Skip to main navigation Skip to search Skip to main content

An Explainable Multi-Modal Hierarchical Attention Model for Developing Phishing Threat Intelligence

  • Yidong Chai (Co-first Author)
  • , Yonghang Zhou (Co-first Author)
  • , Weifeng Li
  • , Yuanchun Jiang*
  • *Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

Abstract

Phishing website attack, as one of the most persistent forms of cyber threats, evolves and remains a major cyber threat. Various detection methods (e.g., lookup systems, fraud cue-based methods) have been proposed to identify phishing websites. The limitations of lookup systems (e.g., failing to address newly created attacks) and the fraud cue-based methods (e.g., relying on feature engineering) motivated the development of deep representation-based methods capable of learning deep fraud cues for enhanced anti-phishing capacity. Focusing mostly on URLs, these methods fail to analyze other two important modalities of website content: textual information and visual design. Moreover, the interpretability of these deep learning based methods is limited, reducing model trustworthiness and preventing relevant and actionable intelligence. As such, we propose a multi-modal hierarchical attention model (MMHAM) which jointly learns the deep fraud cues from the three major modalities of website content for phishing website detection. Specifically, MMHAM features an innovative shared dictionary learning approach for aligning representations from different modalities in the attention mechanism. In our evaluation experiments, the proposed MMHAM not only learned improved deep cues for enhanced phishing detection, but provided a hierarchical interpretability system from which we could develop phishing threat intelligence to inform phishing websites detection at different levels. © 2021 IEEE.
Original languageEnglish
Pages (from-to)790-803
JournalIEEE Transactions on Dependable and Secure Computing
Volume19
Issue number2
Online published12 Oct 2021
DOIs
Publication statusPublished - Mar 2022
Externally publishedYes

Funding

This work was supported in part by the National Natural Science Foundation of China under Grants 91846201, 71722010, 72101079, 72171071, and 91746302, in part by the Research Project of Zhejiang Lab under Grant 2019KE0AB04, and in part by Shanghai Data Exchange Cooperative Program under Grant W2021JSZX0052.

Research Keywords

  • Antiphishing
  • machine learning
  • multimodal systems
  • security and protection

Fingerprint

Dive into the research topics of 'An Explainable Multi-Modal Hierarchical Attention Model for Developing Phishing Threat Intelligence'. Together they form a unique fingerprint.

Cite this