Author : Lt Col Yuvraj Singh
Date of Publication :7th February 2026
Abstract: Electronic mail remains a foundational communication mechanism within defence and government networks, supporting command, control, coordination, and information dissemination. At the same time, e-mail has emerged as one of the most exploited vectors for cyberattacks. Modern malicious e-mail campaigns extend far beyond conventional spam and include spear-phishing, credential harvesting, malware delivery, social engineering, and covert data exfiltration through carefully crafted messages. These attacks are often low-volume, highly targeted, and semantically sophisticated, enabling them to evade traditional rule-based and signature-driven filtering systems. In defence environments, the tolerance for false positives is extremely low, as blocking or delaying legitimate communication can disrupt mission-critical operations. This paper presents a comprehensive machine learning based anomaly detection system for malicious e-mail activity in defence networks. The proposed framework integrates semantic representation learning using transformer-based language models, graph-based structural analysis through graph neural networks, ensemble classification, and reinforcement learning for adaptive decision fusion. The system is designed to detect both known and previously unseen malicious e-mail behaviours while maintaining low false-positive rates, robustness under adversarial conditions, and operational reliability. Extensive experimental evaluation using benchmark datasets and defence-inspired simulated e-mail traffic demonstrates improved detection accuracy, resilience to adversarial manipulation, and suitability for deployment in high-security defence communication infrastructures.
Reference :