HiTPhish: A hierarchical transformer architecture for robust phishing detection
Phishing continues to serve as the primary vector for major cyber incidents, facilitating data breaches, financial theft, and ransomware. Attackers increasingly exploit compromised legitimate infrastructure, which undermines the reliability of URL-based detection and shifts the burden onto the analysis of the HTML source. Models operating on that source face two design limitations: a dependence on handcrafted feature extraction and the systematic truncation of the input. To address them we propose HiTPhish, a hierarchical Transformer architecture that processes raw HTML documents of up to 67,815 tokens without truncation, combining local and global attention mechanisms. It comprises 1.83 million parameters and requires no pre-trained checkpoint, against the 148.7 and 128.1 million of Longformer and BigBird, and trains roughly thirty times faster on documents sixteen times longer. We further introduce an anti-dilution mechanism based on Max-Pooling and Multiple Instance Learning (MIL) that scores every segment independently and forms the document-level decision as the maximum over those scores, so that a malicious signal confined to a small region of the document is not diluted by the benign content surrounding it. Evaluated on four public datasets against those two architectures and a convolutional detector, HiTPhish performs on a par with the long-context baselines under nominal conditions, with no difference among the three Transformer-based systems exceeding 1.9 points of F1-score. The systems separate under signal dilution: with 2000 characters of injected benign content the Miss Rate of the baselines reaches 77.76% while HiTPhish remains below 12%.
Authors
- Felipe Castaño (ORCID: https://orcid.org/0000-0001-9157-4111)
- Rocío Aláiz-Rodríguez (ORCID: https://orcid.org/0000-0003-4164-5887)
- Eduardo Fidalgo (ORCID: https://orcid.org/0000-0003-1202-5232)
- Raúl Orduna
Institutions
- Vicomtech (ES)
- Universidad de León (ES)
Publication Details
- Journal
- Journal of Information Security and Applications
- Published
- 2026-10-07
- DOI
- https://doi.org/10.1016/j.jisa.2026.104669
- Primary Topic
- Spam and Phishing Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00