Pith. sign in

REVIEW 3 major objections 6 minor 101 references

AI voice phishing already draws 16.5% compliance in a national sample, and automation makes several models profitable while human callers at U.S. wages are not.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-14 14:13 UTC pith:EL4AKZ6V

load-bearing objection Solid multi-model population experiment on AI vishing; the automation-economics claim is the real payload and survives large discounts on the intention proxy. the 3 major comments →

arxiv 2607.09970 v1 pith:EL4AKZ6V submitted 2026-07-10 cs.CR cs.CY

Evaluating AI Models' Capability to Automate Voice Phishing Attacks

classification cs.CR cs.CY
keywords vishingAI voice synthesissocial engineeringvoice phishinglarge language modelscompliance ratesautomation economicsmodel release policy
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

Voice phishing used to be limited by the cost of a live caller on every line. This paper asks whether today's AI voice systems and large language models have removed that bottleneck enough to make automated vishing scalable and economically attractive. In a nationally weighted survey of 4,100 U.S. adults, participants heard or read scam conversations produced by six commercial and open voice models plus human baselines across five common scam types. Self-reported willingness to comply averaged 16.5% overall and reached 36.1% for a cloned relative-in-distress scenario. Caller persuasiveness, not human-likeness, was the strongest predictor of compliance, and the best model (Sesame) matched human ratings on key perceptual scales. An economic model calibrated to these rates finds human-operated vishing unprofitable at U.S. wages while Gemini, Sesame, and ElevenLabs show positive expected hourly profit. The paper's central message is therefore that the present danger is cheap scale, not superhuman persuasion, and that model design, consumer protection, and release policy need to respond now.

Core claim

In a large, weighted U.S. sample, AI-generated voice phishing already elicits substantial self-reported compliance (16.5% overall, up to 36.1% in emotionally personalized relative-in-distress scenarios), certain voice models match human perceptual ratings, and an economic calibration shows that automation can turn those rates into positive expected profit for several models while human callers at U.S. wages remain unprofitable. The primary present-day risk is therefore the economics of automation rather than novel persuasive power.

What carries the argument

A between-subjects survey experiment (N=4,100) that randomly assigns participants to audio or transcript versions of five scam scenarios generated by six AI voice systems plus human and neutral controls, measures self-reported compliance (yes/unsure) and perceptual scales (sentiment, persuasiveness, trustworthiness, human-likeness), then feeds model-level persuasion rates into a simple expected-profit formula comparing inference cost against human wage.

Load-bearing premise

Self-reported willingness to comply after hearing a one-shot recording is treated as a usable stand-in for real-world scam success and is plugged directly into the profit calculation as the persuasion probability.

What would settle it

A live, interactive field trial (or tightly controlled interactive lab study) that measures actual financial disclosure or transfer rates under AI-automated vishing, then re-runs the same profit model with observed conversion instead of self-reported intention; if live success falls far below the 16.5%/36% figures or remains unprofitable after safety and telephony friction, the central economic claim fails.

Watch this falsifier — get emailed when new claim-graph text bears on it.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. The paper reports a nationally weighted between-subjects survey experiment (N=4100, 37 conditions) plus 12 qualitative interviews evaluating U.S. adults’ susceptibility to AI-generated voice phishing. Participants rated audio or transcripts from six commercial/open voice systems (Llama FD, Sesame, Gemini, OpenAI AVM, Play.AI, ElevenLabs) and human baselines across five scam scenarios, with neutral and text controls. Self-reported compliance (Yes or Unsure) averaged 16.5% overall and reached 36.1% in a cloned relative-in-distress condition; logistic regression identifies caller persuasiveness as the strongest predictor, while human-likeness does not independently predict compliance. Sesame is statistically comparable to human voices on several perceptual dimensions. An economic model calibrated with experimental persuasion rates, marketing conversion floors, and posted inference costs concludes that human vishing is unprofitable at U.S. wages while Gemini, Sesame, and ElevenLabs yield positive expected hourly profit, so present risk is framed as automation economics rather than superhuman persuasion.

Significance. If the susceptibility estimates and model comparisons hold, this is the first population-level controlled evaluation of multi-vendor AI voice phishing and supplies actionable evidence for consumer protection, platform governance, and model-release policy. Strengths include CPS-matched weighting, Welch ANOVA/Dunnett and logistic regression with effect sizes and VIFs, a psychometrically checked trustworthiness scale (α≈0.93), an ablation of voice vs content vs modality vs relational closeness, qualitative triangulation, and a public repository of instruments and analysis code. The finding that persuasiveness, not human-likeness, drives compliance is policy-relevant and non-obvious. The economic framing is novel for this literature even if calibrated, and the paper is explicit that intention may overstate live behavior.

major comments (3)
  1. [Section 5, Table 5; also §§3.2–3.3, 4.3, 6.2] Sections 3.3, 4.3, and 5 (and Table 5): the headline compliance rates (16.5% overall; 36.1% relative-in-distress) and the profit formula r_j = m p_j q − c_j t treat Yes+Unsure after a one-shot edited recording as persuasion probability p_j. Section 6.2 already notes intention may overstate live compliance, and recordings were cleaned of safety refusals and UX beeps (Section 3.2). Without a sensitivity analysis that discounts p_j (e.g., 25–75% of reported intention) and shows when Gemini/Sesame/ElevenLabs profits remain positive, the claim that AI vishing is already economically viable—and that primary risk is automation economics—is not yet load-bearing. Please add such robustness tables and qualify abstract/conclusion language accordingly.
  2. [Section 5; Tables 5 and D.14] Section 5 calibrations: q = 0.6% is taken as the lowest marketing conversion rate and m(X_i) = $450 from Hiya (2024), with ~12 attempts/hour from ~5-minute calls and a $16,120 pipeline sunk cost. These free parameters dominate the sign of profit (Table 5; also Table D.14 under targeting). The manuscript should either (i) justify fraud-specific ranges with external fraud literature or (ii) report a full parameter sweep (q, m, attempts/hour, wage/inference costs) and state the break-even surfaces. As written, positive profit for three models is an illustration under one calibration, not a robust economic result.
  3. [§§3.2, 4.3, 6.2; Abstract] Section 3.2 and 6.2 (sister-in-distress / ElevenLabs): the clone is not of a person known to the participant, and the accent (Irish) differs from other North American conditions. The paper correctly notes this is not a test of known-voice cloning, yet abstract and §4.3 still foreground “cloned relative-in-distress” as the peak 36.1% result. Please reframe that condition as a high-personalization emotional script with a high-quality clone of an unknown speaker, and avoid language that implies known-person voice cloning was measured.
minor comments (6)
  1. [Abstract; Section 1] Abstract and §1: “would or might comply” and “compliance rate” should consistently flag that the measure is self-reported intention (Yes/Unsure), as already stated in §1 and §3.3, so headline numbers are not read as observed behavioral success.
  2. [Table 1; Figure 5; §4.5] Table 1 and Figure 5: report sample sizes per cell and whether Dunnett comparisons pool across the three unknown-caller scenarios or are scenario-stratified; the text mixes both.
  3. [Section 4.7] Section 4.7 logistic model: Nagelkerke R²=.35 and 83.7% accuracy are useful; also report the base-rate accuracy (always-No) so the lift is interpretable.
  4. [Appendix B; Ethical Considerations] Appendix B: prompts are summarized rather than verbatim for dual-use reasons—state that explicitly in the main text (not only ethics) so readers know why full prompts are unavailable for exact replication.
  5. [Figure 1; Data availability] Figure 1 and demographics: the shorturl repository link is fragile for archival purposes; prefer a durable DOI or institutional archive in the camera-ready version.
  6. [Tables 4, D.9–D.13] Minor consistency: “Llama Full Duplex / Llama FD,” “OAI AVM / OpenAI AVM,” and scale ranges (trustworthiness 9–45 vs sometimes rescaled means in Table 4) should be standardized across tables.

Circularity Check

1 steps flagged

No derivation circularity; main results are direct experimental measurements. Only minor non-load-bearing self-citation for conversion-rate methodology in the secondary economic model.

specific steps
  1. self citation load bearing [Section 5 (Economics of AI-Enhanced Vishing), paragraph calibrating q]
    "To calibrate this quantity, we follow Heiding et al. (2026) and draw on “conversion rates” from the marketing literature as a direct measure of q in legitimate industries. Given that vishers are likely less credible than authentic businesses, we calibrate q = 0.6% (the lowest observed across real industries)."

