LLM-Generated Security Training Samples for Phishing Scenarios

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large language models pose a risk of being misused for planning and executing complex cyberattacks, particularly through email-borne threats, due to their advanced capabilities in generating malicious content and interacting with systems.

Innovation Solution

A security awareness training system generates tailored electronic messages using large language models to educate employees about cyber threats by mimicking authentic communication within organizations, leveraging information from cloud-based productivity suites and identity management systems to create realistic phishing scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If large language models are used to generate malicious content for cyberattacks, then the sophistication and effectiveness of attacks increase, but the risk of security breaches and data compromise increases

Engineering Contradiction:
Improveattack effectivenessVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the harmful capability of large language models to generate malicious content into a beneficial tool for security training. By using the same models to generate realistic phishing emails and cyberattack scenarios for training employees, the system transforms a security risk into a defensive advantage, allowing organizations to leverage AI's generative power for protective purposes rather than offensive ones

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system performs preliminary anti-action by proactively training employees against cyberattacks before actual attacks occur. By generating realistic phishing scenarios and security threats in advance for training purposes, the system prepares users to recognize and resist actual cyberattacks, neutralizing the potential harm before it can be executed

Inventive Principle:
Principle #9Preliminary anti-action

2Adaptability or versatility

If generic security training materials are used, then training coverage is broad, but employee engagement and effectiveness decrease

Engineering Contradiction:
Improvetraining coverageVSAvoidtraining effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by customizing security training content to match each employee's specific role, department, and risk exposure. Instead of uniform generic materials, the system generates tailored phishing scenarios and training content that reflects the actual threats facing different positions within the organization, making training more relevant and effective for each user group

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements dynamics by making training content adaptive and evolving based on user interactions and emerging threats. The large language models generate dynamic training scenarios that can be customized in real-time based on user responses, organizational changes, and new threat vectors, ensuring training remains current and engaging rather than static

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12430601B2Generation of security awareness training samples with large language models
Publication Date: 2025.09.30 VADE USA INC
  • US12430601B2 patent drawing
  • US12430601B2 patent drawing
  • US12430601B2 patent drawing

AI summary

A computer-implemented method of generating security awareness training samples may include receiving, structuring and storing information about a user of an organization into an organization knowledge base and selecting and fetching at least one training template, each including an electronic message template and a prompt template for a large language model. The prompt template(s) and the electronic message template(s) may then be specialized using the information about users of the organization stored in the organization knowledge base. The specialized prompt template(s) may then be submitted to a large language model artificial intelligence system. Textual content may then be received from the large language model responsive to each submitted specialized prompt template. A security awareness training sample may then be generated for each submitted specialized prompt template using the corresponding generated textual content received from the large language model and the corresponding specialized electronic message template(s).