On the Feasibility of Fully AI-automated Vishing Attacks
Jo\~ao Figueiredo, Afonso Carvalho, Daniel Castro, Daniel Gon\c{c}alves, Nuno Santos

TL;DR
This paper demonstrates that AI-powered systems like ViKing can automate convincing vishing attacks, raising security concerns and highlighting the need for enhanced awareness and defenses against AI-enabled social engineering threats.
Contribution
The study introduces ViKing, an AI-based vishing system that automates social engineering attacks, and empirically evaluates its effectiveness through a participant experiment.
Findings
ViKing successfully persuaded many participants to disclose sensitive info.
Interactions with ViKing were perceived as highly realistic.
AI tools like ViKing are accessible to malicious actors.
Abstract
A vishing attack is a form of social engineering where attackers use phone calls to deceive individuals into disclosing sensitive information, such as personal data, financial information, or security credentials. Attackers exploit the perceived urgency and authenticity of voice communication to manipulate victims, often posing as legitimate entities like banks or tech support. Vishing is a particularly serious threat as it bypasses security controls designed to protect information. In this work, we study the potential for vishing attacks to escalate with the advent of AI. In theory, AI-powered software bots may have the ability to automate these attacks by initiating conversations with potential victims via phone calls and deceiving them into disclosing sensitive information. To validate this thesis, we introduce ViKing, an AI-powered vishing system developed using publicly available…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsEthics and Social Impacts of AI · Adversarial Robustness in Machine Learning · Advanced Malware Detection Techniques
