Megha Sharma, Kuldeep Singh, Palvi Aggarwal, V. Dutt
{"title":"GPT钓鱼的效果如何?一项涉及认知偏差和反馈的调查","authors":"Megha Sharma, Kuldeep Singh, Palvi Aggarwal, V. Dutt","doi":"10.1109/EuroSPW59978.2023.00055","DOIUrl":null,"url":null,"abstract":"Phishing scams have increased drastically over the years. Prior research has investigated various ways to prevent phishing email scams. However, little is known about human decisions against phishing emails that contain cognitive biases and are either crafted by humans or large-language models (LLMs). Also, less is known about how humans can be trained against such emails. This research aimed to address this literature gap by investigating the effectiveness of human-crafted phishing emails versus GPT3 crafted phishing emails (GPT-3 being an LLM). The study consisted of two between-subjects conditions (N = 30 per condition): human and GPT. Each condition contained three rounds with a total of 40 trials, and participants were required to mark the degree to which the presented email was genuine or phishing in each trial. The second round provided feedback to participants in both conditions. The results showed that human-crafted emails were more effective in phishing people compared to GPT-3 crafted emails even after training across different cognitive biases. However, humans felt more confident against human-crafted emails compared to GPT-3 crafted emails. We highlight the implications of these results for LLM crafted phishing attacks compared to human-crafted phishing attacks.","PeriodicalId":220415,"journal":{"name":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","volume":"31 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"How well does GPT phish people? An investigation involving cognitive biases and feedback\",\"authors\":\"Megha Sharma, Kuldeep Singh, Palvi Aggarwal, V. Dutt\",\"doi\":\"10.1109/EuroSPW59978.2023.00055\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Phishing scams have increased drastically over the years. Prior research has investigated various ways to prevent phishing email scams. However, little is known about human decisions against phishing emails that contain cognitive biases and are either crafted by humans or large-language models (LLMs). Also, less is known about how humans can be trained against such emails. This research aimed to address this literature gap by investigating the effectiveness of human-crafted phishing emails versus GPT3 crafted phishing emails (GPT-3 being an LLM). The study consisted of two between-subjects conditions (N = 30 per condition): human and GPT. Each condition contained three rounds with a total of 40 trials, and participants were required to mark the degree to which the presented email was genuine or phishing in each trial. The second round provided feedback to participants in both conditions. The results showed that human-crafted emails were more effective in phishing people compared to GPT-3 crafted emails even after training across different cognitive biases. However, humans felt more confident against human-crafted emails compared to GPT-3 crafted emails. We highlight the implications of these results for LLM crafted phishing attacks compared to human-crafted phishing attacks.\",\"PeriodicalId\":220415,\"journal\":{\"name\":\"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)\",\"volume\":\"31 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-07-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/EuroSPW59978.2023.00055\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EuroSPW59978.2023.00055","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
How well does GPT phish people? An investigation involving cognitive biases and feedback
Phishing scams have increased drastically over the years. Prior research has investigated various ways to prevent phishing email scams. However, little is known about human decisions against phishing emails that contain cognitive biases and are either crafted by humans or large-language models (LLMs). Also, less is known about how humans can be trained against such emails. This research aimed to address this literature gap by investigating the effectiveness of human-crafted phishing emails versus GPT3 crafted phishing emails (GPT-3 being an LLM). The study consisted of two between-subjects conditions (N = 30 per condition): human and GPT. Each condition contained three rounds with a total of 40 trials, and participants were required to mark the degree to which the presented email was genuine or phishing in each trial. The second round provided feedback to participants in both conditions. The results showed that human-crafted emails were more effective in phishing people compared to GPT-3 crafted emails even after training across different cognitive biases. However, humans felt more confident against human-crafted emails compared to GPT-3 crafted emails. We highlight the implications of these results for LLM crafted phishing attacks compared to human-crafted phishing attacks.