{"title":"Temporal Resilience of Phishing Detection Models in Machine Learning","authors":"Arvind Abraham, Gilad Gressel, K. Achuthan","doi":"10.2139/ssrn.3511056","DOIUrl":null,"url":null,"abstract":"Despite 10 years of research into phishing detection with machine learning, with models yielding greater than .95 F1-scores, in the past 10 years there has been a 277.51% increase in phishing attacks. In this work we examine the efficiency of a phishing detection model in terms of model drift. That is given a trained phishing detection model, how long will the model maintain the performance. It is important to examine and detect model drift for phishing detection because of the changing nature of the internet and subsequent phishing attacks. It is known that phishing URLs change intermittently, which causes models to become obsolete after a period of time.","PeriodicalId":378066,"journal":{"name":"PSN: Communications (Topic)","volume":"27 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-12-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"PSN: Communications (Topic)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.2139/ssrn.3511056","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Despite 10 years of research into phishing detection with machine learning, with models yielding greater than .95 F1-scores, in the past 10 years there has been a 277.51% increase in phishing attacks. In this work we examine the efficiency of a phishing detection model in terms of model drift. That is given a trained phishing detection model, how long will the model maintain the performance. It is important to examine and detect model drift for phishing detection because of the changing nature of the internet and subsequent phishing attacks. It is known that phishing URLs change intermittently, which causes models to become obsolete after a period of time.