Submitted:
26 August 2025
Posted:
27 August 2025
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Related Work
2.1. Anti-Phishing Education
2.2. LLM Generated Phishing Emails
2.3. Automatic Phishing Detection
2.4. LLM Personalization Methods
2.5. Modeling Human Decision Making
2.5.1. Decision Modeling in Cybersecurity
2.5.2. Decision Modeling from Complex Stimuli
2.6. Decision Modeling Using LLM Embeddings
3. Dataset
4. Conversation Analysis
4.1. Categorization Accuracy
4.2. Categorization Confidence
4.3. Categorization Reaction Time
4.4. Student Learning Outcomes
4.4.1. User Initial Performance
4.4.2. User Training Outcomes
4.4.3. User Final Performance
4.5. Student Quiz Responses
4.5.1. Student Pre-Experiment Quiz
4.5.2. Student Post-Experiment Quiz
4.5.3. Student Post-Experiment Open Response
4.6. User Demographics
4.6.1. Age
4.6.2. Gender
4.6.3. Education
4.6.4. Phishing Experience
4.6.5. Chatbot Experience
4.6.6. Cognitive Model Activity
| Context | Indirect Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| (Student+Teacher) ∼ | ||||||
| Age | -0.00586 | 0.00238 | 0.012 | -0.0109 | -0.0019 | Yes |
| (Student+Teacher) ∼ | ||||||
| AI Generation Perception | 0.00395 | 0.00220 | 0.044 | 0.000156 | 0.00834 | Yes |
| (Student+Teacher) ∼ | ||||||
| Response Message Similarity | 0.00884 | 0.00347 | 0.004 | 0.00285 | 0.0157 | Yes |
| (Teacher) ∼ | ||||||
| Education Years | -0.00582 | 0.00292 | 0.020 | -0.0131 | -0.00137 | Yes |
| (Teacher) ∼ | ||||||
| Response Message Similarity | 0.00922 | 0.00296 | 0.000 | 0.00459 | 0.0165 | Yes |
4.7. Mediation Analysis
4.7.1. Mediation of Student and Teacher Messages
4.7.2. Mediation of Teacher Messages Only
5. Results
6. Discussion
Appendix A.
Appendix A.1. ANOVA Analyses Tables
| Source | Outcome | F | p | |||
| Student | Correct | 22 | 464 | |||
| Teacher | Correct | 25 | 1720 | |||
| Student | Confidence | 22 | 464 | |||
| Teacher | Confidence | 25 | 1720 | |||
| Student | ReactionTime | 22 | 464 | |||
| Teacher | ReactionTime | 25 | 1720 | |||
| Student | User Initial Performance | 22 | 464 | |||
| Teacher | User Initial Performance | 25 | 1720 | |||
| Student | User Improvement | 22 | 464 | |||
| Teacher | User Improvement | 25 | 1720 | |||
| Student | User Final Performance | 22 | 464 | |||
| Teacher | User Final Performance | 25 | 1720 | |||
| Student | Pre-Experiment Quiz Score | 22 | 464 | |||
| Teacher | Pre-Experiment Quiz Score | 25 | 1720 | |||
| Student | AI Gen Percept | 22 | 464 | |||
| Teacher | AI Gen Percept | 25 | 1720 | |||
| Student | Response Mssg Sim | 22 | 464 | |||
| Teacher | Response Mssg Sim | 25 | 1720 | |||
| Student | Age | 22 | 464 | |||
| Teacher | Age | 25 | 1720 | |||
| Student | Gender Number | 22 | 464 | |||
| Teacher | Gender Number | 25 | 1720 | |||
| Student | Education Years | 22 | 464 | |||
| Teacher | Education Years | 25 | 1720 | |||
| Student | Phishing Experience | 22 | 464 | |||
| Teacher | Phishing Experience | 25 | 1720 | |||
| Student | Chatbot Experience | 22 | 464 | |||
| Teacher | Chatbot Experience | 25 | 1720 | |||
| Student | Cognitive Model Activity | 22 | 464 | |||
| Teacher | Cognitive Model Activity | 25 | 1720 |
Appendix A.2. Mediation Analyses
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Age | ||||||
| ∼ Age | -0.0609 | 0.0211 | 0.00396 | -0.102 | -0.0195 | Yes |
| User Improvement | ||||||
| ∼ Age | 0.00136 | 0.0212 | 0.949 | -0.0402 | 0.0429 | No |
| Total | -0.0264 | 0.0212 | 0.212 | -0.0679 | 0.0151 | No |
| Direct | -0.0264 | 0.0212 | 0.213 | -0.068 | 0.0151 | No |
| Indirect | 0.00116 | 0.98 | -0.00254 | 0.00219 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Education Years | ||||||
| ∼ Education Years | -0.0326 | 0.0212 | 0.124 | -0.0741 | 0.00893 | No |
| User Improvement | ||||||
| ∼ Education Years | -0.214 | 0.0207 | -0.255 | -0.173 | Yes | |
