AI-Driven Synthetic Threats in Cybersecurity: A User-Centered Framework for Awareness, Detection, and Protective Behavior

Reem Almarwani, Maryam Almarwani, Fatimah Almarwani · IEEE Access · 2026

The rapid advancement of artificial intelligence has ushered in a new generation of cybersecurity threats driven by highly realistic AI-generated content, including deepfakes, synthetic audio, and algorithmically produced text. Recent international assessments highlight escalating risks related to identity impersonation, large-scale deception, and the manipulation of digital evidence, underscoring the need for socio-technical defense models that go beyond purely technical detection. This paper introduces and empirically validates theAI-Cyber-User Awareness Framework, a unified socio-technical model that explains how AI-driven threats interact with user cognition and cybersecurity behavior. The framework is grounded in Technology Threat Avoidance Theory (TTAT), cognitive security principles, and contemporary research on AI-enabled deception. It is constructed through a structured literature analysis of twenty-five peer-reviewed studies and then quantitatively validated using survey data fromn= 144 participants in a Middle Eastern context. The empirical study operationalizes key constructs—AI threat awareness, detection competence, AI literacy, risk perception, and protective cybersecurity behavior—and evaluates their relationships using correlation, regression, and mediation analysis. Results reveal a pronounced confidence-competence gap: objective detection accuracy remains low (mean = 42.53%) despite moderate perceived preparedness. Detection competence emerges as the strongest predictor of protective cybersecurity behavior and significantly mediates the influence of awareness and AI literacy. By integrating technical, cognitive, and behavioral dimensions into a single explanatory model, the proposed framework advances theoretical understanding of AI-driven cyber deception and provides a practical foundation for designing human-centered cybersecurity interventions that prioritize detection skill development rather than awareness-raising alone.

Read the paper · More papers on PaperTik