Phishing URL Detection Using Hybrid CNN-BiLSTM Character-Level Deep Learning

Alrafiful Rahman(1*),Pratiwi Rachmadi(2),Farah Kaylila(3),Sae Khatami(4),Maria Stefani(5)
(1) IKPIA Perbanas
(2) IKPIA Perbanas
(3) IKPIA Perbanas
(4) IKPIA Perbanas
(5) IKPIA Perbanas
(*) Corresponding Author
DOI : 10.35889/progresif.v22i3.3753

Abstract

Phishing attacks conducted through fraudulent URLs continue to become a significant cybersecurity challenge, demanding detection methods that are both rapid and reliable. This research introduces a hybrid deep learning model that integrates Convolutional Neural Network (CNN) and Bidirectional Long Short-Term Memory (BiLSTM) architectures for automated phishing URL detection. The CNN component is utilized to identify lexical and character-level patterns within URLs, whereas BiLSTM captures contextual dependencies from both forward and backward sequence directions. The proposed model was trained using 450,176 labeled URL samples with character-level tokenization, minimizing the need for manual feature extraction. Experimental evaluations demonstrated excellent performance, achieving an accuracy of 99.78%, while precision and recall consistently remained above 99% according to confusion matrix analysis. Furthermore, the trained model was implemented into a Python-based check_link() function that integrates deep learning prediction scores with rule-based analysis to categorize URLs into safe, suspicious, or dangerous classes. Nevertheless, inference testing revealed that the model is sensitive to incomplete URL formats, particularly legitimate domains lacking the www prefix. In general, the CNN-BiLSTM approach proved highly effective for large-scale phishing URL classification, although incorporating additional external features may help reduce false positive predictions.

Keywords: Phising; URL; Deep learning; Convolutional Neural Network; Bidirectional Long Short-Term Memory.

References


H. Kibriya, R. Amin, S. S. Alshamrani, S. Rehman, M. Hassan, and F. S. Alsubaei, “Lightweight malicious URL detection using deep learning and large language models,” Sci. Rep., vol. 15, no. 1, pp. 1–18, 2025, doi: 10.1038/s41598-025-26653-2.

M. Elsadig et al., “Intelligent Deep Machine Learning Cyber Phishing URL Detection Based on BERT Features Extraction,” Electron., vol. 11, no. 22, 2022, doi: 10.3390/electronics11223647.

S. S. Roy, A. I. Awad, L. A. Amare, M. T. Erkihun, and M. Anas, “Multimodel Phishing URL Detection Using LSTM, Bidirectional LSTM, and GRU Models,” Future Internet, vol. 14, no. 11. p. 340, 2022. doi: 10.3390/fi14110340.

Y. A. Kustiawan and K. I. Ghauth, “PhishOFE: A Novel Machine Learning Framework for Real-Time Phishing URL Detection With Optimized Feature Engineering,” IEEE Access, vol. 13, no. August, pp. 169606–169627, 2025, doi: 10.1109/ACCESS.2025.3614126.

S. Gopali, A. Siami Namin, F. Abri, and K. Jones, “The Performance of Sequential Deep Learning Models in Detecting Phishing Websites Using Contextual Features of URLs,” May 2024, pp. 1064–1066. doi: 10.1145/3605098.3636164.

S. Sahoo, S. Kumar, N. Donthu, and A. K. Singh, “Artificial intelligence capabilities, open innovation, and business performance – Empirical insights from multinational B2B companies,” Ind. Mark. Manag., vol. 117, pp. 28–41, 2024, doi: https://doi.org/10.1016/j.indmarman.2023.12.008.

A. Safi and S. Singh, “A systematic literature review on phishing website detection techniques,” J. King Saud Univ. - Comput. Inf. Sci., vol. 35, no. 2, pp. 590–611, 2023, doi: 10.1016/j.jksuci.2023.01.004.

M. Aljabri and R. M. A. Mohammad, “Click fraud detection for online advertising using machine learning,” Egypt. Informatics J., vol. 24, no. 2, pp. 341–350, 2023, doi: 10.1016/j.eij.2023.05.006.

D. Dahliana, M. M. Mokhtar, and R. Peramita, “The Role of Islam in the Development of Information and Communication Technology in the Digital Age : A Systematic Literature Review,” vol. 1, no. 2024, pp. 74–82, 2025.

K. M. Alshamrani, D. A. Alzahrani, Y. S. Alghamdi, L. M. Aljohani, and Z. F. Al Nufaiei, “Saudi Radiology Technologists’ Perception of Occupational Hazards from a Personal and Social Lens,” Risk Manag. Healthc. Policy, vol. 17, no. October, pp. 2609–2622, 2024, doi: 10.2147/RMHP.S492974.

F. Shirazi, N. Hajli, J. Sims, and F. Lemke, “The role of social factors in purchase journey in the social commerce era,” Technol. Forecast. Soc. Change, vol. 183, p. 121861, 2022, doi: https://doi.org/10.1016/j.techfore.2022.121861.

S. K. H. Ahammad et al., “Phishing URL detection using machine learning methods,” Adv. Eng. Softw., vol. 173, p. 103288, 2022, doi: https://doi.org/10.1016/j.advengsoft.2022.103288.

M. Alani, H. Tawfik, M. Saeed, and O. Anya, Applications of Big Data Analytics: Trends, Issues, and Challenges. 2018. doi: 10.1007/978-3-319-76472-6.

