Source-linked AI summary
Security Education in Higher Education through AI-Powered Gamification
Bingjun Li, Christopher Buzaid, Weihao Qu
TL;DR
Traditional cybersecurity awareness training struggles to address increasingly sophisticated AI-enhanced attacks and engage learners. This paper develops short, mobile-friendly AI-powered games and evaluates them with college students, finding high engagement, validated simulation realism, and strong preference for mobile-first learning.
Problem
Traditional awareness programs rely on repetitive tutorials or standardized quizzes that inadequately address sophisticated, context-sensitive AI-enhanced phishing attacks and evolving digital threats.
Method
The paper develops short, mobile-friendly AI-powered games using adaptive personalization, responsive scenarios, and multiple cybersecurity-focused game formats, then evaluates them through a two-tiered strategy.
Results
The two-tiered evaluation found high engagement and learning outcomes, with technical experts validating simulation realism and general students (N=50) overwhelmingly preferring mobile-first training over traditional desktop training.
Takeaways & Limitations
AI-powered gamification shows potential as a scalable approach for making cybersecurity education more engaging, adaptive, and oriented toward practical behavioral application.
Takeaways & Limitations
Conventional static training remains inadequate for dynamic AI-driven threats, so effective preparation requires interactive, scenario-based, and experiential approaches that support active decision-making.
Abstract
from arXiv · showhide
Cybersecurity education is facing more challenges as AI-driven attacks are becoming increasingly realistic and difficult to detect. Traditional video-based cybersecurity training in higher education often suffers from both low engagement and limited effectiveness. This dilemma motivates educators to explore innovative approaches, such as AI-powered gamification, which can deliver engaging, meaningful, and personalized learning experiences. By presenting content in a more interactive and user-friendly way, these methods have the potential to significantly improve both learner engagement and educational outcomes. This paper explores AI-powered gamification in cybersecurity education through the development of several short, mobile-friendly games. These games cover a range of topics from password security to text and phone scam recognition, incorporate multiple gamification strategies, including quiz-based, narrative-based, and simulation-based designs, as well as interactive formats such as TikTok Mini-Games. We conducted a two-tiered evaluation with 59 college students (comprising 9 technical experts and 50 general users), and the results indicate the potential of AI-powered gamification to improve engagement and increase attention to cybersecurity topics in higher education.
I. INTRODUCTION
Higher education cybersecurity education faces persistent engagement and effectiveness challenges, motivating AI-powered gamification as a more interactive, adaptive, and mobile-friendly approach. The paper develops short AI-powered games and evaluates their engagement and educational effectiveness among college students.
- Motivation: Traditional video-based training often appears monotonous and disconnected from real-life scenarios, limiting engagement and long-term impact.The stated challenge is a persistent gap between security awareness and behavioral change.
- Motivation: Gamification integrates game design elements into education to increase motivation, participation, concentration, and learning outcomes.Challenges, feedback, and rewards support active participation and persistence.
- Motivation: Lengthy, desktop-based gamified platforms can reduce accessibility and engagement for time-constrained students who prefer mobile-friendly learning.Learners may lose interest before reaching intended outcomes when modules are too long or inflexible.
- Approach: AI-powered gamification can provide short, personalized experiences by identifying learner weaknesses and generating customized micro-learning modules.The passage gives phishing recognition and password protocols as examples of weaknesses that can be addressed.
- Contribution: The paper develops several short, mobile-friendly AI-powered cybersecurity games and evaluates their engagement and educational effectiveness among college students.The contribution targets multiple cybersecurity aspects and assesses both acceptance and educational effectiveness.
- Contribution: The paper presents AI-powered gamification as a scalable and effective model for fostering long-term behavioral change in higher-education cybersecurity education.This is stated as the paper’s initial contribution toward demonstrating the model’s potential.
A. Gamification versus Game-based Learning (GBL)
Gamification adds motivational elements to existing learning activities, whereas game-based learning uses complete games or simulations as the instructional medium. The section frames realistic, adaptive experiences as a response to sophisticated attacks that can bypass static awareness training.
- Gamification versus Game-Based Learning: Gamification adds points, levels, badges, leaderboards, feedback, and rewards to non-game learning contexts to encourage motivation and persistence.Game-based learning differs by using complete games or interactive simulations as the primary instructional medium.
- Gamification versus Game-Based Learning: Game-based learning centers experiential learning, problem-solving, and situated cognition within authentic interactive environments.It transforms the learning activity itself into a complete game experience.
- Cybersecurity Context: Higher-education cybersecurity threats increasingly exploit human behavior through phishing, ransomware, and social engineering rather than only technical vulnerabilities.The section therefore calls for adaptive, interactive, learner-centered approaches beyond passive awareness modules.
- Case Study: A September 2025 text scam used a government impersonation, urgent payment confirmation, and a lookalike website to obtain personal and credit-card information.The provided card was subsequently added to a different digital wallet.
