{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,9,3]],"date-time":"2026-09-03T02:28:12Z","timestamp":1788402492076,"version":"build-2803163510"},"publisher-location":"New York, NY, USA","reference-count":95,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,12,5]],"date-time":"2022-12-05T00:00:00Z","timestamp":1670198400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Hilti"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,12,5]]},"DOI":"10.1145\/3564625.3567980","type":"proceedings-article","created":{"date-parts":[[2022,12,2]],"date-time":"2022-12-02T20:01:29Z","timestamp":1670011289000},"page":"171-185","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":35,"title":["SpacePhish: The Evasion-space of Adversarial Attacks against Phishing Website Detectors using Machine Learning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6890-9611","authenticated-orcid":false,"given":"Giovanni","family":"Apruzzese","sequence":"first","affiliation":[{"name":"Institute of Information Systems, University of Liechtenstein, Liechtenstein"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3612-1934","authenticated-orcid":false,"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[{"name":"Department of Mathematics, University of Padua, Italy and Department of Computer Science, Delft University of Technology, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9530-4725","authenticated-orcid":false,"given":"Ying","family":"Yuan","sequence":"additional","affiliation":[{"name":"Department of Mathematics, University of Padua, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,12,5]]},"reference":[{"key":"e_1_3_2_2_3_1","unstructured":"2021. S&T Artificial Intelligence and Machine Learning Strategic Plan. Technical Report. US Department of Homeland Security. 24 pages. https:\/\/www.dhs.gov\/sites\/default\/files\/publications\/21_0730_st_ai_ml_strategic_plan_2021.pdf  2021. S&T Artificial Intelligence and Machine Learning Strategic Plan. Technical Report. US Department of Homeland Security. 24 pages. https:\/\/www.dhs.gov\/sites\/default\/files\/publications\/21_0730_st_ai_ml_strategic_plan_2021.pdf"},{"key":"e_1_3_2_2_4_1","unstructured":"2022. All Adversarial Examples Papers. https:\/\/nicholas.carlini.com\/writing\/2019\/all-adversarial-example-papers.html.  2022. All Adversarial Examples Papers. https:\/\/nicholas.carlini.com\/writing\/2019\/all-adversarial-example-papers.html."},{"key":"e_1_3_2_2_5_1","unstructured":"2022. Machine Learning Security Evasion Competition. https:\/\/mlsec.io\/.  2022. Machine Learning Security Evasion Competition. https:\/\/mlsec.io\/."},{"key":"e_1_3_2_2_6_1","unstructured":"2022. PhishTank. https:\/\/phishtank.org\/.  2022. PhishTank. https:\/\/phishtank.org\/."},{"key":"e_1_3_2_2_7_1","volume-title":"State of the Phish","year":"2022","unstructured":"2022. State of the Phish 2022 . Technical Report. ProofPoint . https:\/\/www.proofpoint.com\/it\/resources\/threat-reports\/state-of-phish 2022. State of the Phish 2022. Technical Report. ProofPoint. https:\/\/www.proofpoint.com\/it\/resources\/threat-reports\/state-of-phish"},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417233"},{"key":"e_1_3_2_2_9_1","volume-title":"USENIX Security Symposium.","author":"Acharya Bhupendra","year":"2021","unstructured":"Bhupendra Acharya and Phani Vadrevu . 2021 . {PhishPrint}: Evading Phishing Detection Crawlers by Prior Profiling . In USENIX Security Symposium. Bhupendra Acharya and Phani Vadrevu. 2021. {PhishPrint}: Evading Phishing Detection Crawlers by Prior Profiling. In USENIX Security Symposium."