    The calibration method for the conversion probability q that enters the profit formula is justified by citation to a prior paper with overlapping authors (Heiding et al. 2026). This is minor and non-load-bearing for the primary experimental claims (compliance, perceptual ratings, detection); it affects only the secondary economic viability numbers and the value itself is taken as an external marketing floor rather than derived from the present data. No uniqueness or forcing of the main results occurs.

full rationale

The paper's core claims (compliance rates of 16.5% overall / up to 36.1% for relative-in-distress, persuasiveness as strongest predictor via logistic regression, Sesame parity with human baselines via Dunnett/ANOVA, detection accuracies) are obtained by direct measurement in a between-subjects survey (N=4100) against external human-voice and text-transcript controls, plus 12 interviews. These quantities do not reduce to their inputs by construction, fit, or definition. The economic analysis in Section 5 is a simple expected-profit calculation r_j = m(X_i) p_j q - c_j t that plugs the experimentally measured p_j (self-reported Yes/Unsure) together with external prices/wages for c_j, m=$450 from Hiya (2024), and q=0.6% (lowest marketing conversion). This is arithmetic, not a forced prediction or self-definitional loop; the paper itself flags the intention-behavior gap and other limitations. The sole mild circularity-adjacent element is a self-citation (Heiding et al. 2026, overlapping authors) used only to justify the conversion-rate calibration approach for the secondary economic claim; it is not a uniqueness theorem, ansatz, or load-bearing premise for the susceptibility results. No fitted-input-as-prediction, renaming of known results, or self-definitional identities appear. Score 1 reflects only that minor methodological self-citation.

Axiom & Free-Parameter Ledger

5 free parameters · 5 axioms · 1 invented entities

Empirical social-science paper. Load-bearing content is measurement design plus a small set of economic calibrations, not new physical entities. Free parameters live almost entirely in Section 5’s profit model and a few design choices (attempt duration, development hours). Domain assumptions cover intention-as-susceptibility, edited-audio as attacker capability, and marketing conversion floors as fraud q. No new particles or forces; the only constructed instrument is the 9-item Caller Trustworthiness Scale, which is a measurement tool with reported factor structure, not an ontological invention.

free parameters (5)
  • conversion_rate_q = 0.006
    Probability that persuasion becomes payment; set to 0.6% as the lowest marketing-industry conversion rate (Section 5), not estimated from fraud data.
  • average_take_m = 450 USD
    Dollars extracted per successful phish; fixed at $450 for all targets from Hiya (2024) industry report (Section 5).
  • attempts_per_hour = ~12 / hour
    Assumes ~5-minute calls → ~12 attempts/hour to convert per-minute inference costs into hourly profit (Section 5 footnote).
  • pipeline_development_hours = 260 hours; ~$16120
    Sunk cost for an AI vishing system estimated at 260 hours × ~$62/hr ML engineer wage ≈ $16,120, used for break-even day counts (Section 5).
  • human_wage_and_model_inference_costs_c_j = human 2.88 $/attempt-scale; models 0.13–1.50 as tabulated
    Human cost calibrated to U.S. non-farm hourly wage $34.55; model c_j taken from posted prices (Table 5). Choices drive sign of profit.
axioms (5)
  • domain assumption Self-reported Yes/Unsure after a passive recording is a valid indicator of susceptibility usable as p_j in attacker profit.
    Stated in Sections 3.3 and 4.3; authors note it may overestimate behavior but still feed it into economics.
  • domain assumption Post-editing out safety refusals, disclaimers, and turn-taking beeps represents realistic malicious deployment of consumer voice models.
    Section 3.2 Conversation Design; without this, measured success would be lower.
  • ad hoc to paper Marketing conversion rates are a conservative lower bound for fraud conversion q.
    Section 5 calibration following Heiding et al. (2026); not independently validated on vishing payouts.
  • standard math Standard survey sampling/weighting and Likert psychometrics (Welch ANOVA, logistic OR, Cronbach α) correctly recover population effects.
    Sections 3.1 and 3.4; conventional social-science toolkit.
  • domain assumption YouGov opt-in panel after propensity matching and post-stratification is representative of U.S. internet-using adults for this outcome.
    Section 3.1; design effect 1.21, effective N≈3388.
invented entities (1)
  • 9-item Caller Trustworthiness Scale no independent evidence
    purpose: Composite predictor of compliance when no validated caller-trust instrument existed.
    Newly developed in Section 3.3; EFA single factor, α=.927. Measurement construct, not a physical entity; independent_evidence false outside this study’s internal consistency.

