用AI模拟社交工程攻击,个性化防护用户免受欺骗
Personalized Attacks of Social Engineering in Multi-turn Conversations: LLM Agents for Simulation and Detection
- 构建多轮对话攻击模拟框架,生成真实感强的社交工程场景
- 基于1000+场模拟对话,发现人格特质显著影响用户被操控风险
- 提出个性化防御系统,结合用户性格预判并实时识别攻击
大型语言模型驱动的聊天机器人快速发展,给社交媒体平台带来严重的社交工程(SE)攻击风险。多轮对话中的SE检测远比单次交互复杂,因其具有动态演化特性。本研究提出一种基于LLM代理的框架SE-VSim,通过生成多轮对话来模拟社交工程攻击机制,并为不同人格特征的受害者建模,评估心理特质如何影响其易受操控程度。基于超过1000条模拟对话的数据集,分析了伪装成招聘者、资助机构和记者的攻击者获取敏感信息的多种策略。在此基础上,提出概念验证系统SE-OmniGuard,利用用户人格先验知识,评估攻击策略并监控对话中信息交换,实现对用户的个性化防护。
原文摘要 · Abstract (English)
The rapid advancement of conversational agents, particularly chatbots powered by Large Language Models (LLMs), poses a significant risk of social engineering (SE) attacks on social media platforms. SE detection in multi-turn, chat-based interactions is considerably more complex than single-instance detection due to the dynamic nature of these conversations. A critical factor in mitigating this threat is understanding the SE attack mechanisms through which SE attacks operate, specifically how attackers exploit vulnerabilities and how victims' personality traits contribute to their susceptibility. In this work, we propose an LLM-agentic framework, SE-VSim, to simulate SE attack mechanisms by generating multi-turn conversations. We model victim agents with varying personality traits to assess how psychological profiles influence susceptibility to manipulation. Using a dataset of over 1000 simulated conversations, we examine attack scenarios in which adversaries, posing as recruiters, funding agencies, and journalists, attempt to extract sensitive information. Based on this analysis, we present a proof of concept, SE-OmniGuard, to offer personalized protection to users by leveraging prior knowledge of the victims personality, evaluating attack strategies, and monitoring information exchanges in conversations to identify potential SE attempts.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。