Human error remains a primary vector for cyber attacks, making ethical phishing simulations a critical defense strategy. Designing such simulations requires balancing ease of use with meaningful control over generative AI. We introduce Damocles, a platform for ethical phishing campaigns, and report a within-subjects study (N = 30) comparing two interaction modalities built on the same scaffolded prompt-configuration workflow. In the Black-Box condition, users configured scenarios through high-level controls while the LLM prompt remained hidden. In the Glass-Box condition, the same choices generated a prompt that was visible, updated in real time, and editable before generation. Results show that the Glass-Box approach achieved comparable email quality and safety to the Black-Box condition, while maintaining comparable usability ((Formula presented.)) and workload (NASA-TLX). Behavioural analysis revealed a non-significant trend toward lower AI Retention Rate in the Glass-Box condition (p =.085, r =.52), interpreted cautiously as a preliminary signal of possible differences in textual reliance on AI-generated drafts. These findings position scaffolded prompt visibility and editability as EUD-inspired mechanisms for supporting end-user control without degrading output quality or increasing perceived workload.

Opening the black box: how EUD interfaces foster user agency and quality in generative phishing simulations

Spano, Lucio Davide;Cau, Federico Maria;Mocci, Matteo;
2026-01-01

Abstract

Human error remains a primary vector for cyber attacks, making ethical phishing simulations a critical defense strategy. Designing such simulations requires balancing ease of use with meaningful control over generative AI. We introduce Damocles, a platform for ethical phishing campaigns, and report a within-subjects study (N = 30) comparing two interaction modalities built on the same scaffolded prompt-configuration workflow. In the Black-Box condition, users configured scenarios through high-level controls while the LLM prompt remained hidden. In the Glass-Box condition, the same choices generated a prompt that was visible, updated in real time, and editable before generation. Results show that the Glass-Box approach achieved comparable email quality and safety to the Black-Box condition, while maintaining comparable usability ((Formula presented.)) and workload (NASA-TLX). Behavioural analysis revealed a non-significant trend toward lower AI Retention Rate in the Glass-Box condition (p =.085, r =.52), interpreted cautiously as a preliminary signal of possible differences in textual reliance on AI-generated drafts. These findings position scaffolded prompt visibility and editability as EUD-inspired mechanisms for supporting end-user control without degrading output quality or increasing perceived workload.
2026
automation bias; End-user development; generative AI; human-centered AI; phishing simulation; prompt engineering
File in questo prodotto:
File Dimensione Formato  
Opening the black box how EUD interfaces foster user agency and quality in generative phishing simulations-2.pdf

accesso aperto

Tipologia: versione editoriale (VoR)
Dimensione 1.94 MB
Formato Adobe PDF
1.94 MB Adobe PDF Visualizza/Apri

I metadati presenti in IRIS UNICA sono rilasciati con licenza Creative Commons CC0 1.0 Universal, mentre i file delle pubblicazioni sono protetti da diritto d'autore, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11584/493985
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
  • OpenAlex 0
social impact