pith-pipeline@v1.1.0-grok45 · 37858 in / 3999 out tokens · 43546 ms · 2026-07-14T14:13:54.878120+00:00 · methodology

0 comments
read the original abstract

Voice phishing (vishing) attacks have traditionally been limited by the need for human operators. The rapid emergence of high-quality AI voice synthesis and large language models (LLMs) reduces this bottleneck and enables scalable, automated scams. In this paper, we conduct a large-scale survey experiment (N=4100) and qualitative interviews (N=12) to assess U.S. adults' susceptibility to AI-powered voice phishing attacks. Participants were exposed to audio recordings or transcripts of scam scenarios generated using leading voice models such as Llama Full Duplex (Llama FD), Sesame, Gemini, OAI AVM, Play$.$AI, and ElevenLabs and the corresponding human baselines. The results show high compliance rates. Up to 36% of participants would or might comply with phishing requests in the "relative-in-distress" category. Overall compliance rate across all five scam categories was 16.5%, a striking figure given the low cost and high scalability of AI-automated voice phishing. Caller persuasiveness was the strongest predictor of compliance and certain models (most notably Sesame) achieved ratings comparable to human voices, or sometimes even slightly surpassing them. Our economic analysis suggests that while human-operated vishing is unprofitable at US wages, AI-powered vishing appears to be economically viable for several models. The primary risk of present-day AI-enabled vishing thus lies in the economics of automation rather than novel or "superhuman" persuasive techniques, though these cannot be ruled out for future systems. This raises significant concerns for the design of AI systems, consumer protection, and model release policies.

Figures

Figures reproduced from arXiv: 2607.09970 by Andrew Kao, Christine Lehane, Claudio Mayrink Verdun, Fred Heiding, Irina-Elena Veliche, Lauren Deason, Simon Lermen, Vitor Albiero.

Figure 1
Figure 1. Figure 1: Sample demographics. Unweighted sample (blue, hatched), weighted sample (teal), and US population [PITH_FULL_IMAGE:figures/full_fig_p005_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: Impact of Scam Context on AI Model Percep [PITH_FULL_IMAGE:figures/full_fig_p011_2.png] view at source ↗
Figure 4
Figure 4. Figure 4: AI voice performance relative to human baseline [PITH_FULL_IMAGE:figures/full_fig_p013_4.png] view at source ↗
Figure 6
Figure 6. Figure 6: AI misclassification rate relative to human correct [PITH_FULL_IMAGE:figures/full_fig_p015_6.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

101 extracted references · 2 canonical work pages

  1. [1]

    Frontiers in Computer Science , volume=

    Phishing attacks: A recent comprehensive study and a new anatomy , author=. Frontiers in Computer Science , volume=. 2021 , publisher=

  2. [2]

    2024 Conference on Empirical Methods in Natural Language Processing, EMNLP 2024 , pages=

    Defending Against Social Engineering Attacks in the Age of LLMs , author=. 2024 Conference on Empirical Methods in Natural Language Processing, EMNLP 2024 , pages=. 2024 , organization=

  3. [3]

    2024 , eprint=

    Badllama 3: removing safety finetuning from Llama 3 in minutes , author=. 2024 , eprint=

  4. [4]

    2003 , publisher=

    The art of deception: Controlling the human element of security , author=. 2003 , publisher=

  5. [5]

    Proceedings of the SIGCHI conference on human factors in computing systems , pages=

    Who falls for phish? A demographic analysis of phishing susceptibility and effectiveness of interventions , author=. Proceedings of the SIGCHI conference on human factors in computing systems , pages=

  6. [6]

    Computers & Security , volume=

    Which factors predict susceptibility to phishing? An empirical study , author=. Computers & Security , volume=. 2024 , publisher=

  7. [7]

