TrainShield: Targeted Awareness for Cybersecurity Training
2026-08-03 • Cryptography and Security
Cryptography and SecurityComputers and Society
AI summaryⓘ
The authors explain that many cybersecurity problems arise from how people behave, not just technical gaps, and traditional training often misses the mark because it happens separately from real work. They created TrainShield, a system that teaches users about security risks right when those risks show up during their normal tasks, using quick lessons personalized to the situation and the user's understanding. Their approach helps users think carefully about security decisions by turning risky events into learning moments. A small study showed people found this method more useful and engaging than usual long training sessions, though some content still needs fine-tuning to meet user expectations.
cybersecurity traininghuman behaviorphishing detectiondata loss preventionadaptive learninguser modelingcontextual trainingmicro-learninglarge language modelsbehavioral theories
Authors
Giovanni Pizzenti, Alberto Verna, Nikhil Jha, Giuseppe Tipaldo, Stefano Traverso, Marco Mellia
Abstract
In recent years, cybersecurity threats have increasingly exploited human behaviour rather than purely technical vulnerabilities, exposing the limits of traditional awareness programmes delivered outside real-world contexts. To bridge this gap, we introduce TrainShield, an interaction paradigm for contextual cybersecurity training that embeds adaptive learning interventions directly within user workflows. The system integrates real-time risk detection (e.g., phishing and data loss prevention) with event-triggered hypermedia overlays that dynamically connect users to context-specific learning nodes embedded within their browsing workflow to deliver personalised micro-learning content and structured feedback tailored to the user's knowledge level and current context. This approach operationalises behavioural theories by transforming security incidents into immediate learning opportunities, shifting users from automatic to reflective decision-making at critical moments. We further formalise a design model that maps detected events to adaptive training instances, combining user modelling, context extraction, and large language model (LLM)-based content generation. A preliminary study indicates that the approach is perceived as useful in increasing risk awareness and is preferred over lengthy and asynchronous traditional training formats, while also highlighting challenges in aligning generated content with user expectations. Overall, the results suggest that embedding contextual, event-driven training within everyday interactions is a promising direction for behaviour-oriented cybersecurity education.