Gradient Boosting Decision Trees for Real-Time Phishing Attack Prevention in Cybersecurity
Bibliographic record
Abstract
Phishing remains one of the most persistent threats in cybersecurity, exploiting human and technical vulnerabilities to compromise sensitive information. Traditional detection methods in network security often struggle to keep pace with the dynamic and evolving nature of phishing attacks, highlighting the need for more adaptive and intelligent solutions. This research uses a comprehensive quantitative analysis to evaluate the effectiveness of machine learning using Gradient Boosting Decision Trees (GBDT) for real-time phishing attack prevention. The proposed model used in this study integrates textual features derived from TF-IDF with dimensionality reduction and lightweight heuristic indicators, enabling efficient and accurate classification of phishing attempts in near real-time. Using a benchmark dataset of $\mathbf{5, 8 0 9}$ email messages, the model achieved 97.16% accuracy, with substantial precision, recall, and ROC-AUC performance, demonstrating its robustness for practical deployment in intrusion detection and phishing defense systems. Unlike prior approaches that rely solely on traditional classification or heavy deep learning models, this study underscores the value of GBDT as a balanced solution that offers high detection capability and computational efficiency. The uniqueness of this research lies in its demonstration of how boosting techniques within the machine learning domain can provide scalable, real-time defense mechanisms against phishing, making it a compelling contribution to advancing proactive network security and cybersecurity strategies.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.002 | 0.001 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.001 | 0.002 |
| Science and technology studies | 0.001 | 0.000 |
| Scholarly communication | 0.001 | 0.002 |
| Open science | 0.001 | 0.000 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".