A Hybrid Graph Neural Network Framework for Malicious URL Classification

Sarah Mohammed Alshehri, Sanaa Abdullah Sharaf, Rania Molla · Electronics · 2025

The increasing reliance on Internet-based services has been accompanied by a rapid growth in cyber threats, particularly phishing attacks using misleading Uniform Resource Locators (URLs) to mislead users and compromise sensitive data. This paper proposes a hybrid deep learning architecture that integrates Graph Convolutional Networks (GCN), Attention Mechanism and Long Short-Term Memory (LSTM) networks, and for accurate classification of malicious and benign URLs. The model combines sequential pattern recognition through LSTM, structural graph representations via GCN, and feature prioritization using attention to enhance detection performance. Experiments were conducted on a labeled URL dataset of 100,000 and subsequently 200,000 samples, using consistent training and testing splits. The proposed model showed stable performance across different dataset sizes and ultimately outperformed other approaches on the expanded dataset, demonstrating stronger generalization capabilities. These findings highlight the effectiveness of the proposed hybrid model in capturing structural URL features, providing a reliable approach for detecting phishing attacks via structural URL analysis, and offer a foundation for future research on graph-based cybersecurity systems.

Read the paper · More papers on PaperTik