Sign In to Follow Application
View All Documents & Correspondence

Artificial Intelligence Based System For Phishing Attack Detection

Abstract: ABSTRACT Disclosed herein is a user interface (104) integrated into a user device (102), the user interface (104) configured to receive uniform resource locator (URL) inputs, email content, webpage data, and communication metadata, and to display phishing detection results to a user, a communication network (106) configured to facilitate data exchange within the system (100), a processing unit (110) connected to the user device (102) via the communication network (106), the processing unit (110) configured to process received data to perform phishing detection operations, wherein the processing unit (110) further comprises a data input module (112), a data preprocessing module (114), a multi-modal feature extraction module (116),an adaptive feature fusion module (118), a classification module (120), a detection module (122), a false positive suppression module (124), a drift detection and model optimization module (126) and an output module (128).

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
19 March 2026
Publication Number
13/2026
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
Parent Application

Applicants

SR UNIVERSITY
ANANTHSAGAR, HASANPARTHY (M), WARANGAL URBAN, TELANGANA - 506371, INDIA

Inventors

1. PENUGONDA ANUSHA
PHD STUDENT SCHOLAR (CSE), SR UNIVERSITY, ANANTHSAGAR, HASANPARTHY (M), WARANGAL URBAN, TELANGANA - 506371, INDIA
2. DR. BRIJ KISHOR TIWARI
ASSISTANT PROFESSOR (CS&AI), SR UNIVERSITY, ANANTHSAGAR, HASANPARTHY (M), WARANGAL URBAN, TELANGANA - 506371, INDIA
3. DR. MANOJ KUMAR
SCHOOL OF COMPUTER SCIENCE, UNIVERSITY OF WOLLONGONG IN DUBAI, DUBAI KNOWLEDGE VILLAGE, DUBAI, UAE

Claims

1. A system (100) for detecting phishing attacks in digital communications, the system (100) comprising (100) a user interface (104) integrated into a user device (102), the user interface (104) configured to receive uniform resource locator (URL) inputs, email content, webpage data, and communication metadata, and to display phishing detection results to a user; a communication network (106) configured to facilitate data exchange within the system (100); a processing unit (110) connected to the user device (102) via the communication network (106), the processing unit (110) configured to process received data to perform phishing detection operations, wherein the processing unit (110) further comprises: a data input module (112) configured to receive data from the user device (102); a data preprocessing module (114) configured to validate, clean, tokenize, encode, normalize, and transform the received data into structured machine-readable feature representations; a multi-modal feature extraction module (116) configured to derive structural features, lexical features, temporal patterns, semantic attributes, and behavioral indicators from the transformed data; an adaptive feature fusion module (118) configured to dynamically combine extracted features using weighted hierarchical aggregation to generate a unified feature vector; a classification module (120) configured to analyze the unified feature vector to identify structural and sequential phishing patterns using convolutional neural network architecture and a long short-term memory architecture; a detection module (122) configured to detect previously unseen phishing attacks by identifying latent probabilistic behavior patterns independent of predefined blacklist rules; a false positive suppression module (124) configured to apply confidence calibration and multi-threshold validation to refine classification output and reduce misclassification rates; a drift detection and model optimization module (126) configured to monitor statistical variations in incoming data streams and automatically initiate incremental retraining of the classification module (120) upon detection of distributional drift; and an output module (128) configured to transmit a phishing risk score, classification results, and threat alerts to the user device (102) for display.

2. The system (100) as claimed in claim 1, wherein the user interface (104) is configured to display a visual phishing risk indicator comprising a graded threat level representation based on the generated phishing risk score.

3. The system (100) as claimed in claim 1, wherein the cloud database (108) is configured to store communication data, extracted feature representations, historical phishing detection records, model training datasets, and generated phishing risk assessments to support continuous learning and threat analysis within the system (100).

4. The system (100) as claimed in claim 1, wherein the multi-modal feature extraction module (116) is further configured to extract structural hyperlink graph patterns, token distribution metrics, domain registration attributes, temporal request frequency parameters, and behavioral navigation indicators from the transformed data to construct feature representations associated with phishing activity.

5. The system (100) as claimed in claim 1, wherein the adaptive feature fusion module (118) is further configured to apply hierarchical feature weighting and cross-domain correlation mapping to integrate heterogeneous structural, lexical, and behavioral features into a normalized unified feature vector suitable for deep learning analysis.

6. The system (100) as claimed in claim 1, wherein the classification module (120) is further configured to perform spatial feature learning using a convolutional neural network architecture and sequential dependency modeling using a long short-term memory architecture to identify latent phishing patterns within the unified feature vector.

7. The system (100) as claimed in claim 1, wherein the detection module (122) is further configured to determine probabilistic anomaly scores by comparing extracted behavioral patterns with learned benign interaction profiles to detect previously unseen phishing attempts without reliance on static blacklist databases.

8. The system (100) as claimed in claim 1, wherein the false positive suppression module (124) is further configured to perform probabilistic confidence calibration and adaptive threshold evaluation to filter ambiguous classification outputs and improve decision reliability during phishing detection.

9. The system (100) as claimed in claim 1, wherein the drift detection and model optimization module (126) is further configured to continuously evaluate statistical distribution changes in incoming communication data streams and initiate automated incremental retraining of the classification module (120) using updated phishing datasets.

