| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Spear phishing in veliki jezikovni modeli : vpliv na varnostno ozaveščenost uporabnikov
Authors:ID Zaluberšek, Matic (Author)
ID Mihelič, Anže (Mentor) More about this mentor... New window
Files:.pdf VS_Zalubersek_Matic_2026.pdf (668,16 KB)
MD5: 13EC2F9CEBA4C9C7C95C7EBA077B1C5D
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FVV - Faculty of Criminal Justice and Security
Abstract:V diplomski nalogi je bil izveden sistematični pregled literature o spear phishingu, velikih jezikovnih modelih (large language model, LLM) in varnostni ozaveščenosti uporabnikov. Namen je bil pokazati, kako LLM vplivajo na nastanek in prepričljivost ciljanih prevar ter katere obrambe in vrste izobraževanja najbolje delujejo. Gradivo je bilo iskano v bazah Scopus, Web of Science in IEEE Xplore; vključene so bile recenzirane objave iz let 2010–2025 (s poudarkom 2023–2025). Ugotovili smo, da LLM znižajo strošek in čas priprave napadov ter izboljšajo jezik in ton sporočil, zato so le-ta težje prepoznavna, tudi v SMS. Pokazano je bilo, da uporabniki pogosto precenijo svojo sposobnost prepoznavanja, kar poveča tveganje. Najboljše rezultate prinašajo kratki, redni in po vlogah prilagojeni programi ozaveščanja, povezani s konkretnimi koraki (npr. preverjanje po drugem kanalu) in krepitvijo samoučinkovitosti, samo opozarjanje na grožnjo ni zadostovalo. Kot učinkovita se je pokazala večslojna obramba: avtentikacija e-pošte (SPF, DKIM, DMARC), večfaktorska prijava, hibridna detekcija ter jasen in kratek načrt odziva.
Keywords:informacijska varnost, varnostna ozaveščenost, spear phishing, veliki jezikovni modeli, socialni inženiring, diplomske naloge
Publication status:Published
Publication version:Version of Record
Place of publishing:Ljubljana
Place of performance:Ljubljana
Publisher:M. Zaluberšek
Year of publishing:2026
Year of performance:2026
Number of pages:VI f., 30 str.
PID:20.500.12556/DKUM-97816 New window
UDC:004.056(043.2)
COBISS.SI-ID:283860739 New window
Publication date in DKUM:07.07.2026
Views:212
Downloads:9
Metadata:XML DC-XML DC-RDF
Categories:FVV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:16.04.2026

Secondary language

Language:English
Title:Spear phishing and large language models: Impact on user security awareness : diplomsko delo visokošolskega študijskega programa Informacijska varnost
Abstract:A systematic literature review on spear phishing, large language models (LLMs), and user security awareness was conducted. The aim was to show how LLMs affect the creation and persuasiveness of targeted scams and which defenses and training approaches work best. Material was searched in Scopus, Web of Science, and IEEE Xplore; peer-reviewed publications from 2010–2025 were included, with emphasis on 2023–2025. It was found that LLMs lower the cost and time of preparing attacks and improve language and tone, making messages harder to detect, including over SMS. Users were found to often overestimate their detection ability, which increases risk. The best results were achieved by short, regular, role-specific awareness programs paired with concrete steps (e.g., out-of-band verification) and strengthened self-efficacy; mere warnings about threats were not sufficient. Effective protection was shown to be multilayered: email authentication (SPF, DKIM, DMARC), multi-factor authentication, hybrid detection, and a clear, concise incident response plan.
Keywords:spear phishing, phishing, bulk phishing, clone phishing, vishing, smishing, social engineering, targeted attacks, cybersecurity, information security, security awareness, user awareness, human factor, user vulnerability, optimism bias, self-efficacy, perceived vulnerability, psychological factors, user education, security training, SETA, fear appeal, Protection Motivation Theory, phishing simulations, incident reporting, email, fraudulent emails, credential theft, malicious links, scam detection, phishing detection, hybrid detection, machine learning, LLM, large language models, artificial intelligence, generative artificial intelligence, ChatGPT, Claude, Gemini, prompt injection, data leakage, privacy, attack automation, LLM agents, SpearBot, attack personalization, SPF, DKIM, DMARC, MFA, systematic literature review.


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica