research

Using Codebooks to Detect Cybercrime Topics in Text Narratives

Published
Published
Reviewed
Reviewed
Next review due
Review due
Version
Version 1

The proposed contribution is a generalist-oriented prompting method that uses qualitative codebooks to detect cybercrime incidents in consumer narratives with pretrained language models.

By

MACHINE_LEARNINGEMPIRICAL
Trust and provenance

Editorial record

AI-assistance disclosure

Research Intelligence analysis generated with AI and checked against cited source evidence.

This record says human review did not occur.

Sources

  • arxiv.org2609.16000v1

    Claims attributed to the linked primary source in this content record.

    Version
    2609.16000v1
    Retrieved
    Reuse
    link-only

MACHINE LEARNING · EMPIRICAL

Original research: Using Codebooks to Detect Cybercrime Topics in Text Narratives · 2609.16000v1

Paper authors: Shufan Chai, Liangliang Sun, Jessica Staddon

Source license: CC BY-SA 4.0. This article summarizes and interprets the source using AI. Attribution does not imply endorsement by the source authors.

This adapted analysis is shared under the same CC BY-SA 4.0 license. Semantic status: supported by automated evidence review. Human scientific review and independent replication have not been established.

TL;DR

The proposed contribution is a generalist-oriented prompting method that uses qualitative codebooks to detect cybercrime incidents in consumer narratives with pretrained language models.

Source: E003, E008

For impostor scams, the codebook condition achieved strong average precision and recall and improved average precision relative to the baseline.

Source: E010

For identity theft, baseline precision was weaker, while the codebook condition attained stronger average precision and recall and improved average precision over baseline.

Source: E006

In the reported case studies, every evaluated model apart from the identified exception surpassed the stated precision-and-recall threshold under codebook prompting.

Source: E003, E009

Generalization may be limited to cybercrime attributes or events that are amenable to qualitative analysis and codebook development.

Source: E005

The study evaluates only a single prompt template and does not establish whether more elaborate templates would improve performance.

Source: E016

The findings suggest that resource-constrained organizations may be able to use pretrained models, potentially including lower-cost options, without specialized model development or domain expertise.

Source: E016

Significance

The proposed contribution is a generalist-oriented prompting method that uses qualitative codebooks to detect cybercrime incidents in consumer narratives with pretrained language models.

Source: E003, E008

The findings suggest that resource-constrained organizations may be able to use pretrained models, potentially including lower-cost options, without specialized model development or domain expertise.

Source: E016

Research Question

The research examines whether general-purpose pretrained language models can identify cybercrime in narrative text when guided by researcher-authored coding guidance.

Source: E004

Contribution

The proposed contribution is a generalist-oriented prompting method that uses qualitative codebooks to detect cybercrime incidents in consumer narratives with pretrained language models.

Source: E003, E008

Tested Scope

The empirical scope covers impostor scams and identity theft as the studied detection topics.

Source: E014

The approach assumes that its codebooks have been rigorously developed so that independent human annotators can apply them reliably and consistently.

Source: E001

Datasets

The impostor-scam corpus comprises deduplicated complaint narratives and includes both positive and negative labels.

Source: E017

The identity-theft corpus comprises deduplicated complaint narratives and includes both positive and negative labels.

Source: E018

The datasets were derived from publicly available, privacy-scrubbed consumer narratives whose submitters had consented to public release.

Source: E007

Method

The codebook condition uses a shared prompt structure containing a classification instruction, topic-specific coding guidance, a complaint narrative, and a constrained binary response.

Source: E002, E013

Baseline

The baseline uses the same prompt structure but omits the coding guidance.

Source: E012

Environment Sample

The evaluation compares codebook and baseline prompts across language models from the Gemini and GPT families, with repeated runs and generally default settings where feasible.

Source: E015

Metrics

Prompt performance is assessed using precision and recall.

Source: E015

Findings

For impostor scams, the codebook condition achieved strong average precision and recall and improved average precision relative to the baseline.

Source: E010

For identity theft, baseline precision was weaker, while the codebook condition attained stronger average precision and recall and improved average precision over baseline.

Source: E006

In the reported case studies, every evaluated model apart from the identified exception surpassed the stated precision-and-recall threshold under codebook prompting.

Source: E003, E009

Training Setup

Development of the impostor-scam codebook included an inter-annotator agreement assessment on a shared narrative set, with strong reported agreement.

Source: E017

Limitations

Generalization may be limited to cybercrime attributes or events that are amenable to qualitative analysis and codebook development.

Source: E005

The study evaluates only a single prompt template and does not establish whether more elaborate templates would improve performance.

Source: E016

Failure Modes

Public availability of a detector and its codebook could enable users to alter narratives strategically in order to influence classification outcomes.

Source: E005, E011

Practical Implications

The findings suggest that resource-constrained organizations may be able to use pretrained models, potentially including lower-cost options, without specialized model development or domain expertise.

Source: E016

Evidence and source

Show evidence locators

Evidence labels locate support in the original paper; they do not establish independent replication.

  1. E001 · page 45 https://www.fdic.gov/consumer-resource-center/cybersecurity: Evidence E001
  2. E002 · page 31 While it is possible for an incident to involve both identity theft and an impostor: Evidence E002
  3. E003 · page 1Introduction: Evidence E003
  4. E004 · page 1Introduction: Evidence E004
  5. E005 · page 55 https://www.fdic.gov/consumer-resource-center/cybersecurity: Evidence E005
  6. E006 · page 43 Both “imposter” and “impostor” are common spellings and we did not observe any: Evidence E006
  7. E007 · page 21 While it is possible for an incident to involve both identity theft and an impostor: Evidence E007
  8. E008 · page 1Abstract: Evidence E008
  9. E009 · page 31 While it is possible for an incident to involve both identity theft and an impostor: Evidence E009
  10. E010 · page 43 Both “imposter” and “impostor” are common spellings and we did not observe any: Evidence E010
  11. E011 · page 65 https://www.fdic.gov/consumer-resource-center/cybersecurity: Evidence E011
  12. E012 · page 31 While it is possible for an incident to involve both identity theft and an impostor: Evidence E012
  13. E013 · page 31 While it is possible for an incident to involve both identity theft and an impostor: Evidence E013
  14. E014 · page 21 While it is possible for an incident to involve both identity theft and an impostor: Evidence E014
  15. E015 · page 31 While it is possible for an incident to involve both identity theft and an impostor: Evidence E015
  16. E016 · page 65 https://www.fdic.gov/consumer-resource-center/cybersecurity: Evidence E016
  17. E017 · page 31 While it is possible for an incident to involve both identity theft and an impostor: Evidence E017
  18. E018 · page 31 While it is possible for an incident to involve both identity theft and an impostor: Evidence E018