arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

工程化欺骗:评估大语言模型生成的鱼叉式网络钓鱼中的个性化 pretext

Engineered Persuasion: Evaluating Personalized Pretexts in LLM-Generated Spear Phishing

Jerson Francia, Derek Hansen, Benjamin Schooley, Shydra Valynn Murray

arXiv 2609.04410首次发表:更新:

发表机构

Brigham Young University(杨百翰大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究评估LLM生成的鱼叉式网络钓鱼中个性化 pretext 的效果,发现随个性化级别提升可信度和点击意图增加,合适细节可提升可信度,相关结果可用于工作场所网络安全培训。

AI 中文摘要

大型语言模型可以低成本地将工作场所细节插入网络钓鱼 pretext 中,但这些细节可能会支持或破坏消息的可信度。我们招募了180名美国在职成年人,在一项公开调查中评估模拟的AI生成网络钓鱼电子邮件。这些电子邮件使用四个累积级别的信息:工作场所(第1级);收件人姓名和职位;工作职责;以及同事/共享项目背景(第4级)。参与者对每条消息的可信度进行0至100分的评分,选择一个指定操作(打开链接、调查、删除或举报),并解释他们评分最高和最低的消息突出的原因。在1436次有效评估中,敏感性分析显示,可信度随每个个性化级别增加2.40分,而点击意图的几率随每个级别增加28%。在未表达点击意图的参与者中,调查行为仍然常见,举报行为减少,删除行为增加。事后描述性分析发现,来自提及提供的同事的指定人员的消息,比来自部门或实体的消息获得更高的评分和点击意图。定性编码显示了添加细节为何有利或有害:与参与者角色和日常工作匹配的细节支持可信度,而不正确、模糊或渠道不合适的细节会引起怀疑。总之,结果表明,个性化不仅仅是添加更多细节的问题,还取决于 pretext 是否符合收件人的工作背景。我们讨论了这种区别如何为工作场所网络安全培训提供信息。

英文摘要

Large language models can insert workplace details into phishing pretexts at low cost, but those details may either support or undermine a message's credibility. We recruited 180 U.S. working adults to evaluate simulated, AI-generated phishing emails in a disclosed survey. The emails used four cumulative levels of information: workplace (Level 1); recipient name and job title; job responsibilities; and coworker/shared-project context (Level 4). Participants rated each message's convincingness from 0 to 100, chose one stated action (open the link, investigate, delete, or report), and explained why their highest- and lowest-rated messages stood out. Across 1,436 valid evaluations, convincingness increased by 2.40 points per personalization level in a sensitivity analysis, while the odds of expressing click intention increased by 28\% per level. Among participants who did not express an intention to click, investigation remained common, reporting declined, and deletion increased. A post-hoc descriptive analysis found higher ratings and click intention for messages from a named person who referenced a supplied coworker than for messages from a department or entity. Qualitative coding showed why added detail could help or hurt: details that matched participants' roles and routines supported credibility, while incorrect, vague, or channel-inappropriate details raised suspicion. Together, the results highlight that personalization is not simply a matter of adding more details: it depends on whether the pretext fits the recipient's work context. We discuss how this distinction can inform workplace cybersecurity training.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