A Feature-Driven Approach to Phishing URL Detection Using Machine Learning

Tajuddeen Mashkur Muhammad, Agwom Itserim Emmanuel, Fatimah Adamu-Fika, Kamaludeen Shehu Bature, Abdullahi Danladi Maiauduga, Aanuoluwapo Enyojo Baba-Onoja, Onyinye Vivian Okpoko · Advances in Multidisciplinary & Scientific Research Journal Publication · 2025

1, 2, *3, 4, 5, 6 & 7 1,2,3,4,5Department of Cyber Security, Air Force Institute of Technology, Kaduna, Nigeria. 6,7Department of Computer Science, Air Force Institute of Technology, Kaduna, Nigeria. *Corresponding Author: [email protected] ABSTRACT Phishing attacks continue to pose a major cybersecurity threat by exploiting malicious URLs to deceive users and steal sensitive information. This study proposes a feature-driven machine learning system for phishing URL detection, leveraging customised lexical, structural, and domain-based attributes. Using publicly available datasets from PhishTank and OpenPhish, three models—LightGBM, XGBoost, and Logistic Regression—were evaluated. Among them, LightGBM achieved the best performance, with 93.2% accuracy and a 93.2% F1-score. Feature importance analysis highlighted the central role of URL length, suspicious keywords, and domain-related features in distinguishing phishing URLs from benign ones. The findings demonstrate the effectiveness of tailored feature engineering in improving detection accuracy and provide practical insights for building scalable, real-time phishing prevention tools. Future work will extend this framework by incorporating more diverse datasets, exploring deep learning approaches, and validating deployment in real-world environments. Keywords: Cybersecurity, Feature Extraction, LightGBM, Machine Learning, Malicious URLs, Phishing Detection.

Read the paper · More papers on PaperTik