| Total | -0.0264 | 0.0212 | 0.212 | -0.0679 | 0.0151 | No |
| Direct | -0.0334 | 0.0207 | 0.106 | -0.074 | 0.00713 | No |
| Indirect | 0.007 | 0.00466 | 0.1 | -0.00167 | 0.017 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Age | -0.0609 | 0.0211 | 0.00396 | -0.102 | -0.0195 | Yes |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.093 | 0.0211 | 0.0516 | 0.134 | Yes | |
| Total | 0.046 | 0.0211 | 0.0299 | 0.00448 | 0.0874 | Yes |
| Direct | 0.0518 | 0.0211 | 0.0141 | 0.0104 | 0.0932 | Yes |
| Indirect | -0.00586 | 0.00238 | 0.012 | -0.0109 | -0.0019 | Yes |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Education Years | -0.0326 | 0.0212 | 0.124 | -0.0741 | 0.00893 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.093 | 0.0211 | 0.0516 | 0.134 | Yes | |
| Total | -0.151 | 0.0209 | -0.192 | -0.11 | Yes | |
| Direct | -0.148 | 0.0209 | -0.189 | -0.107 | Yes | |
| Indirect | -0.00287 | 0.00208 | 0.1 | -0.0085 | 0.000427 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Phishing Experience | 0.0242 | 0.0212 | 0.254 | -0.0173 | 0.0657 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.093 | 0.0211 | 0.0516 | 0.134 | Yes | |
| Total | 0.172 | 0.0209 | 0.131 | 0.213 | Yes | |
| Direct | 0.17 | 0.0208 | 0.129 | 0.211 | Yes | |
| Indirect | 0.00215 | 0.00202 | 0.26 | -0.00159 | 0.0064 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Chatbot Experience | 0.000442 | 0.0212 | 0.983 | -0.0411 | 0.042 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.093 | 0.0211 | 0.0516 | 0.134 | Yes | |
| Total | -0.0209 | 0.0212 | 0.323 | -0.0624 | 0.0206 | No |
| Direct | -0.021 | 0.0211 | 0.32 | -0.0623 | 0.0204 | No |
| Indirect | 0.00202 | 0.94 | -0.00374 | 0.00476 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ AI Generation Perception | 0.0403 | 0.0212 | 0.0567 | -0.00115 | 0.0818 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.093 | 0.0211 | 0.0516 | 0.134 | Yes | |
| Total | -0.12 | 0.021 | -0.161 | -0.0788 | Yes | |
| Direct | -0.124 | 0.0209 | -0.165 | -0.0829 | Yes | |
| Indirect | 0.00395 | 0.0022 | 0.044 | 0.000156 | 0.00834 | Yes |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Pre Experiment Quiz Score | -0.0079 | 0.0212 | 0.709 | -0.0494 | 0.0336 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.093 | 0.0211 | 0.0516 | 0.134 | Yes | |
| Total | 0.0702 | 0.0211 | 0.0288 | 0.112 | Yes | |
| Direct | 0.0709 | 0.021 | 0.0297 | 0.112 | Yes | |
| Indirect | -0.000738 | 0.00204 | 0.684 | -0.0046 | 0.00331 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Response Message Similarity | 0.149 | 0.0209 | 0.108 | 0.191 | Yes | |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.093 | 0.0211 | 0.0516 | 0.134 | Yes | |
| Total | 0.235 | 0.0206 | 0.195 | 0.275 | Yes | |
| Direct | 0.226 | 0.0208 | 0.185 | 0.267 | Yes | |
| Indirect | 0.00884 | 0.00347 | 0.004 | 0.00285 | 0.0157 | Yes |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Age | -0.0347 | 0.0239 | 0.147 | -0.0817 | 0.0122 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.109 | 0.0238 | 0.0625 | 0.156 | Yes | |
| Total | 0.0323 | 0.0239 | 0.177 | -0.0146 | 0.0793 | No |
| Direct | 0.0362 | 0.0238 | 0.129 | -0.0105 | 0.0829 | No |
| Indirect | -0.00383 | 0.00258 | 0.1 | -0.00978 | 0.00013 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Education Years | -0.0563 | 0.0239 | 0.0186 | -0.103 | -0.00944 | Yes |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.109 | 0.0238 | 0.0625 | 0.156 | Yes | |
| Total | -0.109 | 0.0238 | -0.155 | -0.0619 | Yes | |
| Direct | -0.103 | 0.0237 | -0.149 | -0.0562 | Yes | |
| Indirect | -0.00582 | 0.00292 | 0.02 | -0.0131 | -0.00137 | Yes |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Phishing Experience | -0.00269 | 0.0239 | 0.91 | -0.0497 | 0.0443 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.109 | 0.0238 | 0.0625 | 0.156 | Yes | |
