing protection for a broader range of online entities and contributing to a safer digital ecosystem.

cs.CR

DomainHarvester: Harvesting Infrequently Visited Yet Trustworthy Domain Names

In cybersecurity, allow lists play a crucial role in distinguishing safe websites from potential threats. Conventional methods for compiling allow lists, focusing heavily on website popularity, often overlook infrequently visited legitimate domains. This paper introduces DomainHarvester, a system aimed at generating allow lists that include trustworthy yet infrequently visited domains. By adopting an innovative bottom-up methodology that leverages the web's hyperlink structure, DomainHarvester identifies legitimate yet underrepresented domains. The system uses seed URLs to gather domain names, employing machine learning with a Transformer-based approach to assess their trustworthiness. DomainHarvester has developed two distinct allow lists: one with a global focus and another emphasizing local relevance. Compared to six existing top lists, DomainHarvester's allow lists show minimal overlaps, 4\% globally and 0.1\% locally, while significantly reducing the risk of including malicious domains, thereby enhancing security. The contributions of this research are substantial, illuminating the overlooked aspect of trustworthy yet underrepresented domains and introducing DomainHarvester, a system that goes beyond traditional popularity-based metrics. Our methodology enhances the inclusivity and precision of allow lists, offering significant advantages to users and businesses worldwide, especially in non-English speaking regions.

cs.CR

Collapsing Behavior of the Ferrimagnetic Ground State of the $S=1/2$ Heisenberg Antiferromagnet on the Lieb Lattice due to Frustration

We study the $S = 1/2$ Heisenberg antiferromagnet on the Lieb lattice accompanied by additional interactions that create frustration. The system exhibits a ferrimagnetic ground state in the absence of frustration. Further, we successfully observe a novel type of collapsing behavior of the ferrimagnetism via numerical diagonalization. The ferrimagnetic state is observed to collapse in a discontinuous manner. Furthermore, different ground states with small spontaneous magnetizations are obtained before the spontaneous magnetization finally disappears.

cond-mat.str-el

ChatSpamDetector: Leveraging Large Language Models for Effective Phishing Email Detection

The proliferation of phishing sites and emails poses significant challenges to existing cybersecurity efforts. Despite advances in malicious email filters and email security protocols, problems with oversight and false positives persist. Users often struggle to understand why emails are flagged as potentially fraudulent, risking the possibility of missing important communications or mistakenly trusting deceptive phishing emails. This study introduces ChatSpamDetector, a system that uses large language models (LLMs) to detect phishing emails. By converting email data into a prompt suitable for LLM analysis, the system provides a highly accurate determination of whether an email is phishing or not. Importantly, it offers detailed reasoning for its phishing determinations, assisting users in making informed decisions about how to handle suspicious emails. We conducted an evaluation using a comprehensive phishing email dataset and compared our system to several LLMs and baseline systems. We confirmed that our system using GPT-4 has superior detection capabilities with an accuracy of 99.70%. Advanced contextual interpretation by LLMs enables the identification of various phishing tactics and impersonations, making them a potentially powerful tool in the fight against email-based phishing threats.

cs.CR