Privacy-Preserving and Explainable Phishing Website Detection Using Federated Continual Learning
Phishing websites are continuously modified to imitate legitimate services, evade static blacklists, and exploit user trust. Machine-learning-based detection can identify previously unseen patterns, but conventional centralized training requires sensitive URL, browsing, webpage, and behavioral information to be collected at a central location. This paper proposes FedXPhish, a privacy-preserving and explainable phishing website detection framework that unifies multimodal feature analysis, federated learning, continual learning, differential privacy, secure aggregation, robust aggregation, and explainable artificial intelligence (XAI). Each participating client extracts URL lexical, domain/TLS, HTML/text, visual, and behavioral features locally. A local multimodal classifier is trained without transferring raw data. Protected updates are securely aggregated to obtain a global model. Continual learning enables adaptation to emerging phishing campaigns while replay and proximal regularization reduce catastrophic forgetting. SHAP and LIME are used to provide global and instance-level explanations. The paper defines a timeaware, non-IID evaluation protocol covering detection performance, privacy, continual adaptation, communication efficiency, explanation quality, and robustness to malicious clients. The work is positioned as a conference-ready research framework; numerical results are deliberately not fabricated and should be inserted after implementation and experimentation.
Authors
- Jyoti Sarwade
- Tanvi Khadse
- Sonal Kotkar
- Dhanshri Pansare
- Siddhi Pawar
Institutions
- G.S. Science, Arts And Commerce College (IN)
Publication Details
- Journal
- International Journal of Innovative Research in Technology
- Published
- 2026-09-16
- DOI
- https://doi.org/10.64643/ijirt.208519-459
- Primary Topic
- Spam and Phishing Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00