{"id":"https://openalex.org/W4404567806","doi":"https://doi.org/10.1145/3688459.3688460","title":"You Know What? - Evaluation of a Personalised Phishing Training Based on Users' Phishing Knowledge and Detection Skills","display_name":"You Know What? - Evaluation of a Personalised Phishing Training Based on Users' Phishing Knowledge and Detection Skills","publication_year":2024,"publication_date":"2024-09-30","ids":{"openalex":"https://openalex.org/W4404567806","doi":"https://doi.org/10.1145/3688459.3688460"},"language":"en","primary_location":{"id":"doi:10.1145/3688459.3688460","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3688459.3688460","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 European Symposium on Usable Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3688459.3688460","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5092665652","display_name":"Lorin Sch\u00f6ni","orcid":"https://orcid.org/0000-0002-9483-617X"},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":true,"raw_author_name":"Lorin Sch\u00f6ni","raw_affiliation_strings":["Security, Privacy and Society, ETH Zurich, Zurich, Switzerland,"],"raw_orcid":"https://orcid.org/0000-0002-9483-617X","affiliations":[{"raw_affiliation_string":"Security, Privacy and Society, ETH Zurich, Zurich, Switzerland,","institution_ids":["https://openalex.org/I35440088"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5114729463","display_name":"Victor Carles","orcid":null},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Victor Carles","raw_affiliation_strings":["Security, Privacy and Society, ETH Zurich, Zurich, Switzerland,"],"raw_orcid":"https://orcid.org/0009-0003-2149-7132","affiliations":[{"raw_affiliation_string":"Security, Privacy and Society, ETH Zurich, Zurich, Switzerland,","institution_ids":["https://openalex.org/I35440088"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5079874685","display_name":"Martin Strohmeier","orcid":"https://orcid.org/0000-0002-1936-0933"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Martin Strohmeier","raw_affiliation_strings":["Cyber-Defence Campus, armasuisse, Thun, Switzerland,"],"raw_orcid":"https://orcid.org/0000-0002-1936-0933","affiliations":[{"raw_affiliation_string":"Cyber-Defence Campus, armasuisse, Thun, Switzerland,","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5033826310","display_name":"Peter Mayer","orcid":"https://orcid.org/0000-0002-6267-4874"},"institutions":[{"id":"https://openalex.org/I102335020","display_name":"Karlsruhe Institute of Technology","ror":"https://ror.org/04t3en479","country_code":"DE","type":"education","lineage":["https://openalex.org/I102335020","https://openalex.org/I1305996414"]},{"id":"https://openalex.org/I177969490","display_name":"University of Southern Denmark","ror":"https://ror.org/03yrrjy16","country_code":"DK","type":"education","lineage":["https://openalex.org/I177969490"]}],"countries":["DE","DK"],"is_corresponding":false,"raw_author_name":"Peter Mayer","raw_affiliation_strings":["Department of Mathematics and Computer Science, University of Southern Denmark, Odense, Denmark and SECUSO, Karlsruhe Institute of Technology, Odense, Germany,"],"raw_orcid":"https://orcid.org/0000-0002-6267-4874","affiliations":[{"raw_affiliation_string":"Department of Mathematics and Computer Science, University of Southern Denmark, Odense, Denmark and SECUSO, Karlsruhe Institute of Technology, Odense, Germany,","institution_ids":["https://openalex.org/I177969490","https://openalex.org/I102335020"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5042008708","display_name":"Verena Zimmermann","orcid":"https://orcid.org/0000-0002-6873-8146"},"institutions":[{"id":"https://openalex.org/I35440088","display_name":"ETH Zurich","ror":"https://ror.org/05a28rw58","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I35440088"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Verena Zimmermann","raw_affiliation_strings":["Security, Privacy and Society, ETH Zurich, Zurich, Switzerland,"],"raw_orcid":"https://orcid.org/0000-0002-6873-8146","affiliations":[{"raw_affiliation_string":"Security, Privacy and