Hybrid feature selection with SHAP-based explainable AI for interpretable phishing website detection
Phishing websites remain a significant cybersecurity threat, exploiting users through deceptive web interfaces and continuously evolving attack strategies. Despite the effectiveness of machine learning approaches, many existing solutions suffer from limited interpretability, redundant feature representations, and evaluation practices that may lead to overly optimistic performance estimates. This study proposes a phishing website detection framework that integrates hybrid feature selection with explainable artificial intelligence (XAI). The proposed approach combines Mutual Information, Χ², and SHapley Additive exPlanations (SHAP)-based feature importance to identify the most informative and discriminative features from complementary statistical, information-theoretic, and model-driven perspectives. The framework was evaluated using the PhiUSIIL dataset and further validated on an external URL-only dataset to assess generalization capability. To ensure reliable performance estimation and prevent information leakage, feature selection was performed independently within each fold of a 10-fold stratified cross-validation procedure. Five machine learning classifiers, namely Decision Tree, Random Forest, XGBoost, LightGBM, and CatBoost, were evaluated using classifier-specific feature subsets generated independently within the cross-validation procedure. Experimental results demonstrate that the proposed hybrid feature selection framework substantially reduces the feature space while maintaining predictive performance comparable to that achieved using all available features. Across the evaluated classifiers, XGBoost provided the most balanced overall performance. Additional analyses showed that the near-perfect performance observed on the PhiUSIIL dataset was dataset-dependent, with lower performance obtained on the external dataset and under an oracle-informed worst-case feature perturbation scenario, highlighting the sensitivity of the framework under more demanding evaluation conditions. SHAP further improves model interpretability by providing both global and local explanations of feature contributions while supporting the feature selection process. Overall, the findings demonstrate that integrating statistical, information-theoretic, and explainability-driven feature selection can substantially reduce feature dimensionality while preserving predictive performance and improving model interpretability. The proposed framework provides an interpretable and computationally efficient basis for phishing website detection, while its practical deployment remains dependent on feature-extraction costs and validation under heterogeneous operational conditions.
Authors
- Norah Alsuqayh
- Areej Alhogail
- Abdulrahman Mirza
Institutions
- King Saud University (SA)
Publication Details
- Journal
- Journal of King Saud University - Computer and Information Sciences
- Published
- 2026-09-30
- DOI
- https://doi.org/10.1007/s44443-026-01281-6
- Primary Topic
- Spam and Phishing Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00