Stop the Clock - Counteracting Bias Exploited by Attackers through an Interactive Augmented Reality Phishing Training
Authors
Social & Collaborative VRCybersecurity Training & AwarenessContext-Aware ComputingCybersecurity EngineersHCI Researchers
Research Background and Issues
- Issues and Challenges: The authors identify that phishing attacks are becoming increasingly sophisticated, exploiting cognitive biases such as authority or urgency to deceive users. These cognitive biases are typically useful psychological shortcuts in daily life, but hackers leverage them to compel individuals into making risky decisions.
- Significance: The scale and damage of phishing attacks continue to grow, and traditional technical countermeasures (e.g., blacklists) are not entirely reliable in mitigating threats. Furthermore, phishing attacks directly exploit human cognitive biases, underscoring the importance of human-centered security solutions.
- Research Motivation and Related Work: Traditional phishing training methods (e.g., text-based or click-based training) have shown limited effectiveness, whereas interactive training can better enhance user engagement and awareness. Augmented reality (AR) technology offers a more immersive learning experience and has the potential to bridge the gap between humans and technology.
Solution
- Proposed Solution: The authors designed an interactive phishing training system based on augmented reality (AR), enabling users to "combat" common cognitive biases in phishing emails through visualization and gesture interaction. For instance, users can counteract the urgency induced by phishing emails by interacting with a virtual clock.
- Innovations:
- Leveraging AR technology to overlay interactive content directly onto users' actual devices, creating a contextual and real-time learning experience.
- Focusing on dynamic visualization and interactive design targeting cognitive biases.
- Systematically comparing the effectiveness of AR training, click-based training, and traditional text-based training methods.
- Implementation Steps and Key Technologies:
- Expert Workshops: Identifying the most common cognitive biases in phishing emails and designing appropriate visualization and interaction methods.
- Technical Implementation: Developing a system comprising an interactive web application and an AR application, with the latter utilizing devices such as HoloLens 2 for gesture operations and dynamic visualization.
- User Experiment: Recruiting 117 participants to conduct experiments on three training methods to evaluate their effectiveness under different conditions.
Research Outcomes
- Specific Findings:
- All training conditions significantly improved users' phishing detection rates, with AR training showing the most notable improvement, raising detection rates from 67% pre-training to 93%.
- AR training demonstrated stronger positive effects in enhancing user interest and engagement in cybersecurity.
- Advantages:
- Compared to traditional text-based training, interactive training (especially AR) more effectively improves phishing detection capabilities and enhances users' long-term cybersecurity awareness.
- AR technology provides an immersive and dynamic learning experience, increasing user engagement and triggering systematic thinking.
- Experimental Results:
- Under interactive conditions, users were more inclined to focus on key cues generating cognitive biases rather than the overall content of phishing emails.
- Phishing email detection capabilities showed sustained improvement, with strong performance even three weeks post-experiment.
- Limitations and Future Directions:
- AR technology received lower usability scores, significantly influenced by users' technological affinity.
- Complex interaction designs or elements with negative emotions (e.g., fear-based designs) exhibited lower acceptance in AR environments.
- Future work should focus on optimizing the usability and interaction of AR technology and systematically investigating the long-term training effects, particularly in real-world workplace scenarios.
Through this study, the authors establish a critical foundation for the potential of interactive training and AR technology in addressing phishing issues within the cybersecurity domain, emphasizing the effectiveness of combining technology with human behavior to counteract cyber threats.
Research Questions / Practical Problems
Question signals indexed for this paper.
help
Research Questions
3- Can AR technology in interactive training for spear-phishing emails effectively help users recognize cognitive biases?Category: XR Teaching and Skill TrainingSimilar questionsarrow_forward
- Compared with traditional text-based and click-through training, what advantages does AR training offer for improving phishing detection rates?Category: XR Teaching and Skill TrainingSimilar questionsarrow_forward
- Can AR training improve users' phishing awareness and interest over the long term?Category: XR Teaching and Skill TrainingSimilar questionsarrow_forward
lightbulb
Practical Problems
1- Users easily make wrong decisions due to cognitive biases when facing sophisticated phishing attacks.Category: XR Teaching and Skill TrainingSimilar questionsarrow_forward
No related papers with ≥60% similarity
Based on Jaccard similarity of research subtopics & professions (≥60%)
Quick Actions
AdRecommended
Learn AI Coding at CodeNow
open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3714023
At a Glance
fact_checkPaper Snapshot
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Social & Collaborative VR, Cybersecurity Training & Awareness, Context-Aware Computing
work
Professions
Cybersecurity Engineers, HCI Researchers
article
Content Status
Full text indexed
hub
Related Papers
0 related papers