{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T00:48:28Z","timestamp":1782262108888,"version":"3.54.5"},"reference-count":40,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100013804","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100013804","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,12]]},"DOI":"10.1016\/j.eswa.2026.133324","type":"journal-article","created":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T15:47:54Z","timestamp":1781884074000},"page":"133324","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"PC","title":["Anti-APhish: A robust and adaptive detection approach against evolving AI-powered phishing URLs"],"prefix":"10.1016","volume":"331","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6176-9804","authenticated-orcid":false,"given":"Ziliang","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7325-7307","authenticated-orcid":false,"given":"Ning","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenbo","family":"Shi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhiquan","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"14","key":"10.1016\/j.eswa.2026.133324_bib0001","doi-asserted-by":"crossref","first-page":"4816","DOI":"10.3390\/s21144816","article-title":"Identifying and mitigating phishing attack threats in IoT use cases using a threat modelling approach","volume":"21","author":"Abbas","year":"2021","journal-title":"Sensors"},{"key":"10.1016\/j.eswa.2026.133324_bib0002","unstructured":"Agarwal, S., Suarez-Tangil, G., & Vasek, M. (2025). An overview of 7726 user reports: Uncovering SMS scams and scammer strategies. arXiv preprint arXiv:2508.05276."},{"key":"10.1016\/j.eswa.2026.133324_bib0003","article-title":"Improved attack detection in IoT and IIot networks using attention mechanisms in convolutional neural networks","volume":"296","author":"Ahmad","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133324_bib0004","series-title":"2023 IEEE conference on communications and network security (CNS)","first-page":"1","article-title":"Exploring the dark side of AI: Advanced phishing attack design and deployment using chatGPT","author":"Begou","year":"2023"},{"key":"10.1016\/j.eswa.2026.133324_bib0005","unstructured":"Blake, S. E. (2025). Phishsense-1B: A technical perspective on an AI-powered phishing detection model. arXiv preprint arXiv:2503.10944."},{"key":"10.1016\/j.eswa.2026.133324_bib0006","series-title":"2022 International conference on advancements in smart, secure and intelligent computing (ASSIC)","first-page":"1","article-title":"An efficient phishing attack detection using machine learning algorithms","author":"Chinnasamy","year":"2022"},{"key":"10.1016\/j.eswa.2026.133324_bib0007","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2025.104251","article-title":"Effective ensemble learning phishing detection system using hybrid feature selection","volume":"242","author":"Connolly","year":"2025","journal-title":"Journal of Network and Computer Applications"},{"key":"10.1016\/j.eswa.2026.133324_bib0008","doi-asserted-by":"crossref","first-page":"217","DOI":"10.1007\/s40745-022-00379-8","article-title":"Modeling hybrid feature-based phishing websites detection using machine learning techniques","volume":"11","author":"Das Gupta","year":"2024","journal-title":"Annals of Data Science"},{"key":"10.1016\/j.eswa.2026.133324_bib0009","first-page":"2024","article-title":"David versus goliath: Can machine learning detect LLM-generated text? A case study in the detection of phishing emails","volume":"3731","author":"Greco","year":"2024","journal-title":"ITASEC"},{"key":"10.1016\/j.eswa.2026.133324_bib0010","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1016\/j.comcom.2021.04.023","article-title":"A novel approach for phishing URLs detection using lexical based machine learning in a real-time environment","volume":"175","author":"Gupta","year":"2021","journal-title":"Computer Communications"},{"key":"10.1016\/j.eswa.2026.133324_bib0011","doi-asserted-by":"crossref","first-page":"9233","DOI":"10.1007\/s12652-022-04426-3","article-title":"Highly accurate phishing URL detection based on machine learning","volume":"14","author":"Jall","year":"2023","journal-title":"J Ambient Intell Human Comput"},{"key":"10.1016\/j.eswa.2026.133324_bib0012","article-title":"An effective new penetration test approach to detect web attacks on web applications","volume":"298","author":"Kaya","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133324_bib0013","article-title":"Toxicity in online platforms and AI systems: A survey of needs, challenges, mitigations, and future directions","volume":"299","author":"Khapre","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133324_bib0014","series-title":"Working Paper","article-title":"URLNet: Learning a URL representation with deep learning for malicious URL detection","author":"Le","year":"2018"},{"key":"10.1016\/j.eswa.2026.133324_bib0015","doi-asserted-by":"crossref","unstructured":"Li, Y., Liu, Y., Li, P., Jia, Y., & Wang, Y. (2025). Continuous multi-task pre-training for malicious URL detection and webpage classification. arXiv preprint arXiv:2402.11495.","DOI":"10.2139\/ssrn.5168205"},{"key":"10.1016\/j.eswa.2026.133324_bib0016","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110707","article-title":"TransURL: Improving malicious URL detection with multi-layer transformer encoding and multi-scale pyramid features","volume":"253","author":"Liu","year":"2024","journal-title":"Computer Networks"},{"key":"10.1016\/j.eswa.2026.133324_bib0017","series-title":"2020 IEEE international conference for innovation in technology (INOCON)","first-page":"1","article-title":"Anti-phishing system using LSTM and CNN","author":"M","year":"2020"},{"key":"10.1016\/j.eswa.2026.133324_bib0018","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2024.104004","article-title":"Evolving techniques in cyber threat hunting: A systematic review","volume":"232","author":"Mahboubi","year":"2024","journal-title":"Journal of Network and Computer Applications"},{"key":"10.1016\/j.eswa.2026.133324_bib0019","series-title":"Concept drift detection in phishing using autoencoders","first-page":"1","volume":"(vol.1366","author":"Menon","year":"2021"},{"key":"10.1016\/j.eswa.2026.133324_bib0020","series-title":"2024 