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISI53945.2021.9624751"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3375708.3380315"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"crossref","unstructured":"Giovanni Apruzzese Mauro Andreolini Luca Ferretti Mirco Marchetti and Michele Colajanni. 2021. Modeling Realistic Adversarial Attacks against Network Intrusion Detection Systems. ACM Digital Threats: Res. and Practice(2021).  Giovanni Apruzzese Mauro Andreolini Luca Ferretti Mirco Marchetti and Michele Colajanni. 2021. Modeling Realistic Adversarial Attacks against Network Intrusion Detection Systems. ACM Digital Threats: Res. and Practice(2021).","DOI":"10.1145\/3469659"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/NCA.2018.8548327"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.23919\/CYCON.2019.8756865"},{"key":"e_1_3_2_2_15_1","volume-title":"Wissam Mallouli, Luis Burdalo\u00a0Rapa, Athanasios Vasileios\u00a0Grammatopoulos, and Fabio Di\u00a0Franco.","author":"Apruzzese Giovanni","year":"2022","unstructured":"Giovanni Apruzzese , Pavel Laskov , Edgardo Montes\u00a0de Oca , Wissam Mallouli, Luis Burdalo\u00a0Rapa, Athanasios Vasileios\u00a0Grammatopoulos, and Fabio Di\u00a0Franco. 2022 . The Role of Machine Learning in Cybersecurity. ACM Digital Threats: Research and Practice( 2022). Giovanni Apruzzese, Pavel Laskov, Edgardo Montes\u00a0de Oca, Wissam Mallouli, Luis Burdalo\u00a0Rapa, Athanasios Vasileios\u00a0Grammatopoulos, and Fabio Di\u00a0Franco. 2022. The Role of Machine Learning in Cybersecurity. ACM Digital Threats: Research and Practice(2022)."},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00010"},{"key":"e_1_3_2_2_17_1","volume-title":"Dos and Don\u2019ts of Machine Learning in Computer Security. In USENIX Secur. Symp.","author":"Arp Daniel","year":"2022","unstructured":"Daniel Arp , Erwin Quiring , Feargus Pendlebury , Alexander Warnecke , Fabio Pierazzi , Christian Wressnegger , Lorenzo Cavallaro , and Konrad Rieck . 2022 . Dos and Don\u2019ts of Machine Learning in Computer Security. In USENIX Secur. Symp. Daniel Arp, Erwin Quiring, Feargus Pendlebury, Alexander Warnecke, Fabio Pierazzi, Christian Wressnegger, Lorenzo Cavallaro, and Konrad Rieck. 2022. Dos and Don\u2019ts of Machine Learning in Computer Security. In USENIX Secur. Symp."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLANT53170.2021.9690540"},{"key":"e_1_3_2_2_19_1","volume-title":"USENIX Sec. Symp.","author":"Bagdasaryan Eugene","year":"2021","unstructured":"Eugene Bagdasaryan and Vitaly Shmatikov . 2021 . Blind backdoors in deep learning models . In USENIX Sec. Symp. Eugene Bagdasaryan and Vitaly Shmatikov. 2021. Blind backdoors in deep learning models. In USENIX Sec. Symp."},{"key":"e_1_3_2_2_20_1","volume-title":"Proc. APWG Symp. Elec. Crime Res.","author":"Bahnsen Alejandro\u00a0Correa","year":"2018","unstructured":"Alejandro\u00a0Correa Bahnsen , Ivan Torroledo , Luis\u00a0David Camacho , and Sergio Villegas . 2018 . DeepPhish: simulating malicious AI . In Proc. APWG Symp. Elec. Crime Res. Alejandro\u00a0Correa Bahnsen, Ivan Torroledo, Luis\u00a0David Camacho, and Sergio Villegas. 2018. DeepPhish: simulating malicious AI. In Proc. APWG Symp. Elec. Crime Res."},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"crossref","unstructured":"Khalid Binsaeed Gianluca Stringhini and Ahmed\u00a0E Youssef. 2020. Detecting Spam in Twitter Microblogging Services: A Novel Machine Learning Approach based on Domain Popularity. Int. J. Adv. Comput. Sci. Appl(2020).  Khalid Binsaeed Gianluca Stringhini and Ahmed\u00a0E Youssef. 2020. Detecting Spam in Twitter Microblogging Services: A Novel Machine Learning Approach based on Domain Popularity. Int. J. Adv. Comput. Sci. Appl(2020).","DOI":"10.14569\/IJACSA.2020.0111103"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"crossref","unstructured":"Franziska Boenisch Verena Battis Nicolas Buchmann and Maija Poikela. 