International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1723012

1723012 Vol 10 · Issue 3 Download Paper

Machine Learning-Based Phishing Detection Techniques: A Systematic Literature Review

Ekpo Precious Emmanuel Solomon Ahiba Assoc. Prof. Vivian Nwaocha Eru Akwuma Nathaniel Ojima Gabriella Ob'lama

Subject area: Science,Engineering and Technology  ·  Area of research: Machine Learning

DOI: 10.64388/IREV10I3-1723012

Abstract

Phishing remains a persistent cybersecurity threat because attackers combine social engineering with rapidly changing emails, websites, URLs, text messages, QR codes, and mobile channels. Static blacklists and manually defined rules are increasingly inadequate for previously unseen campaigns. This study systematically reviews machine learning-based phishing detection research published between 2020 and 2026. A PRISMA-guided protocol was used to identify, screen, appraise, and synthesise 50 studies. The review examined the techniques employed, their reported effectiveness, the datasets and evaluation metrics used, and the principal limitations and emerging research directions. Five technique families were identified: traditional machine learning, ensemble learning, deep learning, transformer and large-language-model approaches, and explainable or hybrid intelligent systems. Traditional classifiers remain attractive for efficiency and interpretability, while ensemble, deep, transformer, multimodal, and continual-learning methods increasingly address complex features, contextual language, concept drift, and cross-channel attacks. PhishTank, OpenPhish, the UCI Phishing Websites dataset, ISCX-URL2016, SpamAssassin, Enron, and related repositories were commonly used. Accuracy was reported in 48 of the 50 studies, followed by precision (43), recall (42), and F1-score (41), whereas ROC-AUC, Matthews correlation coefficient, and error-rate measures were less frequent. Dataset ageing, class imbalance, weak cross-dataset generalisation, adversarial manipulation, computational cost, and limited explainability remain major barriers. Practical progress depends on adaptive, lightweight, explainable, and robust models evaluated with current datasets and standardised multi-metric protocols.

Keywords

Cybersecurity, deep learning, explainable artificial intelligence, large language models, machine learning, phishing detection, systematic literature review, transformer models

References

[1] Z. Alkhalil, C. Hewage, L. Nawaf, and I. Khan, “Phishing attacks: A recent comprehensive study and a new anatomy,” Frontiers in Computer Science, vol. 3, 2021. Crossref

[2] S. Kavya and D. Sumathi, “Staying ahead of phishers: A review of recent advances and emerging methodologies in phishing detection,” Artificial Intelligence Review, vol. 58, no. 2, 2024. Crossref

[3] A. E. Aassal, S. Baki, A. Das, and R. Verma, “An in-depth benchmarking and evaluation of phishing detection research for security needs,” IEEE Access, vol. 8, pp. 22170–22192, 2020. Crossref

[4] R. Abdillah, Z. Shukur, M. Mohd, and M. Z. Murah, “Phishing classification techniques: A systematic literature review,” IEEE Access, vol. 10, pp. 41574–41591, 2022. Crossref

[5] K. Subashini and V. Narmatha, “Detecting phishing websites using recent techniques: A systematic literature review,” ITM Web of Conferences, vol. 57, art. no. 01008, 2023. Crossref

[6] A. Aljofey et al., “An effective detection approach for phishing websites using URL and HTML features,” Scientific Reports, vol. 12, art. no. 8842, 2022. Crossref

[7] Y. Al-Tamimi and M. Shkoukani, “Employing cluster-based class decomposition approach to detect phishing websites using machine learning classifiers,” International Journal of Data and Network Science, vol. 7, no. 1, pp. 313–328, 2023. Crossref

[8] Y. Wei and Y. Sekiya, “Sufficiency of ensemble machine learning methods for phishing websites detection,” IEEE Access, vol. 10, pp. 124103–124113, 2022. Crossref

[9] N. Innab et al., “Phishing attacks detection using ensemble machine learning algorithms,” Computers, Materials & Continua, vol. 80, no. 1, pp. 1325–1345, 2024. Crossref

[10] Z. Alshingiti, R. Alaqel, J. Al-Muhtadi, E.-H. Qazi, K. Saleem, and M. H. Faheem, “A deep learning-based phishing detection system using CNN, LSTM, and LSTM-CNN,” Electronics, vol. 12, no. 1, art. no. 232, 2023. Crossref

[11] U. A. Butt, R. Amin, H. Aldabbas, S. Mohan, B. Alouffi, and A. Ahmadian, “Cloud-based email phishing attack using machine and deep learning algorithm,” Complex & Intelligent Systems, vol. 9, no. 3, pp. 3043–3070, 2023. Crossref

[12] R. Melendez, M. Ptaszynski, and F. Masui, “Comparative investigation of traditional machine-learning models and transformer models for phishing email detection,” Electronics, vol. 13, no. 24, art. no. 4877, 2024. Crossref

[13] S. S. Shafin, “An explainable feature selection framework for web phishing detection with machine learning,” Data Science and Management, vol. 8, no. 2, pp. 127–136, 2025. Crossref

[14] T. Kehkashan et al., “Explainable phishing website detection for secure and sustainable cyber infrastructure,” Scientific Reports, vol. 15, art. no. 41751, 2025. Crossref

[15] M. N. Suhaimee et al., “Real-time incremental transformer with continual learning for adaptive phishing email detection,” pp. 1–6, 2025.

