vix.ing · top · new · best · stats · spec

A Hybrid Deep Learning and Anomaly Detection Framework for Real-Time Malicious URL Classification

2025/11/30 by Khaled, Berkani, Zeraoulia Rafik, Rafik, Zeraoulia
Computer Science · Social Sciences · #Spam and Phishing Detection #Cybercrime and Law Enforcement Studies #Misinformation and Its Impacts

paper · pdf · doi:10.48550/arxiv.2512.03462

Abstract

Malicious URLs remain a primary vector for phishing, malware, and cyberthreats. This study proposes a hybrid deep learning framework combining HashingVectorizer n-gram analysis, SMOTE balancing, Isolation Forest anomaly filtering, and a lightweight neural network classifier for real-time URL classification. The multi-stage pipeline processes URLs from open-source repositories with statistical features (length, dot count, entropy), achieving O(NL + EBdh) training complexity and a 20 ms prediction latency. Empirical evaluation yields 96.4% accuracy, 95.4% F1-score, and 97.3% ROC-AUC, outperforming CNN (94.8%) and SVM baselines with a 50 ×--100 × speedup (Table~\reftab:comp-complexity). A multilingual Tkinter GUI (Arabic/English/French) enables real-time threat assessment with clipboard integration. The framework demonstrates superior scalability and resilience against obfuscated URL patterns.

Citations

Related