Beyond the human firewall: A systematic analysis of deepfake-mediated social engineering and the erosion of traditional security awareness

Main Article Content

Mohd Ruhaifi Zainol
Marhakim Mokhtar
Mohamad Fadli Zolkipli

Abstract

The proliferation of generative artificial intelligence has transformed the cyber threat landscape, particularly in the domain of social engineering. Deepfake technology, encompassing synthetic audio and video generation, has emerged as a vector for advanced phishing campaigns that can bypass conventional controls, exposing limitations of traditional Security Awareness Training (SAT) when confronted with AI-driven deception. This paper presents a systematic analysis of empirical evidence on deepfake-enabled social engineering and its implications for existing security-awareness frameworks, drawing on 56 primary studies involving 86,155 participants, supplemented by 47 documented corporate incidents and a review of current technical detection methods. Pooled human detection accuracy for deepfake content was 55.54% (95% CI [52.3%, 58.8%]), only marginally above chance; the pooled estimate is, however, accompanied by substantial heterogeneity (I² = 78.4%) and should be interpreted as an average performance rather than a uniform inability to discriminate. Traditional SAT was associated with a non-significant +1.6% improvement in deepfake detection, whereas SAT incorporating synthetic-media examples produced significant gains of +8.1% to +15.5%. The study identifies three persistent limitations in current awareness training: the absence of deepfake-specific detection heuristics, inadequate calibration of trust in response to synthetic authority cues, and insufficient inoculation against cognitive-load manipulation; a 21.1-percentage-point laboratory-to-field performance gap was also observed. The paper proposes a resilience-oriented training framework that integrates technical literacy, psychological preparedness, and organisational verification mechanisms. Rather than declaring the “human firewall” obsolete, the analysis argues for its reconceptualisation as a complementary safeguard within layered, procedure-anchored defence.

Article Details

Section

Review Articles

How to Cite

[1]
M. R. Zainol, M. Mokhtar, and M. F. Zolkipli, “Beyond the human firewall: A systematic analysis of deepfake-mediated social engineering and the erosion of traditional security awareness”, J. Appl. Comput. Inf. Technol., vol. 1, no. 2, pp. 138–154, Aug. 2026, doi: 10.67131/jacoit.v1i2.25.