Using Small Language Models to Predict Psychological Vulnerabilities in Cybersec
github.com
github.com
Fine-tuned Phi-3 Mini on synthetic data mapping 100 psychological indicators across 10 vulnerability categories Implemented differential privacy (epsilon < 0.8) to prevent individual profiling while enabling aggregate analysis Real-time inference with quantization and ONNX optimization for edge deployment Complete Docker stack with SIEM integration patterns
Key challenges solved:
Privacy-preserving psychological assessment in workplace environments Balancing accuracy vs inference speed for real-time security operations Creating synthetic training data that captures psychological manipulation patterns Integrating with existing security workflows (Splunk, Phantom, etc.)
The framework moves beyond "train users to be more secure" (which doesn't work) toward "predict when users are vulnerable" (which does). Early pilot shows 47% reduction in successful social engineering attacks. I've released two implementation guides: a 7-page quick-start for prototyping and a 67-page production deployment guide with complete working code. Both include validation methodologies for measuring real-world effectiveness. The approach generalizes beyond security - any domain where psychological states influence decision-making could benefit from this predictive capability. Code and documentation: [link to repository] Live demo: [link to Hugging Face Space] What are your thoughts on using psychological frameworks in AI systems? Have you encountered similar challenges with human factors in security?
I'm on my phone and can't dive deep right now, but are you able to create detections in SIEMs to identify these kinds of users and behaviors based on this research?