{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,24]],"date-time":"2026-03-24T11:09:30Z","timestamp":1774350570169,"version":"3.50.1"},"reference-count":88,"publisher":"Association for Computing Machinery (ACM)","issue":"2","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Internet Technol."],"published-print":{"date-parts":[[2026,5,31]]},"abstract":"<jats:p>As Large Language Models (LLMs) generate increasingly sophisticated text-image pairs, the risk of LLMs being used for phishing is growing, posing significant challenges for Internet security. We conduct a detailed, IRB-approved study of pairs (uc,pc) where uc is a user property (e.g., demographic or behavioral) and pc is a property of the post content (e.g., topic, emotion, and recency). Unlike past research that focuses either on user properties alone or post content alone, we conduct a comprehensive statistical analysis of more than 1,400 hypotheses involving such (uc,pc) pairs and identify the conditions on user-content pairs that have a significantly higher click probability compared with pairs that do not satisfy the condition. The results include highly nuanced findings connecting susceptibility to phishing with the combination of user properties and post content properties. They also cast some light on contradictory findings from prior work on understanding human susceptibility to phishing.<\/jats:p>","DOI":"10.1145\/3799891","type":"journal-article","created":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T05:41:48Z","timestamp":1772257308000},"page":"1-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["AI-Generated Phishing: Combining Human Behavior with Post Content to Assess Susceptibility"],"prefix":"10.1145","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9719-2461","authenticated-orcid":false,"given":"Natalia","family":"Denisenko","sequence":"first","affiliation":[{"name":"Northwestern University","place":["Evanston, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5941-4684","authenticated-orcid":false,"given":"Valerio","family":"La Gatta","sequence":"additional","affiliation":[{"name":"Northwestern University","place":["Evanston, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1470-8053","authenticated-orcid":false,"given":"Marco","family":"Postiglione","sequence":"additional","affiliation":[{"name":"Northwestern University","place":["Evanston, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-6837-3366","authenticated-orcid":false,"given":"Lirika","family":"Sola","sequence":"additional","affiliation":[{"name":"Northwestern University","place":["Evanston, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5451-0482","authenticated-orcid":false,"given":"Youdinghuan","family":"Chen","sequence":"additional","affiliation":[{"name":"Northwestern University","place":["Evanston, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7191-0296","authenticated-orcid":false,"given":"V.S.","family":"Subrahmanian","sequence":"additional","affiliation":[{"name":"Northwestern University","place":["Evanston, United States"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,3,24]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.716"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1186\/S42400-020-00047-5"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/SCC.2016.61"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3210029"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/ECRIME.2017.7945048"},{"key":"e_1_3_2_7_2","first-page":"271","volume-title":"Learning from the Past & Charting the Future of the Discipline. 14th Americas Conference on Information Systems, AMCIS 2008, Toronto, Ontario, Canada, August 14-17, 2008","author":"Bailey Janet L.","year":"2008","unstructured":"Janet L. Bailey, Robert B. Mitchell, and Bradley K. Jensen. 2008. Analysis of Student Vulnerabilities to Phishing. In Learning from the Past & Charting the Future of the Discipline. 14th Americas Conference on Information Systems, AMCIS 2008, Toronto, Ontario, Canada, August 14-17, 2008. Izak Benbasat and Ali R. Montazemi (Eds.). Association for Information Systems, 271. Retrieved from http:\/\/aisel.aisnet.org\/amcis2008\/271"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0224216"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-9868.2010.00746.x"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.2478\/gfkmir-2014-0022"},{"key":"e_1_3_2_11_2","unstructured":"Mazal Bethany Athanasios Galiopoulos Emet Bethany Mohammad Bahrami Karkevandi Nishant Vishwamitra and Peyman Najafirad. 2024. Large Language Model Lateral Spear Phishing: A Comparative Study in Large-Scale Organizational Settings. arXiv:2401.09727. Retrieved from https:\/\/arxiv.org\/abs\/2401.09727"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103313"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/1978942.1979459"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1177\/0018720816665025"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11409-019-09197-5"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.paid.2021.111335"},{"key":"e_1_3_2_17_2","volume-title":"The Twelfth International Conference on Learning Representations, ICLR 2024, Vienna, Austria, May 7-11, 2024","author":"Chen Canyu","year":"2024","unstructured":"Canyu Chen and Kai Shu. 2024. Can LLM-Generated Misinformation Be Detected?. In The Twelfth International Conference on Learning Representations, ICLR 2024, Vienna, Austria, May 7-11, 2024. OpenReview.net. Retrieved from https:\/\/openreview.net\/forum?id=ccxD4mtkTU"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/2030376.2030387"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103780"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1080\/01611194.2019.1623343"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.5220\/0012797900003767"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/1299015.1299019"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1080\/02699939208411068"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3472749.3474784"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1016\/J.COSE.2020.101862"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1016\/J.IM.2023.103858"},{"key":"e_1_3_2_27_2","unstructured":"Recorded Future. 2024. Security Challenges Rise as QR Code and AI-Generated Phishing Proliferate. Retrieved from https:\/\/www.recordedfuture.com\/research\/qr-code-and-ai-generated-phishing-proliferate. [Accessed 2025-02-11]."},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1016\/J.COSE.2023.103671"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.17705\/1JAIS.00447"},{"key":"e_1_3_2_30_2","volume-title":"The Italian Conference on CyberSecurity","author":"Greco Francesco","year":"2024","unstructured":"Francesco Greco, Giuseppe Desolda, Andrea Esposito, and Alessandro Carelli. 2024. David versus Goliath: Can Machine Learning Detect LLM-Generated Text? A Case Study in the Detection of Phishing Emails. In The Italian Conference on CyberSecurity."