| Total | 0.0798 | 0.0239 | 0.033 | 0.127 | Yes | |
| Direct | 0.0801 | 0.0237 | 0.0336 | 0.127 | Yes | |
| Indirect | -0.000295 | 0.00264 | 0.848 | -0.00468 | 0.00516 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Chatbot Experience | 0.0254 | 0.0239 | 0.288 | -0.0215 | 0.0724 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.109 | 0.0238 | 0.0625 | 0.156 | Yes | |
| Total | -0.0248 | 0.0239 | 0.301 | -0.0717 | 0.0222 | No |
| Direct | -0.0275 | 0.0238 | 0.247 | -0.0742 | 0.0192 | No |
| Indirect | 0.00279 | 0.00288 | 0.316 | -0.00189 | 0.00933 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ AI Generation Perception | 0.00958 | 0.0239 | 0.689 | -0.0374 | 0.0565 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.109 | 0.0238 | 0.0625 | 0.156 | Yes | |
| Total | -0.082 | 0.0239 | -0.129 | -0.0351 | Yes | |
| Direct | -0.083 | 0.0237 | -0.13 | -0.0365 | Yes | |
| Indirect | 0.00105 | 0.00283 | 0.756 | -0.00371 | 0.00719 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Pre Experiment Quiz Score | 0.00486 | 0.0239 | 0.839 | -0.0421 | 0.0518 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.109 | 0.0238 | 0.0625 | 0.156 | Yes | |
| Total | 0.052 | 0.0239 | 0.0298 | 0.00511 | 0.0989 | Yes |
| Direct | 0.0515 | 0.0238 | 0.0305 | 0.00484 | 0.0981 | Yes |
| Indirect | 0.000529 | 0.00242 | 0.88 | -0.0038 | 0.00657 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Response Message Similarity | 0.106 | 0.0238 | 0.0591 | 0.153 | Yes | |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.109 | 0.0238 | 0.0625 | 0.156 | Yes | |
| Total | 0.217 | 0.0234 | 0.171 | 0.263 | Yes | |
| Direct | 0.208 | 0.0234 | 0.162 | 0.254 | Yes | |
| Indirect | 0.00922 | 0.00296 | 0.00459 | 0.0165 | Yes |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Age | -0.131 | 0.045 | 0.00371 | -0.22 | -0.0428 | Yes |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.0628 | 0.0453 | 0.166 | -0.0262 | 0.152 | No |
| Total | 0.092 | 0.0452 | 0.0424 | 0.00316 | 0.181 | Yes |
| Direct | 0.102 | 0.0455 | 0.0255 | 0.0126 | 0.191 | Yes |
| Indirect | -0.01 | 0.00724 | 0.104 | -0.0292 | 0.000972 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Education Years | 0.0234 | 0.0454 | 0.607 | -0.0658 | 0.113 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.0628 | 0.0453 | 0.166 | -0.0262 | 0.152 | No |
| Total | -0.247 | 0.044 | -0.333 | -0.16 | Yes | |
| Direct | -0.248 | 0.044 | -0.334 | -0.162 | Yes | |
| Indirect | 0.0016 | 0.00366 | 0.58 | -0.00317 | 0.0116 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Phishing Experience | 0.0839 | 0.0452 | 0.0642 | -0.00498 | 0.173 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.0628 | 0.0453 | 0.166 | -0.0262 | 0.152 | No |
| Total | 0.353 | 0.0425 | 0.269 | 0.436 | Yes | |
| Direct | 0.35 | 0.0427 | 0.266 | 0.434 | Yes | |
| Indirect | 0.00281 | 0.00433 | 0.5 | -0.00345 | 0.0142 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Chatbot Experience | -0.0704 | 0.0453 | 0.121 | -0.159 | 0.0186 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.0628 | 0.0453 | 0.166 | -0.0262 | 0.152 | No |
| Total | -0.000662 | 0.0454 | 0.988 | -0.0899 | 0.0886 | No |
| Direct | 0.00378 | 0.0455 | 0.934 | -0.0856 | 0.0931 | No |
| Indirect | -0.00444 | 0.00473 | 0.264 | -0.0177 | 0.00179 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ AI Generation Perception | 0.114 | 0.0451 | 0.0121 | 0.025 | 0.202 | Yes |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.0628 | 0.0453 | 0.166 | -0.0262 | 0.152 | No |
| Total | -0.192 | 0.0446 | -0.279 | -0.104 | Yes | |
| Direct | -0.202 | 0.0447 | -0.29 | -0.114 | Yes | |
| Indirect | 0.00975 | 0.00632 | 0.06 | 0.00106 | 0.0258 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Pre Experiment Quiz Score | -0.0423 | 0.0454 | 0.351 | -0.131 | 0.0468 | No |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.0628 | 0.0453 | 0.166 | -0.0262 | 0.152 | No |
