IDEAS home Printed from https://ideas.repec.org/a/gam/jftint/v18y2026i2p101-d1865066.html

A Temporally Dynamic Feature-Extraction Framework for Phishing Detection with LIME and SHAP Explanations

Author

Listed:
  • Chris Mayo

    (School of Computing and Creative Technologies, University of the West of England, Bristol BS16 1QY, UK)

  • Michael Tchuindjang

    (School of Computing and Creative Technologies, University of the West of England, Bristol BS16 1QY, UK)

  • Sarfraz Brohi

    (School of Computing and Creative Technologies, University of the West of England, Bristol BS16 1QY, UK)

  • Nikolaos Ersotelos

    (School of Computing and Creative Technologies, University of the West of England, Bristol BS16 1QY, UK)

Abstract

Phishing remains one of the most pervasive social engineering threats, exploiting human vulnerabilities and continuously evolving to bypass static detection mechanisms. Existing machine learning models achieve high accuracy but often act as opaque systems that lack robustness to evolving tactics and explainability, limiting trust and real-world deployment. In this research, we propose a dynamic Explainable AI (XAI) approach for phishing detection that integrates temporally aware feature extraction with dual interpretability through LIME and SHAP applied to the resulting window-level features. The novelty of this research lies in a temporally dynamic feature framework that simulates a plausible email reading progression using a heuristic temporal model and employs a sliding window aggregation method to capture behavioural and temporal patterns within email content. Using an aggregated dataset of 82,500 phishing and legitimate emails, dynamic features were extracted and used to train four classifiers: Random Forest, XGBoost, Multi-Layer Perceptron, and Logistic Regression. Ensemble models demonstrated strong performance with XGBoost achieving 94% accuracy and Random Forest 93%. This research addresses an important gap by combining dynamically constructed temporal features with transparent explanations, achieving high detection performance while preserving interpretability. These findings demonstrate that dynamic temporal modelling with explainable learning can enhance the trustworthiness and practicality of phishing detection systems, highlighting that temporally structured features and explainable learning can enhance the trustworthiness and practical deployability of phishing detection systems without incurring excessive computational overhead.

Suggested Citation

  • Chris Mayo & Michael Tchuindjang & Sarfraz Brohi & Nikolaos Ersotelos, 2026. "A Temporally Dynamic Feature-Extraction Framework for Phishing Detection with LIME and SHAP Explanations," Future Internet, MDPI, vol. 18(2), pages 1-26, February.
  • Handle: RePEc:gam:jftint:v:18:y:2026:i:2:p:101-:d:1865066
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/1999-5903/18/2/101/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/1999-5903/18/2/101/
    Download Restriction: no
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:2:p:101-:d:1865066. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.