PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
June 26, 2026International Journal of Human-Computer Interaction0 citations

Beyond Structural Equation Modeling: A Complementary ML-XAI Approach to Predicting and Interpreting Phishing Security Behavior

View Full Paper
AGAnderson Kevin GwenhureMBMohan Bhandari

Key Points

  • This research aims to enhance predictions of phishing security behavior using machine learning techniques in a university student population.
  • Evaluated seven supervised classification algorithms using a cross-validation pipeline.
  • Sample included 535 university students to assess their phishing-related email security behavior.
  • Employing explainability techniques like SHAP and LIME to analyze prediction results.
  • Random Forest classifier achieved an accuracy of 85.05% and ROC-AUC of 0.920.
  • Perceived importance identified as the primary behavioral driver for phishing security behavior.
  • Cluster analysis revealed four distinct behavioral profiles requiring tailored intervention strategies.

Abstract

Phishing remains one of the most prevalent cybersecurity threats, yet behavioral research has relied predominantly on Structural Equation Modeling, a method optimized for population-level explanation but limited for individual-level prediction. This study applies a complementary Machine Learning and Explainable AI framework to predict phishing-related email security behavior among 535 university students. Seven supervised classification algorithms were evaluated within a cross-validation pipeline; Random Forest achieved the strongest performance (accuracy = 0.8505; ROC-AUC = 0.920). Explainability techniques including SHAP, LIME, DiCE counterfactual analysis, and SHAP-value clustering revealed that insecure behavior primarily reflects a failure of behavioral activation rather than awareness deficit. Perceived importance emerged as the dominant behavioral driver, while cluster analysis identified four statistically validated behavioral profiles with distinct intervention requirements. These findings challenge information-deficit assumptions underlying conventional awareness programs and demonstrate how predictive modeling can enable personalized, activation-oriented phishing mitigation strategies.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Gwenhure et al. (2026) studied this question.

synapsesocial.com/papers/6a3e1a93030ad1a9b3092ffdhttps://doi.org/10.1080/10447318.2026.2688498
Ask AI
Helpful
Bookmark
Share
View Full Paper