<link rel="stylesheet" href="styles.f3b1fba60ec7970c.css">

Phishing Agent: An Explainable Multi-Agent Phishing Detection System Using Fine-Tuned BERT Semantic Classification and Threat-Intelligence Evidence Fusion

dc.contributor.advisorYerima, Suleiman
dc.contributor.advisorAwad, Ahmed
dc.contributor.authorALMARZOOQI, ABDULRAHMAN ABDULLA
dc.date.accessioned2026-07-30T07:26:37Z
dc.date.issued2026-07-23
dc.description.abstractPhishing remains one of the most persistent cyber threats because it combines social engineering, changing infrastructure, persuasive language, and brand impersonation. Current phishing detectors often struggle with paraphrased attacks, limited threat-intelligence integration, and weak analyst-facing explanations. This dissertation proposes the Phishing Agent, an explainable multi-agent phishing-detection system that combines a fine-tuned BERT semantic classifier with structured threat-intelligence evidence fusion. The system uses four constrained agents: the Extractor Agent, Intelligence Agent, Analyzer Agent, and Synthesizer Agent. The system was trained and evaluated on a corrected constituent-only corpus of 81,888 records from six public email datasets after excluding an aggregate file to reduce duplicate contamination and train/test leakage risk. On the held-out test set, the TF-IDF and Random Forest baseline achieved 0.9787 accuracy, 0.9812 precision, 0.9759 recall, and 0.9785 F1-score. The fine-tuned BERT classifier achieved 0.9944 accuracy, 0.9948 precision, 0.9939 recall, and 0.9944 F1-score, reducing total misclassifications from 254 to 67. In a controlled supplementary check of 100 paraphrased samples, BERT showed no measured accuracy drop, although this should be interpreted as limited robustness evidence rather than full adversarial validation. The end-to-end demonstration produced a PHISHING verdict for a banking-themed lure, extracted URL and domain indicators, and generated a SOC-style report with an evidence breakdown, a fusion score of 0.885, and a recommended action. The main contribution is a modular phishing-analysis architecture that integrates semantic classification, corroborative threat intelligence, and analyst-friendly explanation. Keywords: phishing detection; fine-tuned BERT; multi-agent systems; explainable AI; threat-intelligence evidence fusion
dc.identifier.urihttps://bspace.buid.ac.ae/handle/1234/3874
dc.language.isoen
dc.titlePhishing Agent: An Explainable Multi-Agent Phishing Detection System Using Fine-Tuned BERT Semantic Classification and Threat-Intelligence Evidence Fusion
dc.typeDissertation

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
24000119.pdf
Size:
1.84 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.34 KB
Format:
Item-specific license agreed upon to submission
Description: