{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T20:57:17Z","timestamp":1777669037773,"version":"3.51.4"},"reference-count":51,"publisher":"SAGE Publications","issue":"4","license":[{"start":{"date-parts":[[2018,12,10]],"date-time":"2018-12-10T00:00:00Z","timestamp":1544400000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"funder":[{"DOI":"10.13039\/100009226","name":"National Security Agency","doi-asserted-by":"publisher","award":["Science of Security Lablet through North Carolina"],"award-info":[{"award-number":["Science of Security Lablet through North Carolina"]}],"id":[{"id":"10.13039\/100009226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Hum Factors"],"published-print":{"date-parts":[[2019,6]]},"abstract":"<jats:sec>\n                    <jats:title>Objective:<\/jats:title>\n                    <jats:p>Evaluate the effectiveness of training embedded within security warnings to identify phishing webpages.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Background:<\/jats:title>\n                    <jats:p>More than 20 million malware and phishing warnings are shown to users of Google Safe Browsing every week. Substantial click-through rate is still evident, and a common issue reported is that users lack understanding of the warnings. Nevertheless, each warning provides an opportunity to train users about phishing and how to avoid phishing attacks.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Method:<\/jats:title>\n                    <jats:p>To test use of phishing-warning instances as opportunities to train users\u2019 phishing webpage detection skills, we conducted an online experiment contrasting the effectiveness of the current Chrome phishing warning with two training-embedded warning interfaces. The experiment consisted of three phases. In Phase 1, participants made login decisions on 10 webpages with the aid of warning. After a distracting task, participants made legitimacy judgments for 10 different login webpages without warnings in Phase 2. To test the long-term effect of the training, participants were invited back a week later to participate in Phase 3, which was conducted similarly as Phase 2.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Results:<\/jats:title>\n                    <jats:p>Participants differentiated legitimate and fraudulent webpages better than chance. Performance was similar for all interfaces in Phase 1 for which the warning aid was present. However, training-embedded interfaces provided better protection than the Chrome phishing warning on both subsequent phases.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Conclusion:<\/jats:title>\n                    <jats:p>Embedded training is a complementary strategy to compensate for lack of phishing webpage detection skill when phishing warning is absent.<\/jats:p>\n                  <\/jats:sec>\n                  <jats:sec>\n                    <jats:title>Application:<\/jats:title>\n                    <jats:p>Potential applications include development of training-embedded warnings to enable security training at scale.<\/jats:p>\n                  <\/jats:sec>","DOI":"10.1177\/0018720818810942","type":"journal-article","created":{"date-parts":[[2018,12,10]],"date-time":"2018-12-10T19:14:27Z","timestamp":1544469267000},"page":"577-595","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":23,"title":["Embedding Training Within Warnings Improves Skills of Identifying Phishing Webpages"],"prefix":"10.1177","volume":"61","author":[{"given":"Aiping","family":"Xiong","sequence":"first","affiliation":[{"name":"Purdue University, Lafayette, Indiana, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Robert W.","family":"Proctor","sequence":"additional","affiliation":[{"name":"Purdue University, Lafayette, Indiana, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weining","family":"Yang","sequence":"additional","affiliation":[{"name":"Purdue University, Lafayette, Indiana, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ninghui","family":"Li","sequence":"additional","affiliation":[{"name":"Purdue University, Lafayette, Indiana, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2018,12,10]]},"reference":[{"key":"bibr1-0018720818810942","first-page":"446","volume-title":"Proceedings of the World Congress on Engineering","author":"Al-Daeef M. M.","year":"2017"},{"key":"bibr2-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-77366-5_33"},{"key":"bibr3-0018720818810942","doi-asserted-by":"publisher","DOI":"10.4324\/9781315799438"},{"key":"bibr4-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.198"},{"key":"bibr5-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1177\/0018720816665025"},{"key":"bibr6-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2013.106"},{"key":"bibr7-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1016\/j.apergo.2013.10.005"},{"key":"bibr8-0018720818810942","unstructured":"Chou N., Ledesma R., Teraguchi Y., Mitchell J. C. (2004). Client-side defense against web-based identity theft. In Proceedings of the 11th Annual Network and Distributed System Security Symposium. http:\/\/crypto.stanford.edu\/SpoofGuard\/webspoof.pdf"},{"key":"bibr9-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/1073001.1073009"},{"key":"bibr10-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/1124772.1124861"},{"key":"bibr11-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2006.10.009"},{"key":"bibr12-0018720818810942","first-page":"239","volume-title":"Neuroeconomics, judgment, and decision making","author":"Downs J. S.","year":"2015"},{"key":"bibr13-0018720818810942","doi-asserted-by":"crossref","first-page":"1065","DOI":"10.1145\/1357054.1357219","volume-title":"Proceedings of the SIGCHI Conference on Human Factors in Computing Systems","author":"Egelman S.","year":"2008"},{"key":"bibr14-0018720818810942","unstructured":"FBI (2018). 