| Total | 0.112 | 0.0451 | 0.0136 | 0.0231 | 0.2 | Yes |
| Direct | 0.115 | 0.0451 | 0.0114 | 0.026 | 0.203 | Yes |
| Indirect | -0.00287 | 0.00459 | 0.48 | -0.0177 | 0.0027 | No |
| Path | Coef. | SE | p | CI 2.5% | CI 97.5% | Sig |
| Message Email Similarity | ||||||
| ∼ Response Message Similarity | 0.336 | 0.0428 | 0.252 | 0.42 | Yes | |
| User Improvement | ||||||
| ∼ Message Email Similarity | 0.0628 | 0.0453 | 0.166 | -0.0262 | 0.152 | No |
| Total | 0.201 | 0.0445 | 0.114 | 0.289 | Yes | |
| Direct | 0.203 | 0.0473 | 0.11 | 0.296 | Yes | |
| Indirect | -0.00185 | 0.0162 | 0.912 | -0.0355 | 0.0283 | No |
Appendix A.3. Pre-experiment Instructions
- Real sender does not match the claimed sender: Phishing emails often pretend to be from reputable companies, but you can usually spot a fake by checking the address that sent the message. If the From address is a series of numbers, an odd mix of characters, or not the official domain of the company it claims to be from, it’s likely a phishing attempt.
- Email requests credentials: Legitimate companies will never ask for sensitive information via email. If the email requests your username, password, credit card information, or other sensitive data, it’s a phishing attempt.
- Suspicious subject line: Phishing emails often use alarmist, threatening, or enticing subject lines to grab your attention. If the subject is odd, generic, or doesn’t match the content, it could be a phishing email.
- Urgent tone: Phishing scams create a sense of urgency to panic you into acting without thinking. If an email asks for immediate action (e.g., “Your account will be suspended unless you update your information”), it’s likely a scam.
- Too-good-to-be-true offers: Emails that promise rewards, discounts, or prizes in exchange for personal information are likely phishing.
- Link does not match the text: A common tactic is disguising a dangerous link with innocent-looking text. Hover your cursor over links before clicking. If the URL doesn’t match the link text, or looks suspicious in any way, do not click. For instance, if the link text reads “bank.com” but hovering shows “hackingsite.com”, it’s a phishing attempt.
Appendix A.4. Pre-experiment Quiz
-
What type of language do phishing emails often use to create a sense of panic?
- Urgent language
- Friendly language
- Rude language
- Mean language
-
What might a phishing email request of you that would compromise your identity?
- Personal information like your favorite color
- Sensitive information like credit card numbers
- Sensitive information like your celebrity crush
- Irrelevant information like your dog’s name
-
What types of actions might phishing emails request from you that could lead to malware being installed on your computer?
- Clicking links only
- Downloading attachments only
- Replying with your computer’s information only
- All of the above
-
How might a phishing email try to ensure that you are susceptible to a phishing attempt?
- Being overly friendly
- Calling you a generic title
- Using poor grammar
- Saying you won the lottery
-
How might a phishing email attempt to convince you that it was sent from a legitimate source?
- Using an email from a website that you have never heard of
- Sending the email from a website with a famous company name
- Adding a link to a real website in the text of the email
- Using another website name that is different from the one sending the email
-
How might a phishing email convince you to click on a fake link?
- Adding a lot of random numbers and letters into the link
- Changing the text of the link (can be checked by hovering over it)
- Changing the color of the link to make it look like you’ve clicked it before
- Keeping the link short so it looks legitimate
Appendix A.5. Experiment Questions
-
Is this a phishing email?
