Ijraset Journal For Research in Applied Science and Engineering Technology
Authors: Eda Kavya, A S N Chakravarthy
DOI Link: https://doi.org/10.22214/ijraset.2026.84746
Certificate: View Certificate
Phishing attacks remain a prevalent and rapidly evolving cybersecurity threat, leveraging deceptive Uniform Resource Locators (URLs) and fraudulent websites to steal sensitive user data, financial credentials, and personal information. Traditional detection mechanisms, such as blacklist-based and heuristic approaches, struggle to mitigate zero-day phishing threats due to their reliance on static, manually updated databases. While machine learning and ensemble techniques have enhanced detection accuracy, existing literature predominantly focuses on offline evaluations using static datasets, offering limited support for real-time deployment, adaptability to evolving attack patterns, and continuous monitoring. To bridge this gap, this paper introduces a hybrid machine learning framework for real-time phishing website detection. The proposed architecture integrates an Artificial Neural Network (ANN) and a Bagging K-Nearest Neighbors (Bagging-KNN) classifier through a Logistic Regression-based stacking ensemble, combining their complementary learning capabilities to maximize classification performance while minimizing prediction error. Developed using the PhiUSIIL Phishing URL Dataset, the framework implements a leakage-free machine learning pipeline encompassing automated data cleaning, a train/test split performed prior to any preprocessing, feature engineering, StandardScaler-based normalization, SMOTE-based class balancing, and SelectKBest feature selection, all splitting-dependent steps fitted exclusively on the training partition. The framework’s efficacy is validated using Accuracy, Precision, Recall, F1-score, ROC-AUC, and Confusion Matrix analysis. Beyond offline validation, the model is operationalized through two real-time deployment channels: a Gradio-based web interface for on-demand URL analysis, and a Chrome browser extension that automatically screens the active browser tab using a combination of rule-based checks, live queries to the deployed model, and a local heuristic fallback. By unifying ensemble learning, a leakage-conscious preprocessing pipeline, and dual real-time deployment tools, the proposed framework provides an effective, transparently evaluated solution for real-world phishing detection, while explicitly discussing the boundaries within which its strongest offline results should be interpreted.
The text presents a machine-learning-based phishing URL detection system designed to identify malicious URLs and provide real-time protection through both a web application and a Chrome browser extension.
Phishing attacks are a major cybersecurity threat because attackers use deceptive URLs to steal credentials, commit financial fraud, and distribute malware. Traditional blacklist-based detection has limitations because modern phishing campaigns frequently change domains, use free hosting, impersonate legitimate brands, and hide malicious characteristics through URL obfuscation.
To overcome these limitations, the study uses machine learning to detect phishing URLs based on their structural and lexical characteristics, without depending entirely on live webpage content.
The proposed system uses a hybrid stacking ensemble consisting of:
This combination is intended to take advantage of the different strengths of neural-network and instance-based learning.
The model was trained using the PhiUSIIL Phishing URL Dataset, containing legitimate and phishing URLs with numerous URL, domain, security, and webpage-related features.
A sample of 50,000 records was used for training and evaluation. The target labels were:
Several non-predictive identifier fields, including URL and domain identifiers, were removed before modeling.
A major contribution of the study is its data-leakage-safe preprocessing pipeline.
The process follows this order:
The test set is never used during scaling, SMOTE, or feature selection, helping prevent information leakage and making the evaluation more reliable.
The ANN uses a multilayer perceptron with:
The second base learner is a bagging ensemble of 10 KNN classifiers, with each KNN using k=5 and training on a random 80% subset of the training data.
Their outputs are combined using Logistic Regression through a stacking framework with 5-fold stratified cross-validation.
The proposed model was evaluated on 11,750 test samples.
The reported confusion matrix shows:
| Actual / Predicted | Legitimate | Phishing |
|---|---|---|
| Legitimate | 5,875 | 0 |
| Phishing | 0 | 5,875 |
The model therefore produced no false positives or false negatives on the reported test set.
Reported performance metrics were:
These results indicate perfect classification performance on the selected test set.
The system is not limited to offline experimentation. It is deployed through two interfaces:
This practical deployment distinguishes the study from many previous works that evaluate phishing models only using offline datasets.
The study identifies that much existing phishing research focuses on offline classification, while relatively little attention is given to real-time deployment and the difference between features available during offline training and those available when detecting a URL in practice.
The main contributions are therefore:
This paper presented a hybrid stacking ensemble for phishing URL detection, combining an ANN and Bagging KNN as base learners with a Logistic Regression meta-learner, trained using a leakage-conscious pipeline in which all splitting-dependent operations were fitted exclusively on the training partition. The stacking ensemble achieved perfect classification (Accuracy, Precision, Recall, F1-Score, and AUC-ROC all 1.0000) on the held-out test set, a result interpreted with explicit caution regarding content-based feature separability and test-set class balance rather than presented as unqualified superiority. The trained model was deployed through a Gradio web interface and a companion Chrome browser extension, together demonstrating both on-demand and passive real-time detection use cases, validated through a documented live test case on the browser extension.