Society, ETH Zurich, Zurich, Switzerland,","institution_ids":["https://openalex.org/I35440088"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5092665652"],"corresponding_institution_ids":["https://openalex.org/I35440088"],"apc_list":null,"apc_paid":null,"fwci":7.416,"has_fulltext":true,"cited_by_count":10,"citation_normalized_percentile":{"value":0.97228084,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"14"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9950000047683716,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11045","display_name":"Privacy, Security, and Data Protection","score":0.9948999881744385,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/phishing","display_name":"Phishing","score":0.9537501931190491},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6036961674690247},{"id":"https://openalex.org/keywords/training","display_name":"Training (meteorology)","score":0.4538206160068512},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.417293518781662},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3413727879524231},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.305178165435791},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.1704276204109192}],"concepts":[{"id":"https://openalex.org/C83860907","wikidata":"https://www.wikidata.org/wiki/Q135005","display_name":"Phishing","level":3,"score":0.9537501931190491},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6036961674690247},{"id":"https://openalex.org/C2777211547","wikidata":"https://www.wikidata.org/wiki/Q17141490","display_name":"Training (meteorology)","level":2,"score":0.4538206160068512},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.417293518781662},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3413727879524231},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.305178165435791},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.1704276204109192},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C153294291","wikidata":"https://www.wikidata.org/wiki/Q25261","display_name":"Meteorology","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3688459.3688460","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3688459.3688460","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 European Symposium on Usable Security","raw_type":"proceedings-article"},{"id":"pmh:oai:sdu.dk:openaire/d2012a37-e3a1-4bdf-94f5-1bf5e8067b84","is_oa":true,"landing_page_url":"https://portal.findresearcher.sdu.dk/da/publications/d2012a37-e3a1-4bdf-94f5-1bf5e8067b84","pdf_url":"https://findresearcher.sdu.dk/ws/files/281251674/You_Know_What_-_Evaluation_of_a_Personalised_Phishing_Training_Based_on_Users_Phishing_Knowledge_and_Detection_Skills.pdf","source":{"id":"https://openalex.org/S4306400423","display_name":"University of Southern Denmark Research Portal (University of Southern Denmark)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I177969490","host_organization_name":"University of Southern Denmark","host_organization_lineage":["https://openalex.org/I177969490"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Sch\u00f6ni, L, Carles, V, Strohmeier, M, Mayer, P & Zimmermann, V 2024, You Know What? - Evaluation of a Personalised Phishing Training Based on Users' Phishing Knowledge and Detection Skills. in F Karegar & A Farooq (eds), Proceedings of the 2024 European Symposium on Usable Security : EuroUSEC '24. Association for Computing Machinery, pp. 1-14, 2024 European Symposium on Usable Security, EuroUSEC 2024, Karlstad, Sweden, 30/09/2024. https://doi.org/10.1145/3688459.3688460","raw_type":"info:eu-repo/semantics/publishedVersion"},{"id":"pmh:doi:10.3929/ethz-b-000689291","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Conference Paper"}],"best_oa_location":{"id":"doi:10.1145/3688459.3688460","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3688459.3688460","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 European Symposium on Usable Security","raw_type":"proceedings-article"},"sustainable_development_goals":[{"display_name":"Quality