    Computers in Human Behavior , pages=

    Uncovering Vulnerability to Fraud and Scams among Adult Victims in Online and Offline Contexts: A Systematic Review , author=. Computers in Human Behavior , pages=. 2025 , publisher=

  8. [8]

    Computer Speech & Language , volume=

    Vishing: Detecting social engineering in spoken communication—A first survey & urgent roadmap to address an emerging societal challenge , author=. Computer Speech & Language , volume=. 2025 , publisher=

  9. [9]

    Engineering Proceedings , VOLUME =

    Toapanta, Fabricio and Rivadeneira, Belén and Tipantuña, Christian and Guamán, Danny , TITLE =. Engineering Proceedings , VOLUME =. 2024 , NUMBER =

  10. [10]

    Scientific Reports , volume=

    The potential of generative AI for personalized persuasion at scale , author=. Scientific Reports , volume=. 2024 , publisher=

  11. [11]

    2020 , isbn =

    Dubiel, Mateusz and Halvey, Martin and Gallegos, Pilar Oplustil and King, Simon , title =. 2020 , isbn =. doi:10.1145/3405755.3406120 , booktitle =

  12. [12]

    LLMs unlock new paths to monetizing exploits , note =

    Carlini, Nicholas and Nasr, Milad and Debenedetti, Edoardo and Wang, Barry and Choquette-Choo, Christopher and Ippolito, Daphne and Tramèr, Florian and Jagielski, Matthew , year =. LLMs unlock new paths to monetizing exploits , note =

  13. [13]

    Computers & Security , volume=

    The silence of the phishers: Early-stage voice phishing detection with runtime permission requests , author=. Computers & Security , volume=. 2025 , publisher=

  14. [14]

    Artificial Intelligence Review , volume=

    Digital deception: Generative artificial intelligence in social engineering and phishing , author=. Artificial Intelligence Review , volume=. 2024 , publisher=

  15. [15]

    Datenbank-Spektrum , volume=

    How to win arguments: Empowering virtual agents to improve their persuasiveness , author=. Datenbank-Spektrum , volume=. 2020 , publisher=

  16. [16]

    Proceedings of the 6th ACM Conference on Conversational User Interfaces , pages=

    The impact of perceived tone, age, and gender on voice assistant persuasiveness in the context of product recommendations , author=. Proceedings of the 6th ACM Conference on Conversational User Interfaces , pages=

  17. [17]

    arXiv preprint arXiv:2507.16291 , year=

    Talking Like a Phisher: LLM-based attacks on voice phishing classifiers , author=. arXiv preprint arXiv:2507.16291 , year=

  18. [18]

    , author=

    Social psychological aspects of computer-mediated communication. , author=. American psychologist , volume=. 1984 , publisher=

  19. [19]

    PloS one , volume=

    How do you say ‘Hello’? Personality impressions from brief novel voices , author=. PloS one , volume=. 2014 , publisher=

  20. [20]

    PloS one , volume=

    The sound of trustworthiness: Acoustic-based modulation of perceived voice personality , author=. PloS one , volume=. 2017 , publisher=

  21. [21]

    Warren, Kevin and Tucker, Tyler and Crowder, Anna and Olszewski, Daniel and Lu, Allison and Fedele, Caroline and Pasternak, Magdalena and Layton, Seth and Butler, Kevin and Gates, Carrie and others , booktitle=

  22. [22]

    IEEE Access , volume=

    Devising and detecting phishing emails using large language models , author=. IEEE Access , volume=. 2024 , publisher=

  23. [23]

    2007 , publisher=

    Using multivariate statistics , author=. 2007 , publisher=

  24. [24]

    Sounds Vishy: Automating Vishing Attacks with AI-Powered Systems , year =

    Figueiredo, Jo\. Sounds Vishy: Automating Vishing Attacks with AI-Powered Systems , year =. doi:10.1145/3708821.3733866 , booktitle =

  25. [25]

    arXiv preprint arXiv:2409.13793 , year=

    On the feasibility of fully ai-automated vishing attacks , author=. arXiv preprint arXiv:2409.13793 , year=

  26. [26]

    2020 , url =

    Vincenzo Ciancaglini and Craig Gibson and David Sancho and Odhrán McCarthy and Maria Eira and Philipp Amann and Aglika Klayn , title =. 2020 , url =

  27. [27]

