research

Using Codebooks to Detect Cybercrime Topics in Text Narratives

The proposed contribution is a generalist-oriented prompting method that uses qualitative codebooks to detect cybercrime incidents in consumer narratives with pretrained language models.

Published
Published
Reviewed
Reviewed
Next review due
Review due
Version
Version 1

By

MACHINE_LEARNINGEMPIRICAL
About this BaitaPhish analysis and its review
Trust and provenance

Editorial record

AI-assistance disclosure

Research Intelligence analysis generated with AI and checked against cited source evidence.

This record says human review did not occur.

Sources

  • arxiv.org2609.16000v1

    Claims attributed to the linked primary source in this content record.

    Version
    2609.16000v1
    Retrieved
    Reuse
    link-only

TL;DR

  • For impostor scams, the codebook condition achieved strong average precision and recall and improved average precision relative to the baseline.

    Source: [10]

  • For identity theft, baseline precision was weaker, while the codebook condition attained stronger average precision and recall and improved average precision over baseline.

    Source: [6]

  • In the reported case studies, every evaluated model apart from the identified exception surpassed the stated precision-and-recall threshold under codebook prompting.

    Source: [3], [9]

  • Generalization may be limited to cybercrime attributes or events that are amenable to qualitative analysis and codebook development.

    Source: [5]

Why This Matters

Source-paper contributions

The proposed contribution is a generalist-oriented prompting method that uses qualitative codebooks to detect cybercrime incidents in consumer narratives with pretrained language models.

Source: [3], [8]

The findings suggest that resource-constrained organizations may be able to use pretrained models, potentially including lower-cost options, without specialized model development or domain expertise.

Source: [16]

Research question and scope

The research examines whether general-purpose pretrained language models can identify cybercrime in narrative text when guided by researcher-authored coding guidance.

Source: [4]

Tested scope and boundaries

The empirical scope covers impostor scams and identity theft as the studied detection topics.

Source: [14]

The approach assumes that its codebooks have been rigorously developed so that independent human annotators can apply them reliably and consistently.

Source: [1]

Evaluation datasets

The impostor-scam corpus comprises deduplicated complaint narratives and includes both positive and negative labels.

Source: [17]

The identity-theft corpus comprises deduplicated complaint narratives and includes both positive and negative labels.

Source: [18]

The datasets were derived from publicly available, privacy-scrubbed consumer narratives whose submitters had consented to public release.

Source: [7]

How the method works

The codebook condition uses a shared prompt structure containing a classification instruction, topic-specific coding guidance, a complaint narrative, and a constrained binary response.

Source: [2], [13]

Comparison baseline

The baseline uses the same prompt structure but omits the coding guidance.

Source: [12]

Evaluation environment

The evaluation compares codebook and baseline prompts across language models from the Gemini and GPT families, with repeated runs and generally default settings where feasible.

Source: [15]

Evaluation metrics

Prompt performance is assessed using precision and recall.

Source: [15]

Key Findings

Paper reports

For impostor scams, the codebook condition achieved strong average precision and recall and improved average precision relative to the baseline.

Source: [10]

For identity theft, baseline precision was weaker, while the codebook condition attained stronger average precision and recall and improved average precision over baseline.

Source: [6]

In the reported case studies, every evaluated model apart from the identified exception surpassed the stated precision-and-recall threshold under codebook prompting.

Source: [3], [9]

Training Setup

Development of the impostor-scam codebook included an inter-annotator agreement assessment on a shared narrative set, with strong reported agreement.

Source: [17]

Limitations

Generalization may be limited to cybercrime attributes or events that are amenable to qualitative analysis and codebook development.

Source: [5]

The study evaluates only a single prompt template and does not establish whether more elaborate templates would improve performance.

Source: [16]

Failure Modes

Public availability of a detector and its codebook could enable users to alter narratives strategically in order to influence classification outcomes.

Source: [5], [11]

Paper Details

Machine Learning · Empirical

Original research: Using Codebooks to Detect Cybercrime Topics in Text Narratives · 2609.16000v1

Paper authors: Shufan Chai, Liangliang Sun, Jessica Staddon

Source license: CC BY-SA 4.0. This article summarizes and interprets the source using AI. Attribution does not imply endorsement by the source authors.

This adapted analysis is shared under the same CC BY-SA 4.0 license. Semantic status: supported by automated evidence review. Human scientific review and independent replication have not been established.

Canonical source identity
arXiv 2609.16000
Analyzed source version
v1
Source retrieved
BaitaPhish analysis published
BaitaPhish analysis reviewed

Evidence & Provenance

Show evidence locators

Evidence labels locate support in the original paper; they do not establish independent replication.

  1. E001 · page 4 — 5 https://www.fdic.gov/consumer-resource-center/cybersecurity: Evidence E001
  2. E002 · page 3 — 1 While it is possible for an incident to involve both identity theft and an impostor: Evidence E002
  3. E003 · page 1 — Introduction: Evidence E003
  4. E004 · page 1 — Introduction: Evidence E004
  5. E005 · page 5 — 5 https://www.fdic.gov/consumer-resource-center/cybersecurity: Evidence E005
  6. E006 · page 4 — 3 Both “imposter” and “impostor” are common spellings and we did not observe any: Evidence E006
  7. E007 · page 2 — 1 While it is possible for an incident to involve both identity theft and an impostor: Evidence E007
  8. E008 · page 1 — Abstract: Evidence E008
  9. E009 · page 3 — 1 While it is possible for an incident to involve both identity theft and an impostor: Evidence E009
  10. E010 · page 4 — 3 Both “imposter” and “impostor” are common spellings and we did not observe any: Evidence E010
  11. E011 · page 6 — 5 https://www.fdic.gov/consumer-resource-center/cybersecurity: Evidence E011
  12. E012 · page 3 — 1 While it is possible for an incident to involve both identity theft and an impostor: Evidence E012
  13. E013 · page 3 — 1 While it is possible for an incident to involve both identity theft and an impostor: Evidence E013
  14. E014 · page 2 — 1 While it is possible for an incident to involve both identity theft and an impostor: Evidence E014
  15. E015 · page 3 — 1 While it is possible for an incident to involve both identity theft and an impostor: Evidence E015
  16. E016 · page 6 — 5 https://www.fdic.gov/consumer-resource-center/cybersecurity: Evidence E016
  17. E017 · page 3 — 1 While it is possible for an incident to involve both identity theft and an impostor: Evidence E017
  18. E018 · page 3 — 1 While it is possible for an incident to involve both identity theft and an impostor: Evidence E018