Title: Adversarial threat evaluation of machine learning-based phishing detectors: a cybersecurity-focused black-box perspective

Authors: Eiman Tamah Al-Shammari

Addresses: Department of Information Science, College of Life Sciences, Kuwait University, Sabah Al Salem University City, P.O. Box 5969, Safat 13060, Shadadiya, Kuwait

Abstract: Phishing attacks often succeed through subtle URL modifications that evade detection. We evaluated five URL-based classifiers under a label-preserving black-box attacker with a fixed edit budget across three scenarios: unaltered data, edited phishing URLs, and mixed streams. Model reasoning was examined using permutation-based importance, TreeSHAP, and Kernel-LIME. On clean data, ensemble models achieved F1 scores of approximately 0.981, MLP reached 0.978, and linear models attained 0.971. Under maximum perturbation (k = 9), XGBoost and MLP maintained F1 above 0.975, while other models declined slightly. Precision remained stable; decreases reflected missed detections. A lightweight augmentation technique improved adversarial recall by 0.003 to 0.007 without reducing precision. Attribution analysis showed ensemble models shifted toward fragile features as edits increased, and growing SHAP-LIME divergence may indicate stability drift during deployment.

Keywords: phishing detection; adversarial robustness; URL features; mixed‑set evaluation; SHAP; LIME; interpretability.

DOI: 10.1504/IJICS.2026.153346

International Journal of Information and Computer Security, 2026 Vol.29 No.4, pp.436 - 450

Received: 12 Apr 2025
Accepted: 20 Sep 2025

Published online: 01 May 2026 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article