PhishTect: A Hybrid SMOTEN–FT-Transformer–PSO Framework for Enhanced Phishing Website Detection on Imbalanced Data

##plugins.themes.bootstrap3.article.main##

M Hizbul Wathan
Muhammad Kalam Sabili

Abstract

Phishing websites remain a major cybersecurity threat, while conventional blacklist-based detection systems often fail to identify newly emerging and zero-day attacks. In addition, phishing datasets are frequently imbalanced, causing machine learning models to exhibit poor minority-class detection performance. To address these challenges, this study proposes PhishTect, a hybrid phishing detection framework that integrates Synthetic Minority Oversampling for Nominal Data (SMOTEN), Feature Tokenizer Transformer (FT-Transformer), and Particle Swarm Optimization (PSO). Unlike existing approaches that typically focus on balancing, deep learning, or optimization techniques separately, the proposed framework combines these components within a unified architecture. SMOTEN is employed to balance categorical phishing data, FT-Transformer learns contextual representations from tabular features, and PSO optimizes model hyperparameters to improve predictive capability. Experiments conducted on the PhishTank dataset evaluated three scenarios: baseline FT-Transformer, FT-Transformer with SMOTEN, and the proposed SMOTEN–FT-Transformer–PSO framework. The proposed model achieved the best performance, obtaining 96.62% accuracy, 0.9696 F1-score, 0.9963 ROC-AUC, and 0.997 PR-AUC. The results demonstrate that integrating oversampling, Transformer-based feature learning, and swarm intelligence optimization significantly improves phishing detection effectiveness, robustness, and generalization on imbalanced cybersecurity datasets.

##plugins.themes.bootstrap3.article.details##

How to Cite
[1]
M. H. Wathan and M. K. Sabili, “PhishTect: A Hybrid SMOTEN–FT-Transformer–PSO Framework for Enhanced Phishing Website Detection on Imbalanced Data”, coreid, vol. 4, no. 2, pp. 78–90, Aug. 2026.


Section
Articles

References

Anti-Phishing Working Group, “apwg_trends_report_q1_2025,” 2025. [Online]. Available: https://docs.apwg.org/reports/apwg_trends_report_q1_2025.pdf

IBM Institute for Business Value, “IBM: X-Force Threat Intelligence Index,” 2022. doi: 10.12968/S1361-3723(22)70561-1.

B. B. Gupta et al., “A Hybrid CNN-Brown-Bear Optimization Framework for Enhanced Detection of URL Phishing Attacks,” Comput. Mater. Contin., vol. 81, no. 3, pp. 4853–4874, 2024, doi: 10.32604/cmc.2024.057138.

M. Shariyab, “Phishing Website Detection,” Int. J. Res. Appl. Sci. Eng. Technol., vol. 12, no. 5, pp. 642–650, 2024, doi: 10.22214/ijraset.2024.61274.

A. Alhuzali, A. Alloqmani, M. Aljabri, and F. Alharbi, “In-Depth Analysis of Phishing Email Detection: Evaluating the Performance of Machine Learning and Deep Learning Models Across Multiple Datasets,” Appl. Sci., vol. 15, no. 6, 2025, doi: 10.3390/app15063396.

I. Abousaber, “A Novel Explainable Attention-Based Meta-Learning Framework for Imbalanced Brain Stroke Prediction,” Sensors, vol. 25, no. 6, 2025, doi: 10.3390/s25061739.

N. Q. Do, A. Selamat, O. Krejcar, E. Herrera-Viedma, and H. Fujita, “Deep Learning for Phishing Detection: Taxonomy, Current Challenges and Future Directions,” IEEE Access, vol. 10, pp. 36429–36463, 2022, doi: 10.1109/ACCESS.2022.3151903.

O. K. Sahingoz, E. Buber, and E. Kugu, “DEPHIDES: Deep Learning Based Phishing Detection System,” IEEE Access, vol. 12, pp. 8052–8070, 2024, doi: 10.1109/ACCESS.2024.3352629.

D. Dablain, B. Krawczyk, and N. V. Chawla, “DeepSMOTE: Fusing Deep Learning and SMOTE for Imbalanced Data,” 2023. doi: 10.1109/TNNLS.2021.3136503.

S. K. Birthriya, P. Ahlawat, and A. K. Jain, “Intelligent phishing website detection: A CNN-SVM approach with nature-inspired hyperparameter tuning,” Cyber Secur. Appl., vol. 3, 2025, doi: 10.1016/j.csa.2025.100100.

H. Fares et al., “Machine Learning Approach for Email Phishing Detection,” in Procedia Computer Science, 2024, pp. 746–751. doi: 10.1016/j.procs.2024.11.179.

S. Sindhu, S. P. Patil, A. Sreevalsan, F. Rahman, and A. N. Saritha, “Phishing detection using random forest, SVM and neural network with backpropagation,” in Proceedings of the International Conference on Smart Technologies in Computing, Electrical and Electronics, ICSTCEE 2020, 2020, pp. 391–394. doi: 10.1109/ICSTCEE49637.2020.9277256.

X. Yang, J. Yuan, and N. Yang, “Phishing Website Detection on Imbalanced Datasets Based on Diffusion Model and Multi-Head Self-Attention,” in Proceedings of 2025 2nd International Conference on Communication Security and Information Processing, CSIP 2025, 2025, pp. 1–6. doi: 10.1145/3744668.3744669.

J. W. Lee, Y. E. Jeon, and J. I. Seo, “An integrated oversampling and noise reduction method for robust predictive analytics,” Decis. Anal. J., vol. 16, p. 100612, 2025, doi: 10.1016/j.dajour.2025.100612.

