{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T15:43:08Z","timestamp":1782834188314,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,9,30]],"date-time":"2024-09-30T00:00:00Z","timestamp":1727654400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,9,30]]},"DOI":"10.1145\/3688459.3688465","type":"proceedings-article","created":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T08:31:55Z","timestamp":1732091515000},"page":"15-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Eyes on the Phish(er): Towards Understanding Users' Email Processing Pattern and Mental Models in Phishing Detection"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7741-0022","authenticated-orcid":false,"given":"Sijie","family":"Zhuo","sequence":"first","affiliation":[{"name":"University of Auckland, AucklandAuckland, New Zealand,"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5971-2705","authenticated-orcid":false,"given":"Robert","family":"Biddle","sequence":"additional","affiliation":[{"name":"University of Auckland, Auckland, New Zealand and Carleton University, Auckland, Canada,"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-8625-216X","authenticated-orcid":false,"given":"Jared","family":"Daniel Recomendable","sequence":"additional","affiliation":[{"name":"University of Auckland, Auckland, New Zealand,"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6987-0803","authenticated-orcid":false,"given":"Giovanni","family":"Russello","sequence":"additional","affiliation":[{"name":"University of Auckland, Auckland, New Zealand,"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5541-4425","authenticated-orcid":false,"given":"Danielle","family":"Lottridge","sequence":"additional","affiliation":[{"name":"University of Auckland, Auckland, New Zealand,"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,11,20]]},"reference":[{"key":"e_1_3_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-07674-4_89"},{"key":"e_1_3_3_1_3_2","unstructured":"Hugh Aver. 2021. 6 antiphishing tips. https:\/\/www.kaspersky.com\/blog\/how-to-protect-yourself-from-phishing\/42317\/"},{"key":"e_1_3_3_1_4_2","doi-asserted-by":"crossref","unstructured":"Nils Begou Jeremy Vinoy Andrzej Duda and Maciej Korczynski. 2023. Exploring the Dark Side of AI: Advanced Phishing Attack Design and Deployment Using ChatGPT. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2309.10463 (2023).","DOI":"10.1109\/CNS59707.2023.10288940"},{"key":"e_1_3_3_1_5_2","doi-asserted-by":"crossref","unstructured":"Virginia Braun and Victoria Clarke. 2006. Using thematic analysis in psychology. Qualitative research in psychology 3 2 (2006) 77\u2013101.","DOI":"10.1191\/1478088706qp063oa"},{"key":"e_1_3_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3407023.3409178"},{"key":"e_1_3_3_1_7_2","doi-asserted-by":"crossref","unstructured":"Casey\u00a0Inez Canfield Baruch Fischhoff and Alex Davis. 2016. Quantifying phishing susceptibility for detection and behavior decisions. Human factors 58 8 (2016) 1158\u20131172.","DOI":"10.1177\/0018720816665025"},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/1943403.1943454"},{"key":"e_1_3_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40498-6_58"},{"key":"e_1_3_3_1_10_2","doi-asserted-by":"crossref","unstructured":"Matt Dixon James Nicholson Dawn Branley-Bell Pam Briggs and Lynne Coventry. 2022. Holding Your Hand on the Danger Button: Observing User Phish Detection Strategies Across Mobile and Desktop. Proceedings of the ACM on Human-Computer Interaction 6 MHCI (2022) 1\u201322.","DOI":"10.1145\/3546730"},{"key":"e_1_3_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-61061-0_6"},{"key":"e_1_3_3_1_12_2","doi-asserted-by":"crossref","unstructured":"Kacper\u00a0T Gradonm. 2023. Electric Sheep on the Pastures of Disinformation and Targeted Phishing Campaigns: The Security Implications of ChatGPT. IEEE Security & Privacy 21 3 (2023) 58\u201361.","DOI":"10.1109\/MSEC.2023.3255039"},{"key":"e_1_3_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOTEH57020.2023.10094141"},{"key":"e_1_3_3_1_14_2","doi-asserted-by":"crossref","unstructured":"Brynne Harrison Elena Svetieva and Arun Vishwanath. 