A Framework for Optimising Phishing Websites Detection via Ensemble Learning and Synthetic Minority Oversampling Techniques

Main Article Content

Daniel Asuquo
Fredrick Umoh
Kingsley Attai
Kingsley Akputu
Avwokuruaye Oghenetega
Kitoye Ebire Okonny
Udoinyang G. Inyang
Isah R. Saidu

Abstract

Phishing websites remain one of the most prevalent forms of cyber-attacks. They often exploit users, through deceptive web interfaces, to steal sensitive information such as login credentials, financial data, and personal records. The increasing sophistication of phishing strategies has reduced the effectiveness of traditional rule-based detection systems. This necessitates the adoption of intelligent and adaptive machine learning (ML) approaches. This study presents a robust ML-based framework for phishing websites detection using ensemble learning and Synthetic Minority Oversampling Technique (SMOTE). The proposed framework integrates comprehensive data preprocessing techniques, including constant and duplicate feature removal, Standard Scaler (Z-score normalization), and class balancing through SMOTE to improve model robustness and predictive capability. Three supervised learning algorithms, namely Decision Tree (DT), Random Forest (RF), and Extreme Gradient Boosting (XGBoost), were implemented and evaluated using an 8:2 train-test split, 5-fold cross-validation, and GridSearchCV-based hyperparameter optimization. Experimental results demonstrate that ensemble models outperform the standalone DT model across all evaluation metrics. Among the evaluated models, RF achieved the best overall performance with an accuracy of 97.13%, recall of 96.07%, F1-score of 95.86%, and area under the curve-receiver operating characteristics (AUC-ROC) of 0.9951 on the baseline dataset. Following the application of SMOTE, recall improved further to 96.46%, indicating enhanced capability in identifying phishing websites. Additionally, SHapley Additive exPlanations (SHAP) was incorporated to improve model interpretability and identify the most influential phishing indicators. The findings reveal that domain age and URL structural characteristics significantly influence phishing detection. Overall, the findings demonstrate the effectiveness and interpretability of the evaluated tree-based framework within the structured-feature dataset considered in this study. Future work should therefore evaluate the framework on recent and continuously evolving datasets and investigate its robustness against emerging phishing strategies and changes in website characteristics.

Article Details

Section

Regular Paper

Author Biographies

Daniel Asuquo, University of Uyo

Professor Daniel E. Asuquo

Department of Information Systems

Faculty of Computing

University of Uyo, Nigeria

 

Fredrick Umoh, University of Uyo

Lecturer, Akwa Ibom State Polytechnic

PG Student, Department of Cybersecurity, TETFund Centre of Excellence in Computational Intelligence Research, UNIUYO, Nigeria

Kingsley Attai, Ritman University

Lecturer, Department of Computer Science, Faculty of Computing, Ritman University, Ikot Ekpene, Nigeria

Ag. Dean, Faculty of Computing, Ritman University, Ikot Ekpene, Nigeria

Kingsley Akputu, Admiralty University of Nigeria

Lecturer, Department of Computing Sciences, Faculty of Science, Admiralty University of Nigeria, Ibusa, Nigeria

Avwokuruaye Oghenetega, Admiralty University of Nigeria

Lecturer, Department of Computing Sciences, Faculty of Science, Admiralty University of Nigeria, Ibusa, Nigeria

Kitoye Ebire Okonny, Ignatius Ajuru University of Education

Director, ICT Centre, Ignatius Ajuru University of Education, Port Harcourt, Nigeria

Udoinyang G. Inyang, University of Uyo

Professor, Department of Data Science, Faculty of Computing, University of Uyo,Nigeria

Director, TETFund Centre of Excellence in Computational Intelligence Research, UNIUYO, Nigeria

Isah R. Saidu, Ignatius Ajuru University of Education

Deputy Vice Chancellor, Admiralty University of Nigeria, Ibusa, Delta State, Nigeria

Professor, Department of Computing Sciences, Faculty of Science, Admiralty University of Nigeria, Ibusa, Delta State, Nigeria

How to Cite

A Framework for Optimising Phishing Websites Detection via Ensemble Learning and Synthetic Minority Oversampling Techniques. (2026). International Journal of Management and Data Analytics (IJMADA), 6(1), 297-316. http://ijmada.com/index.php/ijmada/article/view/153

References

Adebowale, M. A., Lwin, K. T., Sanchez, E., & Hossain, M. A. (2019). Intelligent web-phishing detection and protection scheme using integrated features of images, frames and text. Expert Systems with Applications, 115, 300-313. https://doi.org/10.1016/j.eswa.2018.07.067.

Alabdan, R. (2020). Phishing Attacks Survey: Types, Vectors, and Technical Approaches. Future Internet, 12(10), 168. https://doi.org/10.3390/fi12100168

Alnemari, S., & Alshammari, M. (2023). Detecting phishing domains using machine learning. Applied Sciences, 13(8), 4649. https://doi.org/10.3390/app13084649

Alsariera, Y. A., Elijah, A. V., & Balogun, A. O. (2020). Phishing website detection: Forest by penalizing attributes algorithm and its enhanced variations. Arabian Journal for Science and Engineering, 45, 10459–10470. https://doi.org/10.1007/s13369-020-04812-7

Alsenani, T. R., Ayon, S. I., Yousuf, S. M., Anik, F. B. K., & Chowdhury, M. E. S. (2023). Intelligent feature selection model based on particle swarm optimization to detect phishing websites. Multimedia Tools and Applications, 82(29), 44943-44975.

Alshingiti, Z., Alaqel, R., Al-Muhtadi, J., Haq, Q. E. U., Saleem, K., & Faheem, M. H. (2023). A Deep Learning-Based Phishing Detection System Using CNN, LSTM, and LSTM-CNN. Electronics, 12(1), 232. https://doi.org/10.3390/electronics12010232

Asuquo, D. E., Umoh, U. A., Osang, F. B. and Okokon, E. W. (2020). Performance Evaluation of C4.5, Random Forest and Naïve Bayes Classifiers in Employee Performance and Promotion Prediction, African Journal of Management Information System, 2(4), 41-55.

Babagoli, M., Aghababa, M. P., & Solouk, V. (2019). Heuristic nonlinear regression strategy for detecting phishing websites. Soft Computing, 23(12), 4315-4327.

Balogun, A. O., Adewole, K. S., Raheem, M., Oluwatobi, A. N., Hamza-Usman,F. E., Mabayoje, M. A., Akintola, A., Asaju-Gbolagade, A. W., Muhammed, K. J., Gbenga, J. R., & Adeyemo, V. E. (2021). Improving the phishing website detection using empirical analysis of Function Tree and its variants. Heliyon, 7(7). https://doi.org/10.1016/j.heliyon.2021.e07437.

Batista, G. E., Prati, R. C., & Monard, M. C. (2004). A study of the behavior of several methods for balancing machine learning training data. ACM SIGKDD explorations newsletter, 6(1), 20-29.

Benavides-Astudillo, E., Fuertes, W., Sanchez-Gordon, S., Nuñez-Agurto, D., & Rodríguez-Galán, G. (2023). A Phishing-Attack-Detection Model Using Natural Language Processing and Deep Learning. Applied Sciences, 13(9), 5275. https://doi.org/10.3390/app13095275.

Chawla, N. V., Bowyer, K. W., Hall, L. O., & Kegelmeyer, W. P. (2002). SMOTE: Synthetic minority over-sampling technique. Journal of Artificial Intelligence Research, 16, 321–357. https://doi.org/10.1613/jair.953

Chawla, N. V., Japkowicz, N., & Kotcz, A. (2004). Special issue on learning from imbalanced data sets. ACM SIGKDD explorations newsletter, 6(1), 1-6.

Elshewey, A. M., Osman, A. M., El-Bakry, H. M., & Youssef, R. Y. (2026). An enhanced deep learning model for phishing detection based on bayesian optimization and hybrid CNN VGG19 model. Cluster Computing, 29(4), 231. https://doi.org/10.1007/s10586-025-05896-8

García, V., Sánchez, J. S., & Mollineda, R. A. (2012). On the effectiveness of preprocessing methods when dealing with different levels of class imbalance. Knowledge-Based Systems, 25(1), 13–21. https://doi.org/10.1016/j.knosys.2011.06.013

Gupta, B.B., Yadav, K., Razzak, I., Psannis, K., Castiglione, A. and Chang, X. (2021). A novel approach for phishing URLs detection using lexical based machine learning in a real-time environment. Comput. Commun., 175, 47-57. https://doi.org/10.1016/j.comcom.2021.04.023.

Haixiang, G., Yijing, L., Shang, J., Mingyun, G., Yuanyue, H., & Bing, G. (2017). Learning from class-imbalanced data: Review of methods and applications. Expert systems with applications, 73, 220-239.

Heartfield, R., & Loukas, G. (2016). A taxonomy of attacks and a survey of defence mechanisms for semantic social engineering attacks. ACM Computing Surveys, 48(3), 1–37. https://doi.org/10.1145/2835375

Innab, N., Abdelgader, A., Awad, M., Abu-Zanona, M., Elzaghmouri, B., Zawaideh, F., & Alawneh, M. (2024). Phishing attacks detection using ensemble machine learning algorithms. Computers, Materials, & Continua, 80(1), 1325. https://doi.org/10.32604/cmc.2024.051778

Jabir, R., Le, J., & Nguyen, C. (2025). Phishing Attacks in the Age of Generative Artificial Intelligence: A Systematic Review of Human Factors. AI, 6(8), 174. https://doi.org/10.3390/ai6080174

Jain, A. K., & Gupta, B. B. (2021). A survey of phishing attack techniques, defence mechanisms and open research challenges. Enterprise Information Systems, 16(4), 527–565. https://doi.org/10.1080/17517575.2021.1896786

Jha, A., & Jha, A. (2025). Phishing Forensics: A Systematic Approach to Analyzing Mobile and Social Media Fraud. https://doi.org/10.32604/jcs.2025.064429

Kathrine, G.J.W., Praise, P.M., Rose, A.A., Kalaivani, E.C. (2019). Variants of phishing attacks and their detection techniques. Proceedings of the International Conference on Trends in Electronics and Informatics, ICOEI 2019, 255-259. https://doi.org/10.1109/ICOEI.2019.8862697.

Khorshidi, H. A., & Aickelin, U. (2025). A synthetic over-sampling method with minority and majority classes for imbalance problems. Knowledge and Information Systems, 67(7), 5965-5998.

Lakshmi, L., Reddy, M. P., Santhaiah, C., & Reddy, U. J. (2021). Smart phishing detection in web pages using supervised deep learning classification and optimization technique ADAM. Wireless Personal Communications, 118, 3549–3564. https://doi.org/10.1007/s11277-021-08188-x

Manzano, C., Meneses, C., Leger, P., & Fukuda, H. (2022). An empirical evaluation of supervised learning methods for network malware identification based on feature selection. Complexity, 2022(1), 6760920.

Omari, K. (2023). Comparative study of machine learning algorithms for phishing website detection. International Journal of Advanced Computer Science and Applications, 14(9), 415–424. https://doi.org/10.14569/IJACSA.2023.0140945

Rout, N., Mishra, D., & Mallick, M. K. (2018). Handling imbalanced data: A survey. International Proceedings on Advances in Soft Computing, Intelligent Systems and Applications, 431–443. Springer.

Saheed, Y. K., Hambali, M. A., Arowolo, M. O., & Olasupo, Y. A. (2020, November). Application of GA feature selection on Naive Bayes, random forest and SVM for credit card fraud detection. In 2020 international conference on decision aid sciences and application (DASA) (pp. 1091-1097). IEEE.