S. Matharaarachchi, M. Domaratzki, and S. Muthukumarana, “Enhancing SMOTE for imbalanced data with abnormal minority instances,” Mach. Learn. with Appl., vol. 18, p. 100597, 2024, doi: 10.1016/j.mlwa.2024.100597.

F. Danitasari, M. Ryan, D. Handoko, and I. Pramuwardani, “Improving Accuracy of Daily Weather Forecast Model at Soekarno-Hatta Airport Using BILSTM with SMOTE and ADASYN,” J. Penelit. Pendidik. IPA, vol. 10, no. 1, pp. 179–193, 2024, doi: 10.29303/jppipa.v10i1.5906.

D. J. Liu, G. G. Geng, and X. C. Zhang, “Multi-scale semantic deep fusion models for phishing website detection,” Expert Syst. Appl., vol. 209, 2022, doi: 10.1016/j.eswa.2022.118305.

S. K. Birthriya, P. Ahlawat, and A. K. Jain, “Phishing Website Detection with XGBoost and Adaptive Hyperparameter Optimization using the Bat Algorithm,” in Procedia Computer Science, 2025, pp. 1774–1782. doi: 10.1016/j.procs.2025.04.429.

A. X. Wang and B. P. Nguyen, “TTVAE: Transformer-based generative modeling for tabular data generation,” Artif. Intell., vol. 340, 2025, doi: 10.1016/j.artint.2025.104292.

S. Jaradat, M. Elhenawy, R. Nayak, A. Paz, H. I. Ashqar, and S. Glaser, “Multimodal Data Fusion for Tabular and Textual Data: Zero-Shot, Few-Shot, and Fine-Tuning of Generative Pre-Trained Transformer Models,” AI, vol. 6, no. 4, 2025, doi: 10.3390/ai6040072.

S. Asiri, Y. Xiao, and T. Li, “PhishTransformer: A Novel Approach to Detect Phishing Attacks Using URL Collection and Transformer,” Electron., vol. 13, no. 1, 2024, doi: 10.3390/electronics13010030.

T. R. Alsenani, S. I. Ayon, S. M. Yousuf, F. B. K. Anik, and M. E. S. Chowdhury, “Intelligent feature selection model based on particle swarm optimization to detect phishing websites,” Multimed. Tools Appl., vol. 82, no. 29, pp. 44943–44975, 2023, doi: 10.1007/s11042-023-15399-6.

Y. Gorishniy, I. Rubachev, V. Khrulkov, and A. Babenko, “Revisiting Deep Learning Models for Tabular Data,” 2021. [Online]. Available: https://github.com/yandex-research/rtdl

R. M. Mohammad, F. Thabtah, and L. McCluskey, “An assessment of features related to phishing websites using an automated technique,” 2012.

S. A. Tyastama, T. G. Laksana, and A. B. Arifa, “Prediksi Penyakit Ginjal Kronis Menggunakan Hibrid Jaringan Saraf Tiruan Backpropagation dengan Particle Swarm Optimization,” J. Innov. Inf. Technol. Appl., vol. 3, no. 1, pp. 9–16, 2021, doi: 10.35970/jinita.v3i1.588.

M. E. Hossen et al., “Boosting Cervical Cancer Prediction Leveraging a Hybrid FT-Transformer Model,” IEEE Access, vol. 13, pp. 26876–26896, 2025, doi: 10.1109/ACCESS.2025.3538566.

R. Dewi, R. Sri hayati, A. Saleh, D. Y. Hakim Tanjung, and A. Jinan, “Enhancing Machine Learning Algorithm Performance for Pcos Diagnosis Using Smotenc on Imbalanced Data,” JITK (Jurnal Ilmu Pengetah. dan Teknol. Komputer), vol. 11, no. 1, pp. 55–63, 2025, doi: 10.33480/jitk.v11i1.6676.

A. X. Wang, V. T. Le, H. N. Trung, and B. P. Nguyen, “Addressing imbalance in health data: Synthetic minority oversampling using deep learning,” Comput. Biol. Med., vol. 188, 2025, doi: 10.1016/j.compbiomed.2025.109830.

K. Omari and A. Oukhatar, “Advanced Phishing Website Detection with SMOTETomek-XGB: Addressing Class Imbalance for Optimal Results,” in Procedia Computer Science, 2025, pp. 289–295. doi: 10.1016/j.procs.2024.12.031.

H. Dai et al., “FT-Transformer: Resilient and Reliable Transformer with End-to-End Fault Tolerant Attention,” 2025. doi: 10.1145/3712285.3759853.

I. A. Fares and M. Abd Elaziz, “FT-Transformer for Intrusion Detection in IoT Environment,” Bull. Fac. Sci. Zagazig Univ., vol. 2025, no. 1, pp. 114–123, 2025, doi: 10.21608/bfszu.2024.297682.1400.

M. Imani, A. Beikmohammadi, and H. R. Arabnia, “Comprehensive Analysis of Random Forest and XGBoost Performance with SMOTE, ADASYN, and GNUS Under Varying Imbalance Levels,” Technologies, vol. 13, no. 3, 2025, doi: 10.3390/technologies13030088.

G. S. Nayak, B. Muniyal, and M. C. Belavagi, “Enhancing Phishing Detection: A Machine Learning Approach With Feature Selection and Deep Learning Models,” IEEE Access, vol. 13, pp. 33308–33320, 2025, doi: 10.1109/ACCESS.2025.3543738.

G. Sonowal and K. S. Kuppusamy, “PhiDMA – A phishing detection model with multi-filter approach,” J. King Saud Univ. - Comput. Inf. Sci., vol. 32, no. 1, pp. 99–112, 2020, doi: 10.1016/j.jksuci.2017.07.005.