Phishing Email Detection using a Hybrid CNN-MLP Deep Learning Framework
DOI:
https://doi.org/10.33003/fjs-2026-1012-5654Keywords:
Convolutional Neural Network (CNN), Cybersecurity, Deep Learning, Email Security, Phishing DetectionAbstract
Phishing incidents remain highly frequent and destructive cyber threats affecting private users and organizations globally. Malicious actors continuously refine their deceptive strategies to evade traditional rule-based filters and conventional machine learning models, leading to financial losses, credential theft, and data breaches. This study presents an enhanced phishing email detection system based on a hybrid deep learning framework integrating a Convolutional Neural Network (CNN) with a Multi-Layer Perceptron (MLP). The CNN component automatically extracts discriminative textual features from email content, while the MLP component performs accurate email classification as legitimate or phishing. A publicly available phishing email dataset from the Kaggle platform was utilized for model training and evaluation. The dataset underwent preprocessing stages including data cleaning, text normalization, tokenization, sequence padding, and label encoding. The CNN layer extracted relevant textual patterns and semantic representations, while the MLP network performed final classification. The developed system was evaluated using accuracy, precision, recall, and F1-score. Experimental results demonstrated that the CNN–MLP model achieved 98.5% accuracy, 98% precision, 99% recall, and 99% F1-score, indicating strong capability in distinguishing phishing from legitimate emails. Additionally, a web-based application was developed to facilitate real-time phishing detection using direct text input and PDF document analysis through Optical Character Recognition (OCR). The findings demonstrate that integrating CNN-based feature extraction with MLP-based classification provides an effective, reliable, and scalable solution for phishing email detection, contributing to improved cybersecurity protection against evolving phishing attacks.
References
Adebowale, M. A., Lwin, K. T., Sanchez, E., & Hossain, M. A. (2020). Intelligent phishing detection scheme using deep learning algorithms. Applied Computing and Informatics, *16*(1-2), 1-15. https://doi.org/10.1108/jeim-01-2020-0036
Alam, N. A. (2024). Phishing Email Dataset [Data set]. Kaggle. https://www.kaggle.com/datasets/naserabdullahalam/phishing-email-dataset
Al-Subaiey, A., Al-Thani, M., Alam, N. A., Antora, K. F., Khandakar, A., & Zaman, S. A. U. (2024). Novel interpretable and robust web-based AI platform for phishing email detection. arXiv, arXiv:2405.11619. https://doi.org/10.48550/arXiv.2405.11619
Anti-Phishing Working Group (APWG). (2023). Phishing activity trends report. https://docs.apwg.org/reports/apwg_trends_report_q4_2023.pdf
Ayo, F. E., & Alowolodu, O. D. (2024). A deep learning-based approach for detecting phishing websites. Journal of Information Security and Applications, *76*, 103-118.
Jain, A. K., & Gupta, B. B. (2018). Phishing detection: Analysis of visual similarity-based approaches. Security and Communication Networks, *2018*, 1-20. https://doi.org/10.1155/2017/5421046
Selvakumari, M., Sowjanya, M., Das, S., & Padmavathi, S. (2021). Phishing website detection using machine learning and deep learning techniques. Journal of Physics: Conference Series, *1916*(1), 012015. https://doi.org/10.1088/1742-6596/1916/1/012015
Somesha, M., Pais, A. R., Rao, S., & Rathour, V. S. (2020). Efficient deep learning techniques for the detection of phishing websites. Sādhanā, *45*, Article 165. https://doi.org/10.1007/s12046-020-01399-8
Somesha, M., Pais, A. R., Rao, S., & Rathour, V. S. (2021). Performance analysis of machine learning algorithms for phishing detection. Journal of King Saud University - Computer and Information Sciences, *33*(9), 1159-1172. https://doi.org/10.1016/j.jksuci.2019.07.012
Ullah, I., Mahmoud, Q. H., Al-Sanabani, H., & Ahmed, A. (2024). A comprehensive survey of phishing detection techniques using machine learning and deep learning. IEEE Access, *12*, 1-25.
Verizon. (2023). Data Breach Investigations Report (DBIR). https://www.verizon.com/business/resources/reports/dbir/
Downloads
Published
Issue
Section
Categories
License
Copyright (c) 2026 Muhammad Yuguda, Kamil K. Saka, Yusuf Halima Usman

This work is licensed under a Creative Commons Attribution 4.0 International License.