PC2Phish

Project

PC2phish is an innovative project aimed at strengthening the cyber resilience of local public administration through proactive detection of phishing and malware. By combining Artificial Intelligence, contextual analysis, and software monitoring, PC2phish seeks to protect citizens, institutions, and essential public services from digital threats.

About

PC2phish (Proactive Cybersecurity for Phishing) emerges as a response to the growing threat of phishing and malware within local public administration. Many municipal entities store sensitive personal and financial data, making them attractive targets for cyberattacks. The compromise of privileged accounts can expose not only an individual but also dozens or even hundreds of interconnected citizens and organizations.

In this context, PC2phish proposes an Artificial Intelligence–based solution capable of analyzing emails and software behavior in real time, alerting users to potential phishing or malware threats, and strengthening the digital resilience of public institutions. The project will be carried out in partnership with the Municipality of Valongo, demonstrated in a real environment and in compliance with European security and privacy regulations

Resarch Group

GECAD - Research Group on Intelligent Engineering and Computing for Advanced Innovation and Development

 

 

The GECAD (Research Group on Intelligent Engineering and Computing for Advanced Innovation and Development) is the largest Research & Development unit of the Polytechnic of Porto, based at the School of Engineering of the Polytechnic of Porto (ISEP). Coordinated by Professor Zita Vale and with Professor Maria Goreti Carvalho Marreiros as vice-coordinator, the group currently integrates more than 70 researchers, including over 20 PhD holders, with strong expertise in the application of Artificial Intelligence techniques to energy systems and intelligent systems.

  • Multi-agent modeling and simulation of energy systems;
  • Design and development of Demand Response models, applied in both simulated and real scenarios;
  • Management of distributed energy resources in smart grids, including large-scale penetration of electric vehicles and renewable sources;
  • Modeling and simulation of electricity markets;
  • Advanced data analysis and data mining techniques applied to energy and other domains.

 

The scientific recognition of GECAD is evident in multiple indicators: participation in more than 60 national and international projects, dozens of annual publications in prestigious scientific journals, and regular editing of special issues in leading international publications.

Aware of its responsibility to society, GECAD adopts the motto “Intelligence for a Sustainable, Safe, and Inclusive World”, directing its projects toward critical areas such as Energy, Transport, Environment, Economy, Social Inclusion, Critical Infrastructures, Security, Information Accessibility, and new forms of Socialization.

Vision

The goal of PC2phish is to become a reference tool in strengthening the digital protection of local Public Administration. The vision is to provide safer, more reliable, and more resilient public services by reducing cybersecurity incidents. In the long term, the system is expected to be scalable and adaptable to multiple municipalities and public entities in Portugal and across Europe, while ensuring privacy and maintaining compliance with GDPR, NIS2, and the Cyber Resilience Act.

Summary

The PC2phish project aims to develop an Artificial Intelligence-based tool for the proactive detection of phishing emails and malware activity, specifically designed for employees of local Public Administration. Its main goal is to enhance system security, protect sensitive data, and reduce the risk of fraud and human error, while ensuring computational efficiency and privacy preservation.

Main Objectives:
  • Implement contextual email analysis (sender, headers, URLs, attachments)
  • Develop a text content analysis module based on LLM to detect persuasion tactics
  • Monitor software processes to identify malware and abnormal activities
  • Create educational materials and workshops to raise employee awareness
  • Validate the prototype in a real-world environment at the Valongo City Council

Work Packages

  • WP1 – Management, Communication and Dissemination
  • WP2 – Technical Specifications
  • WP3 – Phishing and Malware Detection
  • WP4 – PC2phish Proof of Concept