Awwab Mohammad, N. Praveen, Pandiarajan S, R. Shreeshayana, S. Jagadeesh, Anjali Raj, Basavaraj Patil, Yogesh H. Bhosale, Sanath Nagaraj, D Anil
In order to avoid detection, modern phishing assaults use techniques such as dynamic HTML obfuscation and site mimicry. This study presents NetPhish-Mix, a powerful framework for detecting phishing attempts by combining the analysis of website structure, content, and design. The framework's HGT records the structural relationships between the various components, including domain, URL, and DOM nodes. In addition, the framework can retrieve visual semantics from page screenshots while considering the page layout thanks to a ViT. After temperature calibration, a gated late-fusion procedure modifies the contributions of both modalities as needed to generate trustworthy confidence estimations. The results show significant generalization when tested on distinct and previously withheld datasets, achieving an F1-score of 0.977, an ROC-AUC of 0.997, and a less than 1% false positive rate. The proposed NetPhish-Mix model consistently makes the correct decision in tests that include URL homoglyphs, additional characters in subdomains, and poor images, making it a reliable, easy-to-understand, and practical security automation solution that can identify and stop phishing attempts.