10. A method (300) for detecting phishing attacks, the method (300) comprising: receiving uniform resource locator (URL) inputs, email content, webpage data, and communication metadata, and to display phishing detection results to a user via a user interface (104) integrated into a user device (102); facilitating data exchange within the system (100) via a communication network (106); processing received data to perform phishing detection operations via a processing unit (110) comprising several modules; receiving data from the user device (102) via a data input module (112); validating, cleaning, tokenizing, encoding, normalizing, and transforming the received data into structured machine-readable feature representations via a data preprocessing module (114); deriving structural features, lexical features, temporal patterns, semantic attributes, and behavioral indicators from the transformed data via a multi-modal feature extraction module (116); dynamically combine extracted features using weighted hierarchical aggregation to generate a unified feature vector via an adaptive feature fusion module (118); analyzing the unified feature vector to identify structural and sequential phishing patterns using convolutional neural network architecture and a long short-term memory architecture via a classification module (120); detecting previously unseen phishing attacks by identifying latent probabilistic behavior patterns independent of predefined blacklist rules via a detection module (122); applying confidence calibration and multi-threshold validation to refine classification output and reduce misclassification rates via a false positive suppression module (124); monitoring statistical variations in incoming data streams and automatically initiate incremental retraining of the classification module (120) upon detection of distributional drift via a drift detection and model optimization module (126); transmitting a phishing risk score, classification results, and threat alerts to the user device (102) for display via an output module (128).