- Case Study: Subtle inconsistencies included a Philippine phone number and a fraudulent redirect domain, while urgency and credibility created hesitation even among technologically familiar users.The message was engineered to exploit psychological triggers rather than relying only on technical deception.
- Implications: Conventional tutorials and standardized quizzes inadequately address increasingly sophisticated, AI-enhanced phishing and do not foster the situational awareness needed for evolving threats.The section recommends interactive, scenario-based, and experiential learning that mirrors authentic attacks and engages active decision-making.
D. Gamification in (Cybersecurity) Education
Gamification can make cybersecurity education more active and experiential by placing learners in realistic challenges that support engagement, knowledge retention, and practical performance. AI-powered systems extend this approach through adaptive difficulty, personalized pathways, targeted feedback, and evolving threat scenarios.
- Educational Role: Realistic simulated challenges enable learners to apply cybersecurity knowledge and skills rather than merely memorizing abstract principles.The section positions gamification as an interactive and experiential framework for responding to increasingly sophisticated threats.
- Evidence for Gamification: Gamified cybersecurity education enhances engagement, knowledge retention, and practical performance through active participation, collaboration, and problem-solving.Studies also report gains in conceptual understanding and technical proficiency in realistic learning environments.
- Evidence for Gamification: Gamification transforms cybersecurity instruction from compliance-based learning into an active, experiential process that strengthens competence and confidence.The shift is framed as a consequence of realistic, interactive learning activities.
- Limitations of Existing Systems: Most existing gamified systems use fixed difficulty levels, limiting adaptation to individual learners’ progress and performance.This limitation motivates data-driven personalization of challenges and feedback.
- AI-Powered Gamification: AI-powered gamification analyzes learner behavior and performance in real time to adjust task difficulty, personalize learning pathways, and deliver targeted feedback.The intended effect is to keep learners appropriately challenged while supporting steady skill development and deeper understanding.
- AI-Powered Gamification: In cybersecurity education, adaptive systems can simulate evolving threat scenarios matched to learner proficiency, supporting situational awareness and decision-making under pressure.The approach is presented as promising for more resilient, adaptive, and engaging higher-education cybersecurity education.
III. GAMES
The paper presents AI-powered, mobile-friendly cybersecurity games spanning programming, phishing, passwords, phone scams, and TikTok-style password learning. Sentinel combines responsive AI scenarios, bounded adversarial adaptation, analytics, badges, and interactive simulations.
- A. AI-powered Gamification in Education: An undergraduate student used AI tools to create a mobile-friendly Python game that supported motivation, review, and exam preparation.
- B. Sentinel Security Game Platform Design: Sentinel is an AI-powered platform with subgames for phishing detection, password cracking, text scams, and phone scam awareness.Its interaction engine uses a Google Gemini API LLM configured with an attacker persona.
- B. Sentinel Security Game Platform Design: The phone scam game uses constrained social-engineering tactics, realistic synthesized speech, and adaptive scam sophistication based on users’ detection streaks.The bounded-adversarial framework filters jailbreak attempts and can shift from obvious clues to subtler soft-sell tactics.
- C. Mini games: The phishing and password-cracker games require learners to identify fraudulent indicators and infer passwords from a fictional target’s background.These activities target phishing awareness and common password weaknesses through practical decision-making.
- C. Mini games: The TikTok Filter Password Thinker asks players to choose stronger passwords across five rounds within 20 seconds, delivering cybersecurity concepts in under 30 seconds.The format was designed as a fast-paced, engaging short-video-style learning experience.
- C. Mini games: Across the platform, short mobile-friendly games use interactive simulations and competitive problem-solving to make cybersecurity learning more active and practical.
IV. METHODOLOGY AND EVALUATION
The study used a two-tiered evaluation strategy to assess both the platform’s technical robustness and its broader pedagogical acceptance.
- The evaluation separated technical validation by experts from broad learner-preference assessment.This design addressed both technical robustness and general pedagogical acceptance.
A. Study Design and Participants
The study evaluated the games with nine cybersecurity-trained experts and 50 general learners from diverse academic disciplines. Participants assessed technical quality, engagement, learning, mobile-first format preference, and memorable features.
- Tier 1: Expert Review and Technical Validation: Nine advanced cybersecurity students evaluated scenario accuracy, AI-response realism, and mobile-deployment stability as developers and alpha testers.
- Tier 2: General Learner Preference Survey: Fifty general participants included an equal split of 25 males and 25 females and represented multiple academic disciplines.Education was the largest single cohort with 16 participants, followed by Computer Science & Math with 12.
- Technical Validation: Experts played all five subgames and provided votes and qualitative feedback on mechanics, implementation, and engagement flow.
- Preference Questionnaire: General participants completed a five-point Likert questionnaire measuring learning, self-efficacy, engagement, format preference, memorability, and improvement areas.
