<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-20T17:45:28Z</responseDate><request verb="GetRecord" identifier="oai:opus.lib.uts.edu.au:10453/189678" metadataPrefix="dim">https://opus.lib.uts.edu.au/oai/request</request><GetRecord><record><header><identifier>oai:opus.lib.uts.edu.au:10453/189678</identifier><datestamp>2025-09-08T23:25:47Z</datestamp><setSpec>com_10453_19978</setSpec><setSpec>col_10453_19979</setSpec></header><metadata><dim:dim xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://www.dspace.org/xmlns/dspace/dim http://www.dspace.org/schema/dim.xsd">
   <dim:field mdschema="dc" element="contributor" qualifier="author">Conway, Daniel Edward</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="accessioned">2025-09-08T23:22:08Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="available">2025-09-08T23:22:08Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="issued">2025</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="uri">http://hdl.handle.net/10453/189678</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US.UTF-8">University of Technology Sydney. Faculty of Engineering and Information Technology.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="en_US.UTF-8">Phishing emails are the most common cyber security attack vector in Australia. This particular threat incurs huge costs to industry and falling victim can have substantial negative effects on peoples’ lives. Since technical solutions cannot intercept all such emails, users must detect these messages during their day-to-day email usage, meaning this problem remains one of human decision-making. This work is a structured program of experiments examining one of the major theories of human decision-making: dual-process theory, and then delves into a cue utilisation approach, as applied to this important, real-world problem.&#xd;
&#xd;
Within this framework, phishing emails are conflict problems where messages are constructed to powerfully cue ingrained, simple and fast heuristic responses (System 1) which are, however, in conflict with the answers provided by effortful, elaborative thought (System 2). Following this, System 2 thought is potentially protective against victimisation. However, System 2 processing, unlike System 1, is dependent on working memory.&#xd;
&#xd;
The initial experiments capitalise on this working memory requirement by manipulating how much System 2 processing was available to contribute to a problem by using a visual matrix task to impose cognitive load on participants as they attempted to detect phishing amongst legitimate emails distractors. In doing so we demonstrated that several central predictions of dual-process theories apply to the problem of phishing email detection.&#xd;
&#xd;
The second phase of this research investigated the role of diagnostic ‘cues’ in detecting illegitimate emails, how the use of these cues is impacted by cognitive load, and which cues are diagnostic. These experiments reveal surprising patterns of decision-making in phishing email detection, suggesting that phishing emails may be processed in a global manner.&#xd;
&#xd;
Finally, by applying k-means clustering to our previous data, we found that participants could be grouped into two distinct behavioural categories based on how they attended to features of the phishing emails. We also found that there were differences in the amount of direct cue-utilisation to outcome relationships between groups. This again suggests that global processing is taking place but suggests that there may be an individual difference as to global/local processing between participants.&#xd;
&#xd;
In this novel and ambitious attempt to apply a theoretical model of cognition to a complicated, real-world problem, we found that many of the central predictions of dual-process models hold true. Furthermore, when engaging with cue-utilisation theory, our experiments reveal surprising patterns of decision-making in phishing email detection.</dim:field>
   <dim:field mdschema="dc" element="format">Thesis (PhD)</dim:field>
   <dim:field mdschema="dc" element="language" qualifier="iso" lang="en_US.UTF-8">en_US</dim:field>
   <dim:field mdschema="dc" element="relation">https://opus.lib.uts.edu.au/bitstream/10453/189678/1/thesis.pdf</dim:field>
   <dim:field mdschema="dc" element="rights">info:eu-repo/semantics/openAccess</dim:field>
   <dim:field mdschema="dc" element="rights">The author owns the copyright in this thesis including all reproduction and reuse rights for the work. The work may not be altered without the permission of the copyright owner. Attribution is essential when quoting or paraphrasing from this thesis.</dim:field>
   <dim:field mdschema="dc" element="rights">© 2025 Daniel Edward Conway</dim:field>
   <dim:field mdschema="dc" element="rights">au.edu.uts.lib/cph</dim:field>
   <dim:field mdschema="dc" element="title" lang="en_US.UTF-8">Human Decision-Making In Phishing Email Detection: A Dual Process And Cue-Utilisation Approach</dim:field>
   <dim:field mdschema="dc" element="type">Thesis</dim:field>
   <dim:field mdschema="utslib" element="copyright" qualifier="status" lang="*">open_access</dim:field>
</dim:dim>
</metadata></record></GetRecord></OAI-PMH>