AI scammers outperform humans when it comes to building trust

AI scammers outperform humans when it comes to building trust

AI 诈骗者在建立信任方面表现优于人类

The notion that scammers can use AI to sharpen their deceptions, polish their language, and lubricate their banter with victims is now a reality for anyone fighting the fraud operations that steal tens of billions of dollars a year worldwide. 诈骗者利用人工智能来强化欺骗手段、润色语言并使与受害者的交谈更加顺畅,这一概念对于任何打击每年在全球范围内窃取数百亿美元的欺诈行动的人来说,现在已成为现实。

But can AI fully replace a human scammer, autonomously building the web of deception leading up to the fake investment that defrauds the mark? One study’s experiment suggests that it can—and may even be able to carry out the majority of that long con more effectively than humans. 但人工智能能否完全取代人类诈骗者,自主构建通往虚假投资骗局的欺骗之网?一项研究实验表明,它不仅可以做到,甚至可能比人类更有效地执行大部分长期诈骗过程。

Researchers from four universities—Amrita Vishwa Vidyapeetham in India, Foscari University of Venice, the University of Melbourne, and Ben Gurion University of the Negev—carried out a broad study on the use and potential of generative AI chatbots in the growing scam industry centered around a form of fraud known as “pig butchering,” text-based romance scams that eventually shift to fake crypto investments that steal as much as six-figure sums from victims. 来自印度阿姆里塔大学(Amrita Vishwa Vidyapeetham)、威尼斯大学(Foscari University of Venice)、墨尔本大学和内盖夫本·古里安大学的四所高校研究人员,针对生成式 AI 聊天机器人在日益增长的“杀猪盘”诈骗行业中的应用和潜力进行了广泛研究。“杀猪盘”是一种基于文本的浪漫诈骗,最终会转向虚假加密货币投资,从受害者身上窃取高达六位数的金额。

In their study, the researchers pitted AI chatbots directly against humans in a simulation of the scamming process—or more specifically, the long, trust-building conversations that eventually lead up to soliciting a fake investment from the scam’s target. They found that for the relationship-establishing stages of the scam—the stage that in real-world scams typically represents the longest part of the interactions with the victim, often stretching to months—an AI chatbot performed remarkably effectively, successfully impersonating a human and by some measures outperforming the real human “scammers” in their experiment. 在研究中,研究人员在模拟诈骗过程中让 AI 聊天机器人与人类直接对抗——更具体地说,是模拟那些最终导致向目标索要虚假投资的长期信任建立对话。他们发现,在诈骗的建立关系阶段(在现实诈骗中,这通常是与受害者互动时间最长的部分,往往长达数月),AI 聊天机器人的表现非常出色,成功地模仿了人类,并且在某些指标上甚至超过了实验中的真实人类“诈骗者”。

After a week of talking to 22 test subjects who were recruited to unwittingly serve as “victims,” the chatbots and human scammers were assigned to ask the victim to either download an app or play an online game as a proxy for their willingness to fulfill the scammer’s request. Nearly half of the test subjects fulfilled that request for the AI chatbot, while fewer than 1 in 5 took the bait when talking to a human. The subjects also graded their level of trust with each “person” they were texting with and gave significantly higher scores to the AI bot. 在与 22 名被招募来不知情地充当“受害者”的测试对象交谈一周后,聊天机器人和人类诈骗者被要求让受害者下载应用程序或玩在线游戏,以此作为衡量他们是否愿意满足诈骗者要求的指标。近一半的测试对象满足了 AI 聊天机器人的要求,而与人类交谈时,只有不到五分之一的人上钩。受试者还对他们与之发短信的每个“人”的信任程度进行了评分,结果 AI 机器人获得了明显更高的分数。

That suggests, the researchers argue, that AI chatbots could soon take over much of the scam process as fully independent fraud agents—even replacing the staffers, often forced-labor human trafficking victims, working in scam operations primarily across Southeast Asia. To avoid triggering the safeguards built into large language models to detect scamming, a human scammer would take over the conversation in just the final stage of the process to direct the victim toward a fake investment app or website. 研究人员认为,这表明 AI 聊天机器人可能很快就会作为完全独立的欺诈代理人接管大部分诈骗过程,甚至取代主要在东南亚诈骗窝点工作的员工(这些员工通常是人口贩运的强迫劳动受害者)。为了避免触发大语言模型中内置的诈骗检测安全机制,人类诈骗者只需在过程的最后阶段接管对话,将受害者引导至虚假投资应用程序或网站即可。

