It's a Match - Enhancing the Fit between Users and Phishing Training through Personalisation
Lorin Schöni, Neele Roch, Hannah Sievers, Martin Strohmeier, Peter Mayer, Verena Zimmermann
摘要
Effective training is essential for enhancing users’ ability to detect phishing attempts. Personalised training offers huge potential to more closely align training content with individuals’ needs and skill levels. In an online study, we assigned N=342 participants to personalised training or a random training variant to compare their effectiveness. The personalisation was based on a phishing proficiency score calculated from factors such as detection ability, knowledge, and security attitude. After training, the participants demonstrated greater proficiency, with an increased ability to detect phishing emails and higher security attitudes. These effects were most pronounced in the personalised condition, demonstrating the potential of personalisation to improve training outcomes. Overall, personalised training levelled the playing field, efficiently bringing all groups, regardless of their initial proficiency, to a comparable and desired post-training phishing proficiency level. Finally, we derived recommendations for designing personalised phishing training content and assigning users to suitable training programmes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- What You Decode Depends on Where You Stand: Distance-Based Optical QR CodePulkit Garg, Robin Verma, Somitra Sanadhya, Gaurav GuptaUSENIX Security 2026
- Empowering Parents to Support Children's Online Security and Privacy: Findings from a Randomized Controlled TrialXiaowei Chen, Verena Distler, Chloe Gordon, Yaxing Yao 等CCS 2025
它引用的顶会 Paper5
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 被引用 92 次
- How Experts Detect Phishing Scam EmailsRick WashCSCW 2020 · 被引用 76 次
- Exploring the Use of Personalized AI for Identifying Misinformation on Social MediaFarnaz Jahanbakhsh, Yannis Katsis, Dakuo Wang, Lucian Popa 等CHI 2023 · 被引用 42 次
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing TrainingDaniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen 等CCS 2024 · 被引用 9 次
- Better Together: The Interplay Between a Phishing Awareness Video and a Link-centric Phishing Support ToolBenjamin Maximilian Berens, Florian Schaub, Mattia Mossano, Melanie VolkamerCHI 2024 · 被引用 8 次
相关 Paper
- Judging Phishing Under Uncertainty: How Do Users Handle Inaccurate Automated Advice?Tarini Saka, Kalliopi Vakali, Adam D. G. Jenkins, Nadin Kokciyan 等CHI 2025 · 被引用 1 次
- A Large-Scale Study of Personalized Phishing using Large Language ModelsStefan Czybik, Anne Josiane Kouam, Peter Heubl, Jan Magnus Nold 等USENIX Security 2026 · 被引用 1 次
- Understanding the Efficacy of Phishing Training in PracticeGrant Ho, Ariana Mirian, Elisa Luo, Khang Tong 等S&P 2025
- What Mid-Career Professionals Think, Know, and Feel About Phishing: Opportunities for University IT Departments to Better Empower Employees in Their Anti-Phishing DecisionsAnne Clara Tally, Jacob Abbott, Ashley M. Bochner, Sanchari Das 等CSCW 2023 · 被引用 11 次
- Simulated Stress: A Case Study of the Effects of a Simulated Phishing Campaign on Employees' Perception, Stress and Self-EfficacyMarkus Schöps, Marco Gutfleisch, Eric Wolter, M. Angela SasseUSENIX Security 2024 · 被引用 7 次
