Skip to content
#explainable ai Open access

Explainable AI for phishing URL detection: a Bayesian-optimized stacking ensemble framework with SHAP-guided feature learning

Oct 2026 · Frontiers in Artificial Intelligence · 0 citations · 41 references
Spam and Phishing Detection

Abstract

Phishing remains one of the most persistent and financially damaging threats facing modern organizations, with over 4.7 million incidents recorded in 2023 alone. Existing AI-based phishing detection frameworks are constrained by limited benchmarking scope, absent model interpretability, and insufficient statistical validation — three limitations that collectively restrict operational utility in real-world security environments. We present an explainable, end-to-end machine learning pipeline evaluated on a large public benchmark of 247,950 URLs described by 41 structural and lexical features. The pipeline integrates SHAP-driven feature selection (reducing 41 to 24 features via a 95% cumulative-signal rule), a systematic benchmark of 12 classifiers spanning seven algorithmic families, Bayesian hyperparameter optimization via Optuna TPE sampling (40 trials each for XGBoost and CatBoost), and a heterogeneous stacking ensemble combining Optuna-tuned XGBoost, CatBoost, Extra Trees, and Random Forest under a logistic-regression meta-learner. A four-layer statistical validation protocol — comprising a Friedman omnibus test, Wilcoxon signed-rank tests, paired t-tests, and Cohen's d effect sizes — was applied to five-fold cross-validation accuracy distributions to assess directional consistency, with the limited inferential resolution of five folds explicitly acknowledged. SHAP-driven selection reduced the feature space by 41.5% while retaining 95% of predictive signal. The stacking ensemble achieved 96.75% accuracy, 96.74% F1-score, and AUC of 0.9947, attaining the lowest Brier score among all 13 models (0.0246), indicating superior probability calibration. The Friedman omnibus test confirmed significant performance differences across models (χ 2 F = 59.84, p < 0.0001), and all 12 Wilcoxon pairwise comparisons yielded the minimum attainable p-value ( p = 0.0313), confirming the ensemble never lost a cross-validation fold against any baseline. Post-hoc SHAP analysis identified subdomain structure, URL length, and URL entropy as the dominant phishing indicators at both ensemble and base-learner levels. The co-leaders — the stacking ensemble and Extra Trees — demonstrate that rigorous, interpretable AI pipelines can advance phishing detection accuracy and transparency simultaneously. The framework's calibrated risk scores, threshold flexibility, and multi-level SHAP explainability support analyst-facing decision-making in security operations, while its leakage-free

Read PDF

Similar papers

#artificial intelligence Conference Open access Apr 2020

ECCOLA - a Method for Implementing Ethically Aligned AI Systems

The method, ECCOLA, is presented, which aims at making the high-level AI ethics principles more practical, making it possible for developers to more easily implement them in practice.

Ville Vakkuri, Kai-Kristian Kemell, P. Abrahamsson · 64 citations · ⚡6
#computer vision Review Apr 2024

AI-powered Code Review with LLMs: Early Results

The goal is to not only refine the accuracy of the LLM-based tool but also to underscore its potential in streamlining the software development lifecycle through proactive code improvement and education.

Z. Rasheed, Malik Abdul Sami, Muhammad Waseem et al. · 62 citations · ⚡3
#computer vision Open access Mar 2024

LLM-based agents for automating the enhancement of user story quality: An early report

The use of large language models to automatically improve the user story quality in Austrian Post Group IT agile teams is explored, with a reference model for an Autonomous LLM-based Agent System developed and implemented at the company.

Zheying Zhang, M. Rayhan, Tomas Herda et al. · 48 citations · ⚡4
#computer vision Review Mar 2024

System for systematic literature review using multiple AI agents: Concept and an empirical evaluation

This paper introduces a novel multi-AI-agent system designed to fully automate SLRs, and demonstrates how it substantially reduces the time and effort traditionally required for SLRs while maintaining comprehensiveness and precision.

Abdul Malik Sami, Z. Rasheed, Kai-Kristian Kemell et al. · 44 citations · ⚡2
#computer vision Feb 2024

Can Large Language Models Serve as Data Analysts? A Multi-Agent Assisted Approach for Qualitative Data Analysis

The proposed LLM-based multi-agent system automates qualitative data analysis process, creating opportunities for researchers and practitioners, and future improvements focus on enhancing multilingual performance and integrating continuous expert feedback.

Z. Rasheed, Muhammad Waseem, Aakash Ahmad et al. · 41 citations
#artificial intelligence Conference Open access Jun 2018

The Key Concepts of Ethics of Artificial Intelligence

It is suggested that the focus on finding keywords is the first step in guiding and providing direction for future research in the AI ethics field.

Ville Vakkuri, P. Abrahamsson · 39 citations · ⚡2

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.