Education","id":"https://metadata.un.org/sdg/4","score":0.5}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":48,"referenced_works":["https://openalex.org/W1512117440","https://openalex.org/W1838481526","https://openalex.org/W1994510396","https://openalex.org/W2044519557","https://openalex.org/W2052176706","https://openalex.org/W2071559616","https://openalex.org/W2071869991","https://openalex.org/W2073818218","https://openalex.org/W2099889974","https://openalex.org/W2110065044","https://openalex.org/W2142287040","https://openalex.org/W2157597875","https://openalex.org/W2162532690","https://openalex.org/W2163241745","https://openalex.org/W2284487341","https://openalex.org/W2293424065","https://openalex.org/W2402939184","https://openalex.org/W2568632554","https://openalex.org/W2745971308","https://openalex.org/W2792152564","https://openalex.org/W2807421078","https://openalex.org/W2922335955","https://openalex.org/W2941796164","https://openalex.org/W2945437145","https://openalex.org/W2946688610","https://openalex.org/W2965230330","https://openalex.org/W3001071999","https://openalex.org/W3005886336","https://openalex.org/W3012440729","https://openalex.org/W3022944079","https://openalex.org/W3047864016","https://openalex.org/W3049483075","https://openalex.org/W3125542462","https://openalex.org/W3130705826","https://openalex.org/W3143441212","https://openalex.org/W3184843993","https://openalex.org/W3198950321","https://openalex.org/W4200148862","https://openalex.org/W4226477010","https://openalex.org/W4288057710","https://openalex.org/W4299503428","https://openalex.org/W4309637085","https://openalex.org/W4311221106","https://openalex.org/W4321230699","https://openalex.org/W4367856598","https://openalex.org/W4385251717","https://openalex.org/W4387860877","https://openalex.org/W4389109942"],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W2149202530","https://openalex.org/W2807822918","https://openalex.org/W2921723332","https://openalex.org/W4391093354","https://openalex.org/W2482950156","https://openalex.org/W4396966040","https://openalex.org/W2305322260","https://openalex.org/W3139248031","https://openalex.org/W3042334625"],"abstract_inverted_index":{"Training":[0],"is":[1,150],"important":[2],"to":[3,39,75,100,118,152],"support":[4],"users":[5],"in":[6,32,104],"phishing":[7,12,47,59,79,102,123,133,161],"detection.":[8],"To":[9],"better":[10],"match":[11],"training":[13,20,28,53,56,146],"content":[14],"with":[15,29],"users'":[16],"current":[17],"skills,":[18],"personalised":[19,27,132,160],"has":[21],"huge":[22],"potential.":[23],"Therefore,":[24],"we":[25],"evaluated":[26],"N=96":[30],"participants":[31],"an":[33,76],"online":[34],"study.":[35],"Participants":[36],"were":[37],"assigned":[38],"one":[40],"of":[41,71,122,130,159],"three":[42],"groups":[43,142],"based":[44],"on":[45],"a":[46,105,131],"proficiency":[48,80,103],"score":[49],"and":[50,157],"received":[51],"tailored":[52,145],"material.":[54],"The":[55,125],"enhanced":[57],"overall":[58],"proficiency,":[60,74],"but":[61],"also":[62],"levelled":[63],"the":[64,85,113,128,155],"playing":[65],"field,":[66],"bringing":[67],"all":[68],"groups,":[69],"regardless":[70],"their":[72],"initial":[73],"equivalent":[77],"post-training":[78],"level.":[81],"For":[82],"group":[83],"assignment,":[84],"findings":[86],"show":[87],"that":[88,143],"most":[89],"person-related":[90],"information,":[91],"like":[92,112],"age":[93],"or":[94,115],"personality":[95],"traits,":[96],"do":[97],"not":[98],"seem":[99,117],"affect":[101],"meaningful":[106],"way.":[107],"Yet,":[108],"security":[109],"awareness":[110],"scales":[111],"HAIS-Q":[114],"SA-13":[116],"be":[119],"useful":[120],"indicators":[121],"proficiency.":[124],"results":[126],"demonstrate":[127],"feasibility":[129],"intervention":[134],"using":[135],"relatively":[136],"sparse":[137],"data":[138],"for":[139],"categorisation":[140],"into":[141],"receive":[144],"content.":[147],"Further":[148],"research":[149],"needed":[151],"systematically":[153],"evaluate":[154],"benefits":[156],"challenges":[158],"training.":[162]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":7}],"updated_date":"2026-04-28T14:05:53.105641","created_date":"2025-10-10T00:00:00"}
