AI를 활용한 해킹메일 대응 훈련의 실효성에 대한 연구

A Study on the Effectiveness of AI-Based Hacking Email Response Training

초록

This study empirically examines whether AI-based phishing response training provides more effective learning experiences than conventional manual training, using large-scale data from 12,180 public institution employees, and proposes an automated training framework. Existing manual training has structural limitations in both content diversity and measurement metrics. Recent studies demonstrate that large language models (LLMs) can automatically generate expert-level persuasive text, and since phishing emails are fundamentally persuasive communication, this capability can be leveraged as a training tool. Results show that participants exposed to AI-based training perceived threats more realistically and demonstrated statistically significant improvements in training effectiveness perception and threat identification capability. AI-generated scenarios combining real-time information and personalization maximized training realism through complex social engineering elements, consistent with prior research on LLM persuasion. Based on these findings, this study proposes the Intelligent & Adaptive Phishing Training Framework (IATF) reflecting the core principles of NIST SP 800-50r1.

키워드

Generative AI; Phishing Response Training; Social Engineering; Human-centric Security; Automated Framework
제목
AI를 활용한 해킹메일 대응 훈련의 실효성에 대한 연구
제목 (타언어)
A Study on the Effectiveness of AI-Based Hacking Email Response Training
저자
길문철; 정혜정; 이상진
발행일
2026-06
유형
Y
저널명
정보보호학회논문지
권
36
호
3
페이지
1047 ~ 1063