• Home
  • Search
  • A Gamified Phishing Simulator Using Reinforcement Learning
  • https://doi.org/10.34190/icair.5.1.4339Copy DOI Icon

A Gamified Phishing Simulator Using Reinforcement Learning

Show More
  • Abstract
  • Literature Map
  • Similar Papers
Abstract

An organisation's security is fundamentally reliant on its people. Regardless of the sophistication of its cybersecurity infrastructure, the absence of comprehensive training and awareness can lead to vulnerabilities. Traditional phishing awareness training typically involves sending simulated phishing emails to employees, allowing organisations to monitor actions such as link clicks, email reporting, and responses. While this method offers valuable insights into employee behaviour, it often struggles to engage users effectively. This conventional approach may not create a dynamic learning environment conducive to better retention of vital security practices. Furthermore, users generally do not receive immediate feedback regarding their interactions with phishing links, leaving organisations more susceptible to social engineering attacks. This research seeks to address the issue by developing an interactive gamified phishing simulator that employs reinforcement learning (RL). The methodology for this study consists of two key components. First, a literature review was conducted to assess existing phishing awareness techniques and explore how RL can be applied effectively. This review examined the integration of RL within cybersecurity education and explored the impact of gamification on user behaviour. For the RL agent, a dataset comprising both phishing and legitimate emails was compiled. The agent was then trained to discern phishing emails from legitimate ones based on various email features. Then the agent presents users with email challenges and delivers real-time feedback on their selections. The simulator incorporates a reward and badge system that promotes active participation and ongoing learning. This approach aims to overcome the limitations traditionally associated with static phishing training by fostering continuous learning, ultimately reducing user susceptibility. The effectiveness of the proposed simulator was evaluated based on its classification accuracy of phishing and legitimate emails.

Similar Papers
  • PDF
  • Research Article
  • Citations27

Better beware: comparing metacognition for phishing and legitimate emails

  • Jul 20, 2019
  • Metacognition and Learning
  • Casey Inez Canfield +2
  • Conference Article
  • Citations6

Phishing Using a Modified Bayesian Technique

  • Aug 01, 2010
  • Krist Beck +1
  • Single Book
  • Citations12

Cyber Security and IT Infrastructure Protection

  • Jan 01, 2014
  • John R Vacca
  • Research Article
  • Citations3

User behaviour modelling by abstracting low-level window transition logs

  • Jan 01, 2015
  • International Journal of Computational Science and Engineering
  • Ryohei Saito +2
  • Research Article

AUTOMATED DETECTION OF SQL INJECTION VULNERABILITIES IN CHATBOTS USING REINFORCEMENT LEARNING

  • Sep 26, 2025
  • Cybersecurity Education Science Technique
  • Vladyslav Vikulov +1
  • Research Article

AI-Enabled Dispatching Optimisation Mechanism of Shared Bikes

  • Oct 28, 2025
  • Applied and Computational Engineering
  • Jie Zhang
  • Research Article

A method utilizing deep learning and reinforcement learning for credit card fraud detection

  • Apr 10, 2025
  • Intelligent Decision Technologies
  • Md Nur-E-Arefin +2
  • Conference Article

Intelligent Autonomous Decision-Making System Using Hybrid AI Techniques for Real-Time Data Processing and Optimization

  • Jan 16, 2026
  • Doma Murali Krishna +5
  • Research Article

Forest or trees? Evidence for global processing via an information board study into cues utilised in phishing identification

  • Jul 12, 2025
  • Behaviour & Information Technology
  • Daniel Conway +4
  • Research Article
  • Citations13

The Effect of Rational Based Beliefs and Awareness on Employee Compliance with Information Security Procedures: A Case Study of a Financial Corporation in Israel

  • Jan 01, 2020
  • Interdisciplinary Journal of Information, Knowledge, and Management
  • Golan Carmi +1
  • Book Chapter

Research on Control System of Upper Limb Rehabilitation Training Based on Reinforcement Learning

  • Dec 06, 2022
  • Liangda Wu +4
  • Research Article
  • Citations1

Hardening Email Security via Bayesian Additive Regression Trees

  • Jan 01, 2009
  • BiblioBoard Library Catalog (Open Research Library)
  • Saeed Abu-Nimeh +3
  • Conference Article
  • Citations1

Let's Go Phishing: A Phishing Awareness Campaign Using Smishing, Email Phishing, and Social Media Phishing Tools

  • Jul 09, 2021
  • Eric B Blancaflor +4
  • Research Article
  • Citations34

Measuring cyber secure behavior of elementary and high school students in the Netherlands

  • May 07, 2022
  • Computers & Education
  • Jacob Willem Abraham Witsenboer +2
  • Research Article
  • Citations1

The ADBPSO-LightGBM internal threat detection framework based on hybrid data balancing

  • May 08, 2025
  • Systems Science & Control Engineering
  • Jin-Jie Zheng +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.