← Latest papers
💻 computer science

Forensic Schema for Psychological Manipulation in Cyber Fraud: LLM-Driven Victim Reports Analysis

This paper introduces a forensic schema designed to capture psychological manipulation techniques in cyber fraud, demonstrating that LLM-driven analysis of victim reports can reliably identify distinct manipulation profiles across fraud types while highlighting the critical need for AI-assisted intake processes to gather more actionable evidence details.

Original authors: Zikai Alex Wen, Corrazon Ogot, Juan Li, Yan Bai

Published 2026-07-10
📖 4 min read☕ Coffee break read

Original authors: Zikai Alex Wen, Corrazon Ogot, Juan Li, Yan Bai

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine cyber fraud as a massive, industrialized factory where scammers don't just knock on doors; they build elaborate, psychological trapdoors. For a long time, investigators had a checklist for these crimes that was like a police report for a broken window: it noted what was stolen, when it happened, and how the money moved. But it completely ignored the how of the mind game—the specific tricks the scammers used to trick the victim into handing over the keys.

This paper introduces a new "forensic schema," which is basically a super-detailed detective's notebook designed to catch those mind games. The researchers built a tool with 35 questions split into four sections. The first two sections are the old-school stuff (who, when, where). The third section is the new magic: 11 questions specifically designed to spot psychological manipulation tactics, like pretending to be a police officer, creating fake urgency, or using "love bombing" to build trust. The fourth section is a new addition for the crypto age, asking for specific blockchain details like wallet addresses.

To test this new notebook, the team fed it 10,994 victim reports from across the internet. They didn't read every single one by hand; instead, they used a powerful AI (a Large Language Model) to act as a tireless junior detective, scanning the stories and checking off the boxes. To make sure the AI wasn't just guessing, they had two human experts double-check a sample of the work. The result? The AI and the humans agreed on the answers about 69% of the time, which is just as good as two humans agreeing with each other. This suggests the AI is reliable enough to help sort through thousands of cases.

The Big Discovery: Scammers Have "Signatures"
The most exciting finding is that different types of scams have distinct "psychological fingerprints." It's not a random mix of tricks; each scam type uses a specific recipe.

  • Spoofing scams (pretending to be a bank or government) almost always use Authority (claiming to be an official) and rarely use Fear alone.
  • Sextortion scams are the opposite: they rely heavily on Fear (threats of exposure) but almost never claim to be an official.
  • Crypto investment scams are the most complex, using an average of 3.6 different manipulation tactics per case. They love to use Pretext (fake websites or documents) and Consistency (asking for more money after you've already paid).

The data shows these patterns are real and statistically strong. For instance, the link between "Pretext" (fake documents) and Crypto scams is so strong that it acts like a unique signature, helping investigators tell a crypto scam apart from a regular investment scam, even if the money trail looks similar.

The Missing Puzzle Pieces
However, the paper also found a frustrating gap. While the AI was great at spotting that a trick was used, the victim stories often lacked the details needed to actually catch the bad guys.

  • The "Thin" Evidence: When the AI flagged that a scammer used "Fear" or created "Urgency," the victim's story often just said, "They threatened me," without saying exactly what they said or what deadline they set. It's like knowing a door was kicked down, but not knowing which boot made the hole.
  • The Crypto Blackout: This was the biggest hole. Even though 1,172 of the reports involved cryptocurrency, the victims rarely provided the "keys" needed to trace the money on the blockchain. Only 6.2% of those cases included a transaction hash (the unique ID for a crypto transfer), and only 21.5% gave the wallet address. Without these, the "blockchain tracing" tools investigators use are like trying to find a specific car in a parking lot without a license plate number.

What This Means (And What It Doesn't)
The paper suggests that the best way to fix this isn't just to analyze old reports better, but to change how we collect the stories in the first place. Imagine an AI-powered intake form that listens to a victim's story and, based on the patterns it knows, asks smart follow-up questions in real-time. If the AI hears about a "fake investment," it could instantly ask, "Do you have the website URL?" or "What was the exact deadline they gave you?"

The authors are careful to say this is a suggestion for a better system, not a finished product. They proved that the patterns exist and that the AI can find them, but they also showed that the current "raw data" from victims is often too vague to be fully useful. The solution isn't a magic wand that solves fraud today; it's a blueprint for a smarter way to talk to victims tomorrow, turning vague stories into actionable evidence.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →