Augmenting URL-BERT Based Phishing

Proceedings of International Conference on Computational Technologies for Research in Data Analytics |

Published by Springer | Organized by ICCTRDA

As one of today’s most widespread cybersecurity threats, phishing has driven the development of advanced automated detectors. Current research, however, is largely split between two camps: deep semantic analysis of URLs and computationally heavy visual analysis of entire webpages. To bridge this gap, we proposed and investigated a novel hybrid model. Our hypothesis was that fusing a powerful transformer-based URL classifier with a lightweight visual signal—the perceptual hash of a site’s favicon could offer a more effective and efficient detection solution. To test this, we built both our proposed hybrid model and a strong URL-only baseline. Both were rigorously trained on a 20,000-URL dataset using an early stopping strategy to ensure peak performance, and then evaluated against two distinct hold-out sets totaling 8,000 unseen URLs. Our findings show that the proposed hybrid model shows a slight advantage on our primary test set, achieving an F1-score of 0.9967 to the baseline’s 0.9963. We conclude that this demonstrates a performance ceiling: the semantic signals within a URL, when analyzed by a modern transformer, are so overwhelmingly predictive that the addition of a simple visual feature provides only slight consistent benefit for generalization. This finding is a crucial consideration for future work in feature engineering for phishing detection, suggesting a point of diminishing returns.