Catch Me If You See: Using Visual Cue and Explanatory Feedback to Enhance Human Phishing Detection
Arifa Islam Champa, Md Fazle Rabbi, Farjana Z. Eishita, Minhaz F. Zibran · IEEE Access · 2025
Phishing attacks are a major cybersecurity threat that exploit human weaknesses to steal sensitive information. Although detection systems have improved, phishing attacks remain widespread which highlights the need for human-centered defenses. In this study, we investigate the effectiveness of visual cues and explanatory feedback in improving users’ ability to detect phishing emails.We conduct a user study with 55 participants and first evaluate detection accuracy across two tasks: one without visual cues (task-1) and one with visual cues (task-2), to assess their impact. Upon completion of task-2, the participants receive explanatory feedback. Then they participate in a third task (task-3) to evaluate new emails (without visual cues). Through measuring their accuracy, we examine how email categories influence detection performance and how this changes with visual cues and feedback. Results show that visual cues offer only modest improvements in phishing detection with no statistically significant accuracy gains (task-1: 58.18% vs. task-2: 68.73%), and lead to increased misclassification of legitimate emails. In contrast, explanatory feedback significantly enhances both phishing and legitimate email detection, with overall accuracy improving to 70% in task-3, a gain of 13.82% compared to task-1 and 12.91% compared to task-2, with validated gains confirmed through a follow-up user study. Additionally, detection performance varies across email categories, with emotionally manipulative and deceptive tactics proving more difficult to detect but showing improvement after receiving explanatory feedback. These findings offer actionable insights for designing effective, feedback-based user training programs to complement automated phishing detection systems.