arXiv:2604.23148cs.AI2026-04

用心理模型提升实时增强现实社交攻击的欺骗效率

PhySE: A Psychological Framework for Real-Time AR-LLM Social Engineering Attacks

论文配图:PhySE: A Psychological Framework for Real-Time AR-LLM Social Engineering Attacks
图 1 · 摘自论文原文
  • 用视觉语言模型预训练实现快速人物画像生成
  • 基于目标反应动态调整心理策略,突破固定话术限制
  • 在60人实验中验证了攻击有效性,构建了360条对话数据集

基于增强现实与大语言模型的社交工程攻击(AR-LLM-SE)正威胁真实社交互动。攻击者通过AR眼镜采集目标视觉与语音数据,由大语言模型分析并生成详细社会画像,再由智能代理实时提供对话建议以获取信任并实施钓鱼等行为。现有方法面临两大瓶颈:一是检索增强生成(RAG)导致初期画像形成延迟,影响实时交互;二是攻击策略依赖静态、人工设计的脚本,缺乏心理学依据。为此,我们提出PhySE框架,包含两项创新:(1) 基于视觉语言模型(VLM)的社会情境预训练,实现快速、实时的人物画像生成;(2) 自适应心理代理,根据目标反馈动态调用不同心理策略,超越固定脚本。我们通过60名参与者的伦理审查用户研究,收集了360条跨场景标注对话,验证了该框架的有效性。

原文摘要 · Abstract (English)

The emerging threat of AR-LLM-based Social Engineering (AR-LLM-SE) attacks (e.g. SEAR) poses a significant risk to real-world social interactions. In such an attack, a malicious actor uses Augmented Reality (AR) glasses to capture a target visual and vocal data. A Large Language Model (LLM) then analyzes this data to identify the individual and generate a detailed social profile. Subsequently, LLM-powered agents employ social engineering strategies, providing real-time conversation suggestions, to gain the target trust and ultimately execute phishing or other malicious acts. Despite its potential, the practical application of AR-LLM-SE faces two major bottlenecks, (1) Cold-start personalization, Current Retrieval-Augmented Generation (RAG) methods introduce critical delays in the earliest turns, slowing initial profile formation and disrupting real-time interaction, (2) Static Attack Strategies, Existing approaches rely on fixed-stage, handcrafted social engineering tactics that lack foundation in established psychological theory. To address these limitations, we propose PhySE, a novel framework with two core innovations, (1) VLM-Based SocialContext Training, To eliminate profiling delays, we efficiently pre-train a Visual Language Model (VLM) with social-context data, enabling rapid, on-the-fly profile generation, (2) Adaptive Psychological Agent, We introduce a psychological LLM that dynamically deploys distinct classes of psychological strategies based on target response, moving beyond static, handcrafted scripts. We evaluated PhySE through an IRB-approved user study with 60 participants, collecting a novel dataset of 360 annotated conversations across diverse social scenarios.

社交工程AR安全心理建模LLM攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。