paper-with-me

홈 › Papers

On the Feasibility of Fully AI-automated Vishing Attacks

2024-09-20 · João Figueiredo, Afonso Carvalho, Daniel Castro, Daniel Gonçalves, Nuno Santos

A vishing attack is a form of social engineering where attackers use phone calls to deceive individuals into disclosing sensitive information, such as personal data, financial information, or security credentials. Attackers exploit the perceived urgency and authenticity of voice communication to manipulate victims, often posing as legitimate entities like banks or tech support. Vishing is a particularly serious threat as it bypasses security controls designed to protect information. In this work, we study the potential for vishing attacks to escalate with the advent of AI. In theory, AI-powered software bots may have the ability to automate these attacks by initiating conversations with potential victims via phone calls and deceiving them into disclosing sensitive information. To validate this thesis, we introduce ViKing, an AI-powered vishing system developed using publicly available AI technology. It relies on a Large Language Model (LLM) as its core cognitive processor to steer conversations with victims, complemented by a pipeline of speech-to-text and text-to-speech modules that facilitate audio-text conversion in phone calls. Through a controlled social experiment involving 240 participants, we discovered that ViKing has successfully persuaded many participants to reveal sensitive information, even those who had been explicitly warned about the risk of vishing campaigns. Interactions with ViKing's bots were generally considered realistic. From these findings, we conclude that tools like ViKing may already be accessible to potential malicious actors, while also serving as an invaluable resource for cyber awareness programs.

📄 PDF Abstract BibTeX arXiv:2409.13793

Code (0)

등록된 구현이 없습니다.

Tasks

Large Language ModelSpeech-to-Texttext-to-speechText to Speech

Similar Papers 제목 키워드 기반

Detecting Phishing Sites -- An Overview

2021-03-23 · P. Kalaharsha, B. M. Mehtre

Phishing is one of the most severe cyber-attacks where researchers are interested to find a solution. In phishing, attackers lure end-users and steal their personal in-formation. To minimize the damage caused by phishing…

Automating Privilege Escalation with Deep Reinforcement Learning

2021-10-04 · Kalle Kujanpää, Willie Victor, Alexander Ilin

AI-based defensive solutions are necessary to defend networks and information assets against intelligent automated attacks. Gathering enough realistic data for training machine learning-based defenses is a significant pr…

BIG-bench Machine LearningDeep Reinforcement LearningIntrusion DetectionRed Teaming+3

Adversarial Patch Attacks on Vision-Based Cargo Occupancy Estimation via Differentiable 3D Simulation

2025-11-24 · Mohamed Rissal Hedna, Sesugh Samuel Nder arxiv

Computer vision systems are increasingly adopted in modern logistics operations, including the estimation of trailer occupancy for planning, routing, and billing. Although effective, such systems may be vulnerable to phy…

Adversarial Attacks on Machine Learning Systems for High-Frequency Trading

2020-02-21 · Micah Goldblum, Avi Schwarzschild, Ankit B. Patel, Tom Goldstein

Algorithmic trading systems are often completely automated, and deep learning is increasingly receiving attention in this domain. Nonetheless, little is known about the robustness properties of these models. We study val…

Algorithmic TradingBIG-bench Machine LearningVocal Bursts Intensity Prediction

On the feasibility of attacking Thai LPR systems with adversarial examples

2023-01-13 · Chissanupong Jiamsuchon, Jakapan Suaboot, Norrathep Rattanavipanon

Recent advances in deep neural networks (DNNs) have significantly enhanced the capabilities of optical character recognition (OCR) technology, enabling its adoption to a wide range of real-world applications. Despite thi…

Adversarial AttackLicense Plate RecognitionOptical Character RecognitionOptical Character Recognition (OCR)