Specification

Description:FIELD OF DISCLOSURE
[0001] The present disclosure generally relates to the field of cybersecurity, more specifically relates to artificial intelligence based system for phishing attack detection in digital communications.
BACKGROUND OF THE DISCLOSURE
[0002] The increasing reliance on digital communication platforms, online services, and web-based interactions has significantly expanded the threat landscape associated with fraudulent online activities such as phishing. Phishing attacks typically involve deceptive messages, manipulated websites, or malicious links designed to mislead users into disclosing sensitive information including login credentials, financial data, personal details. By evaluating diverse characteristics of digital communications simultaneously, the system establishes a comprehensive contextual understanding of potentially malicious activities. This multi-dimensional analysis enables the identification of suspicious behavioral patterns that may indicate phishing attempts, thereby enhancing the reliability and effectiveness of threat detection in online environments.
[0003] The system is designed to identify subtle irregularities, hidden associations, and abnormal patterns that may emerge within digital interactions. Through an adaptive analytical framework, the system is capable of recognizing sophisticated phishing behaviors that may not be immediately apparent through simple rule-based examination. This capability allows the system to detect emerging or previously unseen phishing patterns by learning from evolving data characteristics and communication behaviors.
[0004] The disclosed system incorporates adaptive monitoring and continuous optimization capabilities to maintain robust performance in dynamic digital ecosystems. The system is capable of updating its analytical models using newly observed data patterns, thereby allowing the detection framework to remain effective as phishing tactics evolve over time. In addition, mechanisms for reliability assessment and alert generation support accurate decision-making and minimize the likelihood of incorrect threat identification. As a result, the disclosed system provides a flexible, scalable, and resilient approach for safeguarding users against phishing threats across modern digital communication platforms.
[0005] Conventional approaches for detecting phishing activities have primarily relied on static rule-based mechanisms and predefined threat databases. Many security systems analyze limited indicators such as suspicious web addresses, domain characteristics, or keyword patterns within electronic messages to identify potential phishing attempts. These approaches generally depend on previously recorded threat signatures or known malicious patterns stored in blacklists. While such mechanisms provide a basic level of protection, their effectiveness is often limited when dealing with rapidly evolving phishing strategies that employ newly generated links, dynamically created webpages, or modified communication content.
[0006] Another limitation of traditional phishing detection mechanisms lies in their restricted scope of analysis. Many existing solutions evaluate only a single category of information, such as URL characteristics, webpage structures, or email text content. This narrow focus can result in incomplete threat assessment because phishing campaigns often combine multiple deceptive elements across different communication layers. Additionally, systems that rely heavily on manually defined rules or simple pattern matching may struggle to identify complex or subtle behavioral indicators embedded within digital communications. As phishing attacks continue to become more sophisticated, these limited analytical approaches may fail to capture the broader context required for accurate threat identification.
[0007] Existing phishing detection systems frequently encounter challenges related to detection accuracy and operational adaptability. A significant issue associated with many current solutions is the occurrence of false positives, where legitimate communications are incorrectly flagged as malicious. Such inaccuracies can reduce user trust and hinder practical deployment in real-world environments. Some systems lack mechanisms for continuously adapting to newly emerging phishing techniques, which may lead to outdated detection capabilities over time. These limitations highlight the need for more intelligent and adaptive security frameworks capable of analyzing diverse communication data while maintaining high detection reliability and scalability.
[0008] Thus, in light of the above-stated discussion, there exists a need for an artificial intelligence based system for phishing attack detection.
SUMMARY OF THE DISCLOSURE
[0009] The following is a summary description of illustrative embodiments of the invention. It is provided as a preface to assist those skilled in the art to more rapidly assimilate the detailed design discussion which ensues and is not intended in any way to limit the scope of the claims which are appended hereto in order to particularly point out the invention.
[0010] According to illustrative embodiments, the present disclosure focuses on an artificial intelligence based system for phishing attack detection which overcomes the above-mentioned disadvantages or provide the users with a useful or commercial choice.
[0011] An objective of the present disclosure is to provide an intelligent system and method for detecting phishing activities in digital communication environments in order to enhance security for users interacting with online platforms.
[0012] Another objective of the present disclosure is to provide a detection framework capable of analyzing multiple forms of communication data to enable comprehensive identification of potentially malicious digital interactions.
[0013] Another objective of the present disclosure is to provide an adaptive phishing detection mechanism capable of identifying emerging and previously unseen phishing patterns within dynamic communication environments.
[0014] Another objective of the present disclosure is to improve the accuracy and reliability of phishing detection by enabling intelligent analysis of communication characteristics and behavioral indicators.
[0015] Another objective of the present disclosure is to reduce incorrect threat identification and improve trustworthiness in phishing detection outcomes.
[0016] Another objective of the present disclosure is to provide a scalable detection approach capable of operating across diverse digital communication channels and online service platforms.
[0017] Another objective of the present disclosure is to support continuous learning and adaptation in order to maintain effective protection against evolving phishing strategies.
[0018] Another objective of the present disclosure is to provide timely identification and notification of potential phishing threats to assist users in making informed security decisions.
[0019] Another objective of the present disclosure is to enhance overall cybersecurity resilience by enabling proactive identification of fraudulent online activities within modern digital ecosystems.
[0020] Yet another objective of the present disclosure is to enable identification of sophisticated and concealed phishing behaviors through intelligent analysis of digital communication patterns.
[0021] In light of the above, in one aspect of the present disclosure, an artificial intelligence based system for detecting phishing attacks in digital communications is disclosed herein. The system comprises a user interface integrated into a user device, the user interface configured to receive uniform resource locator (URL) inputs, email content, webpage data, and communication metadata, and to display phishing detection results to a user. The system includes a communication network configured to facilitate data exchange within the system. The system also includes a processing unit connected to the user device via the communication network, the processing unit configured to process received data to perform phishing detection operations, wherein the processing unit further comprises a data input module configured to receive data from the user device, a data preprocessing module configured to validate, clean, tokenize, encode, normalize, and transform the received data into structured machine-readable feature representations, a multi-modal feature extraction module configured to derive structural features, lexical features, temporal patterns, semantic attributes, and behavioral indicators from the transformed data, an adaptive feature fusion module configured to dynamically combine extracted features using weighted hierarchical aggregation to generate a unified feature vector, a classification module configured to analyze the unified feature vector to identify structural and sequential phishing patterns using convolutional neural network architecture and a long short-term memory architecture, a detection module configured to detect previously unseen phishing attacks by identifying latent probabilistic behavior patterns independent of predefined blacklist rules, a false positive suppression module configured to apply confidence calibration and multi-threshold validation to refine classification output and reduce misclassification rates, a drift detection and model optimization module configured to monitor statistical variations in incoming data streams and automatically initiate incremental retraining of the classification module upon detection of distributional drift and an output module configured to transmit a phishing risk score, classification results, and threat alerts to the user device for display.
