Scamming the Scammers: Using ChatGPT to Reply Mails for Wasting Time and Resources

Enrico Cambiaso,Luca Caviglione
2023-02-10
Abstract:The use of Artificial Intelligence (AI) to support cybersecurity operations is now a consolidated practice, e.g., to detect malicious code or configure traffic filtering policies. The recent surge of AI, generative techniques and frameworks with efficient natural language processing capabilities dramatically magnifies the number of possible applications aimed at increasing the security of the Internet. Specifically, the ability of ChatGPT to produce textual contents while mimicking realistic human interactions can be used to mitigate the plague of emails containing scams. Therefore, this paper investigates the use of AI to engage scammers in automatized and pointless communications, with the goal of wasting both their time and resources. Preliminary results showcase that ChatGPT is able to decoy scammers, thus confirming that AI is an effective tool to counteract threats delivered via mail. In addition, we highlight the multitude of implications and open research questions to be addressed in the perspective of the ubiquitous adoption of AI.
Cryptography and Security,Artificial Intelligence,Human-Computer Interaction
What problem does this paper attempt to address?
The main problem that this paper attempts to solve is to use artificial intelligence (AI), especially generative AI technologies such as ChatGPT, to combat fraud committed via email. Specifically, the researchers explored how to use ChatGPT to automatically generate reply emails to draw fraudsters into meaningless conversations, thereby wasting their resources and time. This method aims to mitigate the negative impacts of email fraud on individuals and society and reduce the resource consumption for handling these fraudulent emails. The paper mentions that although the scale of the experiment was limited, the preliminary results showed that ChatGPT was able to effectively interact with fraudsters for up to 27 days, and the number of email exchanges with a single fraudster reached 18 at most. This indicates that AI has potential value in combating email fraud. However, this method also raises a series of research and ethical issues, such as how to create more realistic replies to avoid being detected by fraudsters, and the privacy and forensic investigation challenges that may be brought about by automatic email replies. In addition, the paper also explored the directions for future research, including expanding the scope of the experiment, optimizing the test platform to minimize the need for human intervention, and in - depth understanding of the technical requirements and practical application potential of tools such as ChatGPT. In short, this research not only demonstrates the application potential of AI in the field of network security, but also emphasizes the complexity and challenges that need to be faced in implementing such solutions.