An Explainable AI based Cyber Threat Detection Model to Minimize Phishing Attacks and Their Effect
DOI:
https://doi.org/10.33411/IJIST/1993Keywords:
Phishing and Cyber-attacks, Explainable AI, Threat Detection, Ensemble LearningAbstract
Phishing and social engineering rank among the most significant facilitators of cyber-crime, which encompasses data breaches, cyber-attacks, ransomware schemes, and denial of service incidents. A robust threat detection model is essential for reducing the risk of phishing attacks, as these types of attacks are frequently discussed in dark web forums and are thus widely adopted. It has been noted that these attacks can have severe direct or indirect effects on our assets, with the resulting financial damage closely linked to their occurrence. In this research, two methodologies are introduced: the first is an explainable AI (XAI) model specifically designed to assess cyber-risks associated with correlated phishing threats. The second is a hybrid approach referred to as a classifier ensemble, which employs a combination of three top-performing machine learning models through ensemble learning and categorizes them based on several high-impact parameters related to model performance. Ultimately, both proposed models have been compared and evaluated across multiple factors. The proposed model in addition carried out a precision of 97.5%, consider of 98.7%, and F1-score of 98.1%, with an average development of about 2–3% in comparison with baseline models. SHAP evaluation recognized Page Rank, URL Length, Number of Hyperlinks, Domain Age, Google Index, and Phishing Hints because the maximum influential capabilities affecting phishing prediction, while LIME supplied instance-stage reasons to enhance transparency and analyst confidence. The experimental findings display that integrating explainable artificial intelligence with ensemble getting to know appreciably improves phishing detection accuracy whilst simultaneously improving version interpretability, making the proposed framework appropriate for deployment in realistic cybersecurity environments.
References
K. Kalasampath, K. N. Spoorthi, S. Sajeev, S. S. Kuppa, K. Ajay, and A. Maruthamuthu, “A Literature Review on Applications of Explainable Artificial Intelligence (XAI),” IEEE Access, vol. 13, pp. 41111–41140, 2025, doi: 10.1109/ACCESS.2025.3546681.
Z. Cheng, Y. Wu, Y. Li, L. Cai, and B. Ihnaini, “A Comprehensive Review of Explainable Artificial Intelligence (XAI) in Computer Vision,” Sensors 2025, Vol. 25, Page 4166, vol. 25, no. 13, p. 4166, Jul. 2025, doi: 10.3390/S25134166.
O. Kaya, A. F. M. S. Shah, M. A. Karabulut, S. N. Karahan, M. S. Osmanca, and N. Acir, “Explainable Artificial Intelligence (XAI): Concepts, Applications, Challenges, and Future Perspectives,” IEEE Access, vol. 14, pp. 27394–27417, 2026, doi: 10.1109/ACCESS.2026.3663161.
F. Herrera, “Reflections and attentiveness on eXplainable Artificial Intelligence (XAI). The journey ahead from criticisms to human–AI collaboration,” Inf. Fusion, vol. 121, p. 103133, Sep. 2025, doi: 10.1016/J.INFFUS.2025.103133.
A. Søgaard, “Externalist XAI?,” Theor., vol. 91, no. 2, p. e12581, Apr. 2025, doi: 10.1111/THEO.12581
T. Kehkashan et al., “Explainable phishing website detection for secure and sustainable cyber infrastructure,” Sci. Reports 2025 151, vol. 15, no. 1, pp. 41751-, Nov. 2025, doi: 10.1038/s41598-025-27984-w.
R. Ahmed and S. EP, “An intelligent phishing email detection system using ensemble methods and explainable AI,” Knowledge-Based Syst., vol. 337, p. 115388, Mar. 2026, doi: 10.1016/J.KNOSYS.2026.115388.
L. Sawe, J. Gikandi, J. Kamau, and D. Njuguna, “Sentence Level Analysis Model for Phishing Detection Using KNN,” J. Cyber Secur., vol. 6, no. 1, pp. 25–39, Jan. 2024, doi: 10.32604/JCS.2023.045859.