[0022] In one embodiment, the user interface is configured to display a visual phishing risk indicator comprising a graded threat level representation based on the generated phishing risk score.
[0023] In one embodiment, the cloud database is configured to store communication data, extracted feature representations, historical phishing detection records, model training datasets, and generated phishing risk assessments to support continuous learning and threat analysis within the system.
[0024] In one embodiment, the multi-modal feature extraction module is further configured to extract structural hyperlink graph patterns, token distribution metrics, domain registration attributes, temporal request frequency parameters, and behavioral navigation indicators from the transformed data to construct feature representations associated with phishing activity.
[0025] In one embodiment, the adaptive feature fusion module is further configured to apply hierarchical feature weighting and cross-domain correlation mapping to integrate heterogeneous structural, lexical, and behavioral features into a normalized unified feature vector suitable for deep learning analysis.
[0026] In one embodiment, the classification module is further configured to perform spatial feature learning using a convolutional neural network architecture and sequential dependency modeling using a long short-term memory architecture to identify latent phishing patterns within the unified feature vector.
[0027] In one embodiment, the detection module is further configured to determine probabilistic anomaly scores by comparing extracted behavioral patterns with learned benign interaction profiles to detect previously unseen phishing attempts without reliance on static blacklist databases.
[0028] In one embodiment, the false positive suppression module is further configured to perform probabilistic confidence calibration and adaptive threshold evaluation to filter ambiguous classification outputs and improve decision reliability during phishing detection.
[0029] In one embodiment, the drift detection and model optimization module is further configured to continuously evaluate statistical distribution changes in incoming communication data streams and initiate automated incremental retraining of the classification module using updated phishing datasets.
[0030] In light of the above, in one aspect of the present disclosure, a method for detecting phishing attacks is disclosed herein. The method comprises receiving uniform resource locator (URL) inputs, email content, webpage data, and communication metadata, and to display phishing detection results to a user via a user interface integrated into a user device. The method includes facilitating data exchange within the system via a communication network. The method also includes processing received data to perform phishing detection operations via a processing unit comprising several modules. The method also includes receiving data from the user device via a data input module. The method also includes validating, cleaning, tokenizing, encoding, normalizing, and transforming the received data into structured machine-readable feature representations via a data preprocessing module. The method also includes deriving structural features, lexical features, temporal patterns, semantic attributes, and behavioral indicators from the transformed data via a multi-modal feature extraction module. The method also includes dynamically combine extracted features using weighted hierarchical aggregation to generate a unified feature vector via an adaptive feature fusion module. The method also includes analyzing the unified feature vector to identify structural and sequential phishing patterns using convolutional neural network architecture and a long short-term memory architecture via a classification module. The method also includes detecting previously unseen phishing attacks by identifying latent probabilistic behavior patterns independent of predefined blacklist rules via a detection module. The method also includes applying confidence calibration and multi-threshold validation to refine classification output and reduce misclassification rates via a false positive suppression module. The method also includes monitoring statistical variations in incoming data streams and automatically initiate incremental retraining of the classification module upon detection of distributional drift via a drift detection and model optimization module. The method also includes transmitting a phishing risk score, classification results, and threat alerts to the user device for display via an output module.
[0031] These and other advantages will be apparent from the present application of the embodiments described herein.
[0032] The preceding is a simplified summary to provide an understanding of some embodiments of the present invention. This summary is neither an extensive nor exhaustive overview of the present invention and its various embodiments. The summary presents selected concepts of the embodiments of the present invention in a simplified form as an introduction to the more detailed description presented below. As will be appreciated, other embodiments of the present invention are possible utilizing, alone or in combination, one or more of the features set forth above or described in detail below.
[0033] These elements, together with the other aspects of the present disclosure and various features are pointed out with particularity in the claims annexed hereto and form a part of the present disclosure. For a better understanding of the present disclosure, its operating advantages, and the specified object attained by its uses, reference should be made to the accompanying drawings and descriptive matter in which there are illustrated exemplary embodiments of the present disclosure.
BRIEF DESCRIPTION OF THE DRAWINGS
[0034] To describe the technical solutions in the embodiments of the present disclosure or in the prior art more clearly, the following briefly describes the accompanying drawings required for describing the embodiments or the prior art. Apparently, the accompanying drawings in the following description merely show some embodiments of the present disclosure, and a person of ordinary skill in the art can derive other implementations from these accompanying drawings without creative efforts. All of the embodiments or the implementations shall fall within the protection scope of the present disclosure.
[0035] The advantages and features of the present disclosure will become better understood with reference to the following detailed description taken in conjunction with the accompanying drawing, in which:
[0036] FIG. 1 illustrates a block diagram of a system for detecting phishing attacks in digital communications in accordance with an embodiment of the present disclosure;
[0037] FIG. 2 illustrates a functional workflow diagram of a system 100 for detecting phishing attacks in digital communications, in accordance with an embodiment of the present disclosure; and
[0038] FIG. 3 illustrates a flowchart of a method outlining the sequential steps for detecting phishing attacks, in accordance with an embodiment of the present disclosure.
[0039] Like reference, numerals refer to like parts throughout the description of several views of the drawing.
[0040] The system for detecting phishing attacks in digital communications is illustrated in the accompanying drawings, which like reference letters indicate corresponding parts in the various figures. It should be noted that the accompanying figure is intended to present illustrations of exemplary embodiments of the present disclosure. This figure is not intended to limit the scope of the present disclosure. It should also be noted that the accompanying figure is not necessarily drawn to scale.
DETAILED DESCRIPTION OF THE DISCLOSURE
[0041] The following is a detailed description of embodiments of the disclosure depicted in the accompanying drawings. The embodiments are in such detail as to communicate the disclosure. However, the amount of detail offered is not intended to limit the anticipated variations of embodiments; on the contrary, the intention is to cover all modifications, equivalents, and alternatives falling within the scope of the present disclosure.