C. Ethical Considerations and Procedure
The evaluation received institutional ethical approval and used consent, anonymity, controlled mobile gameplay, and separate analyses for expert and general-participant data. The paper also situates the work alongside an earlier comparative phishing-training evaluation.
- Ethical Considerations: The study received Monmouth University Institutional Review Board approval and required electronic informed consent from all participants.
- Ethical Considerations: Data collection was anonymous, with no personally identifiable information linked to performance metrics or survey responses.
- Procedure: Participants accessed five subgames through QR codes on personal mobile devices in a controlled Bring Your Own Device environment.
- Data Analysis: Expert data was analyzed quantitatively and qualitatively for design strengths and bugs, while general-participant data used means and standard deviations.
- Comparative Evaluation with Existing Works: A preliminary study compared gamified phishing modules with Mimecast and no training among 51 college participants, but it was not this paper’s contribution.
V. RESULTS
The two-tiered evaluation found strong engagement, educational clarity, and preference for short mobile-friendly cybersecurity games among experts and general students. Results also identified content expansion, adaptive difficulty, and demographic differences as priorities for future iterations.
- The evaluation yielded distinct insights from technical experts and general students, supporting both system quality and demand for the learning format.
- 7 out of 9 votes rated the TikTok mini-Game highest for engagement, with experts citing its fast-paced design for attention capture.
- 5 votes identified the Text Phishing Detective as having the best learning value for teaching URL spoofing and social-engineering cues.
- 90% of students (45/50) felt more confident avoiding security risks, while 78% (39/50) said the game improved their understanding of online security.
- 92% of participants (46/50) preferred short mobile-friendly games over long desktop training or videos, including 72% (36/50) who strongly agreed.
- Content Expansion received 13 votes, Difficulty Scaling 11 votes, and More examples of real security threats 9 votes as desired improvements.
- 100% of female participants (25/25) responded positively to Q2, while 88% (22/25) of female participants strongly agreed with the mobile format compared with 56% (14/25) of males.
C. Tier 2: General Learner Preferences (N=50) (Qualitative Analysis)
General students remembered interactive password and phishing activities, but their feedback also exposed predictable assessments and requested more age-tailored, varied, and challenging content. The qualitative findings support moving from passive recognition toward active recall and segmented personalization.
- Learning Retention (What Stuck?): Participants frequently remembered the Password Decoding Game and Guessing the Phishing Emails, alongside vulnerability awareness about high-risk targets.
- Critical Feedback on Mechanics: Participants criticized predictable answer choices, especially repeated “all of the above” options that enabled guessing without fully processing the content.
- User Segmentation and Personalization: Participants recommended age-segmented training, with simpler interactions for children and daily digital-safety topics for teens and college students.
- Feature Requests and Future Innovation: Participants requested emerging-threat content on AI deepfakes, AI voice cloning, and catfishing, plus leaderboards, multiplayer competitions, and profile customization.
- Conclusion of Qualitative Findings: The qualitative findings call for randomized answers, more rigorous testing, and age-relevant scenarios to shift training from passive recognition to active recall.
VI. DISCUSSION
The discussion interprets the platform as shifting cybersecurity learning toward active resilience through realistic, adversarial, and time-constrained interactions. It also identifies governance safeguards for generative-AI accuracy, bias, privacy, and ethical research conduct.
- The platform is presented as shifting pedagogy from passive compliance toward active resilience, addressing psychological aspects overlooked by traditional video training.
- The Password Cracker game promotes adversarial thinking by requiring learners to deduce credentials from a fictional target’s background rather than memorize rules.
- The TikTok-style filter game uses time constraints to mimic fast-paced mobile decision-making and raised awareness in under 30 seconds.
- Generative AI is limited to simulating attackers, while explanations of attack mechanisms and prevention are delivered through non-generative interfaces for pedagogical accuracy.
- The Phone Scam module randomizes voice profiles across gender, tone, and accent to reduce reinforcement of stereotypes about cyber attackers.
- Voice inputs are transcribed and immediately discarded, interaction logs contain no PII, and temporary session IDs are purged after gameplay.
VIII. CONCLUSION
The conclusion reports that AI-enhanced, mobile-friendly mini-games produced high engagement and learning outcomes, with experts validating simulation realism and students preferring the mobile-first format. Future work targets curricular integration, resilience-based measurement, and AI-enabled threats.
- The study used Generative AI for responsive scenarios such as the Phone Scam simulator and delivered them through mobile-friendly mini-games.
- Technical experts validated simulation realism, while the general student population (N=50) overwhelmingly preferred the mobile-first approach over traditional desktop training.
- Future research will refine adaptive gamified systems and examine effectiveness across different student populations and learning environments.
- The platform currently operates as a standalone awareness tool, with future work planned to integrate its modules into university Learning Management Systems.
- The paper advocates shifting institutional metrics from compliance-based viewing measures toward resilience-based measures using performance in simulated attacks over time.
- Future iterations will explore deepfake-detection mini-games that train users to identify visual and auditory artifacts in AI-generated media.