arXiv ScienceSearch

arXiv · 2609.00806

Effective Interventions Against AI-Enhanced Scams

Abstract

In 2025, scams were responsible for an estimated $442 billion in direct losses globally. In the United States, reported losses increased by nearly 400% between 2020 and 2025. Though AI in scamming is a relatively new phenomenon, its use significantly changes the economics of scams as well as the bottlenecks in scam operations. In this paper I investigate what interventions will remain effective under this new AI-driven scamming regime. I develop a simple model of scam profits to understand how different interventions asymptotically affect scam operations. I find that three levers--reporting rate, centralization of reporting, and report accuracy--multiply in their effect on expected victims per scam channel, reducing revenue per scam channel while increasing costs. Because effects multiply, interventions affecting all three could have a significant effect on the profitability of the scam business model. My analysis suggests that even modest reporting rates against high-value scam infrastructure could have significant impacts on scam profitability.

Explore related subjects

Keep this discovery

BibTeXRIS

Kyle Fredrickson. 2026-09-01. Effective Interventions Against AI-Enhanced Scams. https://arxiv.org/abs/2609.00806

Cite the original work for its findings. Save a collection to share your selection of sources.

Discover connections

Connections use source metadata and explicit phrase matches, not verified experimental comparisons.

KEEP EXPLORING

Related papers

The Five Safes as a Privacy Context

The Five Safes is a framework used by national statistical offices (NSO) for assessing and managing the disclosure risk of data sharing. It can be understood as a specialization of a broader concept--contextual integrity--to the situation of statistical dissemination by an NSO. We demonstrate this by mapping the five parameters of contextual integrity onto the five dimensions of the Five Safes. We also discuss how each of these two theories can address weaknesses in the other, thereby strengthening them both.

cs.CR

Can escalation channels redirect reward hacking toward defect disclosure?

When coding agents encounter defective test infrastructure they may reward-hack: hardcoding outputs or editing test files to pass tests they cannot legitimately satisfy, a pattern that has now appeared outside benchmarks, in a coordinated multi-agent intrusion of a major AI platform's production infrastructure. The same capability that lets an agent detect and exploit a defect could let it report one, given the right decision environment. We evaluate escalation channels, structured reporting tools available to the agent at the point of conflict, as a decision-environment intervention that both reduces reward hacking and surfaces the infrastructure defects that trigger it. A $2 \times 2$ factorial separates the contributions of an escalation tool, a standalone anti-reward-hacking policy, and their combination. Across 8 frontier models spanning 5 families, the combined intervention reduces reward hacking from 23.6% to 5.3% (mixed-effects logistic OR = 9.2, 95% CI 5.0--16.8, $p < 10^{-12}$) with no detectable cost or performance overhead, eliminating it entirely for 6 of 8 models. Escalation and hacking are near-perfectly mutually exclusive, with 98.7% of escalations involving no hacking (100% under the combined intervention). Beyond reduction, escalation channels function as diagnostic infrastructure: on top of monitoring, escalation adds +10.1 percentage points of defect detection coverage and is more accurate once it fires (99.4% vs 85.8%). Unlike containment-based approaches that risk outpacing growing model capabilities, escalation channels redirect capability toward disclosure rather than exploitation.

cs.AI

What's on Your Mind? Exploring Privacy of Mental Health Apps

Therapy and life-coaching apps have grown rapidly in number, variety, and popularity. At the same time, their users often share highly sensitive and personal information, including mental health issues, trauma experiences, fantasies, desires, and relationship difficulties. This prompts the need to examine privacy practices across the ecosystem. In this paper, we present a comprehensive analysis of a corpus of 25 popular Android mental health and life-coaching apps, such as Replika and Headspace. It builds on static analysis and dynamic network traffic analysis, coupled with identifying gaps between each app's observed behavior and its privacy policies. Our analysis highlights serious concerns and substantial transparency gaps. First, every app in our corpus embeds at least one tracker SDK not named in its privacy policy, and 85\% of the apps we instrument fail to disclose at least half of the trackers detected in their APKs. Second, more than half of the apps declare several dangerous permissions without corresponding privacy-policy disclosures, including camera or microphone permissions. Third, nearly half the apps disclose third-party AI processing (e.g., via OpenAI, Anthropic, and Groq) in their privacy policies, while several use only generic language (e.g., "AI services"), failing to identify which company receives user data. Overall, our results show that current disclosure practices fall short of the transparency needed for meaningful informed consent. We argue for a significantly updated regulatory framework for therapy apps that more closely aligns with the professional and ethical standards that bind licensed human therapists.

cs.CR