🤖 AI Summary
Current public anti-phishing training suffers from methodological rigidity, low immersion, and insufficient adaptability. To address these limitations, this paper introduces a gamified anti-phishing security education tool that pioneers the integration of large language models (LLMs) for dynamic generation of phishing dialogues and assessment items. Leveraging state randomization, time-constrained challenges, and real-time feedback, the tool establishes an immersive learning framework covering clone phishing, SMS phishing, and spear phishing. It enables systematic, risk-free improvement in users’ phishing detection accuracy and response confidence. A user study demonstrates a 24% average increase in phishing identification awareness and a 30% gain in self-reported response confidence among participants. These results empirically validate the efficacy and innovation of LLM-driven gamified pedagogy for enhancing cybersecurity literacy.
📝 Abstract
The increased use of digital devices and applications has led to a rise in phishing attacks. We develop a serious game to raise awareness about phishing attacks and help people avoid these threats in a risk-free learning environment. This game targets three types of phishing-clone phishing, SMS phishing, and spear phishing-and uses a Large Language Model to generate dialogues and questions dynamically. It also incorporates state randomization and time-limited challenges to enhance the gameplay. We evaluated two groups of participants and found that those who played the game showed, on average, a 24% increase in awareness and a 30% boost in confidence.