    2024 , url =

    The Voice. 2024 , url =

  28. [28]

    2025 , url =

    Panel Methodology: Sample Matching and Weighting , howpublished =. 2025 , url =

  29. [29]

    2024 , url =

    Voice Cloning Overview , howpublished =. 2024 , url =

  30. [30]

    Marketing Letters , volume=

    Suckers in the morning, skeptics in the evening: Time-of-Day effects on consumers’ vigilance against manipulation , author=. Marketing Letters , volume=. 2014 , publisher=

  31. [31]

    Contributions to Probability and Statistics: Essays in Honor of Harold Hotelling , editor =

    Levene, Howard , title =. Contributions to Probability and Statistics: Essays in Honor of Harold Hotelling , editor =. 1960 , pages =

  32. [32]

    Mathematical Methods of Statistics , publisher =

    Cram\'. Mathematical Methods of Statistics , publisher =

  33. [33]

    2022 , publisher=

    The weakest link: How to diagnose, detect, and defend users from phishing , author=. 2022 , publisher=

  34. [34]

    ACM Transactions on Computer-Human Interaction , volume=

    The Partner Modelling Questionnaire: A validated self-report measure of perceptions toward machines as dialogue partners , author=. ACM Transactions on Computer-Human Interaction , volume=. 2025 , publisher=

  35. [35]

    2024 , url =

    Ifigeneia Lella and Marianthi Theocharidou and Erika Magonara and Apostolos Malatras and Rossen Svetozarov Naydenov and Cosmin Ciobanu and Georgios Chatzichristos , title =. 2024 , url =. doi:10.2824/0710888ENISA , note =

  36. [36]

    arXiv preprint arXiv:2502.05674 , year=

    ShiftySpeech: A Large-Scale Synthetic Speech Dataset with Distribution Shifts , author=. arXiv preprint arXiv:2502.05674 , year=

  37. [37]

    Journal of Language and Social Psychology , volume=

    Truth-default theory (TDT) a theory of human deception and deception detection , author=. Journal of Language and Social Psychology , volume=. 2014 , publisher=

  38. [38]

    2022 IEEE International Workshop on Information Forensics and Security (WIFS) , pages=

    Open challenges in synthetic speech detection , author=. 2022 IEEE International Workshop on Information Forensics and Security (WIFS) , pages=. 2022 , organization=

  39. [39]

    Sensors , VOLUME =

    Zhang, Bowen and Cui, Hui and Nguyen, Van and Whitty, Monica , TITLE =. Sensors , VOLUME =. 2025 , NUMBER =

  40. [40]

    Plos one , volume=

    Warning: Humans cannot reliably detect speech deepfakes , author=. Plos one , volume=. 2023 , publisher=

  41. [41]

    , title =

    Dunnett, Charles W. , title =. Journal of the American Statistical Association , volume =

  42. [42]

    Welch, B. L. , title =. Biometrika , volume =

  43. [43]

    , title =

    Nunnally, Jum C. , title =

  44. [44]

    Nagelkerke, Nico J. D. , title =. Biometrika , volume =

  45. [45]

    Evaluating large language models’ ability to automate spear phishing , journal =

    Fred Heiding and Simon Lermen and Andrew Kao and Claudio. Evaluating large language models’ ability to automate spear phishing , journal =. 2026 , issn =. doi:https://doi.org/10.1016/j.eswa.2026.131546 , url =

  46. [46]

    The Guardian , year =

    Nick Robins-Early , title =. The Guardian , year =

  47. [47]

    2023 IEEE Symposium on Security and Privacy (SP) , pages=

    Breaking security-critical voice authentication , author=. 2023 IEEE Symposium on Security and Privacy (SP) , pages=. 2023 , organization=

  48. [48]

    28th USENIX Security Symposium (USENIX Security 19) , pages=

    Users really do answer telephone scams , author=. 28th USENIX Security Symposium (USENIX Security 19) , pages=

  49. [49]

    Government Accountability Office , title =

    U.S. Government Accountability Office , title =. 2024 , month = jul, address =

  50. [50]

    Psychology, Crime & Law , pages=

    Reporting fraud victimization to the police: factors that affect whether victims report , author=. Psychology, Crime & Law , pages=. 2025 , publisher=

  51. [51]

