Current Issue

Romanian Journal of Information Technology and Automatic Control / Vol. 36, No. 1, 2026


AI-enhanced social engineering: Emerging threats and human-centric countermeasures

Salko KOVAČIĆ, Ivana BILIĆ

Abstract:

Social engineering is an attack that leverages human decision-making with the purpose of gaining access to information or causing specific actions, rather than exploiting software vulnerabilities. Modern advancements in Artificial Intelligence (AI) have enabled automated target profiling, tailored messages for every user and AI-based voice and video synthesis. Industry reports have shown that phishing activity has grown by in volume 108% since 2022. This study provides an overview of the Proof-of-Concept Human-Centric Social Engineering Shield (HCSES) open-source modular social engineering defense mechanism that incorporates several mechanisms including identity management (Keycloak), honeypot detection (OpenCanary), DNS filtering (Pi-Hole), email analysis (Rspamd) and adaptive learning management. The HC-SES includes adaptive micro-training provided in real time to users based on their behavioral risk assessment at decision-making points. To evaluate the feasibility of HC-SES, we conducted a Proof-of-Concept (PoC) feasibility study at the Dzemal Bijedic University of Mostar (approximately 5.000 users). The technical integration of all modules was successful and demonstrated that Keycloak authentication allowed users to be recognized across federated services, Rspamd detected phishing in approximately 1.000 emails with a 90% precision and less than 5% of login attempts required risk-adaptive Multi-Factor Authentication (MFA), with less than 1% of those being false positives. Participation in training (60%) surpassed the institutional average (40-50%) and the average time it took for participants to complete the training (65%) was less than 48 hours.

Keywords:
Social engineering, Artificial Intelligence (AI), Security awareness, Open-source security, Identity management.

View full article:

CITE THIS PAPER AS:
Salko KOVAČIĆ, Ivana BILIĆ, "AI-enhanced social engineering: Emerging threats and human-centric countermeasures", Romanian Journal of Information Technology and Automatic Control, ISSN 1220-1758, vol. 36(1), pp. 63-76, 2026. https://doi.org/10.33436/v36i1y202605