A machine-learning system can identify fake, or “spoofed”, website addresses, according to research in the International Journal of Electronic Security and Digital Forensics. The work offers a new tool to protect users against phishing attacks, where attackers direct someone to a deceptive website to steal information such as bank logins or personal and private data.
The team combined two deep-learning techniques: a convolutional neural network (CNN), which can identify patterns in data, and a long short-term memory (LSTM) network, which can retain information about sequences in that data. This hybrid CNN-LSTM model achieved accuracy rates of almost 99 per cent on the UCL standard test dataset and almost 97 per cent on the PhishTank dataset.
The findings highlight the potential for automated AI systems in protecting people using online commerce, government services, and other activities. Phishing attacks remain particularly difficult to address as a cybercrime problem because they often simply exploit human behaviour and weaknesses rather than being a technical loophole. If a message is sufficiently convincing and a website realistic, then vulnerable or even simply distracted users might disclose sensitive information without realising they have been duped.
A system to accurately flag spoofed addresses before that happens would be invaluable. For the small percentage that it false-flags, the inconvenience would be negligible compared to what is not lost by blocking spoofed sites.
Santhosh Krishna, B.V., Vidhya, S., Krishnaveni, S. and Ashokkumar, N. (2026) ‘A hybrid deep learning method for URL spoofing in websites’, Int. J. Electronic Security and Digital Forensics, Vol. 18, No. 5, pp.524–537.
News media may use this press release as source material, in whole or in part, provided the content is not materially misrepresented. A link back to the original article is appreciated.