2021. \u201cI Never Thought About Securing My Machine Learning Systems\u201d: A Study of Security and Privacy Awareness of Machine Learning Practitioners. In ACM Mensch und Computer.  Franziska Boenisch Verena Battis Nicolas Buchmann and Maija Poikela. 2021. \u201cI Never Thought About Securing My Machine Learning Systems\u201d: A Study of Security and Privacy Awareness of Machine Learning Practitioners. In ACM Mensch und Computer.","DOI":"10.1145\/3473856.3473869"},{"key":"e_1_3_2_2_24_1","volume-title":"Towards lightweight URL-based phishing detection. Future internet","author":"Butnaru Andrei","year":"2021","unstructured":"Andrei Butnaru , Alexios Mylonas , and Nikolaos Pitropakis . 2021. Towards lightweight URL-based phishing detection. Future internet ( 2021 ). Andrei Butnaru, Alexios Mylonas, and Nikolaos Pitropakis. 2021. Towards lightweight URL-based phishing detection. Future internet (2021)."},{"key":"e_1_3_2_2_25_1","volume-title":"Going spear phishing: Exploring embedded training and awareness","author":"Caputo D","year":"2013","unstructured":"Deanna\u00a0 D Caputo , Shari\u00a0Lawrence Pfleeger , Jesse\u00a0 D Freeman , and M\u00a0Eric Johnson . 2013. Going spear phishing: Exploring embedded training and awareness . IEEE Security & Privacy( 2013 ). Deanna\u00a0D Caputo, Shari\u00a0Lawrence Pfleeger, Jesse\u00a0D Freeman, and M\u00a0Eric Johnson. 2013. Going spear phishing: Exploring embedded training and awareness. IEEE Security & Privacy(2013)."},{"key":"e_1_3_2_2_26_1","volume-title":"USENIX Secur. Symp.","author":"Carlini Nicholas","year":"2021","unstructured":"Nicholas Carlini . 2021 . Poisoning the Unlabeled Dataset of {Semi-Supervised} Learning . In USENIX Secur. Symp. Nicholas Carlini. 2021. Poisoning the Unlabeled Dataset of {Semi-Supervised} Learning. In USENIX Secur. Symp."},{"key":"e_1_3_2_2_27_1","volume-title":"On evaluating adversarial robustness. arXiv:1902.06705","author":"Carlini Nicholas","year":"2019","unstructured":"Nicholas Carlini , Anish Athalye , Nicolas Papernot , Wieland Brendel , Jonas Rauber , Dimitris Tsipras , Ian Goodfellow , Aleksander Madry , and Alexey Kurakin . 2019. On evaluating adversarial robustness. arXiv:1902.06705 ( 2019 ). Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, Aleksander Madry, and Alexey Kurakin. 2019. On evaluating adversarial robustness. arXiv:1902.06705 (2019)."},{"key":"e_1_3_2_2_28_1","volume-title":"Defensive distillation is not robust to adversarial examples. arXiv:1607.04311","author":"Carlini Nicholas","year":"2016","unstructured":"Nicholas Carlini and David Wagner . 2016. Defensive distillation is not robust to adversarial examples. arXiv:1607.04311 ( 2016 ). Nicholas Carlini and David Wagner. 2016. Defensive distillation is not robust to adversarial examples. arXiv:1607.04311 (2016)."},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/EISIC.2017.21"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66402-6_22"},{"key":"e_1_3_2_2_32_1","volume-title":"machine learning can be more secure! A case study on android malware detection","author":"Demontis Ambra","year":"2017","unstructured":"Ambra Demontis , Marco Melis , Battista Biggio , Davide Maiorca , Daniel Arp , Konrad Rieck , Igino Corona , Giorgio Giacinto , and Fabio Roli . 2017. Yes , machine learning can be more secure! A case study on android malware detection . IEEE T. Dependable Secure Comp .( 2017 ). Ambra Demontis, Marco Melis, Battista Biggio, Davide Maiorca, Daniel Arp, Konrad Rieck, Igino Corona, Giorgio Giacinto, and Fabio Roli. 2017. Yes, machine learning can be more secure! A case study on android malware detection. IEEE T. Dependable Secure Comp.