π€ AI Summary
This study addresses the limitations of traditional cybersecurity awareness training, which often lacks contextual relevance and fails to effectively mitigate human-factor risks. To bridge this gap, the authors propose a context-driven, embedded microlearning paradigm that leverages real-time risk detection to trigger personalized, situation-specific security training directly within usersβ workflows. By instantaneously transforming security incidents into reflective learning opportunities, this approach innovatively integrates behavioral theory with event-driven mechanisms to establish a dynamic mapping from observed risk events to adaptive learning instances. Furthermore, large language models are employed to generate hypermedia-based training content on demand. Preliminary experimental results demonstrate that the proposed method significantly enhances usersβ risk awareness and decision-making capabilities, outperforming conventional asynchronous, long-form training in both effectiveness and user acceptance.
π Abstract
In recent years, cybersecurity threats have increasingly exploited human behaviour rather than purely technical vulnerabilities, exposing the limits of traditional awareness programmes delivered outside real-world contexts. To bridge this gap, we introduce TrainShield, an interaction paradigm for contextual cybersecurity training that embeds adaptive learning interventions directly within user workflows. The system integrates real-time risk detection (e.g., phishing and data loss prevention) with event-triggered hypermedia overlays that dynamically connect users to context-specific learning nodes embedded within their browsing workflow to deliver personalised micro-learning content and structured feedback tailored to the user's knowledge level and current context. This approach operationalises behavioural theories by transforming security incidents into immediate learning opportunities, shifting users from automatic to reflective decision-making at critical moments. We further formalise a design model that maps detected events to adaptive training instances, combining user modelling, context extraction, and large language model (LLM)-based content generation.
A preliminary study indicates that the approach is perceived as useful in increasing risk awareness and is preferred over lengthy and asynchronous traditional training formats, while also highlighting challenges in aligning generated content with user expectations. Overall, the results suggest that embedding contextual, event-driven training within everyday interactions is a promising direction for behaviour-oriented cybersecurity education.