[0042] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the embodiments of the present disclosure. It may be apparent to one skilled in the art that embodiments of the present disclosure may be practiced without some of these specific details.
[0043] Various terms as used herein are shown below. To the extent a term is used, it should be given the broadest definition persons in the pertinent art have given that term as reflected in printed publications and issued patents at the time of filing.
[0044] The terms “a” and “an” herein do not denote a limitation of quantity, but rather denote the presence of at least one of the referenced items.
[0045] The terms “having”, “comprising”, “including”, and variations thereof signify the presence of a component. Referring now to FIG. 1 to FIG. 3 to describe various exemplary embodiments of the present disclosure. FIG. 1 illustrates a block diagram of a system for detecting phishing attacks in digital communications in accordance with an embodiment of the present disclosure.
[0046] The system 100 may include a user interface 104, a communication network 106 and a processing unit 110.
[0047] The user interface 104 is integrated into a user device 102 and the user interface 104 is configured to receive uniform resource locator (URL) inputs, email content, webpage data, and communication metadata, and to display phishing detection results to a user. The user device 102 may include computing platforms such as desktop computers, laptops, mobile devices, tablets, or other internet-enabled terminals capable of supporting user interaction. The user interface 104 is configured to receive various categories of digital communication inputs including uniform resource locator (URL) inputs, email content, webpage data, and communication metadata associated with online interactions. Such inputs may be manually entered by the user, uploaded from stored communication records, captured from active browsing sessions or messaging platforms. Upon submission, the received data is transmitted to the system 100 for further analytical processing.
[0048] In one embodiment of the present invention, the user interface 104 is configured to display a visual phishing risk indicator comprising a graded threat level representation based on the generated phishing risk score. The user interface 104 further presents the detection outcomes generated by the system in a clear and accessible format, including phishing risk indications, warning notifications, and security alerts. Through this interface, users are able to obtain timely information regarding potentially malicious communications, thereby enabling informed decision-making while interacting with digital platforms.
[0049] The communication network 106 is configured to facilitate data exchange within the system 100. The communication network 106 may comprise one or more wired or wireless communication infrastructures capable of supporting reliable transmission of digital information across distributed computing environments. the communication network 106 may include local area networks, wide area networks, cellular communication networks, or internet-based connectivity channels that enable seamless interaction between user devices and remote processing resources. Through the communication network 106, communication data received via the user interface 104 is transmitted to the processing components of the system for analysis, while detection results and system-generated alerts are subsequently delivered back to the user device 102.
[0050] In one embodiment of the present invention, the cloud database 108 is configured to store communication data, extracted feature representations, historical phishing detection records, model training datasets, and generated phishing risk assessments to support continuous learning and threat analysis within the system 100. The cloud database 108 further supports organized indexing, retrieval, and updating of stored data to facilitate analytical operations performed by the system 100. The stored datasets may be utilized to support continuous learning processes, historical threat pattern analysis, and long-term monitoring of phishing activities, thereby enhancing the overall detection capability and operational efficiency of the system 100.
[0051] The processing unit 110 is connected to the user device 102 via the communication network 106. The processing unit 110 is configured to process received data to perform phishing detection operations. The processing unit 110 integrates multiple functional modules to process data, including a data input module 112, a data preprocessing module 114, a multi-modal feature extraction module 116, an adaptive feature fusion module 118, a classification module 120, a detection module 122, a false positive suppression module 124, a drift detection and model optimization module 126 and an output module 128.
[0052] The data input module 112 is configured to receive data from the user device 102. The data input module 112 aggregates and organizes the incoming data into a structured input stream suitable for subsequent analytical operations within the system 100.
[0053] The data preprocessing module 114 is configured to validate, clean, tokenize, encode, normalize, and transform the received data into structured machine-readable feature representations. The data preprocessing module 114 validates the integrity and format of incoming data elements to ensure compatibility with subsequent computational processes. The data preprocessing module 114 may further perform cleaning operations to remove redundant characters, corrupted entries, or extraneous symbols present within the received communication data. Additionally, tokenization procedures may be applied to segment textual information contained in URLs, email messages, or webpage content into discrete analytical units.
[0054] The multi-modal feature extraction module 116 is configured to derive structural features, lexical features, temporal patterns, semantic attributes, and behavioral indicators from the transformed data. The multi-modal feature extraction module 116 extracts structural features associated with the composition and arrangement of uniform resource locators, webpage elements, and communication formats. The multi-modal feature extraction module 116 may further derive lexical features from textual components present within URLs, email messages, and webpage content, including token structures, character distributions, and linguistic patterns. the module identifies temporal patterns related to communication timing, transmission frequency, interaction sequences that may indicate suspicious behavior. Semantic attributes associated with the contextual meaning of textual content may also be evaluated to determine inconsistencies or deceptive messaging characteristics. Furthermore, behavioral indicators associated with user interaction patterns or communication sources may be derived to capture anomalies within digital communication activities.
[0055] In one embodiment of the present invention, the multi-modal feature extraction module 116 is further configured to extract structural hyperlink graph patterns, token distribution metrics, domain registration attributes, temporal request frequency parameters, and behavioral navigation indicators from the transformed data to construct feature representations associated with phishing activity. The extracted attributes are organized into structured feature representations that characterize communication behavior and contextual properties of the analyzed data, thereby enabling comprehensive analytical evaluation for identifying potential phishing activity within the system 100.
[0056] The adaptive feature fusion module 118 is configured to dynamically combine extracted features using weighted hierarchical aggregation to generate a unified feature vector. the module dynamically integrates structural, lexical, temporal, semantic, and behavioral features by assigning context-dependent weighting factors to different feature groups. Such weighted integration enables the system 100 to emphasize features that exhibit stronger relevance to phishing detection while maintaining the contribution of complementary feature categories. The adaptive feature fusion module 118 may further perform hierarchical aggregation of related feature subsets in order to capture both localized and global communication characteristics present within the data. Through this adaptive feature fusion process, the adaptive feature fusion module 118 generates a unified feature vector that encapsulates multi-dimensional information associated with the analyzed communication data, thereby enabling comprehensive evaluation of potential phishing patterns within the system 100.
