← Latest papers
💻 computer science

Enhancing User Resilience Against AI-Augmented Phishing: A Two-Stage Framework for Detection and Personalized Training

This paper proposes CyberGLA, a two-stage framework that combines the EmailKnight multi-level email analysis tool for detection with an LLM-based security coach for personalized training, to effectively counter AI-augmented phishing attacks and enhance user resilience.

Original authors: Weihao Qu, Gurmeet Singh, Daniel Crawford, Bingjun Li, Jalen Smith

Published 2026-08-25
📖 5 min read🧠 Deep dive

Original authors: Weihao Qu, Gurmeet Singh, Daniel Crawford, Bingjun Li, Jalen Smith

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the digital age, the email inbox has become a primary battlefield for security, where the most dangerous threats are not just malicious code, but messages designed to trick the human mind. For decades, defenders have relied on two main strategies to stop these attacks: technical filters that scan for known bad patterns, and educational programs that teach people to be suspicious. However, the landscape is shifting rapidly. Modern attackers are now using artificial intelligence to write emails that are grammatically perfect, deeply personalized, and capable of mimicking real conversations, making them far harder to spot than the clumsy spam of the past. This evolution has created a gap where traditional security tools struggle to keep up, and standard training often fails to engage users or address the specific tricks they are facing. The question facing researchers is no longer just how to block bad emails, but how to help people recognize and learn from the sophisticated deceptions that slip through the cracks.

To address this growing challenge, a team of researchers at Monmouth University has developed a new approach called CyberGLA, a system that combines automated detection with personalized learning. Rather than treating security as a static wall or a one-time lecture, this framework operates in two connected stages. The first stage involves a tool named EmailKnight, which acts as a deep-dive scanner for incoming messages. Unlike standard filters that might only look at the sender's address or check for known bad links, EmailKnight examines the email from multiple angles. It checks the technical headers to see if the message truly came from where it claims to be from, looks for signs that the email was routed through suspicious servers, and analyzes the content for the psychological pressure tactics often used in scams. Crucially, it also scans attachments like images and audio files to detect if they have been created or altered by artificial intelligence, a capability that is becoming essential as deepfake technology becomes more common.

When EmailKnight identifies a suspicious message, it does not simply delete it or mark it as spam. Instead, it passes the findings to the second stage of the system: a personalized training coach powered by a large language model. This coach acts as a guide, taking the specific reasons why an email was flagged and turning them into a custom lesson for the user. If a user receives a message that looks like it is from their bank but contains a subtle mismatch in the web address, the system does not just warn them; it immediately offers a short, interactive module that explains exactly what that mismatch means and how to spot similar tricks in the future. The training is dynamic, meaning it adapts to the user's specific vulnerabilities. If a person repeatedly falls for urgent payment scams, the system prioritizes lessons on that specific type of threat, ensuring that the education is relevant to the real risks the user is actually facing.

The researchers tested this two-stage framework to see if it could improve both detection and user awareness. They first evaluated the EmailKnight tool against a set of five hundred malicious emails generated with the help of artificial intelligence, covering various attack methods like spoofed links and AI-generated content. The tool successfully identified the threats that other common security checkers missed, particularly those relying on human psychological tricks or open network vulnerabilities. Following this, the team conducted a pilot study with fifty-one university students to measure the educational impact. The students were divided into groups, with one group using the new CyberGLA system, another using a standard commercial training platform, and a third group receiving no training at all. After a short period of learning, all groups took a quiz to test their knowledge.

The results suggested that the personalized, scenario-based approach was more effective than the traditional methods. The students who used CyberGLA scored significantly higher on the quiz, achieving an average accuracy of over ninety-three percent, compared to eighty-five percent for the group using the commercial platform and eighty-two percent for those with no training. The feedback from the participants indicated that they found the interactive, custom lessons more memorable and engaging than static videos or generic advice. The researchers noted that the system successfully turned a moment of potential danger into a learning opportunity, helping users understand the specific mechanics of the attack they had just encountered. While the study was limited to a small group of students and a short timeframe, the findings suggest that linking technical detection directly to adaptive education can strengthen a person's ability to resist modern phishing attempts. The team plans to expand this work to include larger and more diverse groups, and to explore how these tools can protect other vulnerable populations, such as the elderly, who are increasingly targeted by these sophisticated digital deceptions.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →