增强用户抵御AI增强型钓鱼攻击的能力:一种用于检测和个性化训练的两阶段框架
Enhancing User Resilience Against AI-Augmented Phishing: A Two-Stage Framework for Detection and Personalized Training
AI总结:
针对AI增强型钓鱼攻击带来的新威胁,研究人员提出两阶段反钓鱼框架CyberGLA,结合EmailKnight检测工具与LLM安全教练,实现技术防御与个性化用户训练,以提升用户抵御此类攻击的能力。
AI中文摘要:
人工智能(包括智能体和深度伪造技术)的快速发展加快了钓鱼攻击的速度,降低了攻击者的门槛。现代钓鱼攻击融合了多种策略,包括社会工程学、URL欺骗和AI深度伪造,使攻击者能够制作极具说服力的信息,利用人类的弱点并绕过传统检测系统。与此同时,当前的安全意识教育难以跟上这些不断演变的威胁的速度、复杂性和精密程度。为应对这一挑战,我们提出了两阶段反钓鱼框架CyberGLA,该框架结合了技术防御和以用户为中心的安全教育。在检测阶段,我们引入EmailKnight,这是一种执行多级电子邮件分析的欺骗检测工具;为增强用户意识,训练阶段采用基于大语言模型(LLM)的安全教练,该教练会根据检测阶段的结果动态选择个性化训练模块。这种双重用途的设计理念可有效抵御现代电子邮件钓鱼攻击的不断演变的威胁。
英文摘要:
The rapid development of artificial intelligence, including agents and deepfake techniques, has accelerated phishing attacks and lowered the threshold for attackers. Modern phishing attacks now blend multiple tactics, including social engineering, URL spoofing, and AI deepfakes enabling adversaries to craft highly convincing messages that exploit human vulnerabilities and bypass traditional detection systems. At the same time, current security awareness education struggles to keep up with the speed, sophistication, and complexity of these evolving threats. To address this challenge, we propose a two-stage anti-phishing framework, CyberGLA, that combines technical defense and user-centered security education. In the Detection stage, we introduce EmailKnight, a spoof detection tool that performs multi-level email analysis. To enhance user awareness, the Training stage incorporates a large language model (LLM)-based security coach that dynamically selects personalized training modules based on the outcomes of the Detection stage. This dual purpose design philosophy enables effective protection against the evolving threats of modern email phishing attacks.