VishBox: An AI-Agent-Based Adaptive Voice Phishing Simulation Framework for Cybersecurity Education

Yoonmo Yang, Daon Choi, Yunyi Hong, Jee-Won Park, Jae-Yong Yu, Hee-Dou Kim, Sungmi Park · IEEE Access · 2026

Voice phishing has grown increasingly sophisticated, employing a range of deceptive tactics and social engineering skills to exploit individual and institutional vulnerabilities. In South Korea, countermeasures usually rely on static educational scenarios that fail to capture the dynamic, psychologically adaptive nature of real-time manipulation. This study introduces VishBox, an AI agent-orchestrated simulation framework that enables ethically safe reproduction of attacker-victim interactions through coordinated autonomous agents. VishBox generates high-fidelity synthetic crime dialogues and integrates empirically calibrated victim profiles parameterized by demographics, digital financial literacy, and personality traits, grounded in South Korean empirical studies. The system further incorporates an autonomous risk evaluation process to model escalation and derive personalized prevention strategies. Validation using national crime statistics and a survey with 102 participants shows that VishBox produces psychologically plausible deception patterns that are difficult for humans to distinguish from authentic cases. Simulated vulnerability distributions broadly align with real-world victimization patterns across age groups, while also revealing personality-driven risk scenarios that are underrepresented in incident statistics. Human risk ratings also mirrored the system’s turn-level estimates, confirming the realism of its escalation modeling. By providing a controlled, scalable environment for observing real-time manipulation, VishBox establishes a foundation for behavioral cybersecurity research, adaptive educational design, and evidence-driven policy development against evolving phishing threats.

Read the paper · More papers on PaperTik