{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T00:01:05Z","timestamp":1780963265832,"version":"3.54.1"},"reference-count":61,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T00:00:00Z","timestamp":1779408000000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Information Security and Applications"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.jisa.2026.104486","type":"journal-article","created":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T12:16:25Z","timestamp":1776773785000},"page":"104486","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Adversarial attacks on phishing webpage detectors via heuristic search techniques"],"prefix":"10.1016","volume":"100","author":[{"given":"Giuseppe","family":"Lo Re","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5963-6236","authenticated-orcid":false,"given":"Marco","family":"Morana","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giuseppe","family":"Rizzo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.jisa.2026.104486_bib0001","unstructured":"Anti-Phishing Working Group (APWG). Phishing activity trends report, 2nd quarter 2025. 2025. https:\/\/apwg.org\/trendreports."},{"key":"10.1016\/j.jisa.2026.104486_bib0002","series-title":"Proceedings of the 38th annual computer security applications conference","isbn-type":"print","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1145\/3564625.3567980","article-title":"SpacePhish: the evasion-space of adversarial attacks against phishing website detectors using machine learning","author":"Apruzzese","year":"2022","ISBN":"https:\/\/id.crossref.org\/isbn\/9781450397599"},{"issue":"4","key":"10.1016\/j.jisa.2026.104486_bib0003","doi-asserted-by":"crossref","DOI":"10.1145\/3742895","article-title":"Intriguing properties of adversarial ML attacks in the problem space [extended version]","volume":"28","author":"Cortellazzi","year":"2025","journal-title":"ACM Trans Priv Secur"},{"key":"10.1016\/j.jisa.2026.104486_bib0004","series-title":"Proceedings of the 16th ACM workshop on artificial intelligence and security","first-page":"233","article-title":"Raze to the ground: query-efficient adversarial HTML attacks on machine-learning phishing webpage detectors","author":"Montaruli","year":"2023"},{"key":"10.1016\/j.jisa.2026.104486_bib0005","series-title":"Proceedings of the 29th conference on information communications","isbn-type":"print","doi-asserted-by":"crossref","first-page":"346","DOI":"10.1109\/INFCOM.2010.5462216","article-title":"Phishnet: predictive blacklisting to detect phishing attacks","author":"Prakash","year":"2010","ISBN":"https:\/\/id.crossref.org\/isbn\/9781424458363"},{"key":"10.1016\/j.jisa.2026.104486_bib0006","series-title":"2017\u202fAPWG Symposium on electronic crime research (eCrime)","first-page":"1","article-title":"Classifying phishing URLs using recurrent neural networks","author":"Bahnsen","year":"2017"},{"key":"10.1016\/j.jisa.2026.104486_bib0007","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103668","article-title":"Phishhunter: detecting camouflaged IDN-based phishing attacks via siamese neural network","volume":"138","author":"Wang","year":"2024","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104486_bib0008","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104123","article-title":"Pdsmv3-dcrnn: a novel ensemble deep learning framework for enhancing phishing detection and url extraction","volume":"148","author":"Prasad","year":"2025","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104486_bib0009","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.121183","article-title":"Look before you leap: detecting phishing web pages by exploiting raw URL and HTML characteristics","volume":"236","author":"Opara","year":"2024","journal-title":"Expert Syst Appl"},{"key":"10.1016\/j.jisa.2026.104486_bib0010","series-title":"2018\u202fIEEE International conference on intelligence and security informatics (ISI)","first-page":"220","article-title":"Phishmon: a machine learning framework for detecting phishing webpages","author":"Niakanlahiji","year":"2018"},{"key":"10.1016\/j.jisa.2026.104486_bib0011","series-title":"Special interest tracks