Deep Learning and Explainable AI for Email Phishing Classification: A Comparative Study of TabNet, NODE and FT-Transformer Models
Öz
In the changing landscape of cybersecurity threats, phishing emails indicate a persistent and damaging attack vector. This study investigates the effectiveness of deep learning models on a phishing email classification task using tabular data and focusing on TabNet, NODE (Neural Oblivious Decision Ensembles), and FT-Transformer architectures. The utilized dataset includes eight input features capturing linguistic and structural characteristics of emails, with a binary label indicating phishing or normal classification. Additionally, the NearMiss under-sampling approach is applied to address the significant class imbalance. Experimental results demonstrate that while all three models achieve strong performance, the FT-Transformer model outperforms TabNet and NODE by achieving the highest classification accuracy and balanced precision-recall scores. Additionally, explainable artificial intelligence (XAI) methods, SHAP and LIME, are employed to interpret the FT-Transformer model’s decision-making process, which highlights the critical role of spelling errors, unique word counts, and urgency-related keywords in phishing detection. The findings emphasize the potential of transformer-based approaches for tabular cybersecurity applications and indicate the importance of interpretable AI in enhancing trust and transparency in phishing detection systems.
Anahtar Kelimeler
Kaynakça
- [1] Apwg, “Phishing Activity Trends Report”, 4th Quarter 2023. 2024, Anti-Phishing Working Group, (2024).
- [2] Proofpoint, “2024 State of the Phish – Today’s Cyber Threats and Phishing Protection”, Proofpoint, (2024).
- [3] Ünal, C. and Şahin, İ., “İstenmeyen Elektronik Postaların (SPAM) Filtrelenmesi için Bir Uzman Sistem Tasarımı ve Gerçekleştirilmesi.”, Politeknik Dergisi, 20(2), 267-274, (2017).
- [4] Çıtlak, O., Dörterler, M. and Dogru, İ., “A hybrid spam detection framework for social networks.”, Politeknik Dergisi, 26(2), 823-837, (2022).
- [5] Fan, Z., Li, W., Laskey, K. B. and Chang, K. C., “Investigation of phishing susceptibility with explainable artificial intelligence.”, Future Internet, 16(1), 31, (2024).
- [6] Divakaran, D.M. and A. Oest, “Phishing detection leveraging machine learning and deep learning: A review.”, IEEE Security & Privacy, 20(5): p. 86-95, (2022).
- [7] Zuraiq, A.A. and M. Alkasassbeh. “Phishing detection approaches.”, In 2019 2nd International Conference on new Trends in Computing Sciences (ICTCS), IEEE, (2019).
- [8] Mohammad, R.M., F. Thabtah, and L. McCluskey, “Intelligent rule‐based phishing websites classification.”, IET Information Security, 8(3): p. 153-160, (2014).
Ayrıntılar
Birincil Dil
İngilizce
Konular
Derin Öğrenme, Nöral Ağlar
Bölüm
Araştırma Makalesi
Yazarlar
Burçak Asal
*
0009-0003-3729-8170
Türkiye
Saadin Oyucu
0000-0003-3880-3039
Türkiye
Ferdi Doğan
0000-0002-9203-697X
Türkiye
Onur Polat
0000-0001-9313-4910
Türkiye
Ahmet Aksöz
0000-0002-2563-1218
Türkiye
Erken Görünüm Tarihi
2 Kasım 2025
Yayımlanma Tarihi
29 Mart 2026
Gönderilme Tarihi
17 Temmuz 2025
Kabul Tarihi
29 Eylül 2025
Yayımlandığı Sayı
Yıl 2026 Cilt: 29 Sayı: 3