[1] S. Naseeb, S. Ramzan, A. Raza, M. S. A. Hashmi, Y. H. Gu, M. Syafrudin, and N. L. Fitriyani, “Website phishing attack detection using innovative meta-learning based ensemble approach,” IEEE Access, vol. 13, pp. 164249–164264, 2025. [2] P. Jain, R. Sharma, and A. Gupta, “Phishing website detection using ensemble machine learning techniques,” International Journal of Computer Applications, vol. 185, no. 12, pp. 10–16, 2025. [3] D. T. H. Tham, “Meta-ensemble learning model for phishing website detection,” Journal of Cybersecurity and Privacy, vol. 5, no. 2, pp. 145–158, 2025. [4] S. Giri and S. Banerjee, “Greedy stacking ensemble model for phishing website detection,” International Journal of Information Security, vol. 23, pp. 311–325, 2024. [5] P. T. Duy, T. Nguyen, and L. Pham, “Multimodal learning framework for phishing attack detection using GAN-based adversarial training,” IEEE Transactions on Information Forensics and Security, vol. 19, pp. 2241–2255, 2024. [6] M. Dubey, A. Tripathi, A. Srivastava, and S. Singh, “Phishing detection system: An ensemble approach using character-level CNN and feature engineering,” arXiv preprint, 2025. [7] R. Ji, Y. Zhang, and Q. Wang, “Stacked ensemble model with autoencoder for intrusion detection,” Computers & Security, vol. 130, 2025. [8] S. I. Nova, M. Rahman, and T. Ahmed, “Multi-feature extraction with ensemble learning for phishing website detection,” International Journal of Advanced Computer Science and Applications, vol. 15, no. 4, pp. 233–241, 2024. [9] J. Patni, A. Khandelwal, and S. Verma, “Natural language processing based phishing website detection,” Procedia Computer Science, vol. 215, pp. 521–528, 2025. [10] A. Rahmadeyan, H. Al-Qudah, and S. Khan, “Phishing website detection using artificial neural network and AdaBoost,” Journal of Information Security and Applications, vol. 73, 2023. [11] Z. Alamri, A. Alharbi, and M. Alotaibi, “Optimized ensemble stacking model for phishing website detection,” Future Internet, vol. 17, no. 1, pp. 1–18, 2025. [12] A. Shabbir, M. Iqbal, and F. Khan, “Stacking deep learning models for intelligent pattern detection systems,” IEEE Access, vol. 12, pp. 11034–11046, 2024. [13] H. A. Hilal, “Deep learning-based classification for phishing URL detection,” International Journal of Cybersecurity Intelligence & Cybercrime, vol. 8, no. 1, pp. 45–56, 2025. [14] J. Jesmitha, R. Kumar, and P. Reddy, “Machine learning-based phishing detection with real-time email alert system,” International Journal of Engineering Research and Technology, vol. 14, no. 3, pp. 210–217, 2025. [15] M. Patel, S. Shah, and D. Mehta, “Phishing URL detection using machine learning algorithms,” Journal of Network and Computer Applications, vol. 215, 2025. [16] K. L. Chihnavi, R. Ramesh, and A. Kumar, “Ensemble machine learning framework for phishing website detection,” International Journal of Advanced Research in Computer Science, vol. 16, no. 2, pp. 98–105, 2025. [17] S. Kavya and D. Sumathi, “Hybrid artificial intelligence model for phishing website detection using genetic algorithm,” Expert Systems with Applications, vol. 234, 2024. [18] T. Gandhi, R. Sharma, and P. Agarwal, “BLPDS: Deep learning framework for phishing webpage detection,” IEEE Access, vol. 12, pp. 22145–22158, 2024. [19] K. V. Deshpande and J. Singh, “A systematic review of machine learning techniques for phishing detection,” ACM Computing Surveys, vol. 57, no. 2, 2025. [20] H. Saini and N. Kaur, “Ensemble machine learning approach for phishing URL detection,” International Journal of Information Security Science, vol. 14, no. 1, pp. 55–64, 2025. [21] Prabavathi T. and M. M., “A hybrid deep learning and ensemble framework for real-time phishing website detection using optimized feature selection,” in Proc. 2025 3rd International Conference on Intelligent Cyber Physical Systems and Internet of Things (ICoICI), 2025. [22] A. Sharma and A. Rajput, “A hybrid ensemble learning framework for efficient and real-time phishing website detection using optimized URL and domain features,” Dandao Xuebao (Journal of Ballistics), 2026. [23] S., Gokulnath K., Irfan Mohamed, Manikandan M., and R. A., “Cross-browser real-time phishing website detection framework using behavioral analysis and machine learning,” Indian Journal of Computer Science and Technology, 2026. [24] P. S., S. R., and Thirishya M., “HPD: A hybrid ML system for real-time phishing website detection,” International Journal of Innovative Science and Research Technology, 2025. [25] A. Kulaglic and M. A. B. Al-Tarawneh, “Adaptive phishing website detection using incremental machine learning: A dynamic approach to cybersecurity threats,” International Journal of Advanced Computer Science and Applications, 2026. [26] N. Alsuqayh, A. Mirza, and A. Alhogail, “Exploring feature engineering and explainable AI for phishing website detection: A systematic literature review,” International Journal of Electrical and Computer Engineering, 2025. [27] Shammi L. and Emilin Shyni C., “Stacking ensemble classifier for phishing detection: A cyber security model with efficient feature descriptor,” International Journal of Intelligent Decision Technologies, 2025. [28] K. Jishnu and B. Arthi, “Real-time phishing URL detection framework using knowledge distilled ELECTRA,” Automatika, 2024. [29] A. S. Araujo Arévalo, G. A. Felix-Diaz Monzon, and J. P. Mansilla Lopez, “Intelligent system for phishing detection on web pages using random forest,” in Proc. LACCEI International Multi-Conference for Engineering, Education and Technology, 2023. [30] S. Alnemari and M. Alshammari, “Detecting phishing domains using machine learning,” Applied Sciences, 2023.
Copyright © 2026 Eda Kavya, A S N Chakravarthy. This is an open access article distributed under the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
Paper Id : IJRASET84746
Publish Date : 2026-08-29
ISSN : 2321-9653
Publisher Name : IJRASET
DOI Link : Click Here
Submit Paper Online