[0057] In one embodiment of the present invention, the adaptive feature fusion module 118 is further configured to apply hierarchical feature weighting and cross-domain correlation mapping to integrate heterogeneous structural, lexical, and behavioral features into a normalized unified feature vector suitable for deep learning analysis. The adaptive feature fusion module 118 organizes related feature groups into layered analytical representations and assigns context-dependent weighting parameters to emphasize features exhibiting stronger relevance to phishing detection. The integrated attributes are subsequently normalized and aggregated to generate a unified feature vector representing the combined characteristics of the analyzed communication instance, thereby enabling comprehensive evaluation of phishing-related patterns within the system 100.
[0058] The classification module 120 is configured to analyze the unified feature vector to identify structural and sequential phishing patterns using convolutional neural network architecture and a long short-term memory architecture. The classification module 120 comprises a deep learning-based analytical architecture capable of identifying complex structural and sequential relationships present within the integrated feature representation. The classification module 120 processes the unified feature vector to detect hidden correlations, contextual dependencies, and anomalous patterns that may indicate fraudulent communication behavior. In this module, the CNN processes structural patterns present in the communication data such as URL structures, embedded links, or formatting patterns, while the LSTM (long short term memory) analyzes sequential and contextual relationships within the message content to understand the flow and context of the communication. By evaluating both structural characteristics and sequential relationships present in the communication data, the classification module 120 generates a classification outcome indicative of whether the analyzed communication instance corresponds to a legitimate interaction or a potential phishing attempt within the system 100.
[0059] In one embodiment of the present invention, the classification module 120 is further configured to perform spatial feature learning using a convolutional neural network architecture and sequential dependency modeling using a long short-term memory architecture to identify latent phishing patterns within the unified feature vector. The classification module 120 is further configured to perform sequential dependency modeling through a recurrent learning architecture capable of analyzing contextual dependencies within communication patterns. Through the coordinated evaluation of structural relationships and sequential characteristics, the classification module 120 identifies latent behavioral patterns associated with phishing activity and generates a classification outcome indicative of potential malicious communication within the system 100.
[0060] The detection module 122 is configured to detect previously unseen phishing attacks by identifying latent probabilistic behavior patterns independent of predefined blacklist rules. The detection module 122 analyzes classification outcomes and associated behavioral indicators to determine whether the communication data exhibits patterns commonly associated with deceptive or fraudulent activities. The detection module 122 evaluates underlying probabilistic relationships within the analyzed data to identify anomalous characteristics that may indicate previously unseen phishing attempts. By relying on behavioral pattern recognition rather than predefined threat listings alone, the detection module 122 enables the system 100 to recognize emerging phishing strategies that may involve newly generated URLs, modified webpage structures, or dynamically crafted communication content.
[0061] In one embodiment of the present invention, the detection module 122 is further configured to determine probabilistic anomaly scores by comparing extracted behavioral patterns with learned benign interaction profiles to detect previously unseen phishing attempts without reliance on static blacklist databases. The detection module 122 assesses deviations from established interaction patterns representing legitimate communication behavior and identifies anomalies indicative of potential phishing activity. Based on the evaluated anomaly scores, the detection module 122 determines whether the analyzed communication instance corresponds to a previously unseen phishing attempt and generates corresponding detection outcomes for further processing within the system 100.
[0062] The false positive suppression module 124 is configured to apply confidence calibration and multi-threshold validation to refine classification output and reduce misclassification rates. The false positive suppression module 124 evaluates confidence measures associated with the classification output and performs calibration to ensure that the generated detection results accurately reflect the likelihood of phishing activity. The false positive suppression module 124 may further apply multiple validation thresholds to assess the consistency of classification decisions across different feature indicators and contextual parameters. Through this validation process, the false positive suppression module 124 reduces the likelihood of legitimate communications being incorrectly flagged as phishing attempts. As a result, the false positive suppression module 124 enhances the overall accuracy, stability, and trustworthiness of phishing detection outcomes presented to the user.
[0063] In one embodiment of the present invention, the false positive suppression module 124 is further configured to perform probabilistic confidence calibration and adaptive threshold evaluation to filter ambiguous classification outputs and improve decision reliability during phishing detection.
[0064] The drift detection and model optimization module 126 configured to monitor statistical variations in incoming data streams and automatically initiate incremental retraining of the classification module 120 upon detection of distributional drift. The drift detection and model optimization module 126 continuously evaluates patterns within the incoming data streams to determine whether significant deviations occur in comparison with previously observed data distributions. Such variations may arise due to evolving phishing strategies, newly emerging communication formats, or changes in attacker behavior patterns. Upon identifying distributional drift within the incoming data, the drift detection and model optimization module 126 automatically initiates an optimization process to update the analytical model associated with the classification module 120. The optimization process may include incremental retraining using newly collected communication samples and updated behavioral patterns, thereby enabling the system 100 to maintain accurate phishing detection performance. Through this adaptive monitoring and optimization mechanism, the system 100 is capable of maintaining long-term operational reliability while responding to continuously evolving phishing threats in digital communication environments.
[0065] In one embodiment of the present invention, the drift detection and model optimization module 126 is further configured to continuously evaluate statistical distribution changes in incoming communication data streams and initiate automated incremental retraining of the classification module 120 using updated phishing datasets. Upon detecting significant deviations in the observed data distributions, the drift detection and model optimization module 126 initiates an automated optimization process for updating the analytical model associated with the classification module 120. The optimization process may include incremental retraining using newly collected communication samples and updated phishing datasets to maintain the effectiveness of phishing detection. Through this adaptive updating mechanism, the system 100 is capable of maintaining robust detection performance in the presence of continuously evolving phishing techniques.
[0066] The output module 128 is configured to transmit a phishing risk score, classification results, and threat alerts to the user device 102 for display. The output module 128 organizes the detection results into interpretable notification formats that enable users to understand the potential risk associated with the analyzed communication instance. The transmitted information may include phishing likelihood indicators, warning messages, and security notifications that assist the user in identifying potentially malicious digital interactions.
[0067] FIG. 2 illustrates a functional workflow diagram of a system 100 for detecting phishing attacks in digital communications, in accordance with an embodiment of the present disclosure.
[0068] At step 202, the system receives input communication data such as emails, URLs, webpage content, or online messages. The received data may include the email body, sender information, subject line, embedded links, and webpage references that may potentially contain phishing indicators.
