Bayesian Modeling of Uncertainty in Anti-Phishing Training: A Serious Game for Adversarial Email Crafting

Authors

  • Dimitrios Lappas University of the Aegean
  • Diogo Alexandre Silva
  • Aristeidis Angelos Zoumpakis
  • Panagiotis Karampelas

DOI:

https://doi.org/10.34190/eccws.25.1.4816

Keywords:

Explainability, Serious game, Bayesian inference, Phishing

Abstract

This paper presents a Bayesian-driven serious game designed to support human-centered anti-phishing training through explainable artificial intelligence and adversarial gameplay. As phishing attacks increasingly leverage personalization and AI-assisted social engineering, traditional training approaches and opaque detection systems offer limited support for developing strategic awareness and decision-making under uncertainty. The proposed framework addresses this gap by combining Bayesian explainability with an interactive, adversarial learning environment. The serious game was implemented in a military academy context and centers on a sandboxed anti-phishing platform powered by a Bayesian Network. Participants are tasked with crafting targeted phishing emails for simulated victims using social media-derived contextual information. Each email submission is analyzed by the Bayesian engine, which outputs both a probabilistic phishing likelihood score and an explanation highlighting the linguistic features that contributed most strongly to the classification. Learners then iteratively revise the same email to reduce detectability, effectively attempting to “fool” the system while preserving semantic intent. Evaluation was conducted using two complementary data sources: interaction logs from the game and a post-activity questionnaire. Τhe results suggest that integrating explainable Bayesian models into adversarial serious games can effectively enhance phishing awareness, strategic thinking, and sensitivity to uncertainty. The study highlights the potential of explainable AI not only as a defensive mechanism, but also as a powerful educational tool in cybersecurity training.

Downloads

Published

2026-06-15