VeritaPlugin: Uma Extensão de Navegador para Detecção Semântica de Fraudes no Facebook
Resumo
A Engenharia Social em redes sociais explora vulnerabilidades para iludir usuários, tornando defesas técnicas tradicionais insuficientes. Este trabalho apresenta o VeritaPlugin, uma extensão de navegador que detecta fraudes no Facebook por meio de um pipeline híbrido BERTimbau, RAG determinístico e GPT-4o. A arquitetura opera em conformidade com a LGPD e o resultado apresenta ao usuário a categoria do golpe, enquadramento legal e ações recomendadas. Para calibração, foi construído e disponibilizado o dataset BrScamsFacebook, com 450 instâncias de golpes reais do contexto brasileiro. Na avaliação técnica, o classificador obteve F1-macro de 0,763 ± 0,034 na validação cruzada k=5, superando o baseline.Referências
Ariza, M., de Azambuja, A. J. G., Nobre, J. C., and Granville, L. Z. (2022). Ataques automatizados de engenharia social com o uso de bots em redes sociais profissionais. In Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 153–166. SBC.
Bitaab, M., Karimi, A., Lyu, Z., Mosallanezhad, A., Oest, A., Wang, R., Bao, T., Shoshitaishvili, Y., and Doupé, A. (2025). Scamnet: Toward explainable large language model-based fraudulent shopping website detection. In Proceedings of the AAAI Conference on Artificial Intelligence, volume 39, pages 27841–27848.
Bleiman, R., Park, H., and Rege, A. (2025). Educating students on the behavioral and psychological aspects of romance scam victimization via a social engineering competition. Journal of Cybersecurity Education, Research and Practice, 2025(1).
BRASIL (2018). Lei nº 13.709, de 14 de agosto de 2018. lei geral de proteção de dados. [link].
Chen, Y.-H., Chen, J.-L., and Chiu, S.-P. (2025). Ai-enhanced phishing detection: Leveraging advanced transformer-based representations with gan for robust security. In 2025 27th International Conference on Advanced Communications Technology (ICACT), pages 156–161. IEEE.
Cialdini, R. (2007). Influence: the psychology of persuasion (revision edition).
Daim, T., Yalcin, H., Mermoud, A., and Mulder, V. (2024). Exploring cybertechnology standards through bibliometrics: Case of national institute of standards and technology. World Patent Information, 77:102278.
Ferreira, A., Coventry, L., and Lenzini, G. (2015). Principles of persuasion in social engineering and their use in phishing. In International Conference on Human Aspects of Information Security, Privacy, and Trust, pages 36–47. Springer.
Fischer, M., Haque, R., Stynes, P., and Pathak, P. (2022). Identifying fake news in brazilian portuguese. In International Conference on Applications of Natural Language to Information Systems, pages 111–118. Springer.
Frasão, A., Heinrich, T., and Fulber-Garcia, V. (2025). O cenário atual de golpes em redes sociais: uma revisão da literatura. Computer on the beach, 16:1–8.
Jain, A. K., Panday, A., and Goel, D. (2024). S-defender: A smishing detection approach in mobile environment. In International Conference on Cyber Warfare, Security and Space Computing, pages 68–78. Springer.
Jamil, A., Asif, K., Ghulam, Z., Nazir, M. K., Alam, S. M., and Ashraf, R. (2018). Mpmpa: A mitigation and prevention model for social engineering based phishing attacks on facebook. In 2018 IEEE International Conference on Big Data (Big Data), pages 5040–5048. IEEE.
Kemp, S. (2025). Digital 2025: Brazil — DataReportal – Global Digital Insights. [link].
Kotzias, P., Pachilakis, M., Aldana-Iuit, J., Caballero, J., Sánchez-Rola, I., and Bilge, L. (2025). Ctrl+ alt+ deceive: Quantifying user exposure to online scams. In NDSS.
Laor, T. (2022). My social network: Group differences in frequency of use, active use, and interactive use on facebook, instagram and twitter. Technology in Society, 68:101922.
Mehmood, M. K., Arshad, H., Alawida, M., and Mehmood, A. (2024). Enhancing smishing detection: A deep learning approach for improved accuracy and reduced false positives. IEEE Access, 12:137176–137193.
Mitnick, K. D. and Simon, W. L. (2003). The art of deception: Controlling the human element of security. John Wiley & Sons.
Moreira, L. S., Lunardi, G. M., de Oliveira Ribeiro, M., Silva, W., and Basso, F. P. (2023). A study of algorithm-based detection of fake news in brazilian election: Is bert the best. IEEE Latin America Transactions, 21(8):897–903.
Nascimento, A., Gadelha, T., Monteiro, J. M., and Machado, J. (2023). Uma abordagem para detecçao automática de fraudes em aplicativos de mensagens instantâneas. In Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 251–264. SBC.
Nielsen, J. (1994). Enhancing the explanatory power of usability heuristics. In Proceedings of the SIGCHI conference on Human Factors in Computing Systems, pages 152–158.
NIST (2021). National institute of standards and technology - glossary. [link].
Silva, M. L., Teodoro, E. F., and do Couto, D. P. (2024). Psicanálise e redes sociais: as dinâmicas de captura virtual do desejo e digitalização da subjetividade nas cenas do semiocapitalismo. Pretextos-Revista da Graduação em Psicologia da PUC Minas, 9(17):422–442.
Souza, F., Nogueira, R., and Lotufo, R. (2020). Bertimbau: pretrained bert models for brazilian portuguese. In Brazilian conference on intelligent systems, pages 403–417. Springer.