[16] D. Sivaneswaran, C. T. E. R. Hewage, H. M. K. K. M. B. Herath, R. S. Rathore, V. K. Singh, and W. Jiang, “A systematic literature review of large language models in phishing attack generation and detection,” Array, vol. 30, art. no. 100775, 2026. Crossref

[17] A. Hannousse and S. Yahiouche, “Towards benchmark datasets for machine learning based website phishing detection: An experimental study,” Engineering Applications of Artificial Intelligence, vol. 104, art. no. 104347, 2021. Crossref

[18] P. Afonso, E. Maia, I. Amorim, and I. Praca, “Rethinking phishing detection: How dataset quality affects model generalization,” pp. 542–547, 2025.

[19] B. Sabir, M. A. Babar, R. Gaire, and A. Abuadbba, “Reliability and robustness analysis of machine learning based phishing URL detectors,” IEEE Transactions on Dependable and Secure Computing, pp. 1–18, 2022. Crossref

[20] I. Skula and M. Kvet, “A framework for preparing a balanced and comprehensive phishing dataset,” IEEE Access, vol. 12, pp. 53610–53622, 2024. Crossref

[21] C. Opara, Y. Chen, and B. Wei, “Look before you leap: Detecting phishing web pages by exploiting raw URL and HTML characteristics,” Expert Systems with Applications, vol. 236, art. no. 121183, 2024. Crossref

[22] M. J. Page et al., “The PRISMA 2020 statement: An updated guideline for reporting systematic reviews,” BMJ, vol. 372, art. no. n71, 2021. Crossref

[23] B. Kitchenham and S. Charters, Guidelines for Performing Systematic Literature Reviews in Software Engineering, EBSE Technical Report EBSE-2007-01, Keele University and Durham University, 2007.

[24] A. Awasthi and N. Goel, “Phishing website prediction using base and ensemble classifier techniques with cross-validation,” Cybersecurity, vol. 5, art. no. 22, 2022. Crossref

[25] R. S. Rao, C. Kondaiah, A. R. Pais, and B. Lee, “A hybrid super learner ensemble for phishing detection on mobile devices,” Scientific Reports, vol. 15, art. no. 16839, 2025. Crossref

[26] M. A. Uddin and I. H. Sarker, “An explainable transformer-based model for phishing email detection: A large language model approach,” SSRN Electronic Journal, 2024. Crossref

[27] Z. Fatima et al., “Explainable AI for IoT devices and robotic communication phishing detection,” Engineering, Technology & Applied Science Research, vol. 15, no. 5, pp. 26478–26486, 2025. Crossref

[28] M. C. Calzarossa, P. Giudici, and R. Zieni, “An assessment framework for explainable AI with applications to cybersecurity,” Artificial Intelligence Review, vol. 58, no. 5, 2025. Crossref

[29] Y. Sun, G. Liu, X. Han, W. Zuo, and W. Liu, “FusionNet: An effective network phishing website detection framework based on multi-modal fusion,” pp. 474–481, 2023. Crossref

[30] A. Ejaz, A. N. Mian, and S. Manzoor, “Life-long phishing attack detection using continual learning,” Scientific Reports, vol. 13, art. no. 11488, 2023. Crossref

[31] A. Vulfin, A. E. Sulavko, V. Vasiliev, A. Minko, A. Kirillova, and A. Samotuga, “A multimodal phishing website detection system using explainable artificial intelligence technologies,” Machine Learning and Knowledge Extraction, vol. 8, no. 1, art. no. 11, 2026. Crossref

[32] Y. Wei, M. Nakayama, and Y. Sekiya, “Enhancing generalization in phishing URL detection via a fine-tuned BERT-based multimodal approach,” IEEE Access, vol. 13, pp. 131197–131216, 2025. Crossref

[33] A. Alhuzali, Q. Al-Qahtani, A. Niyazi, L. Alshehri, and F. Alharbi, “PhishNet: A real-time, scalable ensemble framework for smishing attack detection using transformers and LLMs,” Computers, Materials & Continua, vol. 86, no. 1, pp. 1–19, 2025. Crossref

[34] S. Ariyadasa, S. Fernando, and S. Fernando, “PhishRepo: A seamless collection of phishing data to fill a research gap in the phishing domain,” International Journal of Advanced Computer Science and Applications, vol. 13, no. 5, 2022.

