Engineered Persuasion: Evaluating Personalized Pretexts in LLM-Generated Spear Phishing

📅 2026-09-03
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究评估了AI生成的钓鱼邮件中个性化信息对可信度的影响,通过四个层次的工作场所细节来测试其说服力,并分析了哪些细节有助于或损害了邮件的可信度。
📝 Abstract
Large language models can insert workplace details into phishing pretexts at low cost, but those details may either support or undermine a message's credibility. We recruited 180 U.S. working adults to evaluate simulated, AI-generated phishing emails in a disclosed survey. The emails used four cumulative levels of information: workplace (Level 1); recipient name and job title; job responsibilities; and coworker/shared-project context (Level 4). Participants rated each message's convincingness from 0 to 100, chose one stated action (open the link, investigate, delete, or report), and explained why their highest- and lowest-rated messages stood out. Across 1,436 valid evaluations, convincingness increased by 2.40 points per personalization level in a sensitivity analysis, while the odds of expressing click intention increased by 28\% per level. Among participants who did not express an intention to click, investigation remained common, reporting declined, and deletion increased. A post-hoc descriptive analysis found higher ratings and click intention for messages from a named person who referenced a supplied coworker than for messages from a department or entity. Qualitative coding showed why added detail could help or hurt: details that matched participants' roles and routines supported credibility, while incorrect, vague, or channel-inappropriate details raised suspicion. Together, the results highlight that personalization is not simply a matter of adding more details: it depends on whether the pretext fits the recipient's work context. We discuss how this distinction can inform workplace cybersecurity training.
Problem

Research questions and friction points this paper is trying to address.

Large language models
Personalized phishing
Credibility
Behavioral response
Work context
Innovation

Methods, ideas, or system contributions that make the work stand out.

Personalization
Large Language Models
Spear Phishing
Credibility
Workplace Context
J
Jerson Francia
Department of Electrical and Computer Engineering, Brigham Young University, Provo, UT 84602, USA
D
Derek Hansen
Department of Electrical and Computer Engineering, Brigham Young University, Provo, UT 84602, USA
B
Benjamin Schooley
Department of Electrical and Computer Engineering, Brigham Young University, Provo, UT 84602, USA
S
Shydra Valynn Murray
Department of Electrical and Computer Engineering, Brigham Young University, Provo, UT 84602, USA