Research
Publications
Peer-reviewed work from our team measuring how far AI can automate social engineering — and how well it defends against it. Each study tests frontier models on real human subjects rather than on synthetic proxies, which is what makes the numbers usable as a baseline.
This research is the empirical foundation for the benchmarks we build: ScamBench, ManipulationBench, and the Scam Killchain.
Expert Systems with Applications · 2026
Evaluating large language models’ ability to automate spear phishing
F. Heiding, S. Lermen, A. Kao, B. Schneier, A. Vishwanath
A human-subject study measuring whether frontier models can run personalized spear phishing end to end — reconnaissance, targeting, and email generation — benchmarked against human experts.
Key findings
- Fully AI-automated emails matched human experts at a 54% click-through rate, against 12% for the arbitrary-phishing control group.
- Automation cut the cost per target by roughly 92%, with economic analysis pointing to as much as a 50× increase in attacker ROI.
- Models produced accurate, useful target profiles in 88% of cases from open sources alone.
- The same capability cuts both ways: properly prompted models detected phishing intent with over 90% accuracy and few false positives.
Expert Systems with Applications · 2026
Evaluating AI models’ capability to automate voice phishing attacks
F. Heiding, C. Mayrink Verdun, S. Lermen, A. Kao, V. Albiero, L. Deason, I.-E. Veliche, C. Lehane
A large-scale survey experiment (N=4,100) plus qualitative interviews (N=12) testing how US adults respond to voice phishing calls generated by leading speech models, against human baselines.
Key findings
- Overall compliance with the phishing request reached 16.5% across five scam categories, rising to 36% for the “relative in distress” scenario.
- Caller persuasiveness was the strongest predictor of compliance, and some models — Sesame most notably — rated on par with or slightly above human callers.
- Human-operated vishing is unprofitable at US wages; several AI voice models make the same attack economically viable.
- The threat is automation economics rather than novel persuasion tactics — which is what makes it scale.
Read the paper DOI: 10.1016/j.eswa.2026.133620IEEE Access, vol. 12, pp. 42131–42146 · 2024
Devising and Detecting Phishing Emails Using Large Language Models
F. Heiding, B. Schneier, A. Vishwanath, J. Bernstein, P. S. Park
The earlier study in this line of work: comparing LLM-generated phishing emails against human-crafted and V-Triad emails on real participants, then testing whether the same models can detect what they produce.
Key findings
- GPT-4-generated phishing emails performed comparably to hand-crafted expert emails on click-through, at a fraction of the effort.
- LLMs showed strong but inconsistent detection performance, sensitive to how the prompt frames the task.
- Established that offensive and defensive phishing capability rise together in the same models.
Read the paper DOI: 10.1109/ACCESS.2024.3375882
For questions about this work, collaborations, or replication data, please .