Can Artificial Intelligence Predict Human Vulnerability to Cyber Threats? A Machine Learning Approach to Cybersecurity Behaviour

  • Unique Paper ID: 208434
  • PageNo: 110-117
  • Abstract:
  • Individual users, rather than the technical systems around them, are frequently a critical point of vulnerability in cybersecurity: a reused password, an unexamined link, a postponed software update, or a banking session conducted over an unsecured public network can expose individuals to significant cyber risks. Existing approaches to behavioural cybersecurity often reduce vulnerability to a single overall score, which may indicate that an individual is at risk without identifying the specific behaviours contributing to that risk. At the same time, the growing application of supervised machine learning in cybersecurity has focused predominantly on organisational networks, systems, and software rather than on individual behavioural profiles. This paper addresses this gap by developing a multidimensional framework for analysing human vulnerability to cyber threats. The framework incorporates eight behavioural domains—password management, authentication, phishing response, device security, privacy practices, network behaviour, digital payment security, and incident response—along with a transparent and leakage-aware procedure for behavioural risk scoring. It further proposes a supervised machine-learning pipeline using Logistic Regression, Decision Tree, Random Forest, and K-Nearest Neighbours, with model assessment based on accuracy, precision, recall, F1-score, and ROC-AUC rather than accuracy alone. A SHAP-based explainability layer is incorporated to connect model classifications with the behavioural factors underlying them, making the resulting assessment more transparent and actionable. By integrating behavioural cybersecurity measurement, machine learning, and explainable artificial intelligence, the study presents a structured and non-stigmatising approach to understanding individual cybersecurity vulnerability and provides a foundation for future empirical investigation and targeted cybersecurity awareness strategies.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{208434,
        author = {Mahek Chanda and Prof. Nita Patil},
        title = {Can Artificial Intelligence Predict Human Vulnerability to Cyber Threats? A Machine Learning Approach to Cybersecurity Behaviour},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {13},
        number = {no},
        pages = {110-117},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=208434},
        abstract = {Individual users, rather than the technical systems around them, are frequently a critical point of vulnerability in cybersecurity: a reused password, an unexamined link, a postponed software update, or a banking session conducted over an unsecured public network can expose individuals to significant cyber risks. Existing approaches to behavioural cybersecurity often reduce vulnerability to a single overall score, which may indicate that an individual is at risk without identifying the specific behaviours contributing to that risk. At the same time, the growing application of supervised machine learning in cybersecurity has focused predominantly on organisational networks, systems, and software rather than on individual behavioural profiles. This paper addresses this gap by developing a multidimensional framework for analysing human vulnerability to cyber threats. The framework incorporates eight behavioural domains—password management, authentication, phishing response, device security, privacy practices, network behaviour, digital payment security, and incident response—along with a transparent and leakage-aware procedure for behavioural risk scoring. It further proposes a supervised machine-learning pipeline using Logistic Regression, Decision Tree, Random Forest, and K-Nearest Neighbours, with model assessment based on accuracy, precision, recall, F1-score, and ROC-AUC rather than accuracy alone. 
A SHAP-based explainability layer is incorporated to connect model classifications with the behavioural factors underlying them, making the resulting assessment more transparent and actionable. By integrating behavioural cybersecurity measurement, machine learning, and explainable artificial intelligence, the study presents a structured and non-stigmatising approach to understanding individual cybersecurity vulnerability and provides a foundation for future empirical investigation and targeted cybersecurity awareness strategies.},
        keywords = {Cybersecurity behaviour; behavioural risk classification framework; explainable machine learning; SHAP; human factors in security; risk categorisation; digital payment security},
        month = {September},
        }

Cite This Article

Chanda, M., & Patil, P. N. (2026). Can Artificial Intelligence Predict Human Vulnerability to Cyber Threats? A Machine Learning Approach to Cybersecurity Behaviour. International Journal of Innovative Research in Technology (IJIRT), 110–117.

Related Articles