Main Article Content

Phishing website detection using explainable artificial intelligence


Betty Osamegbe Ahubele
Osamudiamen Nelson

Abstract

Phishing attacks remain a pervasive and critically evolving cyber threat, exploiting human psychology and technical vulnerabilities. Traditional countermeasures, like signature-based systems, fail against sophisticated zero-day attacks due to a lack of adaptability. Machine learning (ML) models offer improved detection but often function as "black boxes," providing no insight into their decisions, which hinders trust and adoption. This study addresses this gap by developing a real-time phishing detection system that integrates high accuracy with operational transparency through Explainable AI (XAI). An ensemble ML model combining Random Forest and XGBoost was implemented, with features engineered from Natural Language Processing (BERT embeddings, TF-IDF) and heuristic analysis (URL entropy). The core innovation is the integration of XAI techniques (SHAP) to provide interpretable justifications for each prediction. The system was deployed as a browser extension and a Flask-based API. Evaluation demonstrated robust performance with 95.0% accuracy, 92.0% recall, and a 93.0% F1-score on an independent test set. The XAI components successfully generated actionable insights, fostering transparency. This work presents a viable pathway for developing trustworthy, user-centric cybersecurity tools applicable within institutional and national contexts.


Journal Identifiers


eISSN: 2635-3490
print ISSN: 2476-8316