OSINT Clinic: Co-designing AI-Augmented Collaborative OSINT Investigations for Vulnerability Assessment
Anirban Mukhopadhyay, Kurt Luther
Abstract
Small businesses need vulnerability assessments to identify and mitigate cyber risks. Cybersecurity clinics provide a solution by offering students hands-on experience while delivering free vulnerability assessments to local organizations. To scale this model, we propose an Open Source Intelligence (OSINT) clinic where students conduct assessments using only publicly available data. We enhance the quality of investigations in the OSINT clinic by addressing the technical and collaborative challenges. Over the duration of the 2023-24 academic year, we conducted a three-phase co-design study with six students. Our study identified key challenges in the OS-INT investigations and explored how generative AI could address these performance gaps. We developed design ideas for effective AI integration based on the use of AI probes and collaboration platform features. A pilot with three small businesses highlighted both the practical benefits of AI in streamlining investigations, and limitations, including privacy concerns and difficulty in monitoring progress.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Exploring The Impact of Proactive Generative AI Agent Roles In Time-Sensitive Collaborative Problem-Solving TasksAnirban Mukhopadhyay, Kevin Salubre, Hifza Javed, Shashank Mehrotra et al.CHI 2026 · 2 citations
- Reimagining Emotion AI at Home: Exploring the Potential of Emotion-adaptive Eco-feedback in Personal Assistant Using Matchmaking for AILu Jin, Apostolos K. Vavouris, Nico Castelli, Dominik Pins et al.UbiComp 2026 · 1 citation
Builds on20
- Why Johnny Can't Prompt: How Non-AI Experts Try (and Fail) to Design LLM PromptsJ. D. Zamfirescu-Pereira, Richmond Y. Wong, Bjoern Hartmann, Qian YangCHI 2023 · 892 citations
- The Metacognitive Demands and Opportunities of Generative AILev Tankelevitch, Viktor Kewenig, Auste Simkute, Ava Elizabeth Scott et al.CHI 2024 · 279 citations
- Design Principles for Generative AI ApplicationsJustin D. Weisz, Jessica He, Michael J. Muller, Gabriela Hoefer et al.CHI 2024 · 221 citations
- PentestGPT: Evaluating and Harnessing Large Language Models for Automated Penetration TestingGelei Deng, Yi Liu, Víctor Mayoral Vilches, Peng Liu et al.USENIX Security 2024 · 186 citations
- Is the Most Accurate AI the Best Teammate? Optimizing AI for TeamworkGagan Bansal, Besmira Nushi, Ece Kamar, Eric Horvitz et al.AAAI 2021 · 185 citations
Related papers
- OSINT Research Studios: A Flexible Crowdsourcing Framework to Scale Up Open Source Intelligence InvestigationsAnirban Mukhopadhyay, Sukrit Venkatagiri, Kurt LutherCSCW 2024 · 6 citations
- CyberGym: Evaluating AI Agents' Real-World Cybersecurity Capabilities at ScaleZhun Wang, Tianneng Shi, Jingxuan He, Matthew Cai et al.ICLR 2026 · 83 citations
- CyberGym-E2E: Scalable Real-World Benchmark for AI Agents' End-to-End Cybersecurity CapabilitiesTianneng Shi, Robin Rheem, Dongwei Jiang, Mona Wang et al.ICML 2026 · 3 citations
- Compete, Collaborate, Investigate: Exploring the Social Structures of Open Source Intelligence InvestigationsYasmine Belghith, Sukrit Venkatagiri, Kurt LutherCHI 2022 · 14 citations
- Examining Zero-Shot Vulnerability Repair with Large Language ModelsHammond Pearce, Benjamin Tan, Baleegh Ahmad, Ramesh Karri et al.S&P 2023