and posters of the 14th international conference on world wide web","isbn-type":"print","doi-asserted-by":"crossref","first-page":"1060","DOI":"10.1145\/1062745.1062868","article-title":"Detection of phishing webpages based on visual similarity","author":"Wenyin","year":"2005","ISBN":"https:\/\/id.crossref.org\/isbn\/1595930515"},{"key":"10.1016\/j.jisa.2026.104486_bib0012","series-title":"Proceedings of the 2017\u202fIEEE global communications conference","first-page":"1","article-title":"Visual similarity-based phishing detection scheme using image and CSS with target website finder","author":"Haruta","year":"2017"},{"key":"10.1016\/j.jisa.2026.104486_bib0013","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.124120","article-title":"Phishing webpage detection based on global and local visual similarity","volume":"252","author":"Wang","year":"2024","journal-title":"Expert Syst Appl"},{"key":"10.1016\/j.jisa.2026.104486_bib0014","series-title":"Proceedings of the APWG symposium on electronic crime research (ecrime)","first-page":"1","article-title":"Multimodal large language models for phishing webpage detection and identification","author":"Lee","year":"2024"},{"key":"10.1016\/j.jisa.2026.104486_bib0015","series-title":"Proceedings of the 2018\u202fAPWG symposium on electronic crime research (eCrime)","article-title":"Deepphish: simulating malicious AI","author":"Bahnsen","year":"2018"},{"key":"10.1016\/j.jisa.2026.104486_bib0016","series-title":"Proceedings of the 2024\u202fIEEE symposium on security and privacy (SP)","first-page":"1236","article-title":"Multi-instance adversarial attack on GNN-based malicious domain detection","author":"Nazzal","year":"2024"},{"issue":"9","key":"10.1016\/j.jisa.2026.104486_bib0017","doi-asserted-by":"crossref","first-page":"5210","DOI":"10.1002\/int.22510","article-title":"Advanced evasion attacks and mitigations on practical ML-based phishing website classifiers","volume":"36","author":"Song","year":"2021","journal-title":"Int J Intell Syst"},{"key":"10.1016\/j.jisa.2026.104486_bib0018","unstructured":"Gressel G., Hegde N., Sreekumar A., Radhakrishnan R., Harikumar K., Anjali S., et al. Feature importance guided attack: A model agnostic adversarial attack. 2023. arXiv: 2106.14815\">."},{"key":"10.1016\/j.jisa.2026.104486_bib0019","series-title":"2021\u202fIEEE International confernce on parallel & distributed processing with applications, big data & cloud computing, sustainable computing & communications, social computing & networking (ISPA\/BDCloud\/SocialCom\/SustainCom)","first-page":"1657","article-title":"Generative adverserial analysis of phishing attacks on static and dynamic content of webpages","author":"O\u2019Mara","year":"2021"},{"key":"10.1016\/j.jisa.2026.104486_bib0020","series-title":"Proceedings of the ACM web conference 2024","isbn-type":"print","doi-asserted-by":"crossref","first-page":"1712","DOI":"10.1145\/3589334.3645502","article-title":"\u201cAre adversarial phishing webpages a threat in reality?\u201d understanding the users\u2019 perception of adversarial webpages","author":"Yuan","year":"2024","ISBN":"https:\/\/id.crossref.org\/isbn\/9798400701719"},{"key":"10.1016\/j.jisa.2026.104486_bib0021","series-title":"Computer security \u2013 ESORICS 2023: 28th European symposium on research in computer security, the hague, the Netherlands, september 25\u201329, 2023, Proceedings, Part III","isbn-type":"print","first-page":"162","article-title":"Attacking logo-based phishing website detectors with adversarial perturbations","author":"Lee","year":"2023","ISBN":"https:\/\/id.crossref.org\/isbn\/9783031514784"},{"key":"10.1016\/j.jisa.2026.104486_bib0022","series-title":"Proceedings of the 33rd USENIX security symposium (USENIX security 24)","isbn-type":"print","first-page":"3027","article-title":"It doesn\u2019t look like anything to me: using diffusion model to subvert visual phishing detectors","author":"Hao","year":"2024","ISBN":"https:\/\/id.crossref.org\/isbn\/9781939133441"},{"key":"10.1016\/j.jisa.2026.104486_bib0023","series-title":"Proceedings of the 2024\u202fIEEE symposium on security and privacy (SP)","first-page":"36","article-title":"From