[35] J. C. G. de Barros et al., “Piracema: A phishing snapshot database for building dataset features,” Scientific Reports, vol. 12, art. no. 15149, 2022. Crossref

[36] F. Janez-Martino, R. Alaiz-Rodriguez, V. Gonzalez-Castro, E. Fidalgo, and E. Alegre, “A review of spam email detection: Analysis of spammer strategies and the dataset shift problem,” Artificial Intelligence Review, vol. 56, no. 2, pp. 1145–1173, 2023. Crossref

[37] D. Timko and M. L. Rahman, “Smishing Dataset I: Phishing SMS dataset from Smishtank.com,” pp. 289–294, 2024. Crossref

[38] Y.-D. Tsai, C. Liow, Y. S. Siang, and S.-D. Lin, “Toward more generalized malicious URL detection models,” Proceedings of the AAAI Conference on Artificial Intelligence, vol. 38, no. 19, pp. 21628–21636, 2024. Crossref

[39] D. Chicco and G. Jurman, “The advantages of the Matthews correlation coefficient over F1 score and accuracy in binary classification evaluation,” BMC Genomics, vol. 21, art. no. 6, 2020. Crossref

[40] G. D. Bispo et al., “PHILDER: Lightweight framework for intelligent phishing detection on resource-limited devices,” IEEE Access, vol. 13, pp. 131967–131979, 2025. Crossref

How to cite this paper

Ekpo Precious Emmanuel, Solomon Ahiba, Assoc. Prof. Vivian Nwaocha, Eru Akwuma Nathaniel, Ojima Gabriella Ob'lama "Machine Learning-Based Phishing Detection Techniques: A Systematic Literature Review" Iconic Research And Engineering Journals Volume 10 Issue 3 2026 Page 1196-1206 https://doi.org/10.64388/IREV10I3-1723012
Ekpo Precious Emmanuel, Solomon Ahiba, Assoc. Prof. Vivian Nwaocha, Eru Akwuma Nathaniel, Ojima Gabriella Ob'lama "Machine Learning-Based Phishing Detection Techniques: A Systematic Literature Review" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026, doi: https://doi.org/10.64388/IREV10I3-1723012
Ekpo Precious Emmanuel, Solomon Ahiba, Assoc. Prof. Vivian Nwaocha, Eru Akwuma Nathaniel, Ojima Gabriella Ob'lama (2026). Machine Learning-Based Phishing Detection Techniques: A Systematic Literature Review. Iconic Research And Engineering Journals, 10(3). doi: https://doi.org/10.64388/IREV10I3-1723012
Ekpo Precious Emmanuel, Solomon Ahiba, Assoc. Prof. Vivian Nwaocha, Eru Akwuma Nathaniel, Ojima Gabriella Ob'lama "Machine Learning-Based Phishing Detection Techniques: A Systematic Literature Review" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026. Crossref, https://doi.org/10.64388/IREV10I3-1723012
@article{1723012,
      author = {Ekpo Precious Emmanuel, Solomon Ahiba, Assoc. Prof. Vivian Nwaocha, Eru Akwuma Nathaniel, Ojima Gabriella Ob'lama},
      title = {Machine Learning-Based Phishing Detection Techniques: A Systematic Literature Review},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {3},
      pages = {1196-1206},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1723012.pdf},
      abstract = {Phishing remains a persistent cybersecurity threat because attackers combine social engineering with rapidly changing emails, websites, URLs, text messages, QR codes, and mobile channels. Static blacklists and manually defined rules are increasingly inadequate for previously unseen campaigns. This study systematically reviews machine learning-based phishing detection research published between 2020 and 2026. A PRISMA-guided protocol was used to identify, screen, appraise, and synthesise 50 studies. The review examined the techniques employed, their reported effectiveness, the datasets and evaluation metrics used, and the principal limitations and emerging research directions. Five technique families were identified: traditional machine learning, ensemble learning, deep learning, transformer and large-language-model approaches, and explainable or hybrid intelligent systems. Traditional classifiers remain attractive for efficiency and interpretability, while ensemble, deep, transformer, multimodal, and continual-learning methods increasingly address complex features, contextual language, concept drift, and cross-channel attacks. PhishTank, OpenPhish, the UCI Phishing Websites dataset, ISCX-URL2016, SpamAssassin, Enron, and related repositories were commonly used. Accuracy was reported in 48 of the 50 studies, followed by precision (43), recall (42), and F1-score (41), whereas ROC-AUC, Matthews correlation coefficient, and error-rate measures were less frequent. Dataset ageing, class imbalance, weak cross-dataset generalisation, adversarial manipulation, computational cost, and limited explainability remain major barriers. Practical progress depends on adaptive, lightweight, explainable, and robust models evaluated with current datasets and standardised multi-metric protocols.},
      keywords = {Cybersecurity, deep learning, explainable artificial intelligence, large language models, machine learning, phishing detection, systematic literature review, transformer models},
      month = {September},
      doi = {https://doi.org/10.64388/IREV10I3-1723012}
  }