2016. Individual processing of phishing emails. Online Information Review (2016).","DOI":"10.1108\/OIR-04-2015-0106"},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2015.419"},{"key":"e_1_3_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1016\/S0166-4115(08)62386-9"},{"key":"e_1_3_3_1_17_2","doi-asserted-by":"crossref","unstructured":"G\u00a0Robert\u00a0J Hockey. 1997. Compensatory control in the regulation of human performance under stress and high workload: A cognitive-energetical framework. Biological psychology 45 1-3 (1997) 73\u201393.","DOI":"10.1016\/S0301-0511(96)05223-4"},{"key":"e_1_3_3_1_18_2","doi-asserted-by":"crossref","unstructured":"Mohammad\u00a0S Jalali Maike Bruckes Daniel Westmattelmann and Gerhard Schewe. 2020. Why employees (still) click on phishing links: investigation in hospitals. Journal of Medical Internet Research 22 1 (2020) e16775.","DOI":"10.2196\/16775"},{"key":"e_1_3_3_1_19_2","unstructured":"Rabimba Karanjai. 2022. Targeted phishing campaigns using large scale language models. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2301.00665 (2022)."},{"key":"e_1_3_3_1_20_2","doi-asserted-by":"crossref","unstructured":"Patrick Lawson Carl\u00a0J Pearson Aaron Crowson and Christopher\u00a0B Mayhorn. 2020. Email phishing and signal detection: How persuasion principles and personality influence response patterns and accuracy. Applied Ergonomics 86 (2020) 103084.","DOI":"10.1016\/j.apergo.2020.103084"},{"key":"e_1_3_3_1_21_2","doi-asserted-by":"crossref","unstructured":"John McAlaney and Peter\u00a0J Hills. 2020. Understanding phishing email processing and perceived trustworthiness through eye tracking. Frontiers in Psychology 11 (2020) 537958.","DOI":"10.3389\/fpsyg.2020.01756"},{"key":"e_1_3_3_1_22_2","doi-asserted-by":"crossref","unstructured":"Martijn Meeter Yousri Marzouki Arthur\u00a0E Avramiea Joshua Snell and Jonathan Grainger. 2020. The role of attention in word recognition: Results from OB1-reader. Cognitive science 44 7 (2020) e12846.","DOI":"10.1111\/cogs.12846"},{"key":"e_1_3_3_1_23_2","doi-asserted-by":"crossref","unstructured":"Paula\u00a0MW Musuva Katherine\u00a0W Getao and Christopher\u00a0K Chepken. 2019. A new approach to modelling the effects of cognitive processing and threat detection on phishing susceptibility. Computers in Human Behavior 94 (2019) 154\u2013175.","DOI":"10.1016\/j.chb.2018.12.036"},{"key":"e_1_3_3_1_24_2","unstructured":"Kathryn Parsons Marcus Butavicius Malcolm Pattinson Dragana Calic Agata McCormac and Cate Jerram. 2016. Do users focus on the correct cues to differentiate between phishing and genuine emails? arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1605.04717 (2016)."},{"key":"e_1_3_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-39218-4_27"},{"key":"e_1_3_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3290605.3300748"},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-21814-0_21"},{"key":"e_1_3_3_1_28_2","unstructured":"Proofprint. 2023. 2023 State of the Phishing Report."},{"key":"e_1_3_3_1_29_2","unstructured":"Sayak\u00a0Saha Roy Krishna\u00a0Vamsi Naragam and Shirin Nilizadeh. 2023. Generating Phishing Attacks using ChatGPT. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2305.05133 (2023)."},{"key":"e_1_3_3_1_30_2","unstructured":"Emils Rozentals. 2021. Email load and stress impact on susceptibility to phishing and scam emails."},{"key":"e_1_3_3_1_31_2","doi-asserted-by":"crossref","unstructured":"Cornelia Setz Bert Arnrich Johannes Schumm Roberto La\u00a0Marca Gerhard Tr\u00f6ster and Ulrike Ehlert. 2009. Discriminating stress from cognitive load using a wearable EDA device. IEEE Transactions on information technology in biomedicine 14 2 (2009) 410\u2013417.","DOI":"10.1109\/TITB.2009.2036164"},{"key":"e_1_3_3_1_32_2","unstructured":"Herbert\u00a0Alexander Simon and K\u00a0Anders Ericsson. 