chatbots to phishbots?: phishing scam generation in commercial large language models","author":"Roy","year":"2024"},{"issue":"2","key":"10.1016\/j.jisa.2026.104486_bib0024","article-title":"From ML to LLM: evaluating the robustness of phishing web page detection models against adversarial attacks","volume":"6","author":"Kulkarni","year":"2025","journal-title":"Digit Threats"},{"key":"10.1016\/j.jisa.2026.104486_bib0025","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104115","article-title":"Beyond the west: revealing and bridging the gap between western and chinese phishing website detection","volume":"148","author":"Yuan","year":"2025","journal-title":"Comput Secur"},{"issue":"8","key":"10.1016\/j.jisa.2026.104486_bib0026","doi-asserted-by":"crossref","DOI":"10.3390\/ai6080174","article-title":"Phishing attacks in the age of generative artificial intelligence: a systematic review of human factors","volume":"6","author":"Jabir","year":"2025","journal-title":"AI"},{"key":"10.1016\/j.jisa.2026.104486_bib0027","series-title":"Proceedings of the future technologies conference (FTC)","isbn-type":"print","doi-asserted-by":"crossref","first-page":"174","DOI":"10.1007\/978-3-031-47454-5_13","article-title":"Phishing faster: implementing chatGPT into phishing campaigns","volume":"vol. 1","author":"Langford","year":"2023","ISBN":"https:\/\/id.crossref.org\/isbn\/9783031474545"},{"key":"10.1016\/j.jisa.2026.104486_bib0028","doi-asserted-by":"crossref","first-page":"10989","DOI":"10.1109\/ACCESS.2020.2965184","article-title":"Adversarial examples detection for XSS attacks based on generative adversarial networks","volume":"8","author":"Zhang","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104486_bib0029","series-title":"Neural information processing. ICONIP 2022. communications in computer and information science","first-page":"385","article-title":"Searching for textual adversarial examples with learned strategy","volume":"Vol 1791","author":"Guo","year":"2023"},{"key":"10.1016\/j.jisa.2026.104486_bib0030","unstructured":"Boutsikas J., Eren M.E., Varga C.K., Raff E., Matuszek C., Nicholas C.. Evading malware classifiers via monte carlo mutant feature discovery. In: 12th Annual Malware technical exchange meeting. 2021, arXiv: 2106.07860\">."},{"key":"10.1016\/j.jisa.2026.104486_bib0031","series-title":"Proceedings of the 31st international conference on computational linguistics","first-page":"1057","article-title":"Monte carlo tree search based prompt autogeneration for jailbreak attacks against LLMs","author":"Wu","year":"2025"},{"key":"10.1016\/j.jisa.2026.104486_bib0032","series-title":"Advances in knowledge discovery and data mining: 27th Pacific-Asia conference on knowledge discovery and data mining, PAKDD 2023, Osaka, Japan, May 25\u201328, 2023, Proceedings, Part II","first-page":"454","article-title":"BeamAttack: generating high-quality textual adversarial examples through beam search and mixed semantic spaces","author":"Zhu","year":"2023"},{"key":"10.1016\/j.jisa.2026.104486_bib0033","series-title":"Proceedings of the 2022 conference on empirical methods in natural language processing","first-page":"5490","article-title":"TABS: Efficient textual adversarial attack for pre-trained NL code model using semantic beam search","author":"Choi","year":"2022"},{"key":"10.1016\/j.jisa.2026.104486_bib0034","series-title":"International workshop on advanced imaging technology (IWAIT) 2024","first-page":"1316410","article-title":"Reversible adversarial image examples with beam search attack and grayscale invariance","volume":"Vol. 13164","author":"Zhang","year":"2024"},{"key":"10.1016\/j.jisa.2026.104486_bib0035","series-title":"Proceedings of the thirtieth international joint conference on artificial intelligence, IJCAI-21","first-page":"3293","article-title":"Besa: bert-based simulated annealing for adversarial text attacks","author":"Yang","year":"2021"},{"key":"10.1016\/j.jisa.2026.104486_bib0036","series-title":"Advances in neural information processing systems 36: annual conference on neural information processing systems 2023, NeurIPS 2023, New Orleans, LA, USA, December 10, - 16, 