Claim Missing Document
Check
Articles

Found 1 Documents
Search
Journal : journal of digital technology and computer science

KLASIFIKASI KERENTANAN PHISHING DI KALANGAN MAHASISWA MENGGUNAKAN DECISION TREE Mhd. Murini Ramadhani; Muhammad Ikhsan
Journal of Digital Technology and Computer Science Vol. 3 No. 3 (2026): August 2026
Publisher : Academic Bright Collaboration

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.61220/dtcs.v3i3.1165

Abstract

Purpose – This study aims to classify phishing vulnerability among college students and identify the most influential factors using the C4.5 Decision Tree algorithm. Methods – A quantitative survey was conducted among 171 active Computer Science students at the State Islamic University of North Sumatra, Medan, Indonesia, from the 2023–2025 cohorts. Behavior, Knowledge, and cybersecurity training experience were used as predictor variables, while the vulnerability labels Vulnerable, Alert, and Aware were derived from responses to four hypothetical phishing scenarios. The model was developed using RapidMiner and evaluated through 10-fold cross-validation, a confusion matrix, and multiclass Receiver Operating Characteristic Area Under the Curve (ROC-AUC) using the One-vs-Rest approach. Findings – The dataset consisted of 131 Aware students (76.61%), 28 Alert students (16.37%), and 12 Vulnerable students (7.02%). The primary C4.5 model achieved 85.96% aggregate accuracy, but performance was uneven across classes: the macro-average F1-score was 69.84%, the Alert-class F1-score was 46.51% with 35.71% recall, and the Aware-class F1-score was 93.77%. The macro-average AUC was 0.8263. Phishing knowledge was the dominant predictor and formed the root node of the decision tree. Research implications – The model performed strongly for the Aware class but inconsistently across classes. The findings may inform exploratory cybersecurity education planning, but interpretation should remain cautious because of severe class imbalance, sensitivity to the operational vulnerability cutoffs, and recruitment from a single study program. Originality – The contribution is primarily contextual and application-oriented: phishing vulnerability is operationalized from scenario responses and examined together with behavioral, knowledge, and training factors in an interpretable multiclass model for an educational cybersecurity context, rather than as a methodological innovation in the C4.5 algorithm.