1984. Protocol analysis: Verbal reports as data. Cambridge MA: MIT Press (1984)."},{"key":"e_1_3_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.14722\/usec.2019.23028"},{"key":"e_1_3_3_1_34_2","doi-asserted-by":"crossref","unstructured":"Milica Stojmenovi\u0107 Eric Spero Milo\u0161 Stojmenovi\u0107 and Robert Biddle. 2022. What is beautiful is secure. ACM Transactions on Privacy and Security 25 4 (2022) 1\u201330.","DOI":"10.1145\/3533047"},{"key":"e_1_3_3_1_35_2","unstructured":"Clare Stouffer. 2022. How to Protect Against Phishing. https:\/\/us.norton.com\/blog\/how-to\/how-to-protect-against-phishing"},{"key":"e_1_3_3_1_36_2","unstructured":"Jo\u00e3o Tom\u00e9. 2023. How to Stay Safe from Phishing. https:\/\/blog.cloudflare.com\/stay-safe-phishing-attacks\/"},{"key":"e_1_3_3_1_37_2","doi-asserted-by":"crossref","unstructured":"Tamara Van\u00a0Gog Liesbeth Kester Fleurie Nievelstein Bas Giesbers and Fred Paas. 2009. Uncovering cognitive processes: Different techniques that can contribute to cognitive load research and instruction. Computers in Human Behavior 25 2 (2009) 325\u2013331.","DOI":"10.1016\/j.chb.2008.12.021"},{"key":"e_1_3_3_1_38_2","doi-asserted-by":"crossref","unstructured":"Arun Vishwanath Tejaswini Herath Rui Chen Jingguo Wang and H\u00a0Raghav Rao. 2011. Why do people get phished? Testing individual differences in phishing vulnerability within an integrated information processing model. Decision Support Systems 51 3 (2011) 576\u2013586.","DOI":"10.1016\/j.dss.2011.03.002"},{"key":"e_1_3_3_1_39_2","doi-asserted-by":"crossref","unstructured":"Melanie Volkamer Karen Renaud Benjamin Reinheimer and Alexandra Kunz. 2017. User experiences of torpedo: Tooltip-powered phishing email detection. Computers & Security 71 (2017) 100\u2013113.","DOI":"10.1016\/j.cose.2017.02.004"},{"key":"e_1_3_3_1_40_2","doi-asserted-by":"crossref","unstructured":"Qiuzhen Wang Sa Yang Manlu Liu Zike Cao and Qingguo Ma. 2014. An eye-tracking study of website complexity from cognitive load perspective. Decision support systems 62 (2014) 1\u201310.","DOI":"10.1016\/j.dss.2014.02.007"},{"key":"e_1_3_3_1_41_2","doi-asserted-by":"crossref","unstructured":"Emma\u00a0J Williams and Danielle Polage. 2019. How persuasive is phishing email? The role of authentic design influence and current events in email judgements. Behaviour & Information Technology 38 2 (2019) 184\u2013197.","DOI":"10.1080\/0144929X.2018.1519599"},{"key":"e_1_3_3_1_42_2","unstructured":"Sijie Zhuo Robert Biddle Lucas Betts Nalin Asanka\u00a0Gamagedara Arachchilage Yun\u00a0Sing Koh Giovanni Russello and Danielle Lottridge. 2024. The Impact of Workload on Phishing Susceptibility: An Experiment. Symposium on Usable Security and Privacy (USEC) (2024)."},{"key":"e_1_3_3_1_43_2","doi-asserted-by":"publisher","unstructured":"Sijie Zhuo Robert Biddle Yun\u00a0Sing Koh Danielle Lottridge and Giovanni Russello. 2022. SoK: Human-Centered Phishing Susceptibility. ACM Trans. Priv. Secur. (dec 2022). 10.1145\/3575797 https:\/\/dl.acm.org\/doi\/10.1145\/3575797","DOI":"10.1145\/3575797"}],"event":{"name":"EuroUSEC 2024: The 2024 European Symposium on Usable Security","location":"Karlstad Sweden","acronym":"EuroUSEC 2024"},"container-title":["Proceedings of the 2024 European Symposium on Usable Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3688459.3688465","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3688459.3688465","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:10:29Z","timestamp":1750295429000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3688459.3688465"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,9,30]]},"references-count":42,"alternative-id":["10.1145\/3688459.3688465","10.1145\/3688459"],"URL":"https:\/\/doi.org\/10.1145\/3688459.3688465","relation":{},"subject":[],"published":{"date-parts":[[2024,9,30]]},"assertion":[{"value":"2024-11-20","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}