Detection of Homograph Attacks in Phishing URLs using XGBoost Model — ICACNC 2025 | TechShield Publications
ICACNC 2025 · Conference Article

Detection of Homograph Attacks in Phishing URLs using XGBoost Model

Authors: Muhammad Ahmad Zahoor, Ali Shan Rao, Sana Tariq, Iram Haider

Abstract

Phishing has become one of the most common and dangerous cyber threats. Invaders use fake websites or links that look very similar to the real website so that users can be tricked into sharing personal information, such as passwords, banking details, or login credentials. There is a modern form of phishing known as a homograph attack, in which attackers register URLs that look similar to real websites by using the same characters from different languages or scripts. For a common user, it is difficult to feel the difference, which makes such an attack more effective and dangerous. Traditional URL filters and blacklists are often not enough to detect homograph attacks, since they check whether a URL matches a list of harmful links, while homograph attacks use new or altered URLs that pass such checking. In this study, we aimed to develop a machine learning-based framework for detecting homograph attacks in phishing URLs. We use both Natural Language Processing and String Similarity steps to study the URL structure, indicate suspicious patterns, and capture difficult manipulation at the character level. We trained our system using a phishing dataset containing a wide range of fraudulent and harmless URLs, extracting crucial features used to train and test machine learning models. From the models tested — Random Forest, XGBoost, Long Short-Term Memory (LSTM) networks, and Convolutional Neural Networks (CNN) — we determined which method performs best in identifying homograph-based phishing URLs. XGBoost provides the best accuracy of all models, making it a perfect choice for practical or automated security tools.

Phishing Detection Homograph Attacks Machine Learning URL Analysis Cyber Security XGBoost

Cite This Paper

M. A. Zahoor, A. S. Rao, S. Tariq, and I. Haider, “Detection of Homograph Attacks in Phishing URLs using XGBoost Model,” Proc. Int. Conf. on AI, Cybersecurity, and Next-Gen Computing (ICACNC 2025), The Islamia University of Bahawalpur, Jun. 2025, doi: 10.67535/tsp.000001.006.