- Yes
- No
-
On a scale from 1–5, with 5 being totally confident, how confident are you in your answer to Question 1?
- 1
- 2
- 3
- 4
- 5
-
What action would you take after receiving this email?
- Respond
- Click link
- Check sender
- Check link
- Delete email
- Report email
Appendix A.6. Post-experiment Questionnaire
-
Of the phishing emails you’ve encountered, what percentage do you think were generated by artificial intelligence models?
- 100% of the phishing emails I read were written by an Artificial Intelligence model.
- 75% of the phishing emails I read were written by an Artificial Intelligence model.
- 50% of the phishing emails I read were written by an Artificial Intelligence model.
- 25% of the phishing emails I read were written by an Artificial Intelligence model.
-
Of the ham (i.e., non-phishing) emails you’ve encountered, what percentage do you think were generated by artificial intelligence models?
- 100% of the ham emails I read were written by an Artificial Intelligence model.
- 75% of the ham emails I read were written by an Artificial Intelligence model.
- 50% of the ham emails I read were written by an Artificial Intelligence model.
- 25% of the ham emails I read were written by an Artificial Intelligence model.
-
Of the phishing emails you’ve encountered, what percentage do you think were styled (i.e., appearance and format) by artificial intelligence models?
- 100% of the phishing emails I read were styled by an Artificial Intelligence model.
- 75% of the phishing emails I read were styled by an Artificial Intelligence model.
- 50% of the phishing emails I read were styled by an Artificial Intelligence model.
- 25% of the phishing emails I read were styled by an Artificial Intelligence model.
-
Of the ham (i.e., non-phishing) emails you’ve encountered, what percentage do you think were styled (i.e., appearance and format) by artificial intelligence models?
- 100% of the ham emails I read were styled by an Artificial Intelligence model.
- 75% of the ham emails I read were styled by an Artificial Intelligence model.
- 50% of the ham emails I read were styled by an Artificial Intelligence model.
- 25% of the ham emails I read were styled by an Artificial Intelligence model.
-
What criteria did you use to identify whether an email was a phishing attempt?Open response.
References
- Salemi, A.; Mysore, S.; Bendersky, M.; Zamani, H. LaMP: When Large Language Models Meet Personalization. Arxiv 2024. [Google Scholar]
- Woźniak, S.; Koptyra, B.; Janz, A.; Kazienko, P.; Kocoń, J. Personalized Large Language Models. Arxiv 2024. [Google Scholar]
- Zhang, Z.; Rossi, R.A.; Kveton, B.; Shao, Y.; Yang, D.; Zamani, H.; Dernoncourt, F.; Barrow, J.; Yu, T.; Kim, S.; et al. Personalization of Large Language Models: A Survey. Arxiv 2025. [Google Scholar]
- Malloy, T.; Ferriera, M.; Fang, F.; Gonzalez, C. Improving Online Anti-Phishing Training Using Cognitive Large Language Models. Under Review for Computers and Human Behavior 2025. [Google Scholar]
- Pedersen, K.T.; Pepke, L.; Stærmose, T.; Papaioannou, M.; Choudhary, G.; Dragoni, N. Deepfake-Driven Social Engineering: Threats, Detection Techniques, and Defensive Strategies in Corporate Environments. Journal of Cybersecurity and Privacy 2025, 5, 18. [Google Scholar] [CrossRef]
- Schmitt, M.; Flechais, I. Digital deception: Generative artificial intelligence in social engineering and phishing. Artificial Intelligence Review 2024, 57, 324. [Google Scholar] [CrossRef]
- Jabir, R.; Le, J.; Nguyen, C. Phishing Attacks in the Age of Generative Artificial Intelligence: A Systematic Review of Human Factors. AI 2025, 6, 174. [Google Scholar] [CrossRef]
- Ayodele, T.O. Impact of AI-Generated Phishing Attacks: A New Cybersecurity Threat. In Proceedings of the Intelligent Computing-Proceedings of the Computing Conference. Springer; 2025; pp. 301–320. [Google Scholar]
- Mahal, A.; Singh, K.; Singh, K. Influence of Generative AI on Cyber Security. International journal of all research education and scientific methods 2025, pp. 1922–1928.
- Proofpoint. 2024 State of the Phish: Risky actions, real-world threats and user resilience in an age of human-centric cybersecurity.
