Title: Adversarial threat evaluation of machine learning-based phishing detectors: a cybersecurity-focused black-box perspective
Authors: Eiman Tamah Al-Shammari
Addresses: Department of Information Science, College of Life Sciences, Kuwait University, Sabah Al Salem University City, P.O. Box 5969, Safat 13060, Shadadiya, Kuwait
Abstract: Phishing attacks often succeed through subtle URL modifications that evade detection. We evaluated five URL-based classifiers under a label-preserving black-box attacker with a fixed edit budget across three scenarios: unaltered data, edited phishing URLs, and mixed streams. Model reasoning was examined using permutation-based importance, TreeSHAP, and Kernel-LIME. On clean data, ensemble models achieved F1 scores of approximately 0.981, MLP reached 0.978, and linear models attained 0.971. Under maximum perturbation (k = 9), XGBoost and MLP maintained F1 above 0.975, while other models declined slightly. Precision remained stable; decreases reflected missed detections. A lightweight augmentation technique improved adversarial recall by 0.003 to 0.007 without reducing precision. Attribution analysis showed ensemble models shifted toward fragile features as edits increased, and growing SHAP-LIME divergence may indicate stability drift during deployment.
Keywords: phishing detection; adversarial robustness; URL features; mixed‑set evaluation; SHAP; LIME; interpretability.
DOI: 10.1504/IJICS.2026.153346
International Journal of Information and Computer Security, 2026 Vol.29 No.4, pp.436 - 450
Received: 12 Apr 2025
Accepted: 20 Sep 2025
Published online: 01 May 2026 *