R. J. van Geest, G. Cascavilla, J. Hulstijn, and N. Zannone, “The applicability of a hybrid framework for automated phishing detection,” Comput. Secur., vol. 139, p. 103736, Apr. 2024, doi: 10.1016/J.COSE.2024.103736.
N. Biswas, K. M. M. Uddin, S. T. Rikta, and S. K. Dey, “A comparative analysis of machine learning classifiers for stroke prediction: A predictive analytics approach,” Healthc. Anal., vol. 2, p. 100116, Nov. 2022, doi: 10.1016/J.HEALTH.2022.100116.
I. Markoulidakis and G. Markoulidakis, “Probabilistic Confusion Matrix: A Novel Method for Machine Learning Algorithm Generalized Performance Analysis,” Technol. 2024, Vol. 12, Page 113, vol. 12, no. 7, p. 113, Jul. 2024, doi: 10.3390/TECHNOLOGIES12070113.
B. Wu, S. Yu, L. Peng, and L. Wang, “Interpretable wind speed forecasting with meteorological feature exploring and two-stage decomposition,” Energy, vol. 294, p. 130782, May 2024, doi: 10.1016/J.ENERGY.2024.130782.
S. S. Shafin, “An explainable feature selection framework for web phishing detection with machine learning,” Data Sci. Manag., vol. 8, no. 2, pp. 127–136, Jun. 2025, doi: 10.1016/J.DSM.2024.08.004.
L. Mansour, N. Hilal, N. Abbas, and S. Kadry, “Generalized Explainable AI Framework for Phishing Detection on Heterogeneous Textual Data,” Comput. Decis. Mak. An Int. J., vol. 3, pp. 859–875, Jul. 2026, doi: 10.59543/COMDEM.V3I.18329.
M. A. Uddin, M. Mahiuddin, and I. H. Sarker, “An explainable transformer-based model for phishing email detection: A large language model approach,” Comput. Networks, vol. 277, p. 112061, Mar. 2026, doi: 10.1016/J.COMNET.2026.112061.
Z. Fan, W. Li, K. B. Laskey, and K. C. Chang, “Investigation of Phishing Susceptibility with Explainable Artificial Intelligence,” Futur. Internet 2024, Vol. 16, Page 31, vol. 16, no. 1, p. 31, Jan. 2024, doi: 10.3390/FI16010031.
E. A. El Abdellaoui Alaoui, A. Filali, A. Sallah, M. Hajhouj, A. Hessane, and M. Merras, “Towards Transparent Cybersecurity: The Role of Explainable AI in Mitigating Spam Threats,” Procedia Comput. Sci., vol. 236, pp. 394–401, Jan. 2024, doi: 10.1016/J.PROCS.2024.05.046.
S. J. Almheiri, A. A. Shah, S. Abbas, M. Ahmad, and M. A. Khan, “Smart sustainable cyber security: modelling an interpretable and transparent threat detection with explainable artificial intelligence,” Discov. Sustain. 2025 61, vol. 6, no. 1, pp. 442-, May 2025, doi: 10.1007/S43621-025-01280-Z.
K. S. Alketbi and A. Mehmood, “A Comprehensive Survey of Explainable Artificial Intelligence Techniques for Malicious Insider Threat Detection,” IEEE Access, vol. 13, pp. 121772–121798, 2025, doi: 10.1109/ACCESS.2025.3587114.
H. Alamro et al., “Enhanced intrusion detection in cybersecurity through dimensionality reduction and explainable artificial intelligence,” Sci. Reports 2025 151, vol. 15, no. 1, pp. 33848-, Sep. 2025, doi: 10.1038/s41598-025-06761-9.
