Abstract & Details
Description
Award ID: 2629983
This I-Corps project is based on the development of technology to reduce human vulnerability to phishing attacks. Social engineering attacks, including phishing and spear phishing, are significant cybersecurity risks facing enterprises, yet effective technological solutions for addressing the underlying human risk are lacking. Although organizations invest heavily in annual security awareness training, phishing simulations, and dedicated personnel to enhance awareness, current approaches do not adequately address the risk of recall failure. This technology helps employees to improve recall, and recognize and report phishing threats, which may reduce organizational vulnerability and improve their ability to recognize scams outside the workplace. This may enable organizations to more accurately measure human cybersecurity risk, deliver effective and personalized training, and reduce the financial costs, operational disruptions, and societal harms caused by phishing and other social engineering attacks. This I-Corps project utilizes experiential learning coupled with first-hand investigation of the industry ecosystem to assess the translation potential of a model that estimates an individuals risk of forgetting different types of phishing threats and delivers personalized training interventions to strengthen long-term recall and improve detection and reporting of phishing attacks. This technology uses control-theoretic methods, together with cognitive models, to generate an optimized sequence of periodic training interventions designed to reduce recall risk. It operates as a closed-loop system in which employee engagement data, prior training data, and, when available, phishing-simulation results are continuously collected and analyzed to adapt subsequent interventions. The result is a personalized, continuously adapting training mechanism intended to strengthen long-term recall of social engineering threat patterns so employees can recognize and report attacks when they receive them. Existing solutions primarily build basic knowledge, assess risk intermittently, and support compliance. However, employees often fail to retrieve relevant threat patterns from memory when confronting real attacks. This technology may provide a more effective way to estimate an individual employees risk of recall failure and mitigate that risk through personalized interventions that strengthen the long-term ability to recognize and report phishing attacks. This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
NSF Program Director: Ruth Shuman
This I-Corps project is based on the development of technology to reduce human vulnerability to phishing attacks. Social engineering attacks, including phishing and spear phishing, are significant cybersecurity risks facing enterprises, yet effective technological solutions for addressing the underlying human risk are lacking. Although organizations invest heavily in annual security awareness training, phishing simulations, and dedicated personnel to enhance awareness, current approaches do not adequately address the risk of recall failure. This technology helps employees to improve recall, and recognize and report phishing threats, which may reduce organizational vulnerability and improve their ability to recognize scams outside the workplace. This may enable organizations to more accurately measure human cybersecurity risk, deliver effective and personalized training, and reduce the financial costs, operational disruptions, and societal harms caused by phishing and other social engineering attacks. This I-Corps project utilizes experiential learning coupled with first-hand investigation of the industry ecosystem to assess the translation potential of a model that estimates an individuals risk of forgetting different types of phishing threats and delivers personalized training interventions to strengthen long-term recall and improve detection and reporting of phishing attacks. This technology uses control-theoretic methods, together with cognitive models, to generate an optimized sequence of periodic training interventions designed to reduce recall risk. It operates as a closed-loop system in which employee engagement data, prior training data, and, when available, phishing-simulation results are continuously collected and analyzed to adapt subsequent interventions. The result is a personalized, continuously adapting training mechanism intended to strengthen long-term recall of social engineering threat patterns so employees can recognize and report attacks when they receive them. Existing solutions primarily build basic knowledge, assess risk intermittently, and support compliance. However, employees often fail to retrieve relevant threat patterns from memory when confronting real attacks. This technology may provide a more effective way to estimate an individual employees risk of recall failure and mitigate that risk through personalized interventions that strengthen the long-term ability to recognize and report phishing attacks. This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
NSF Program Director: Ruth Shuman
| Status | Active |
|---|---|
| Effective start/end date | 09/01/26 → 08/31/27 |
Funding
- I-Corps Teams: $50,000.00
Active Fiscal Year
- FY2027
- FY2026
Start Fiscal Year
- FY2026
TIP Programs
- I-Corps Teams
Key Technology Areas
- Artificial Intelligence
- (confidence score: 100%)
- Data and Cybersecurity
- (confidence score: 100%)
Technology Foci
- Cyber-security
- (confidence score: 100%)
- Machine Learning Training Data
- (confidence score: 99%)
- Machine Learning (ML)
- (confidence score: 92%)
- Artificial Intelligence (excluding ML)
- (confidence score: 93%)
Congressional District at Award
- District n. 07 of Washington
Current Congressional District
- District n. 07 of Washington
United States
- Washington
Core Based Statistical Area (CBSA)
- Seattle-Tacoma-Bellevue, WA
County
- County: King, WA
Fingerprint
Explore the research topics touched on by this project. These labels are generated based on the underlying awards/grants. Together they form a unique fingerprint. Learn more about Elsevier's Fingerprint Engine here: https://beta.elsevier.com/products/elsevier-fingerprint-engine