2017 Internet crime report. Retrieved from https:\/\/pdf.ic3.gov\/2017_IC3Report.pdf"},{"key":"bibr15-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/2702123.2702442"},{"key":"bibr16-0018720818810942","first-page":"54","volume":"28","author":"Ferguson A. J.","year":"2005","journal-title":"Educause Quarterly"},{"key":"bibr17-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242660"},{"key":"bibr18-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2006.50"},{"key":"bibr19-0018720818810942","doi-asserted-by":"publisher","DOI":"10.3758\/BF03203619"},{"key":"bibr20-0018720818810942","doi-asserted-by":"publisher","DOI":"10.4324\/9780203816783"},{"key":"bibr21-0018720818810942","unstructured":"Herzberg A., Gbara A. (2004). Trustbar: Protecting (even naive) web users from spoofing and phishing attacks. Cryptology ePrint Archive, Report 2004\/155. http:\/\/eprint.iacr.org\/2004\/155."},{"key":"bibr22-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1017\/S0140525X01000103"},{"key":"bibr23-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/2063176.2063197"},{"key":"bibr24-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/1290958.1290968"},{"key":"bibr25-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1177\/1071181312561447"},{"key":"bibr26-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2013.032213.00009"},{"key":"bibr27-0018720818810942","unstructured":"Kumaraguru P., Cranshaw J., Acquisti R., Cranor L., Hong J., Blair M. A., Pham T. (2009). A real-word evaluation of anti-phishing training (Technical report) Pittsburgh, PA: Carnegie Mellon University."},{"key":"bibr28-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/1240624.1240760"},{"key":"bibr29-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/1754393.1754396"},{"key":"bibr30-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1177\/1557234X0600200109"},{"key":"bibr31-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1111\/j.2044-8295.1996.tb02613.x"},{"key":"bibr32-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/1978942.1979244"},{"key":"bibr33-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1037\/0033-2909.109.2.163"},{"key":"bibr34-0018720818810942","doi-asserted-by":"publisher","DOI":"10.5334\/pb-50-3-4-277"},{"key":"bibr35-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/1029533.1029577"},{"key":"bibr36-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.02.008"},{"key":"bibr37-0018720818810942","first-page":"6452","volume-title":"International encyclopedia of education","author":"Perkins D. N.","year":"1992","edition":"2"},{"key":"bibr38-0018720818810942","unstructured":"PhishTank. (2018). Stats. Retrieved from https:\/\/www.phishtank.com\/stats.php"},{"key":"bibr39-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2010.5462216"},{"key":"bibr40-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1177\/0018720815585906"},{"key":"bibr41-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1093\/acprof:oso\/9780195310443.001.0001"},{"key":"bibr42-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-9280.1992.tb00029.x"},{"key":"bibr43-0018720818810942","volume-title":"Proceedings of the 6th Conference on Email and Anti-Spam, CEAS\u201909","author":"Sheng S.","year":"2009"},{"key":"bibr44-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2007.437"},{"key":"bibr45-0018720818810942","volume-title":"Proceedings of the Network and Distributed System Security Symposium, NDSS 2010","author":"Whittaker C.","year":"2010"},{"key":"bibr46-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1177\/001872088702900509"},{"key":"bibr47-0018720818810942","doi-asserted-by":"publisher","DOI":"10.4018\/jthi.2008010105"},{"key":"bibr48-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/1124772.1124863"},{"key":"bibr49-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1177\/0018720816684064"},{"key":"bibr50-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/3055305.3055310"},{"key":"bibr51-0018720818810942","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242659"}],"container-title":["Human Factors: The Journal of the Human Factors and Ergonomics Society"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0018720818810942","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/0018720818810942","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0018720818810942","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T07:51:51Z","timestamp":1777449111000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0018720818810942"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,12,10]]},"references-count":51,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2019,6]]}},"alternative-id":["10.1177\/0018720818810942"],"URL":"https:\/\/doi.org\/10.1177\/0018720818810942","relation":{},"ISSN":["0018-7208","1547-8181"],"issn-type":[{"value":"0018-7208","type":"print"},{"value":"1547-8181","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,12,10]]}}}