Noor Hazlina Abdul Mutalib, Aznul Qalid Md Sabri, Ainuddin Wahid Abdul Wahab, Erma Rahayu Mohd Faizal Abdullah, “Explainable deep learning approach for advanced persistent threats (APTs) detection in cybersecurity: a review,” Artif. Intell. Rev., vol. 57, no. 297, 2024, [Online]. Available: https://link.springer.com/article
/10.1007/s10462-024-10890-4
J. Sivakumar, N. Rafid Salman, F. Rafid Salman, H. R. Salimova, and E. Ghimire, “Ai-Driven Cyber Threat Detection: Enhancing Security Through Intelligent Engineering Systems,” J. Inf. Syst. Eng. Manag., vol. 10, no. 19s, pp. 790–798, Mar. 2025, doi: 10.52783/JISEM.V10I19S.3116.
A. V. Turukmane, S. Patil, K. Varshinee, L. Yadav, and G. Khekare, “Leveraging Explainable AI for threat detection in Industrial IIoT-based intrusion prevention systems,” Explain. Artif. Intell. Ind. Internet Things Technol. Appl., pp. 211–221, Jan. 2025, doi: 10.1201/9781003537380-11.
I. Elgarhy, M. M. Badr, M. Mahmoud, J. Ni, M. Alsabaan, and T. Alshawi, “Investigation of the Robustness of XAI-Based Federated Learning Against Adversarial Attacks for Smart Grid False Data Detection,” IEEE Internet Things J., vol. 12, no. 15, pp. 32179–32192, 2025, doi: 10.1109/JIOT.2025.3576225.
S. Kumar, “Explainable AI for Intrusion Detection Systems: Enhancing Trust, Transparency, and Real-Time Threat Response,” Int. J. AI, BigData, Comput. Manag., vol. 7, no. 2, pp. 115–123, Apr. 2026, doi: 10.63282/3050-9416.IJAIBDCMS-V7I2P119.
J. Shin, “Feasibility of local interpretable model-agnostic explanations (LIME) algorithm as an effective and interpretable feature selection method: comparative fNIRS study,” Biomed. Eng. Lett. 2023 134, vol. 13, no. 4, pp. 689–703, Jun. 2023, doi: 10.1007/S13534-023-00291-X.
“Phishing Statistics 2024: Trends and Prevention Strategies for 2025.” Accessed: Aug. 10, 2026. [Online]. Available:https://www.sangfor.com/blog/cybersecurity/phishing-
statistics-and-how-to-prevent-phishing
B. V. Pavani, D. Mahitha, and B. U. Maheswari, “Enhancing Online Safety: Phishing URL Detection Using Machine Learning and Explainable AI,” 2024 15th Int. Conf. Comput. Commun. Netw. Technol. ICCCNT 2024, 2024, doi: 10.1109/ICCCNT61001.2024.10723976.
D. M. Belete and M. D. Huchaiah, “Grid search in hyperparameter optimization of machine learning models for prediction of HIV/AIDS test results,” Int. J. Comput. Appl., vol. 44, no. 9, pp. 875–886, Sep. 2022, doi: 10.1080/1206212X.2021.1974663.
E. J. Williams and A. N. Joinson, “Developing a measure of information seeking about phishing,” J. Cybersecurity, vol. 6, no. 1, pp. 1–16, Jan. 2020, doi: 10.1093/CYBSEC/TYAA001.
S. T. Rikta, K. M. M. Uddin, N. Biswas, R. Mostafiz, F. Sharmin, and S. K. Dey, “XML-GBM lung: An explainable machine learning-based application for the diagnosis of lung cancer,” J. Pathol. Inform., vol. 14, p. 100307, Jan. 2023, doi: 10.1016/J.JPI.2023.100307.
T. Sutter, A. S. Bozkir, B. Gehring, and P. Berlich, “Avoiding the Hook: Influential Factors of Phishing Awareness Training on Click-Rates and a Data-Driven Approach to Predict Email Difficulty Perception,” IEEE Access, vol. 10, pp. 100540–100565, 2022, doi: 10.1109/ACCESS.2022.3207272.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 50SEA

This work is licensed under a Creative Commons Attribution 4.0 International License.


