8th International conference on i-SMAC (IoT in social, mobile, analytics and cloud)(i-SMAC)","first-page":"663","article-title":"Analysis of how chatgpt and gemini help in the generation of cyber attacks","author":"Nagarajan","year":"2024"},{"key":"10.1016\/j.eswa.2026.133324_bib0021","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.121183","article-title":"Look before you leap: Detecting phishing web pages by exploiting raw URL and HTML characteristics","volume":"236","author":"Opara","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133324_bib0022","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.127044","article-title":"Evaluating spam filters and stylometric detection of AI-generated phishing emails","volume":"276","author":"Opara","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133324_bib0023","unstructured":"PhishTank (2025). PhishTank: Collaborative clearing house for phishing data. https:\/\/www.phishtank.org\/."},{"key":"10.1016\/j.eswa.2026.133324_bib0024","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103545","article-title":"PhiUSIIL: A diverse security profile empowered phishing URL detection framework based on similarity index and incremental learning","volume":"136","author":"Prasad","year":"2024","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.133324_bib0025","article-title":"StealthPhisher: A defensive framework against phishing attack using hybrid deep learning and genAI","volume":"299","author":"Prasad","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133324_bib0026","series-title":"NDSS","article-title":"BLAG: Improving the accuracy of blacklists","author":"Ramanathan","year":"2020"},{"key":"10.1016\/j.eswa.2026.133324_bib0027","series-title":"2024 IEEE Symposium on security and privacy (SP)","first-page":"36","article-title":"From chatbots to phishbots?: Phishing scam generation in commercial large language models","author":"Roy","year":"2024"},{"key":"10.1016\/j.eswa.2026.133324_bib0028","first-page":"1","article-title":"Reliability and robustness analysis of machine learning based phishing URL detectors","author":"Sabir","year":"2022","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.1016\/j.eswa.2026.133324_bib0029","series-title":"Proceedings of the ACM web conference 2024","first-page":"1724","article-title":"Hyperlink hijacking: Exploiting erroneous URL links to phantom domains","author":"Saric","year":"2024"},{"key":"10.1016\/j.eswa.2026.133324_bib0030","series-title":"Proceedings of the 60th annual meeting of the association for computational linguistics (volume 1: Long papers)","first-page":"46","article-title":"AlephBERT: Language model pre-training and evaluation from sub-word to sentence level","author":"Seker","year":"2022"},{"key":"10.1016\/j.eswa.2026.133324_bib0031","series-title":"2020 International conference on communications, computing, cybersecurity, and informatics (CCCI)","first-page":"1","article-title":"PhishGAN: Data augmentation and identification of homoglyph attacks","author":"Sern","year":"2020"},{"key":"10.1016\/j.eswa.2026.133324_bib0032","doi-asserted-by":"crossref","DOI":"10.1016\/j.array.2026.100775","article-title":"A systematic literature review of large language models in phishing attack generation and detection","volume":"30","author":"Sivaneswaran","year":"2026","journal-title":"Array"},{"key":"10.1016\/j.eswa.2026.133324_bib0033","series-title":"2023 7th International conference on intelligent computing and control systems (ICICCS)","first-page":"1415","article-title":"Exploring techniques for web phishing detection: A comprehensive survey","author":"Suresh Kumar","year":"2023"},{"key":"10.1016\/j.eswa.2026.133324_bib0034","series-title":"Twentieth symposium on usable privacy and security (SOUPS 2024)","first-page":"393","article-title":"What drives SMiShing susceptibility? A U.S. interview study of how and why mobile phone users judge text messages to be real or fake","author":"Tabassum","year":"2024"},{"key":"10.1016\/j.eswa.2026.133324_bib0035","unstructured":"VirusTotal (2025). VirusTotal: Malware and breach detection platform. https:\/\/www.virustotal.com\/."},{"key":"10.1016\/j.eswa.2026.133324_bib0036","article-title":"PDHG: An ethereum phishing detection approach via heterogeneous graph transformer","volume":"298","author":"Wang","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133324_bib0037","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103668","article-title":"PhishHunter: Detecting camouflaged IDN-based phishing attacks via siamese neural network","volume":"138","author":"Wang","year":"2024","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.133324_bib0038","series-title":"ICASSP 2023 - 2023 IEEE international conference on acoustics, speech and signal processing (ICASSP)","first-page":"1","article-title":"A large-scale pretrained deep model for phishing URL detection","author":"Wang","year":"2023"},{"key":"10.1016\/j.eswa.2026.133324_bib0039","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.126982","article-title":"LLM-AE-MP: Web attack detection using a large language model with autoencoder and multilayer perceptron","volume":"274","author":"Yang","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133324_bib0040","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111303","article-title":"AdaptPUD: An accurate URL-based detection approach against tailored deceptive phishing websites","volume":"265","author":"Zhang","year":"2025","journal-title":"Computer Networks"}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426022335?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426022335?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T00:32:35Z","timestamp":1782261155000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426022335"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,12]]},"references-count":40,"alternative-id":["S0957417426022335"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.133324","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,12]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Anti-APhish: A robust and adaptive detection approach against evolving AI-powered phishing URLs","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.133324","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"133324"}}