An Explainable Lightweight Phishing Website Detection Framework Using Consensus Feature Selection and Performance-Weighted Ensemble Learning
DOI:
https://doi.org/10.31033/ABJAR/5.3.2026.120Keywords:
phishing detection, explainable artificial intelligence, SHAP, feature selection, ensemble learning, cybersecurityAbstract
Phishing websites continue to pose a significant cybersecurity threat by deceiving users into disclosing sensitive information through fraudulent web pages that closely imitate legitimate services. Although machine learning has significantly improved phishing detection, many existing approaches rely on high-dimensional feature sets, exhibit limited interpretability, or incur substantial computational overhead. To address these challenges, this paper proposes an explainable lightweight phishing website detection framework that combines consensus feature selection with performance-weighted ensemble learning. The proposed framework first employs Recursive Feature Elimination (RFE), Mutual Information (MI), and SHAP (SHapley Additive exPlanations) to identify the most informative URL-based features through a consensus voting strategy. This process reduces the original 22 URL features to 10 highly discriminative features while preserving classification performance. Subsequently, multiple ensemble classifiers are trained using the selected features, and a Performance-Weighted Consensus Ensemble (PWCE) is constructed by combining classifier probabilities according to their validation performance. Experiments conducted on the publicly available PhiUSIIL Phishing URL dataset demonstrate that the proposed framework achieves an accuracy of 99.987%, an F1-score of 99.989%, and a ROC-AUC of 99.989% while substantially reducing feature dimensionality. Comprehensive evaluations, including five-fold cross-validation, SHAP-based explainability, runtime analysis, calibration assessment, and feature ablation studies, confirm the robustness, efficiency, and interpretability of the proposed framework. The experimental results indicate that accurate phishing detection can be achieved using a compact set of explainable URL features, making the proposed approach suitable for real-time cybersecurity applications.
Downloads
References
L. Tang, & Q. H. Mahmoud. (2021). A survey of machine learning-based solutions for phishing website detection. Machine Learning and Knowledge Extraction, 3(3), 672–694.
A. Almomani, et al. (2023). A systematic literature review on phishing website detection techniques. Journal of King Saud University – Computer and Information Sciences, 35(2), 590–611.
A. Hannousse, & S. Yahiouche. (2021). Towards benchmark datasets for machine learning based website phishing detection: An experimental study. Engineering Applications of Artificial Intelligence, 104, 104347.
M. C. Calzarossa, P. Giudici, & R. Zieni. (2024). Explainable machine learning for phishing feature detection. Quality and Reliability Engineering International, 40, 362–373.
S. S. Shafin. (2025). An explainable feature selection framework for web phishing detection with machine learning. Data Science and Management, 8(2), 127–136.
Ma, J., Saul, L. K., Savage, S., & Voelker, G. M. (2009). Beyond blacklists: Learning to detect malicious web sites from suspicious URLs. Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1245–1254. https://doi.org/10.1145/1557019.1557153
Le, H., Pham, Q., Sahoo, D., & Hoi, S. C. H. (2018). URLNet: Learning a URL representation with deep learning for malicious URL detection. arXiv preprint arXiv:1802.03162.
https://www.kaggle.com/datasets/sharmageetika/phishing-url-dataset.
Bahnsen, A. C., Torroledo, I., Camacho, J., & Vargas, S. (2017). Classifying phishing URLs using recurrent neural networks. APWG Symposium on Electronic Crime Research (eCrime).
Aburrous, M., Hossain, M. A., Dahal, K., & Thabtah, F. (2010). Intelligent phishing website detection system using fuzzy techniques. Expert Systems with Applications, 37(3), 2677–2683.
Sahingoz, O. K., Buber, E., Demir, O., & Diri, B. (2019). Machine learning based phishing detection from URLs. Expert Systems with Applications, 117, 345–357.
Lundberg, S. M., & Lee, S. I. (2017). A unified approach to interpreting model predictions. Advances in Neural Information Processing Systems (NeurIPS 2017).
Guyon, I., Weston, J., Barnhill, S., & Vapnik, V. (2002). Gene selection for cancer classification using support vector machines. Machine Learning, 46(1–3), 389–422.
Peng, H., Long, F., & Ding, C. (2005). Feature selection based on mutual information criteria of max-dependency, max-relevance, and min-redundancy. IEEE Transactions on Pattern Analysis and Machine Intelligence, 27(8), 1226–1238.
Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 785–794.
Ke, G., Meng, Q., Finley, T., Wang, T., Chen, W., Ma, W., Ye, Q., & Liu, T. Y. (2017). LightGBM: A highly efficient gradient boosting decision tree. Advances in Neural Information Processing Systems (NeurIPS 2017).
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Anjali Singh

This work is licensed under a Creative Commons Attribution 4.0 International License.
Research Articles in 'Applied Science and Biotechnology Journal for Advanced Research' are Open Access articles published under the Creative Commons CC BY License Creative Commons Attribution 4.0 International License http://creativecommons.org/licenses/by/4.0/. This license allows you to share – copy and redistribute the material in any medium or format. Adapt – remix, transform, and build upon the material for any purpose, even commercially.