- Hartzler, B.; Hinde, J.; Lang, S.; Correia, N.; Yermash, J.; Yap, K.; Murphy, C.M.; Ruwala, R.; Rash, C.J.; Becker, S.J.; et al. Virtual training is more cost-effective than in-person training for preparing staff to implement contingency management. Journal of Technology in Behavioral Science 2023, 8, 255–264. [Google Scholar] [CrossRef]
- o’Doherty, D.; Dromey, M.; Lougheed, J.; Hannigan, A.; Last, J.; McGrath, D. Barriers and solutions to online learning in medical education–an integrative review. BMC medical education 2018, 18, 130. [Google Scholar] [CrossRef]
- Luo, Y.; Yang, Y. Large language model and domain-specific model collaboration for smart education. Frontiers of Information Technology & Electronic Engineering 2024, 25, 333–341. [Google Scholar] [CrossRef]
- Jampen, D.; Gür, G.; Sutter, T.; Tellenbach, B. Don’t click: towards an effective anti-phishing training. A comparative literature review. Human-centric Computing and Information Sciences 2020, 10, 33. [Google Scholar] [CrossRef]
- Huang, L.; Jia, S.; Balcetis, E.; Zhu, Q. Advert: an adaptive and data-driven attention enhancement mechanism for phishing prevention. IEEE Transactions on Information Forensics and Security 2022, 17, 2585–2597. [Google Scholar] [CrossRef]
- Singh, K.; Aggarwal, P.; Rajivan, P.; Gonzalez, C. Training to detect phishing emails: Effects of the frequency of experienced phishing emails. In Proceedings of the Proceedings of the human factors and ergonomics society annual meeting. SAGE Publications Sage CA: Los Angeles, CA, 2019, Vol. 63, pp. 453–457.
- Brunken, L.; Buckmann, A.; Hielscher, J.; Sasse, M.A. {“To} Do This Properly, You Need More {Resources”}: The Hidden Costs of Introducing Simulated Phishing Campaigns. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 4105–4122.
- Salahdine, F.; Kaabouch, N. Social engineering attacks: A survey. Future internet 2019, 11, 89. [Google Scholar] [CrossRef]
- Abroshan, H.; Devos, J.; Poels, G.; Laermans, E. Phishing happens beyond technology: The effects of human behaviors and demographics on each step of a phishing process. IEEE Access 2021, 9, 44928–44949. [Google Scholar] [CrossRef]
- Singh, K.; Aggarwal, P.; Rajivan, P.; Gonzalez, C. Cognitive elements of learning and discriminability in anti-phishing training. Computers & Security 2023, 127, 103105. [Google Scholar] [CrossRef]
- Malloy, T.; Gonzalez, C. Applying Generative Artificial Intelligence to Cognitive Models of Decision Making. Frontiers in Psychology 2024. [Google Scholar] [CrossRef]
- Google Cloud. Google Cloud Cybersecurity Forecast 2024. https://services.google.com/fh/files/misc/google-cloud-cybersecurity-forecast-2024.pdf, 2024. Accessed: 2025-08-08.
- Sharma, M.; Singh, K.; Aggarwal, P.; Dutt, V. How well does GPT phish people? An investigation involving cognitive biases and feedback. In Proceedings of the 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). IEEE, 2023, pp. 451–457.
- Hasanov, I.; Virtanen, S.; Hakkala, A.; Isoaho, J. Application of large language models in cybersecurity: A systematic literature review. IEEE Access 2024. [Google Scholar] [CrossRef]
- Bethany, M.; Galiopoulos, A.; Bethany, E.; Karkevandi, M.B.; Vishwamitra, N.; Najafirad, P. Large language model lateral spear phishing: A comparative study in large-scale organizational settings. arXiv preprint arXiv:2401.09727, arXiv:2401.09727 2024.
- Hazell, J. Spear Phishing With Large Language Models, 2023, [arXiv:cs.CY/2305.06972]. arXiv:cs.CY/2305.06972].
- Afane, K.; Wei, W.; Mao, Y.; Farooq, J.; Chen, J. Next-Generation Phishing: How LLM Agents Empower Cyber Attackers, 2024, [arXiv:cs.CR/2411.13874].
