Judging Phishing Under Uncertainty: How Do Users Handle Inaccurate Automated Advice?
Tarini Saka, Kalliopi Vakali, Adam D. G. Jenkins, Nadin Kokciyan, Kami Vaniea
Abstract
Providing accurate and actionable advice about phishing emails is challenging. The majority of advice is generic and hard to implement. Phishing emails that pass through filters and land in user inboxes are usually sophisticated and exploit differences between how humans and computers interpret emails. Therefore, users need accurate and relevant guidance to take the right action. This study investigates the effectiveness of guidance based on features extracted from emails, which even in AI-driven systems can sometimes be inaccurate, leading to poor advice. We examined three conditions: control (generic advice), perfect advice, and realistic advice, through an online survey of 489 participants on Prolific, and measured user accuracy and confidence in phishing detection with and without guidance. Our findings indicate that having advice specific to the email is more effective than generic guidance (control). Inaccuracies in the guidance can also impact user decisions and reduce detection accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 61f92554-cf7a-4808-adc1-e41674a5a854Builds on12
- How I Learned to be Secure: a Census-Representative Survey of Security Advice Sources and BehaviorElissa M. Redmiles, Sean Kross, Michelle L. MazurekCCS 2016 · 192 citations
- Cognitive Triaging of Phishing AttacksAmber van der Heijden, Luca AllodiUSENIX Security 2019 · 100 citations
- When Confidence Meets Accuracy: Exploring the Effects of Multiple Performance Indicators on Trust in Machine Learning ModelsAmy Rechkemmer, Ming YinCHI 2022 · 94 citations
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 92 citations
- How Experts Detect Phishing Scam EmailsRick WashCSCW 2020 · 76 citations
Related papers
- It's a Match - Enhancing the Fit between Users and Phishing Training through PersonalisationLorin Schöni, Neele Roch, Hannah Sievers, Martin Strohmeier et al.CHI 2025 · 5 citations
- Lending a Hand: The Effectiveness of Support Systems in Assisting Users to Detect Phishing AttacksKatharina Schiller, Jörg Scheidt, Florian Adamsky, Zinaida BenensonCHI 2026 · 2 citations
- AI2TALE: An Innovative Information Theory-based Approach for Learning to Localize Phishing AttacksVan Nguyen, Tingmin Wu, Xingliang Yuan, Marthie Grobler et al.ICLR 2025
- SoK: PHILTER: Uncovering Security and Functional Gaps in AI-based Phishing Website Detection Literature via an LLM-based Reasoning FrameworkMahbub Alam, Muhammad Lutfor Rahman, Sonjoy Kumar Paul, Amy W. Hays et al.USENIX Security 2026
- Improving Human-AI Collaboration With Descriptions of AI BehaviorÁngel Alexander Cabrera, Adam Perer, Jason I. HongCSCW 2023 · 85 citations
