L2 Regularization to Mitigate Overfitting in Email Phishing Attack Detection by CNN-LSTM
Aji Gautama Putrada, Rizky Farras Aushaf · 2024
Several studies have used convolutional neural networks and long short-term memory (CNN-LSTM) models to detect phishing emails because of their ability to capture attack patterns from raw data well. However, using CNN-LSTM to capture patterns in phishing email text datasets can cause overfitting problems. This research aims to evaluate the effectiveness of L2 Regularization in overfitting phishing email detection by CNN-LSTM. We obtained the phishing email detection dataset from Kaggle. We applied several natural language processing (NLP) pre-processing, such as text cleaning, tokenizing, padding, and Count Vectorization. We then applied CNN-LSTM with L2 Regularization and benchmarked it with four other methods: Original, Dropout, global vector for word embedding (GloVe Embedding), and Combined Method. We used validation loss curve, accuracy, sensitivity, specificity, and g-mean metrics to compare the performance of each method. The test results with Count Vectorization show that the target of the phishing email attack is at the university and that the characteristics of the attack are marked by polite language. This is seen as an attempt by the attacker to make the target more persuasive. The results of the validation loss curve show that the L2 Regularization model training does not experience overfitting, and its curve looks smooth, unlike other methods. Finally, L2 Regularization has the best g-mean compared to other methods, where the value is 0.926.