(2017)."},{"key":"e_1_3_2_2_33_1","volume-title":"Proc. USENIX Secur. Symp.321\u2013338","author":"Demontis Ambra","year":"2019","unstructured":"Ambra Demontis , Marco Melis , Maura Pintor , Matthew Jagielski , Battista Biggio , Alina Oprea , Cristina Nita-Rotaru , and Fabio Roli . 2019 . Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks . In Proc. USENIX Secur. Symp.321\u2013338 . Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019. Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks. In Proc. USENIX Secur. Symp.321\u2013338."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2016.105"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2021.102916"},{"key":"e_1_3_2_2_36_1","volume-title":"Feature Importance Guided Attack: A Model Agnostic Adversarial Attack. arXiv:2106.14815","author":"Gressel Gilad","year":"2021","unstructured":"Gilad Gressel , Niranjan Hegde , Archana Sreekumar , and Michael Darling . 2021. Feature Importance Guided Attack: A Model Agnostic Adversarial Attack. arXiv:2106.14815 ( 2021 ). Gilad Gressel, Niranjan Hegde, Archana Sreekumar, and Michael Darling. 2021. Feature Importance Guided Attack: A Model Agnostic Adversarial Attack. arXiv:2106.14815 (2021)."},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1609\/icwsm.v16i1.19288"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2021.04.023"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"crossref","unstructured":"Payas Gupta Roberto Perdisci and Mustaque Ahamad. 2018. Towards measuring the role of phone numbers in twitter-advertised spam. In ACM AsiaCCS.  Payas Gupta Roberto Perdisci and Mustaque Ahamad. 2018. Towards measuring the role of phone numbers in twitter-advertised spam. In ACM AsiaCCS.","DOI":"10.1145\/3196494.3196516"},{"key":"e_1_3_2_2_40_1","volume-title":"Towards benchmark datasets for machine learning based website phishing detection: An experimental study","author":"Hannousse Abdelhakim","year":"2021","unstructured":"Abdelhakim Hannousse and Salima Yahiouche . 2021. Towards benchmark datasets for machine learning based website phishing detection: An experimental study . Elsevier Eng . Appl. Artifi. Intell.( 2021 ). Abdelhakim Hannousse and Salima Yahiouche. 2021. Towards benchmark datasets for machine learning based website phishing detection: An experimental study. Elsevier Eng. Appl. Artifi. Intell.(2021)."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/APCC47188.2019.9026498"},{"key":"e_1_3_2_2_42_1","volume-title":"Proc. USENIX Security Symp.","author":"Ho Grant","year":"2019","unstructured":"Grant Ho , Asaf Cidon , Lior Gavish , Marco Schweighauser , Vern Paxson , Stefan Savage , Geoffrey\u00a0 M Voelker , and David Wagner . 2019 . Detecting and characterizing lateral phishing at scale . In Proc. USENIX Security Symp. Grant Ho, Asaf Cidon, Lior Gavish, Marco Schweighauser, Vern Paxson, Stefan Savage, Geoffrey\u00a0M Voelker, and David Wagner. 2019. Detecting and characterizing lateral phishing at scale. In Proc. USENIX Security Symp."},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(15)30077-4"},{"key":"e_1_3_2_2_44_1","volume-title":"Development of anti-phishing browser based on random forest and rule of extraction framework. Cybersecurity","author":"Mohith\u00a0Gowda HR","year":"2020","unstructured":"Mohith\u00a0Gowda HR , Adithya MV, 2020. Development of anti-phishing browser based on random forest and rule of extraction framework. Cybersecurity ( 2020 ). Mohith\u00a0Gowda HR, Adithya MV, 2020. Development of anti-phishing browser based on random forest and rule of extraction framework. Cybersecurity (2020)."},{"key":"e_1_3_2_2_45_1","unstructured":"Ankit\u00a0Kumar Jain and Brij\u00a0B Gupta. 