A Proof of Concept for Testing Validity of AI-Generated Content in the Context of Personalized Cybersecurity Training
摘要
As cybersecurity threats become increasingly complex, frequent, and targeted, educating users (who are often viewed as “the weakest link” in the system) to increase their awareness of security and privacy is becoming more critical than ever. However, the effectiveness of the “one-size-fits-all”approach in existing awareness programs to educate people about security and privacy may be limited, as it often overlooks individuals’ unique needs, prior knowledge of specific topics, real-life security behaviors, and preferred learning and delivery methods. Recent advancements in AI tools present opportunities to create personalized content tailored to users’ unique needs and preferences. To explore this potential, we developed a web application that leverages AI tools to offer personalized cybersecurity education. The system first assesses users’ security and privacy knowledge and behaviors, classifies them into categories (e.g., beginner, intermediate, advanced), and then presents AI-generated content in their preferred format (e.g., text, video). While the project is a proof-of-concept, the methods/approaches used in this work can help both academia and industry develop more effective, scalable, and adaptive cybersecurity trainings by integrating AI tools.