Hybrid Ensemble Learning for Malicious URL Detection With BERT and Boosting Models
Junhyeong Lee, Hyun Kwon · IEEE Access · 2026
Malicious Uniform Resource Locator (URL) detection remains a critical and actively researched topic in the field of cybersecurity due to the increasing prevalence and sophistication of web-based threats. In modern military communications, malicious URLs can disrupt command-and-control systems, leading to compromised operational security. Consequently, robust URL detection in military networks is paramount for maintaining mission continuity. However, existing single-model approaches often fall short in addressing the diverse structural and semantic characteristics of modern malicious URLs. To overcome these limitations, this study proposes a hybrid ensemble detection framework that integrates tree-based models with a Bidirectional Encoder Representations from Transformers (BERT). In the data preprocessing stage, key structural features were extracted from URLs, and tokenized sequences were prepared for BERT input. Tree-based models were independently trained on the extracted features, while the BERT model was fine-tuned for binary classification of malicious URLs. Hyperparameters for the tree-based models were optimized using Optuna, and a sampling strategy was adopted for BERT training to mitigate class imbalance and computational cost. Soft Voting was applied to the tree-based models to enhance their collective performance, and the final predictions were generated through Weighted Voting that combined outputs from both the tree-based ensemble and the BERT model. Experimental results demonstrate that the proposed hybrid ensemble significantly outperforms traditional single-model baselines and simple ensemble methods, achieving improved detection accuracy and robustness. These findings demonstrate the effectiveness and practical applicability of the proposed hybrid approach in real-world malicious URL detection systems.