“By having the full first stage of the scam performed automatically with LLMs at scale, you bring the victim up to this point where they have a very high level of trust. Then by transitioning it over to the human scammer at the end, this completely bypasses any vendor safeguards,” says Yisroel Mirsky, a computer science professor at Ben Gurion University of the Negev focused on AI security, who led the research. “With relatively little effort, we’re able to make an agent that can outperform a human at building this exploitable emotional trust.” “通过利用大语言模型(LLM)大规模自动执行诈骗的第一阶段,你可以让受害者达到高度信任的状态。然后通过在最后阶段将其移交给人类诈骗者,这完全绕过了任何供应商的安全防护,”领导这项研究的内盖夫本·古里安大学专注于 AI 安全的计算机科学教授 Yisroel Mirsky 表示。“我们只需付出相对较少的努力,就能制造出一个在建立这种可被利用的情感信任方面胜过人类的代理人。”

Hook, line, and sinker

愿者上钩

To understand how pig butchering works in practice, the researchers interviewed 145 former scam workers, including human-trafficking survivors who had been forced to work in scam compounds in Cambodia, Myanmar, and Laos. Based in part on those interviews, as well as scam transcripts and guides the former scam workers provided, the researchers describe a model for how scamming works they call “hook, line, and sinker.” 为了了解“杀猪盘”在实践中是如何运作的,研究人员采访了 145 名以前的诈骗从业者,其中包括被迫在柬埔寨、缅甸和老挝的诈骗园区工作的贩运受害者。基于这些采访以及前诈骗者提供的诈骗记录和指南,研究人员描述了一种他们称之为“愿者上钩”(hook, line, and sinker)的诈骗运作模式。

A victim is hooked with an initial intriguing message, reeled in with long-term, relationship-building conversation, and only at the end of that process tricked into making a fake investment. (The term “pig butchering” itself describes the same system but with the metaphor of fattening “pigs” by building trust before “butchering” them with the investment fraud—though the term is often discouraged due to its pejorative reference to victims.) 受害者首先被一条引人入胜的信息“钩住”,通过长期的关系建立对话被“拉入”,只有在过程的最后才被诱骗进行虚假投资。(“杀猪盘”一词本身描述了同样的系统,但使用了通过建立信任来“养肥猪”,然后再通过投资欺诈来“宰杀”它们的隐喻——尽管由于该词对受害者有贬义,通常不建议使用。)

In that system of scamming, the researchers realized, the vast majority of scammers’ work is innocuous friendly or romantic conversation. That’s a task, they speculated, that an LLM might be capable of doing just as well as a human. The scam workers the researchers interviewed confirmed that they often used AI to refine their language and conversation, for translation, to make the fake personae they played more convincing, and for video deepfakes. 研究人员意识到,在这种诈骗系统中,绝大多数诈骗者的工作是无害的友好或浪漫对话。他们推测,大语言模型可能能够像人类一样出色地完成这项任务。受访的诈骗者证实,他们经常使用人工智能来润色语言和对话、进行翻译、使他们扮演的虚假角色更具说服力,以及制作视频深度伪造(deepfakes)。

But the researchers decided to test whether an LLM alone could autonomously carry out the conversational phase of the scam with no human in the loop. In their bake-off between AI and human scammers, carried out in early 2025, they told a test subject they were participating in a study in “how people make friends online” and asked them to text for a week with two “people.” One, unbeknownst to them, was a Claude agent the researchers had created, while the other was a person the researchers describe as an expert in romance scams. 但研究人员决定测试大语言模型是否可以在没有人类参与的情况下,自主执行诈骗的对话阶段。在 2025 年初进行的 AI 与人类诈骗者的“比武”中,他们告诉测试对象他们正在参与一项关于“人们如何在线交友”的研究,并要求他们与两个“人”发短信一周。其中一个(受试者不知情)是研究人员创建的 Claude 代理,而另一个是研究人员描述的浪漫诈骗专家。

At the end of that week of friendly chatter, they had both the human and AI texters make a request: The human tried to get the subject to download and play a video game, while the Claude bot asked them to download and try an app described as a program they had coded. (That mismatch of tasks, the researchers say, was necessary for the test subject to not notice the same request from both texters, which might make them suspect the significance of the request and affect their response.) 在那一周的友好聊天结束时,他们让发短信的人类和 AI 都提出了一个请求:人类试图让受试者下载并玩一款电子游戏,而 Claude 机器人则要求他们下载并尝试一个被描述为他们自己编写的应用程序。(研究人员表示,这种任务的不匹配对于测试对象不注意到两个发短信者提出相同的请求是必要的,因为这可能会让他们怀疑请求的意图并影响他们的反应。)

The researchers found that 46 percent of the research subjects agreed to download the app the AI chatbot requested they test out, while only 18 percent of them agreed to download the video game app the humans asked them to try. Despite the asymmetry of those tasks, t 研究人员发现,46% 的研究对象同意下载 AI 聊天机器人要求他们测试的应用程序,而只有 18% 的人同意下载人类要求他们尝试的电子游戏应用程序。尽管这些任务存在不对称性,但……