[0069] At step 204, the received data undergoes data preprocessing, where operations such as cleaning, tokenization, normalization, and formatting are performed. This step removes noise, standardizes textual data, and converts the information into structured machine-readable format suitable for further analysis.
[0070] At step 206, the system 100 performs feature extraction from the processed data. During this stage, significant attributes are derived from different components including the email body, sender details, subject line, URL structure, and webpage characteristics. These attributes represent potential indicators of phishing activity.
[0071] At step 208, the extracted features are analyzed using machine learning models capable of identifying hidden structural and contextual patterns within the communication data.
[0072] At step 210, the system 100 performs phishing classification, where the trained model evaluates the extracted patterns and determines whether the communication corresponds to suspicious phishing behavior.
[0073] At step 212, the classification outcome is generated as a phishing risk assessment, indicating the likelihood of the communication being malicious, thereby assisting the user in avoiding fraudulent interactions.
[0074] FIG. 3 illustrates a flowchart of a method outlining the sequential steps for detecting phishing attacks, in accordance with an embodiment of the present disclosure.
[0075] At step 302, receiving uniform resource locator (URL) inputs, email content, webpage data, and communication metadata, and to display phishing detection results to a user via a user interface 104 integrated into a user device 102.
[0076] At step 304, facilitating data exchange within the system 100 via a communication network 106.
[0077] At step 306, processing received data to perform phishing detection operations via a processing unit 110 comprising several modules.
[0078] At step 308, receiving data from the user device 102 via a data input module 112.
[0079] At step 310, validating, cleaning, tokenizing, encoding, normalizing, and transforming the received data into structured machine-readable feature representations via a data preprocessing module 114.
[0080] At step 312, deriving structural features, lexical features, temporal patterns, semantic attributes, and behavioral indicators from the transformed data via a multi-modal feature extraction module 116.
[0081] At step 314, dynamically combine extracted features using weighted hierarchical aggregation to generate a unified feature vector via an adaptive feature fusion module 118.
[0082] At step 316, analyzing the unified feature vector to identify structural and sequential phishing patterns using convolutional neural network architecture and a long short-term memory architecture via a classification module 120.
[0083] At step 318, detecting previously unseen phishing attacks by identifying latent probabilistic behavior patterns independent of predefined blacklist rules via a detection module 122.
[0084] At step 320, applying confidence calibration and multi-threshold validation to refine classification output and reduce misclassification rates via a false positive suppression module 124.
[0085] At step 322, monitoring statistical variations in incoming data streams and automatically initiate incremental retraining of the classification module 120 upon detection of distributional drift via a drift detection and model optimization module 126.
[0086] At step 324, transmitting a phishing risk score, classification results, and threat alerts to the user device 102 for display via an output module 128.
[0087] In the best mode of operation of the present invention, the system 100 operates to detect phishing activities in digital communications through an integrated sequence of data acquisition, analysis, and result dissemination processes. Initially, a user interacts with a user interface 104 integrated into a user device 102 to submit communication data for analysis. The communication data may include uniform resource locator (URL) inputs, electronic mail content, webpage data, and associated communication metadata obtained during online interactions. Upon submission, the user interface 104 forwards the received data through a communication network 106, which facilitates secure and reliable data exchange between the user device 102 and the processing components of the system 100. The received communication data is processed by a processing unit 110 comprising multiple analytical modules configured to perform phishing detection operations. the data input module 112 receives the submitted data from the user device 102 and forwards it for further processing. The data preprocessing module 114 performs validation, cleaning, tokenization, encoding, normalization, and transformation operations in order to convert the raw communication data into structured machine-readable feature representations. Subsequently, the multi-modal feature extraction module 116 analyzes the transformed data to derive various analytical attributes including structural features, lexical characteristics, temporal interaction patterns, semantic attributes, and behavioral indicators associated with the communication instance. The extracted attributes are then processed by the adaptive feature fusion module 118, which dynamically integrates the heterogeneous feature categories using weighted hierarchical aggregation to generate a unified feature vector representing the communication instance. The classification module 120 analyzes the unified feature vector to identify structural and sequential patterns associated with phishing behavior using advanced analytical architectures capable of evaluating complex relationships within the data. Based on the classification outcome, the detection module 122 evaluates underlying probabilistic behavioral patterns to identify previously unseen phishing attempts without reliance on predefined blacklist rules. The false positive suppression module 124 subsequently refines the classification results by applying confidence calibration and multi-threshold validation mechanisms to reduce misclassification and enhance decision reliability. The drift detection and model optimization module 126 continuously monitors statistical characteristics of incoming communication data streams to identify distributional variations that may indicate evolving phishing strategies. Upon detection of such variations, the drift detection and model optimization module 126 automatically initiates incremental retraining of the classification module 120 using updated datasets in order to maintain detection effectiveness. Finally, the output module 128 generates a phishing risk score along with classification outcomes and corresponding threat alerts, and transmits the results to the user device 102 through the communication network 106. The results are displayed via the user interface 104, enabling the user to receive timely warnings and make informed decisions regarding potentially malicious digital communications.
[0088] The present invention introduces several novel aspects in the field of phishing detection by providing an integrated analytical framework capable of evaluating diverse communication attributes associated with digital interactions. The invention incorporates multi-dimensional analysis of communication data including structural characteristics, textual patterns, temporal interaction behaviors, and contextual attributes derived from digital communications. Such integrated evaluation enables the system to generate comprehensive analytical representations of communication instances, allowing accurate identification of suspicious behavioral patterns within URLs, email content, webpage structures, and associated metadata. these features provide a robust and intelligent phishing detection framework capable of analyzing complex communication patterns while continuously improving detection capability in response to evolving digital threats.
[0089] While the invention has been described in connection with what is presently considered to be the most practical and various embodiments, it will be understood that the invention is not to be limited to the disclosed embodiments, but on the contrary, is intended to cover various modifications and equivalent arrangements included within the scope of the appended claims.
[0090] A person of ordinary skill in the art may be aware that, in combination with the examples described in the embodiments disclosed in this specification, units and algorithm steps may be implemented by electronic hardware, computer software, or a combination thereof.
