Enhancing User Resilience Against AI-Augmented Phishing: A Two-Stage Framework for Detection and Personalized Training

Authors: Weihao Qu, Gurmeet Singh, Daniel Crawford, Bingjun Li, Jalen Smith

Published: 2026-08-21 18:36:13+00:00

Comment: 7 pages, 2 figures, 2 tables. Published in the Journal of The Colloquium for Information Systems Security Education

Journal Ref: Journal of The Colloquium for Information Systems Security Education, 13(1), Article 7 (2026)

AI Summary

This paper proposes CyberGLA, a two-stage anti-phishing framework to counter AI-augmented phishing attacks. It combines EmailKnight, a technical detection tool that performs multi-level email analysis, with an LLM-based security coach that provides personalized training modules based on detected threats. This dual approach aims to enhance user resilience against evolving phishing techniques.

Abstract

The rapid development of artificial intelligence, including agents and deepfake techniques, has accelerated phishing attacks and lowered the threshold for attackers. Modern phishing attacks now blend multiple tactics, including social engineering, URL spoofing, and AI deepfakes enabling adversaries to craft highly convincing messages that exploit human vulnerabilities and bypass traditional detection systems. At the same time, current security awareness education struggles to keep up with the speed, sophistication, and complexity of these evolving threats. To address this challenge, we propose a two-stage anti-phishing framework, CyberGLA, that combines technical defense and user-centered security education. In the Detection stage, we introduce EmailKnight, a spoof detection tool that performs multi-level email analysis. To enhance user awareness, the Training stage incorporates a large language model (LLM)-based security coach that dynamically selects personalized training modules based on the outcomes of the Detection stage. This dual purpose design philosophy enables effective protection against the evolving threats of modern email phishing attacks.


Key findings
EmailKnight successfully flagged all phishing cases in the evaluation, outperforming commercial tools like MailWasher and MXToolbox. Participants trained with CyberGLA showed a significant 20-25% improvement in quiz accuracy compared to those trained with a commercial platform (Mimecast) or no training. The study suggests that combining technical detection with personalized, interactive training is effective in improving phishing awareness and engagement.
Approach
The framework, CyberGLA, operates in two stages: Detection and Training. The Detection stage uses EmailKnight for multi-level email analysis, including authentication checks, URL analysis, and AI-driven attachment analysis for deepfakes. The Training stage employs an LLM-based security coach to dynamically select and deliver personalized training modules to users, informed by the detection outcomes from EmailKnight.
Datasets
UNKNOWN
Model(s)
ResNet, torchaudio (for AI-Driven Attachment Analysis), Large Language Model (LLM)
Author countries
USA