AI-Generated Phishing Susceptibility in Higher Education: The Mediating Role of Attitude and Moderating Effect of Vigilance in the KAB Framework
Main Article Content
Abstract
This study examines university students’ responses to AI-generated phishing emails of varying sophistication and the moderating role of vigilant attitudes. Grounded in the Knowledge–Attitude–Behavior (KAB) framework and the NIST Phish Scale, a counterbalanced, scenario-based survey involved 500 Vietnamese students (548 recruited, 48 excluded) who evaluated low-, medium-, and high-difficulty phishing simulations created via GPT-4 with expert-refined prompts (Cohen’s κ = 0.87). Manipulation checks confirmed difficulty perceptions (M = 2.14, 3.42, 4.21; F = 1,247.6, p < .001). Repeated-measures ANOVA showed a significant difficulty effect (F (1.87, 933.4) = 359.16, p < .001, η2G = .231), moderated by vigilant attitudes in linear mixed-effects modeling (γ11 = −0.55, p < .001; marginal R2 = .421, conditional R2 =.638), with simple slope analyses revealing a 72% reduction in the difficulty effect for high-vigilance students. Multilevel mediation affirmed KAB pathways, with knowledge influencing attitude (a = 0.52, p < .001) and intention (b = −0.63, p < .001), yielding full mediation (ab = −0.33, 95% CI [−0.42, −0.24]; c′ = −0.07, p = .189). A CFA conducted for exploratory purposes on attitude sub-dimensions (CFI = .987, RMSEA = .040) identified procedural verification as a superior moderator over skepticism, advocating process-oriented cybersecurity training.


