An Explainable Lightweight Phishing Website Detection Framework Using Consensus Feature Selection and Performance-Weighted Ensemble Learning

Authors

  • Anjali Singh Department of Computer Science and Engineering, Netaji Subhas University of Technology, Dwarka, New Delhi, India

DOI:

https://doi.org/10.31033/ABJAR/5.3.2026.120

Keywords:

phishing detection, explainable artificial intelligence, SHAP, feature selection, ensemble learning, cybersecurity

Abstract

Phishing websites continue to pose a significant cybersecurity threat by deceiving users into disclosing sensitive information through fraudulent web pages that closely imitate legitimate services. Although machine learning has significantly improved phishing detection, many existing approaches rely on high-dimensional feature sets, exhibit limited interpretability, or incur substantial computational overhead. To address these challenges, this paper proposes an explainable lightweight phishing website detection framework that combines consensus feature selection with performance-weighted ensemble learning. The proposed framework first employs Recursive Feature Elimination (RFE), Mutual Information (MI), and SHAP (SHapley Additive exPlanations) to identify the most informative URL-based features through a consensus voting strategy. This process reduces the original 22 URL features to 10 highly discriminative features while preserving classification performance. Subsequently, multiple ensemble classifiers are trained using the selected features, and a Performance-Weighted Consensus Ensemble (PWCE) is constructed by combining classifier probabilities according to their validation performance. Experiments conducted on the publicly available PhiUSIIL Phishing URL dataset demonstrate that the proposed framework achieves an accuracy of 99.987%, an F1-score of 99.989%, and a ROC-AUC of 99.989% while substantially reducing feature dimensionality. Comprehensive evaluations, including five-fold cross-validation, SHAP-based explainability, runtime analysis, calibration assessment, and feature ablation studies, confirm the robustness, efficiency, and interpretability of the proposed framework. The experimental results indicate that accurate phishing detection can be achieved using a compact set of explainable URL features, making the proposed approach suitable for real-time cybersecurity applications.

Downloads

Download data is not yet available.

References

L. Tang, & Q. H. Mahmoud. (2021). A survey of machine learning-based solutions for phishing website detection. Machine Learning and Knowledge Extraction, 3(3), 672–694.

A. Almomani, et al. (2023). A systematic literature review on phishing website detection techniques. Journal of King Saud University – Computer and Information Sciences, 35(2), 590–611.

A. Hannousse, & S. Yahiouche. (2021). Towards benchmark datasets for machine learning based website phishing detection: An experimental study. Engineering Applications of Artificial Intelligence, 104, 104347.

M. C. Calzarossa, P. Giudici, & R. Zieni. (2024). Explainable machine learning for phishing feature detection. Quality and Reliability Engineering International, 40, 362–373.

S. S. Shafin. (2025). An explainable feature selection framework for web phishing detection with machine learning. Data Science and Management, 8(2), 127–136.

Ma, J., Saul, L. K., Savage, S., & Voelker, G. M. (2009). Beyond blacklists: Learning to detect malicious web sites from suspicious URLs. Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1245–1254. https://doi.org/10.1145/1557019.1557153

Le, H., Pham, Q., Sahoo, D., & Hoi, S. C. H. (2018). URLNet: Learning a URL representation with deep learning for malicious URL detection. arXiv preprint arXiv:1802.03162.

https://www.kaggle.com/datasets/sharmageetika/phishing-url-dataset.

Bahnsen, A. C., Torroledo, I., Camacho, J., & Vargas, S. (2017). Classifying phishing URLs using recurrent neural networks. APWG Symposium on Electronic Crime Research (eCrime).

Aburrous, M., Hossain, M. A., Dahal, K., & Thabtah, F. (2010). Intelligent phishing website detection system using fuzzy techniques. Expert Systems with Applications, 37(3), 2677–2683.

Sahingoz, O. K., Buber, E., Demir, O., & Diri, B. (2019). Machine learning based phishing detection from URLs. Expert Systems with Applications, 117, 345–357.

Lundberg, S. M., & Lee, S. I. (2017). A unified approach to interpreting model predictions. Advances in Neural Information Processing Systems (NeurIPS 2017).

Guyon, I., Weston, J., Barnhill, S., & Vapnik, V. (2002). Gene selection for cancer classification using support vector machines. Machine Learning, 46(1–3), 389–422.

Peng, H., Long, F., & Ding, C. (2005). Feature selection based on mutual information criteria of max-dependency, max-relevance, and min-redundancy. IEEE Transactions on Pattern Analysis and Machine Intelligence, 27(8), 1226–1238.

Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 785–794.

Ke, G., Meng, Q., Finley, T., Wang, T., Chen, W., Ma, W., Ye, Q., & Liu, T. Y. (2017). LightGBM: A highly efficient gradient boosting decision tree. Advances in Neural Information Processing Systems (NeurIPS 2017).

Published

2026-05-30
CITATION
DOI: 10.31033/ABJAR/5.3.2026.120
Published: 2026-05-30

How to Cite

Singh, A. (2026). An Explainable Lightweight Phishing Website Detection Framework Using Consensus Feature Selection and Performance-Weighted Ensemble Learning. Applied Science and Biotechnology Journal for Advanced Research, 5(3), 42–57. https://doi.org/10.31033/ABJAR/5.3.2026.120

Issue

Section

Articles