2023","article-title":"CamoPatch: an evolutionary strategy for generating camoflauged adversarial patches","author":"Williams","year":"2023"},{"issue":"3","key":"10.1016\/j.jisa.2026.104486_bib0037","doi-asserted-by":"crossref","DOI":"10.3390\/electronics13030650","article-title":"Score-based black-box adversarial attack on time series using simulated annealing classification and post-processing based defense","volume":"13","author":"Liu","year":"2024","journal-title":"Electronics"},{"issue":"2","key":"10.1016\/j.jisa.2026.104486_bib0038","article-title":"Multi-spacephish: extending the evasion-space of adversarial attacks against phishing website detectors using machine learning","volume":"5","author":"Yuan","year":"2024","journal-title":"Digit Threats"},{"issue":"3","key":"10.1016\/j.jisa.2026.104486_bib0039","first-page":"2497","article-title":"Monte Carlo tree search: a review of recent modifications and applications","volume":"56","author":"undefinedwiechowski","year":"2022","journal-title":"Artif Intell Rev"},{"key":"10.1016\/j.jisa.2026.104486_bib0040","series-title":"Proceedings of the 17th European conference on machine learning","first-page":"282","article-title":"Bandit based Monte-Carlo planning","author":"Kocsis","year":"2006"},{"issue":"1","key":"10.1016\/j.jisa.2026.104486_bib0041","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1080\/00207548808947840","article-title":"Filtered beam search in scheduling","volume":"26","author":"Peng","year":"1988","journal-title":"Int J Prod Res"},{"issue":"4598","key":"10.1016\/j.jisa.2026.104486_bib0042","doi-asserted-by":"crossref","first-page":"671","DOI":"10.1126\/science.220.4598.671","article-title":"Optimization by simulated annealing","volume":"220","author":"Kirkpatrick","year":"1983","journal-title":"Science"},{"issue":"1","key":"10.1016\/j.jisa.2026.104486_bib0043","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1093\/biomet\/57.1.97","article-title":"Monte Carlo sampling methods using Markov chains and their applications","volume":"57","author":"Hastings","year":"1970","journal-title":"Biometrika"},{"key":"10.1016\/j.jisa.2026.104486_bib0044","series-title":"Computer security \u2013 ESORICS 2017: 22nd European symposium on research in computer security, Oslo, Norway, September 11\u201315, 2017","first-page":"370","article-title":"DeltaPhish: detecting phishing webpages in compromised websites","author":"Corona","year":"2017"},{"key":"10.1016\/j.jisa.2026.104486_bib0045","unstructured":"Putra I.K.A.A.. Phishing website dataset. 2023. 10.5281\/zenodo.8041386."},{"issue":"3","key":"10.1016\/j.jisa.2026.104486_bib0046","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1049\/iet-ifs.2013.0202","article-title":"Intelligent rule-based phishing websites classification","volume":"8","author":"Mohammad","year":"2014","journal-title":"IET Inf Secur"},{"key":"10.1016\/j.jisa.2026.104486_bib0047","series-title":"2020\u202fIEEE International conference on electronics, computing and communication technologies (CONECCT)","first-page":"1","article-title":"A feature selection comparative study for web phishing datasets","author":"Sharma","year":"2020"},{"key":"10.1016\/j.jisa.2026.104486_bib0048","doi-asserted-by":"crossref","DOI":"10.1007\/s11235-017-0414-0","article-title":"Towards detection of phishing websites on client-side using machine learning based approach","volume":"68","author":"Jain","year":"2018","journal-title":"Telecommun Syst"},{"key":"10.1016\/j.jisa.2026.104486_bib0049","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2021.104347","article-title":"Towards benchmark datasets for machine learning based website phishing detection: an experimental study","volume":"104","author":"Hannousse","year":"2021","journal-title":"Eng Appl Artif Intell"},{"key":"10.1016\/j.jisa.2026.104486_bib0050","series-title":"2017\u202fIEEE Symposium on security and privacy (SP)","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"key":"10.1016\/j.jisa.2026.104486_bib0051","series-title":"Proceedings of the 8th international conference on database theory (ICDT 2001)","first-page":"420","article-title":"On the surprising behavior of distance metrics in high dimensional