VeriPhish: Bridging AI Explainability and Accuracy in Phishing Detection Through XAI and LLMs
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14610%2F25%3A00143083" target="_blank" >RIV/00216224:14610/25:00143083 - isvavai.cz</a>
Výsledek na webu
<a href="https://ieeexplore.ieee.org/document/11295116" target="_blank" >https://ieeexplore.ieee.org/document/11295116</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/ICCST63435.2025.11295116" target="_blank" >10.1109/ICCST63435.2025.11295116</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
VeriPhish: Bridging AI Explainability and Accuracy in Phishing Detection Through XAI and LLMs
Popis výsledku v původním jazyce
Phishing attacks have evolved into a significant cybersecurity threat, becoming more frequent and increasingly difficult to defend against. While machine learning techniques show promise for detecting these threats, they typically operate as "black boxes," providing little insight into their decision-making processes. This lack of transparency undermines user confidence and reduces the effectiveness of threat response. To address this challenge, we introduce VeriPhish, a framework designed to improve phishing detection through a three-part architecture. The framework combines a machine learning classifier using domain-specific features, a dual-explanation layer that integrates LIME and SHAP for detailed feature-level analysis, and an LLM enhancement module that leverages DeepSeek v3 to convert technical explanations into understandable natural language. Our experiments demonstrate that VeriPhish achieves 98.4 % accuracy across all tested metrics, performing comparably to existing deep learning methods while offering superior explainability. The framework provides explanations with 94.2% accuracy and shows 96.8 % consistency between the LLM-generated explanations and the model's predictions. VeriPhish is available as both a fully functional GUI application and a lightweight Chrome extension, demonstrating its versatility across various deployment contexts. This work shows that high detection accuracy can be successfully paired with effective explainability in security applications, addressing the critical gap between AI-driven systems and user trust in phishing detection.
Název v anglickém jazyce
VeriPhish: Bridging AI Explainability and Accuracy in Phishing Detection Through XAI and LLMs
Popis výsledku anglicky
Phishing attacks have evolved into a significant cybersecurity threat, becoming more frequent and increasingly difficult to defend against. While machine learning techniques show promise for detecting these threats, they typically operate as "black boxes," providing little insight into their decision-making processes. This lack of transparency undermines user confidence and reduces the effectiveness of threat response. To address this challenge, we introduce VeriPhish, a framework designed to improve phishing detection through a three-part architecture. The framework combines a machine learning classifier using domain-specific features, a dual-explanation layer that integrates LIME and SHAP for detailed feature-level analysis, and an LLM enhancement module that leverages DeepSeek v3 to convert technical explanations into understandable natural language. Our experiments demonstrate that VeriPhish achieves 98.4 % accuracy across all tested metrics, performing comparably to existing deep learning methods while offering superior explainability. The framework provides explanations with 94.2% accuracy and shows 96.8 % consistency between the LLM-generated explanations and the model's predictions. VeriPhish is available as both a fully functional GUI application and a lightweight Chrome extension, demonstrating its versatility across various deployment contexts. This work shows that high detection accuracy can be successfully paired with effective explainability in security applications, addressing the critical gap between AI-driven systems and user trust in phishing detection.
Klasifikace
Druh
D - Stať ve sborníku
CEP obor
—
OECD FORD obor
10200 - Computer and information sciences
Návaznosti výsledku
Projekt
—
Návaznosti
I - Institucionalni podpora na dlouhodoby koncepcni rozvoj vyzkumne organizace
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název statě ve sborníku
2025 IEEE International Carnahan Conference on Security Technology (ICCST)
ISBN
9798331523190
ISSN
—
e-ISSN
—
Počet stran výsledku
6
Strana od-do
1-6
Název nakladatele
IEEE
Místo vydání
New York, NY
Místo konání akce
San Antonio, TX, USA
Datum konání akce
13. 10. 2025
Typ akce podle státní příslušnosti
WRD - Celosvětová akce
Kód UT WoS článku
001710575400035