    Spam & Scam Report 2024 , author =

    The True Cost of Spam and Scam Calls in America: U.S. Spam & Scam Report 2024 , author =. 2024 , month = mar, note =

  52. [52]

    2024 , month = may, note =

    State of the Call 2024: Global Phone Spam and Fraud Trends , author =. 2024 , month = may, note =

  53. [53]

    The Guardian , year =

    Dan Milmo , title =. The Guardian , year =

  54. [54]

    2024 , date =

    Justin Brookman , title =. 2024 , date =

  55. [55]

    The Voice Clone Crisis: How AI Scammers Can Steal Your Voice in 15 Seconds , year =

  56. [56]

    Cohen, Jacob , title =

  57. [57]

    , title =

    Cronbach, Lee J. , title =. Psychometrika , year =

  58. [58]

    Archives of Psychology , year =

    Likert, Rensis , title =. Archives of Psychology , year =

  59. [59]

    Biometrika , volume=

    The central role of the propensity score in observational studies for causal effects , author=. Biometrika , volume=. 1983 , publisher=

  60. [60]

    , title =

    Lohr, Sharon L. , title =

  61. [61]

    , title =

    Cochran, William G. , title =

  62. [62]

    2024 , publisher=

    Designing experiments and analyzing data: A model comparison perspective , author=. 2024 , publisher=

  63. [63]

    1996 , publisher=

    Multiple comparisons: theory and methods , author=. 1996 , publisher=

  64. [64]

    2025 , date =

    Ozan Ucar , title =. 2025 , date =

  65. [65]

    Allen , title =

    Jeffrey M. Allen , title =. 2025 , date =

  66. [66]

    2024 , month =

    The Near-Term Impact of. 2024 , month =

  67. [67]

    2024 , url =

    Facing Reality?. 2024 , url =

  68. [68]

    2025 , date =

    Avery Lotz , title =. 2025 , date =

  69. [69]

    interview study of how and why mobile phone users judge text messages to be real or fake , author=

    What drives \ SMiShing \ susceptibility? a \ US \ . interview study of how and why mobile phone users judge text messages to be real or fake , author=. Twentieth Symposium on Usable Privacy and Security (SOUPS 2024) , pages=

  70. [70]

    Scientific Reports , volume=

    People are poorly equipped to detect AI-powered voice clones , author=. Scientific Reports , volume=. 2025 , publisher=

  71. [71]

    Proceedings of the SIGCHI conference on Human Factors in computing systems , pages=

    Why phishing works , author=. Proceedings of the SIGCHI conference on Human Factors in computing systems , pages=

  72. [72]

    Twenty-First Symposium on Usable Privacy and Security (SOUPS 2025) , year =

    Zhang, Yichen and Xian, Lu and Schaub, Florian , title =. Twenty-First Symposium on Usable Privacy and Security (SOUPS 2025) , year =

  73. [73]

    28th USENIX Security Symposium (USENIX Security 19) , pages=

    Cognitive triaging of phishing attacks , author=. 28th USENIX Security Symposium (USENIX Security 19) , pages=

  74. [74]

    Proceedings of the 1st International Workshop on Deepfake Detection for Audio Multimedia , pages=

    Human Perception of Audio Deepfakes , author=. Proceedings of the 1st International Workshop on Deepfake Detection for Audio Multimedia , pages=. 2022 , organization=

  75. [75]

    2024 IEEE Symposium on Security and Privacy (SP) , pages=

    From chatbots to phishbots?: Phishing scam generation in commercial large language models , author=. 2024 IEEE Symposium on Security and Privacy (SP) , pages=. 2024 , organization=

  76. [76]

    2024 , month = feb, day =

  77. [77]

    Interaction studies

    The uncanny advantage of using androids in cognitive and social science research , author=. Interaction studies. social behaviour and communication in biological and artificial systems , volume=. 2006 , publisher=

  78. [78]

    Cognition , volume=

    Deviation from typical organic voices best explains a vocal uncanny valley , author=. Cognition , volume=. 2024 , publisher=

  79. [79]

    2024 , month = may, day =

    Amy Bunn , title =. 2024 , month = may, day =

  80. [80]

    Yan, Ziwei and Zhao, Yanjie and Wang, Haoyu , booktitle=

Showing first 80 references.