Safi, A. & Singh, S. (2023). A systematic literature review on phishing website detection techniques. Journal of King Saud University - Computer and Information Sciences, 35(2), 590-611. https://doi.org/10.1016/j.jksuci.2023.01.004.

Safitra, M. F., Lubis, M., & Fakhrurroja, H. (2023). Counterattacking Cyber Threats: A Framework for the Future of Cybersecurity. Sustainability, 15(18), 13369. https://doi.org/10.3390/su151813369

Sahingoz, O. K., Buber, E., Demir, O., & Diri, B. (2019). Machine learning based phishing detection from URLs. Expert Systems with Applications, 117, 345-357. https://doi.org/10.1016/j.eswa.2018.09.029

Shaukat, M. W., Amin, R., Muslam, M. M. A., Alshehri, A. H., & Xie, J. (2023). A hybrid approach for alluring ads phishing attack detection using machine learning. Sensors, 23(19), 8070. https://doi.org/10.3390/s23198070

Tang, L., & Mahmoud, Q. (2021). A survey of machine learning-based solutions for phishing website detection. Machine Learning and Knowledge Extraction, 3(3), 672–694. https://doi.org/10.3390/make3030034

Ubing, A., Kamilia, S., Abdullah, A., Zaman, N., & Supramaniam, M. (2019). Phishing website detection: An improved accuracy through feature selection and ensemble learning. International Journal of Advanced Computer Science and Applications, 10(3), 252–257Vrbančič, G., Fister, I., Jr, & Podgorelec, V. (2020). Datasets for phishing websites detection. Data in brief, 33, 106438. https://doi.org/10.1016/j.dib.2020.106438

Ul Hassan, I., Ali, R. H., Ul Abideen, Z., Khan, T. A., & Kouatly, R. (2022). Significance of machine learning for detection of malicious websites on an automated framework under an unbalanced dataset. Digital, 2(4), 501–519. https://doi.org/10.3390/digital2040027

Vrbančič, G., Fister, I., Jr, & Podgorelec, V. (2020). Datasets for phishing websites detection. Data in brief, 33, 106438. https://doi.org/10.1016/j.dib.2020.106438

Wilk-Jakubowski, J. L., Pawlik, L., Wilk-Jakubowski, G., & Sikora, A. (2025). Machine Learning and Neural Networks for Phishing Detection: A Systematic Review (2017–2024). Electronics, 14(18), 3744. https://doi.org/10.3390/electronics14183744

Xiao, X., Xiao, W., Zhang, D., Zhang, B., Hu, G., Li, Q., & Xia, S. (2021). Phishing websites detection via CNN and multi-head self-attention on imbalanced datasets. Computers & Security, 108, 102372. https://doi.org/10.1016/j.cose.2021.102372

Yerima, S. Y., & Alzaylaee, M. K. (2020). High accuracy phishing detection based on convolutional neural networks. In 2020 3rd International Conference on Computer Applications & Information Security (ICCAIS) (pp. 1-6). IEEE. https://doi.org/10.1109/ICCAIS48893.2020.9096869

Zamir, A., Khan, H. U., Iqbal, T., Yousaf, N., Aslam, F., Anjum, A., & Hamdani, M. (2020). Phishing web site detection using diverse machine learning algorithms. The Electronic Library, 38(1), 65-80. https://doi.org/10.1108/EL-05-2019-0118

Zhang, J., et al. (2024). GrabPhisher: Phishing scams detection in ethereum via temporally evolving GNNs. IEEE Transactions on Services Computing, 17(2), 512–526.

Zheng, Q., Yu, C., Cao, J., Xu, Y., Xing, Q., & Jin, Y. (2024). Advanced payment security system: XGBoost, LightGBM, and SMOTE integrated. arXiv preprint arXiv:2406.04658.

Similar Articles

You may also start an advanced similarity search for this article.