space","author":"Aggarwal","year":"2001"},{"issue":"5","key":"10.1016\/j.jisa.2026.104486_bib0052","article-title":"Evaluating realistic adversarial attacks against machine learning models for windows PE malware detection","volume":"16","author":"Imran","year":"2024","journal-title":"Fut Internet"},{"key":"10.1016\/j.jisa.2026.104486_bib0053","series-title":"In proceedings of the 2020 international joint conference on neural networks (IJCNN)","first-page":"1","article-title":"When explainability meets adversarial learning: detecting adversarial examples using SHAP signatures","author":"Fidel","year":"2020"},{"key":"10.1016\/j.jisa.2026.104486_bib0054","series-title":"Proceedings of the 31st international conference on neural information processing systems","isbn-type":"print","first-page":"4768","article-title":"A unified approach to interpreting model predictions","author":"Lundberg","year":"2017","ISBN":"https:\/\/id.crossref.org\/isbn\/9781510860964"},{"key":"10.1016\/j.jisa.2026.104486_bib0055","series-title":"Proceedings of the 16th international conference on wireless communications and signal processing (WCSP)","first-page":"626","article-title":"Information importance-aware defense against adversarial attack for automatic modulation classification: an XAI-based approach","author":"Wang","year":"2024"},{"key":"10.1016\/j.jisa.2026.104486_bib0056","doi-asserted-by":"crossref","DOI":"10.1016\/j.inffus.2024.102303","article-title":"Adversarial attacks and defenses in explainable artificial intelligence: a survey","volume":"107","author":"Baniecki","year":"2024","journal-title":"Inf Fusion"},{"issue":"1","key":"10.1016\/j.jisa.2026.104486_bib0057","doi-asserted-by":"crossref","DOI":"10.1145\/2133360.2133363","article-title":"Isolation-based anomaly detection","volume":"6","author":"Liu","year":"2012","journal-title":"ACM Trans Knowl Discov Data"},{"key":"10.1016\/j.jisa.2026.104486_bib0058","series-title":"Proceedings of the 2000\u202fACM SIGMOD international conference on management of data","isbn-type":"print","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1145\/342009.335388","article-title":"Lof: identifying density-based local outliers","author":"Breunig","year":"2000","ISBN":"https:\/\/id.crossref.org\/isbn\/1581132174"},{"issue":"5","key":"10.1016\/j.jisa.2026.104486_bib0059","doi-asserted-by":"crossref","first-page":"351","DOI":"10.1080\/08839514.2013.785791","article-title":"One-class support vector machines approach to anomaly detection","volume":"27","author":"Hejazi","year":"2013","journal-title":"Appl Artif Intell"},{"issue":"3","key":"10.1016\/j.jisa.2026.104486_bib0060","doi-asserted-by":"crossref","first-page":"212","DOI":"10.1080\/00401706.1999.10485670","article-title":"A fast algorithm for the minimum covariance determinant estimator","volume":"41","author":"Rousseeuw","year":"1999","journal-title":"Technometrics"},{"issue":"4","key":"10.1016\/j.jisa.2026.104486_bib0061","doi-asserted-by":"crossref","first-page":"2411","DOI":"10.1109\/TSC.2023.3234806","article-title":"Adversarial autoencoder data synthesis for enhancing machine learning-based phishing detection algorithms","volume":"16","author":"Shirazi","year":"2023","journal-title":"IEEE Trans Serv Comput"}],"container-title":["Journal of Information Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S221421262600116X?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S221421262600116X?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T23:29:16Z","timestamp":1780961356000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S221421262600116X"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":61,"alternative-id":["S221421262600116X"],"URL":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104486","relation":{},"ISSN":["2214-2126"],"issn-type":[{"value":"2214-2126","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Adversarial attacks on phishing webpage detectors via heuristic search techniques","name":"articletitle","label":"Article Title"},{"value":"Journal of Information Security and Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104486","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"104486"}}