Adversarial attacks on phishing webpage detectors via heuristic search techniques
- Autori: Lo Re, G.; Morana, M.; Rizzo, G.
- Anno di pubblicazione: 2026
- Tipologia: Articolo in rivista
- OA Link: http://hdl.handle.net/10447/707089
Abstract
Phishing remains one of the most prevalent cybersecurity threats, endangering users’ personal data, financial assets and online privacy. Although Machine Learning Phishing Website Detectors (ML-PWDs) are an effective tool for identifying malicious webpages, recent studies have revealed that these models are vulnerable to adversarial attacks. In this study, we present a new adversarial attack strategy capable of operating in the problem space, which uses heuristic search algorithms, including Beam Search, Simulated Annealing and Monte Carlo Tree Search, to generate adversarial samples that evade state-of-the-art detectors while maintaining visual and functional fidelity. Our approach optimizes the trade-off between the number of manipulations and attack success, minimizing the distance from the original sample. Experiments on two public datasets demonstrate that our method reduces the average detection rate from 0.80 to 0.05 on Zenodo and from 0.82 to 0.03 on δ Phish, while requiring up to 70% fewer manipulations than competing attacks. Furthermore, the generated samples remain closer to the originals in the L 0 and L 2 metrics, indicating strong statistical plausibility. These results highlight the effectiveness of our approach in evading ML-PWDs and its potential for evaluating and strengthening the adversarial robustness of real-world detection systems.