},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3461672"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1093\/geronb\/gbaa228"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3664476.3670465"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.4018\/IJSPPC.311060"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/2591971.2591996"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1108\/OIR-04-2015-0106"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2015.419"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1108\/ICS-03-2018-0038"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.9734\/BJAST\/2015\/14975"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1111\/jcom.12160"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30120"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1037\/0022-3514.77.6.1121"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833766"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2018.2869171"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.apergo.2020.103084"},{"key":"e_1_3_2_46_2","unstructured":"Jehyun Lee Peiyuan Lim Bryan Hooi and Dinil Mon Divakaran. 2024. Multimodal Large Language Models for Phishing Webpage Detection and Identification. arXiv:2408.05941. Retrieved from https:\/\/arxiv.org\/abs\/2408.05941"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.3"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1057\/s41300-023-00176-2"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.3390\/ijerph20043514"},{"key":"e_1_3_2_50_2","first-page":"169","volume-title":"PACIS","author":"Lei Wenjing","year":"2021","unstructured":"Wenjing Lei, Siqi Hu, and Carol Hsu. 2021. Understanding Optimism Bias in Phishing: A Health Belief Model Perspective. In PACIS. 169."},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3336141"},{"key":"e_1_3_2_52_2","unstructured":"Alessandro Mascellino. 2024. Phishing Attacks Double in 2024. Retrieved from https:\/\/www.infosecurity-magazine.com\/news\/2024-phishing-attacks-double\/. [Accessed 2025-02-11]."},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/3481357.3481515"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/INNOVATIONS.2012.6207742"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1177\/1071181319631044"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1080\/0960085X.2021.1931494"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/2890509"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1108\/ICS-02-2023-0023"},{"key":"e_1_3_2_59_2","first-page":"6","volume-title":"Australasian Conference on Information Systems, ACIS 2015, Adelaide, SA, Australia, November 30 - December 4, 2015","author":"Parsons Kathryn","year":"2015","unstructured":"Kathryn Parsons, Marcus A. Butavicius, Malcolm R. Pattinson, Agata McCormac, Dragana Calic, and Cate Jerram. 2015. Do Users Focus on the Correct Cues to Differentiate Between Phishing and Genuine Emails?. In Australasian Conference on Information Systems, ACIS 2015, Adelaide, SA, Australia, November 30 - December 4, 2015. 6. Retrieved from https:\/\/aisel.aisnet.org\/acis2015\/6"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-39218-4_27"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1177\/0735633117699232"},{"key":"e_1_3_2_62_2","unstructured":"Kevin Poireault. 2023. Record Number of Mobile Phishing Attacks in 2022. Retrieved from https:\/\/www.infosecurity-magazine.com\/news\/record-number-of-mobile-phishing\/. [Accessed 2025-02-11]."},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103558"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1016\/J.ESWA.2018.09.029"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1177\/00187208231173263"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1002\/acp.4075"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1177\/0018720819855570"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1177\/1541931213601915"},{"key":"e_1_3_2_69_2","unstructured":"Lookout Security. 2023. The Global State of Mobile Phishing. Retrieved from https:\/\/resources.lookout.com\/resources\/global-state-of-mobile-phishing-report. [Accessed 2025-02-11]."},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cub.2011.10.030"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1145\/1753326.1753383"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1016\/J.CHB.2016.02.050"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512266"},{"key":"e_1_3_2_74_2","unstructured":"Ruixiang Tang Yu-Neng Chuang and Xia Hu. 2023. The Science of Detecting LLM-Generated Texts. arXiv:2303.07205. Retrieved from https:\/\/arxiv.org\/abs\/2303.07205"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-40690-5_54"},{"key":"e_1_3_2_76_2","unstructured":"Tripwire. 2024. Cybersecurity in the Age of AI: Exploring AI-Generated Cyber Attacks. Retrieved from https:\/\/www.tripwire.com\/state-of-security\/cybersecurity-age-ai-exploring-ai-generated-cyber-attacks. [Accessed 2025-02-11]."},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1145\/2699026.2699115"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2017.09.004"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2011.03.002"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.17705\/1JAIS.00442"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1287\/ISRE.2016.0680"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.4018\/IJCBPL.2015100101"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2018.06.004"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1080\/0144929X.2018.1519599"},{"key":"e_1_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.1287\/ISRE.2014.0522"},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1287\/isre.2014.0522"},{"key":"e_1_3_2_87_2","unstructured":"Junchao Wu Shu Yang Runzhe Zhan Yulin Yuan Derek F. Wong and Lidia S. Chao. 2023. A Survey on LLM-generated Text Detection: Necessity Methods and Future Directions. arXiv2310.14724. Retrieved from https:\/\/arxiv.org\/abs\/2310.14724"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.11591\/ijece.v13i2.pp1922-1931"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.1145\/3575797"}],"container-title":["ACM Transactions on Internet Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3799891","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,24]],"date-time":"2026-03-24T09:01:55Z","timestamp":1774342915000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3799891"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,24]]},"references-count":88,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,5,31]]}},"alternative-id":["10.1145\/3799891"],"URL":"https:\/\/doi.org\/10.1145\/3799891","relation":{},"ISSN":["1533-5399","1557-6051"],"issn-type":[{"value":"1533-5399","type":"print"},{"value":"1557-6051","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,24]]},"assertion":[{"value":"2025-03-24","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-02-14","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-03-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}