- Myung, J.; Lee, N.; Zhou, Y.; Jin, J.; Putri, R.; Antypas, D.; Borkakoty, H.; Kim, E.; Perez-Almendros, C.; Ayele, A.A.; et al. Blend: A benchmark for llms on everyday knowledge in diverse cultures and languages. Advances in Neural Information Processing Systems 2024, 37, 78104–78146. [Google Scholar]
- Liu, J.; Qiu, Z.; Li, Z.; Dai, Q.; Zhu, J.; Hu, M.; Yang, M.; King, I. A Survey of Personalized Large Language Models: Progress and Future Directions. Arxiv 2025. [Google Scholar]
- Islam, S.B.; Rahman, M.A.; Hossain, K.S.M.T.; Hoque, E.; Joty, S.; Parvez, M.R. Open-RAG: Enhanced Retrieval-Augmented Reasoning with Open-Source Large Language Models. Arxiv 2024. [Google Scholar]
- Jin, C.; Zhang, Z.; Jiang, X.; Liu, F.; Liu, X.; Liu, X.; Jin, X. RAGCache: Efficient Knowledge Caching for Retrieval-Augmented Generation. Arxiv 2024. [Google Scholar]
- Sun, C.; Yang, K.; Reddy, R.G.; Fung, Y.R.; Chan, H.P.; Small, K.; Zhai, C.; Ji, H. Persona-DB: Efficient Large Language Model Personalization for Response Prediction with Collaborative Data Refinement. Arxiv 2025. [Google Scholar]
- Gonzalez, C.; Lerch, J.F.; Lebiere, C. Instance-based learning in dynamic decision making. Cognitive Science 2003, 27, 591–635. [Google Scholar] [CrossRef]
- Gonzalez, C. Building Human-Like Artificial Agents: A General Cognitive Algorithm for Emulating Human Decision-Making in Dynamic Environments. Perspectives on Psychological Science 2023, p. 17456916231196766.
- Pollini, A.; Callari, T.C.; Tedeschi, A.; Ruscio, D.; Save, L.; Chiarugi, F.; Guerri, D. Leveraging human factors in cybersecurity: an integrated methodological approach. Cognition, Technology & Work 2022, 24, 371–390. [Google Scholar]
- Kavak, H.; Padilla, J.J.; Vernon-Bido, D.; Diallo, S.Y.; Gore, R.; Shetty, S. Simulation for cybersecurity: state of the art and future directions. Journal of Cybersecurity 2021, 7, tyab005. [Google Scholar] [CrossRef]
- Lake, B.M.; Ullman, T.D.; Tenenbaum, J.B.; Gershman, S.J. Building machines that learn and think like people. Behavioral and brain sciences 2017, 40, e253. [Google Scholar] [CrossRef] [PubMed]
- Collins, K.M.; Sucholutsky, I.; Bhatt, U.; Chandra, K.; Wong, L.; Lee, M.; Zhang, C.E.; Zhi-Xuan, T.; Ho, M.; Mansinghka, V.; et al. Building machines that learn and think with people. Nature human behaviour 2024, 8, 1851–1863. [Google Scholar] [CrossRef] [PubMed]
- Malloy, T.; Cleotilde, G. Learning to Defend by Attacking (and Vice-Versa): Transfer Learning in Cyber-Security Games. In Proceedings of the IEEE European Symposium on Security and Privacy Workshop Series; 2023. [Google Scholar]
- Kar, D.; Nguyen, T.H.; Fang, F.; Brown, M.; Sinha, A.; Tambe, M.; Jiang, A.X. Trends and applications in Stackelberg security games. In Handbook of dynamic game theory; Springer, 2016; pp. 1–47.
- Sinha, A.; Fang, F.; An, B.; Kiekintveld, C.; Tambe, M. Stackelberg security games: Looking beyond a decade of success. In Proceedings of the Proceedings of the International Joint Conference on Artifical Intelligence. IJCAI, 2018.
- Du, Y.; Prebot, B.; Malloy, T.; Fang, F.; Cleotilde, G. Experimental Evaluation of Cognitive Agents for Collaboration in Human-Autonomy Cyber Defense Teams. Under Review for Computers and Human Behavior: Artificial Agents 2025.
- Du, Y.; Prebot, B.; Malloy, T.; Cleotilde, G. A Cyber-War Between Bots: Cognitive Attackers are More Challenging for Defenders than Strategic Attackers. ACM Transactions on Social Computing 2024.
- Malloy, T.; Ferriera, M.; Fang, F.; Gonzalez, C. Using Cognitive Models to Improve Training Against Human and GPT-4 Generated Social Engineering Attacks. In Proceedings of the International Conference on Human Computer Interaction, 2025.