[0091] The foregoing descriptions of specific embodiments of the present disclosure have been presented for purposes of illustration and description. They are not intended to be exhaustive or to limit the present disclosure to the precise forms disclosed, and many modifications and variations are possible in light of the above teaching. The embodiments were chosen and described to best explain the principles of the present disclosure and its practical application, and to thereby enable others skilled in the art to best utilize the present disclosure and various embodiments with various modifications as are suited to the particular use contemplated. It is understood that various omissions and substitutions of equivalents are contemplated as circumstances may suggest or render expedient, but such omissions and substitutions are intended to cover the application or implementation without departing from the scope of the present disclosure.
[0092] Disjunctive language such as the phrase “at least one of X, Y, Z,” unless specifically stated otherwise, is otherwise understood with the context as used in general to present that an item, term, etc., may be either X, Y, or Z, or any combination thereof (e.g., X, Y, and/or Z). Thus, such disjunctive language is not generally intended to, and should not, imply that certain embodiments require at least one of X, at least one of Y, or at least one of Z to each be present.
[0093] In a case that no conflict occurs, the embodiments in the present disclosure and the features in the embodiments may be mutually combined. The foregoing descriptions are merely specific implementations of the present disclosure but are not intended to limit the protection scope of the present disclosure. Any variation or replacement readily figured out by a person skilled in the art within the technical scope disclosed in the present disclosure shall fall within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure shall be subject to the protection scope of the claims.
, Claims:I/We Claim:
1. A system (100) for detecting phishing attacks in digital communications, the system (100) comprising (100)
a user interface (104) integrated into a user device (102), the user interface (104) configured to receive uniform resource locator (URL) inputs, email content, webpage data, and communication metadata, and to display phishing detection results to a user;
a communication network (106) configured to facilitate data exchange within the system (100);
a processing unit (110) connected to the user device (102) via the communication network (106), the processing unit (110) configured to process received data to perform phishing detection operations, wherein the processing unit (110) further comprises:
a data input module (112) configured to receive data from the user device (102);
a data preprocessing module (114) configured to validate, clean, tokenize, encode, normalize, and transform the received data into structured machine-readable feature representations;
a multi-modal feature extraction module (116) configured to derive structural features, lexical features, temporal patterns, semantic attributes, and behavioral indicators from the transformed data;
an adaptive feature fusion module (118) configured to dynamically combine extracted features using weighted hierarchical aggregation to generate a unified feature vector;
a classification module (120) configured to analyze the unified feature vector to identify structural and sequential phishing patterns using convolutional neural network architecture and a long short-term memory architecture;
a detection module (122) configured to detect previously unseen phishing attacks by identifying latent probabilistic behavior patterns independent of predefined blacklist rules;
a false positive suppression module (124) configured to apply confidence calibration and multi-threshold validation to refine classification output and reduce misclassification rates;
a drift detection and model optimization module (126) configured to monitor statistical variations in incoming data streams and automatically initiate incremental retraining of the classification module (120) upon detection of distributional drift; and
an output module (128) configured to transmit a phishing risk score, classification results, and threat alerts to the user device (102) for display.
2. The system (100) as claimed in claim 1, wherein the user interface (104) is configured to display a visual phishing risk indicator comprising a graded threat level representation based on the generated phishing risk score.
3. The system (100) as claimed in claim 1, wherein the cloud database (108) is configured to store communication data, extracted feature representations, historical phishing detection records, model training datasets, and generated phishing risk assessments to support continuous learning and threat analysis within the system (100).
4. The system (100) as claimed in claim 1, wherein the multi-modal feature extraction module (116) is further configured to extract structural hyperlink graph patterns, token distribution metrics, domain registration attributes, temporal request frequency parameters, and behavioral navigation indicators from the transformed data to construct feature representations associated with phishing activity.
5. The system (100) as claimed in claim 1, wherein the adaptive feature fusion module (118) is further configured to apply hierarchical feature weighting and cross-domain correlation mapping to integrate heterogeneous structural, lexical, and behavioral features into a normalized unified feature vector suitable for deep learning analysis.
6. The system (100) as claimed in claim 1, wherein the classification module (120) is further configured to perform spatial feature learning using a convolutional neural network architecture and sequential dependency modeling using a long short-term memory architecture to identify latent phishing patterns within the unified feature vector.
7. The system (100) as claimed in claim 1, wherein the detection module (122) is further configured to determine probabilistic anomaly scores by comparing extracted behavioral patterns with learned benign interaction profiles to detect previously unseen phishing attempts without reliance on static blacklist databases.
8. The system (100) as claimed in claim 1, wherein the false positive suppression module (124) is further configured to perform probabilistic confidence calibration and adaptive threshold evaluation to filter ambiguous classification outputs and improve decision reliability during phishing detection.
9. The system (100) as claimed in claim 1, wherein the drift detection and model optimization module (126) is further configured to continuously evaluate statistical distribution changes in incoming communication data streams and initiate automated incremental retraining of the classification module (120) using updated phishing datasets.
10. A method (300) for detecting phishing attacks, the method (300) comprising:
receiving uniform resource locator (URL) inputs, email content, webpage data, and communication metadata, and to display phishing detection results to a user via a user interface (104) integrated into a user device (102);
facilitating data exchange within the system (100) via a communication network (106);
processing received data to perform phishing detection operations via a processing unit (110) comprising several modules;
receiving data from the user device (102) via a data input module (112);
validating, cleaning, tokenizing, encoding, normalizing, and transforming the received data into structured machine-readable feature representations via a data preprocessing module (114);
deriving structural features, lexical features, temporal patterns, semantic attributes, and behavioral indicators from the transformed data via a multi-modal feature extraction module (116);
dynamically combine extracted features using weighted hierarchical aggregation to generate a unified feature vector via an adaptive feature fusion module (118);
analyzing the unified feature vector to identify structural and sequential phishing patterns using convolutional neural network architecture and a long short-term memory architecture via a classification module (120);
detecting previously unseen phishing attacks by identifying latent probabilistic behavior patterns independent of predefined blacklist rules via a detection module (122);
applying confidence calibration and multi-threshold validation to refine classification output and reduce misclassification rates via a false positive suppression module (124);
monitoring statistical variations in incoming data streams and automatically initiate incremental retraining of the classification module (120) upon detection of distributional drift via a drift detection and model optimization module (126);
transmitting a phishing risk score, classification results, and threat alerts to the user device (102) for display via an output module (128).

Documents

Application Documents

# Name Date
7 202641033357-DRAWINGS [19-03-2026(online)].pdf 2026-03-19
8 202641033357-DECLARATION OF INVENTORSHIP (FORM 5) [19-03-2026(online)].pdf 2026-03-19
9 202641033357-COMPLETE SPECIFICATION [19-03-2026(online)].pdf 2026-03-19