C. Opara, Y. Chen, and B. Wei, “Look before you leap: Detecting phishing web pages by exploiting raw URL and HTML characteristics,” Expert Syst. Appl., vol. 236, no. October 2020, p. 121183, 2024, doi: 10.1016/j.eswa.2023.121183.

S. Kavya and D. Sumathi, “Staying ahead of phishers: a review of recent advances and emerging methodologies in phishing detection,” Artif. Intell. Rev., vol. 58, no. 2, p. 50, 2024, doi: 10.1007/s10462-024-11055-z.

R. Chinnasamy, M. Subramanian, S. V. Easwaramoorthy, and J. Cho, “Deep learning-driven methods for network-based intrusion detection systems: A systematic review,” ICT Express, vol. 11, no. 1, pp. 181–215, 2025, doi: 10.1016/j.icte.2025.01.005.

T. M. Bao, K. Shashvat, N. G. Nhu, and D.-N. Le, “A Comparative Analysis of Machine Learning Algorithms for Spam and Phishing URL Classification,” Comput. Mater. Contin., vol. 87, no. 2, p. 35, 2026, doi: https://doi.org/10.32604/cmc.2025.075161.

Z. Zhang, Y. Yang, N. Lu, W. Shi, and Z. Liu, “Anti-APhish: A Robust and Adaptive Detection Approach Against Evolving AI-powered Phishing URLs,” Expert Syst. Appl., vol. 331, no. Part C, p. 133324, 2026, doi: https://doi.org/10.1016/j.eswa.2026.133324.

J. D. Bhosale, S. S. Thorat, P. V. Pancholi, and P. R. Mutkule, “Machine Learning-Based Algorithms for the Detection of Leaf Disease in Agriculture Crops,” Int. J. Recent Innov. Trends Comput. Commun., vol. 11, no. April, pp. 45–50, 2023, doi: 10.17762/ijritcc.v11i5s.6596.

R. Kaur, D. Gabrijelčič, and T. Klobučar, “Artificial intelligence for cybersecurity: Literature review and future research directions,” Inf. Fusion, vol. 97, no. April, p. 101804, 2023, doi: 10.1016/j.inffus.2023.101804.

N. Nagy et al., “Phishing URLs Detection Using Sequential and Parallel ML Techniques: Comparative Analysis,” Sensors, vol. 23, no. 7, p. 3467, 2023, doi: 10.3390/s23073467.

A. Chakraborty, M. Kumar, and N. Chaurasia, “Secure framework for IoT applications using Deep Learning in fog Computing,” J. Inf. Secur. Appl., vol. 77, p. 103569, 2023, doi: https://doi.org/10.1016/j.jisa.2023.103569.

A. Rahman, L. S. Istiyowati, V. Valentinus, I. Ivan, and Z. Azis, “Implementasi Data Mining Dalam Prediksi Harga Saham BBNI Dengan Pemodelan Matematika Menggunakan Metode LSTM Dengan Optimasi Adam,” JUTECH J. Educ. Technol., vol. 5, no. 2, pp. 427–439, 2024, doi: 10.31932/jutech.v5i2.4137.

A. Rahman, V. Paramarta, A. N. Ida, M. H. Akbar, and V. S. M. Simanjuntak, “Perbandingan Kinerja SVR dan XGBoost untuk Peramalan Emisi CO₂ Global berbasis Machine Learning,” J. Komtika (Komputasi dan Inform., vol. 9, no. 1, pp. 37–44, 2025, doi: 10.31603/komtika.v9i1.13449.

A. Rahman and A. Bustamam, “Deep learning with concatenate model to detect COVID-19 lung disease with CT scan images,” in AIP Conference Proceedings, AIP Publishing, 2022. doi: 10.1063/5.0072411.

P. Maneriker, J. W. Stokes, E. G. Lazo, D. Carutasu, F. Tajaddodianfar, and A. Gururajan, “URLTran: Improving Phishing URL Detection Using Transformers,” Proc. - IEEE Mil. Commun. Conf. MILCOM, vol. 2021-Novem, pp. 197–204, 2021, doi: 10.1109/MILCOM52596.2021.9653028.

P. Xu, “A Transformer-based Model to Detect Phishing URLs,” 2021, [Online]. Available: http://arxiv.org/abs/2109.02138

R. Liu et al., “PyraTrans: Attention-Enriched Pyramid Transformer for Malicious URL Detection,” pp. 1–12, 2023, [Online]. Available: http://arxiv.org/abs/2312.00508

Y. Lin et al., “Phishpedia: A hybrid deep learning based approach to visually identify phishing webpages,” Proc. 30th USENIX Secur. Symp., pp. 3793–3810, 2021.

A. Kulkarni, V. Balachandran, D. M. Divakaran, and T. Das, “From ML to LLM: Evaluating the Robustness of Phishing Web Page Detection Models against Adversarial Attacks,” Digit. Threat. Res. Pract., vol. 6, no. 2, pp. 1–26, 2025, doi: 10.1145/3737295.

J. L. Wilk-Jakubowski, L. Pawlik, G. Wilk-Jakubowski, and A. Sikora, “Machine Learning and Neural Networks for Phishing Detection: A Systematic Review (2017–2024),” Electron., vol. 14, no. 18, pp. 1–65, 2025, doi: 10.3390/electronics14183744.


How To Cite This :

Refbacks

  • There are currently no refbacks.