Zainab Shaker Matar Al-Husseini
Department of Computer Science, College of Science, University of Diyala, Diyala, Iraq

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Phishing Email Detection Using Large Language Models and Explainable Artificial Intelligence Zainab Mohammed Ali; Zainab Shaker Matar Al-Husseini
Vokasi UNESA Bulletin of Engineering, Technology and Applied Science Vol. 3 No. 3 (2026): (In Progress)
Publisher : Universitas Negeri Surabaya or The State University of Surabaya

Show Abstract | Download Original | Original Source | Check in Google Scholar

Abstract

Phishing is a significant issue in cybersecurity; nowadays, with the help of generative artificial intelligence, attackers are capable of creating very convincing fake emails at large scale, which overwhelms traditional detection mechanisms. This paper suggests a hybrid model consisting of a fine-tuned Bidirectional Encoder Representations from Transformers model and a SHapley Additive explanations explainability layer to classify phishing in real-time. The model was trained over 120,000 labeled examples on three benchmark datasets, which were consolidated, with a fourteen-dimensional URL structural feature module added. The proposed framework was able to classify 98.70% of the 12,000-instances test set. Precision and recall were 98.40% and 98.90%, yielding an F1-score of 98.65%. The region below the receiver operating characteristic curve was 0.997. False positive rate was 0.90 which is sufficient to meet enterprise deployment. McNemar testing showed all the improvements greater than six baselines to be statistically significant (p less than 0.0001). In adversarial attacks, the lowest F1-score was 93.80, which is 6.20 percentage points better than the best baseline. The mean accuracy of cross-dataset generalization was 96.70 percent, which is 3.30 percentage points higher than the previous best benchmark. SHapley analysis found the top three discriminative features as URL entropy, sender domain anomaly, and urgency-linguistic patterns. The proposed architecture offers a correct, robust and interpretable phishing detection system; future research will focus on adversarial training and multilingual extension.