It's a Match - Enhancing the Fit between Users and Phishing Training through Personalisation
Authors
Explainable AI (XAI)Cybersecurity Training & Awareness
Research Background and Problem
- Problem and Challenges: The authors identified the prevalence of a "one-size-fits-all" approach in traditional anti-phishing training, which overlooks individual differences in users' knowledge, experience, and skills, thereby limiting the effectiveness of such training.
- Significance: Phishing is one of the major cybersecurity threats, with the number of related emails continuously increasing. Current technical defense measures are insufficient to replace the human ability to effectively identify phishing attempts, making it crucial to enhance users' phishing detection capabilities.
- Research Motivation: The potential of personalized training has been demonstrated in the education field, but there is a lack of systematic empirical research in phishing or broader cybersecurity training. Additionally, resource and budget constraints, as well as data privacy concerns, hinder the implementation of personalized training. This study aims to validate the effectiveness of a simple modular personalized approach, laying the groundwork for future advanced personalization research.
Solution
- Method: The authors proposed a personalized training scheme based on users' phishing detection abilities and evaluated it in an online study. A total of 342 participants were assigned to receive either personalized training, randomly assigned training, or basic training through educational videos only.
- Innovations:
- Personalized Assessment Model: A comprehensive scoring method was used to categorize participants into low, medium, and high ability groups based on their phishing detection skills, knowledge levels, and security attitudes.
- Modular Design: Training content was tailored to the three ability levels—educational videos, interactive quizzes, and warning banners.
- Data Privacy-Friendly Approach: The personalization method did not rely on sensitive data (e.g., age or other potentially discriminatory information).
- Implementation Steps:
- Collect users' ability data through preliminary questionnaires and tests, and assign them to corresponding training groups using the scoring model.
- Assign training content based on the needs of each ability group. The low-ability group received the full training package, the medium-ability group received quizzes and banners only, and the high-ability group received banners only.
- Conduct post-training tests to evaluate the effectiveness of the training.
Research Findings
- Specific Findings:
- Significant Training Effectiveness: Phishing detection abilities improved significantly across all ability groups, with the low-ability group showing the most notable improvement.
- Advantages of Modularity: Interactive quizzes and warning banners played a key role in reinforcing knowledge and improving vigilance, while educational videos enhanced users' foundational understanding.
- Preference for Personalization: Users generally preferred personalized allocation, especially when the training content matched their ability levels.
- Efficiency Improvement: Personalized training reduced the time spent on unnecessary content, making the learning process more targeted.
- Comparison with Existing Methods:
- Compared to the random assignment group and the video-only group, the personalized allocation group showed greater improvements in phishing detection ability, self-assessed knowledge, and security attitudes.
- While educational videos were effective, their impact was less pronounced when used alone compared to when combined with interactive components.
- Experimental and Evaluation Results:
- The personalized group achieved an average improvement of 19% in phishing detection ability (measured by test accuracy).
- Random group assignments that did not match users' abilities led to less consistent improvement.
- Training that matched users' ability levels resulted in more significant improvements in both overall ability and subjective evaluations.
- Limitations and Future Directions:
- Sample Representativeness: The study primarily focused on English-speaking users from Western regions, lacking validation across other cultural and linguistic contexts.
- Lack of Long-Term Effects: The study did not examine the retention of training effects over several months, which should be addressed in future follow-up studies.
- Needs of Advanced Users: While the training was highly effective for lower-ability groups, further research is needed to enhance training for high-ability users, such as incorporating in-depth technical details or more complex scenario simulations.
- Potential for Dynamic Personalization: Future studies could leverage AI tools to further optimize personalization and adjust training content based on users' professional roles or industry characteristics.
Through this study, the authors successfully enhanced the effectiveness of phishing training using a simple modular personalized approach, providing practical and theoretical support for the design of advanced personalized training in the future.
Research Questions / Practical Problems
Question signals indexed for this paper.
help
Research Questions
3- Can personalized training effectively improve users' phishing detection ability?Category: Cyber Threats and ProtectionSimilar questionsarrow_forward
- Is modular training based on user ability levels (e.g., high, medium, low) superior to random assignment or generic training?Category: Cyber Threats and ProtectionSimilar questionsarrow_forward
- How can phishing training be personalized without relying on sensitive data?Category: Cyber Threats and ProtectionSimilar questionsarrow_forward
lightbulb
Practical Problems
1- Traditional one-size-fits-all phishing training ignores individual differences and has limited effectiveness.Category: Cyber Threats and ProtectionSimilar questionsarrow_forward
No related papers with ≥60% similarity
Based on Jaccard similarity of research subtopics & professions (≥60%)
Quick Actions
AdRecommended
Learn AI Coding at CodeNow
open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3713845
At a Glance
fact_checkPaper Snapshot
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
6 authors
sell
Subtopics
Explainable AI (XAI), Cybersecurity Training & Awareness
work
Professions
—
article
Content Status
Full text indexed
hub
Related Papers
0 related papers