- Laird, J.E.; Newell, A.; Rosenbloom, P.S. Soar: An architecture for general intelligence. Artificial intelligence 1987, 33, 1–64. [Google Scholar] [CrossRef]
- Prieto, I.; Blakely, B. Proposed uses of generative AI in a cybersecurity-focused soar agent. In Proceedings of the Proceedings of the AAAI Symposium Series, 2023, Vol. 2, pp. 386–390.
- Malloy, T.; Du, Y.; Fang, F.; Gonzalez, C. Accounting for Transfer of Learning in Human Behavior Models. In Proceedings of the Human Computation and Crowdsourcing, 2023.
- Malloy, T.; Sims, C.R. Efficient Visual Representations for Learning and Decision Making. Psychological review 2024, in press.
- Malloy, T.; Du, Y.; Fang, F.; Gonzalez, C. Generative Environment-Representation Instance-Based Learning: A Cognitive Model. In Proceedings of the AAAI Symposium on Integration of Cognitive Architectures and Generative Models, 2023.
- Mitsopoulos, K.; Bose, R.; Mather, B.; Bhatia, A.; Gluck, K.; Dorr, B.; Lebiere, C.; Pirolli, P. Psychologically-Valid Generative Agents: A Novel Approach to Agent-Based Modeling in Social Sciences. In Proceedings of the Proceedings of the 2023 AAAI Fall Symposium on Integrating Cognitive Architectures and Generative Models. AAAI Press, 2023, pp. 1–6.
- West, R.L.; Eckler, S.; Conway-Smith, B.; Turcas, N.; Tomkins-Flanagan, E.; Kelly, M.A. Bridging Generative Networks with the Common Model of Cognition. In Proceedings of the Proceedings of the 2023 AAAI Fall Symposium on Integrating Cognitive Architectures and Generative Models. AAAI Press, 2023.
- Xu, T.; Singh, K.; Rajivan, P. Modeling Phishing Decision using Instance Based Learning and Natural Language Processing. In Proceedings of the HICSS, 2022, pp. 1–10.
- Malloy, T.; Ferreira, M.J.; Fang, F.; Gonzalez, C. Leveraging a Cognitive Model to Measure Subjective Similarity of Human and GPT-4 Written Content. arXiv preprint, arXiv:2409.00269 2024.
- Anderson, J.R.; Matessa, M.; Lebiere, C. ACT-R: A theory of higher level cognition and its relation to visual attention. Human–Computer Interaction 1997, 12, 439–462. [Google Scholar] [CrossRef]
- Wu, S.; Oltramari, A.; Francis, J.; Giles, C.L.; Ritter, F.E. LLM-ACTR: from Cognitive Models to LLMs in Manufacturing Solutions. In Proceedings of the Proceedings of the AAAI Symposium Series, 2025, Vol. 5, pp. 340–349.
- Llaca-Sánchez, B.A.; García-Noguez, L.R.; Aceves-Fernández, M.A.; Takacs, A.; Tovar-Arriaga, S. Exploring LLM Embedding Potential for Dementia Detection Using Audio Transcripts. Eng 2025, 6, 163. [Google Scholar] [CrossRef]
- OpenAI. OpenAI API Documentation. https://platform.openai.com/docs/, 2025. Accessed: May 18, 2025.
- Gonzalez, C.; Dutt, V. Instance-based learning: integrating sampling and repeated decisions from experience. Psychological review 2011, 118, 523. [Google Scholar] [CrossRef]
- Fiedler, K.; Schott, M.; Meiser, T. What mediation analysis can (not) do. Journal of Experimental Social Psychology 2011, 47, 1231–1236. [Google Scholar] [CrossRef]
- Baron, R.M.; Kenny, D.A. The moderator–mediator variable distinction in social psychological research: Conceptual, strategic, and statistical considerations. Journal of personality and social psychology 1986, 51, 1173. [Google Scholar] [CrossRef] [PubMed]
- Bodker, S.; Andersen, P.B. Complex mediation. Human-computer interaction 2005, 20, 353–402. [Google Scholar] [CrossRef]
- Vig, J.; Gehrmann, S.; Belinkov, Y.; Qian, S.; Nevo, D.; Singer, Y.; Shieber, S. Investigating gender bias in language models using causal mediation analysis. Advances in neural information processing systems 2020, 33, 12388–12401. [Google Scholar]
- Vallat, R. Pingouin: statistics in Python. Journal of Open Source Software 2018, 3, 1026. [Google Scholar] [CrossRef]
- Alwanain, M.I. Phishing awareness and elderly users in social media. International Journal of Computer Science and Network Security 2020, 20, 114–119. [Google Scholar]
| 1 | |
| 2 | |
| 3 |




Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).