Tan, X. W., See, K., and Kok, S. (2024). Scamgpt-j: Inside the scammer’s mind, a generative ai-based approach toward combating messaging scams. arXiv preprint arXiv:2412.13528.
Wang, Y., Yao, Q., Kwok, J. T., and Ni, L. M. (2020). Generalizing from a few examples: A survey on few-shot learning. ACM computing surveys (csur), 53(3):1–34.
Bitaab, M., Karimi, A., Lyu, Z., Mosallanezhad, A., Oest, A., Wang, R., Bao, T., Shoshitaishvili, Y., and Doupé, A. (2025). Scamnet: Toward explainable large language model-based fraudulent shopping website detection. In Proceedings of the AAAI Conference on Artificial Intelligence, volume 39, pages 27841–27848.
Bleiman, R., Park, H., and Rege, A. (2025). Educating students on the behavioral and psychological aspects of romance scam victimization via a social engineering competition. Journal of Cybersecurity Education, Research and Practice, 2025(1).
BRASIL (2018). Lei nº 13.709, de 14 de agosto de 2018. lei geral de proteção de dados. [link].
Chen, Y.-H., Chen, J.-L., and Chiu, S.-P. (2025). Ai-enhanced phishing detection: Leveraging advanced transformer-based representations with gan for robust security. In 2025 27th International Conference on Advanced Communications Technology (ICACT), pages 156–161. IEEE.
Cialdini, R. (2007). Influence: the psychology of persuasion (revision edition).
Daim, T., Yalcin, H., Mermoud, A., and Mulder, V. (2024). Exploring cybertechnology standards through bibliometrics: Case of national institute of standards and technology. World Patent Information, 77:102278.
Ferreira, A., Coventry, L., and Lenzini, G. (2015). Principles of persuasion in social engineering and their use in phishing. In International Conference on Human Aspects of Information Security, Privacy, and Trust, pages 36–47. Springer.
Fischer, M., Haque, R., Stynes, P., and Pathak, P. (2022). Identifying fake news in brazilian portuguese. In International Conference on Applications of Natural Language to Information Systems, pages 111–118. Springer.
Frasão, A., Heinrich, T., and Fulber-Garcia, V. (2025). O cenário atual de golpes em redes sociais: uma revisão da literatura. Computer on the beach, 16:1–8.
Jain, A. K., Panday, A., and Goel, D. (2024). S-defender: A smishing detection approach in mobile environment. In International Conference on Cyber Warfare, Security and Space Computing, pages 68–78. Springer.
Jamil, A., Asif, K., Ghulam, Z., Nazir, M. K., Alam, S. M., and Ashraf, R. (2018). Mpmpa: A mitigation and prevention model for social engineering based phishing attacks on facebook. In 2018 IEEE International Conference on Big Data (Big Data), pages 5040–5048. IEEE.
Kemp, S. (2025). Digital 2025: Brazil — DataReportal – Global Digital Insights. [link].
Kotzias, P., Pachilakis, M., Aldana-Iuit, J., Caballero, J., Sánchez-Rola, I., and Bilge, L. (2025). Ctrl+ alt+ deceive: Quantifying user exposure to online scams. In NDSS.
Laor, T. (2022). My social network: Group differences in frequency of use, active use, and interactive use on facebook, instagram and twitter. Technology in Society, 68:101922.
Mehmood, M. K., Arshad, H., Alawida, M., and Mehmood, A. (2024). Enhancing smishing detection: A deep learning approach for improved accuracy and reduced false positives. IEEE Access, 12:137176–137193.
Mitnick, K. D. and Simon, W. L. (2003). The art of deception: Controlling the human element of security. John Wiley & Sons.
Moreira, L. S., Lunardi, G. M., de Oliveira Ribeiro, M., Silva, W., and Basso, F. P. (2023). A study of algorithm-based detection of fake news in brazilian election: Is bert the best. IEEE Latin America Transactions, 21(8):897–903.
Nascimento, A., Gadelha, T., Monteiro, J. M., and Machado, J. (2023). Uma abordagem para detecçao automática de fraudes em aplicativos de mensagens instantâneas. In Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSeg), pages 251–264. SBC.
Nielsen, J. (1994). Enhancing the explanatory power of usability heuristics. In Proceedings of the SIGCHI conference on Human Factors in Computing Systems, pages 152–158.
NIST (2021). National institute of standards and technology - glossary. [link].
Silva, M. L., Teodoro, E. F., and do Couto, D. P. (2024). Psicanálise e redes sociais: as dinâmicas de captura virtual do desejo e digitalização da subjetividade nas cenas do semiocapitalismo. Pretextos-Revista da Graduação em Psicologia da PUC Minas, 9(17):422–442.
Souza, F., Nogueira, R., and Lotufo, R. (2020). Bertimbau: pretrained bert models for brazilian portuguese. In Brazilian conference on intelligent systems, pages 403–417. Springer.
Tan, X. W., See, K., and Kok, S. (2024). Scamgpt-j: Inside the scammer’s mind, a generative ai-based approach toward combating messaging scams. arXiv preprint arXiv:2412.13528.
Wang, Y., Yao, Q., Kwok, J. T., and Ni, L. M. (2020). Generalizing from a few examples: A survey on few-shot learning. ACM computing surveys (csur), 53(3):1–34.
Publicado
01/09/2026
Como Citar
NORÕES, Bruna Assis; ROCHA, Bianca Monsores da Silva; MOTTA, Rebeca.
VeritaPlugin: Uma Extensão de Navegador para Detecção Semântica de Fraudes no Facebook. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 1292-1307.
DOI: https://doi.org/10.5753/sbseg.2026.26924.