2018. Towards detection of phishing websites on client-side using machine learning based approach. Telecom. Syst. (2018).  Ankit\u00a0Kumar Jain and Brij\u00a0B Gupta. 2018. Towards detection of phishing websites on client-side using machine learning based approach. Telecom. Syst. (2018)."},{"key":"e_1_3_2_2_46_1","unstructured":"Ankit\u00a0Kumar Jain and Brij\u00a0B Gupta. 2019. A machine learning based approach for phishing detection using hyperlinks information. J. Ambient Intell. Human. Comp.(2019).  Ankit\u00a0Kumar Jain and Brij\u00a0B Gupta. 2019. A machine learning based approach for phishing detection using hyperlinks information. J. Ambient Intell. Human. Comp.(2019)."},{"key":"e_1_3_2_2_47_1","volume-title":"Int. Conf. Learn. Repr.(2022)","author":"Jia Jinyuan","year":"2022","unstructured":"Jinyuan Jia , Binghui Wang , Xiaoyu Cao , Hongbin Liu , and Neil\u00a0Zhenqiang Gong . 2022 . Almost tight l0-norm certified robustness of top-k predictions against adversarial perturbations . Int. Conf. Learn. Repr.(2022) . Jinyuan Jia, Binghui Wang, Xiaoyu Cao, Hongbin Liu, and Neil\u00a0Zhenqiang Gong. 2022. Almost tight l0-norm certified robustness of top-k predictions against adversarial perturbations. Int. Conf. Learn. Repr.(2022)."},{"key":"e_1_3_2_2_48_1","volume-title":"Machine Learning: Trends, Perspectives, and Prospects. Science 349, 6245","author":"Jordan I","year":"2015","unstructured":"Michael\u00a0 I Jordan and Tom\u00a0 M Mitchell . 2015 . Machine Learning: Trends, Perspectives, and Prospects. Science 349, 6245 (2015), 255\u2013260. Michael\u00a0I Jordan and Tom\u00a0M Mitchell. 2015. Machine Learning: Trends, Perspectives, and Prospects. Science 349, 6245 (2015), 255\u2013260."},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCT.2019.8711324"},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453100"},{"key":"e_1_3_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2005.126"},{"key":"e_1_3_2_2_52_1","volume-title":"Catching Transparent Phish: Analyzing and Detecting MITM Phishing Toolkits. In ACM Conf. Comp. Commun. Secur.","author":"Kondracki Brian","year":"2021","unstructured":"Brian Kondracki , Babak\u00a0Amin Azad , Oleksii Starov , and Nick Nikiforakis . 2021 . Catching Transparent Phish: Analyzing and Detecting MITM Phishing Toolkits. In ACM Conf. Comp. Commun. Secur. Brian Kondracki, Babak\u00a0Amin Azad, Oleksii Starov, and Nick Nikiforakis. 2021. Catching Transparent Phish: Analyzing and Detecting MITM Phishing Toolkits. In ACM Conf. Comp. Commun. Secur."},{"key":"e_1_3_2_2_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00028"},{"key":"e_1_3_2_2_54_1","volume-title":"Deep learning. Nature 521, 7553","author":"LeCun Yann","year":"2015","unstructured":"Yann LeCun , Yoshua Bengio , and Geoffrey Hinton . 2015. Deep learning. Nature 521, 7553 ( 2015 ), 436. Yann LeCun, Yoshua Bengio, and Geoffrey Hinton. 2015. Deep learning. Nature 521, 7553 (2015), 436."},{"key":"e_1_3_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.14722\/madweb.2020.23007"},{"key":"e_1_3_2_2_56_1","first-page":"12849","article-title":"Practical no-box adversarial attacks against DNNs","volume":"33","author":"Li Qizhang","year":"2020","unstructured":"Qizhang Li , Yiwen Guo , and Hao Chen . 2020 . Practical no-box adversarial attacks against DNNs . NeurIPS 33 (2020), 12849 \u2013 12860 . Qizhang Li, Yiwen Guo, and Hao Chen. 2020. Practical no-box adversarial attacks against DNNs. NeurIPS 33 (2020), 12849\u201312860.","journal-title":"NeurIPS"},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/2872427.2883060"},{"key":"e_1_3_2_2_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176321"},{"key":"e_1_3_2_2_59_1","volume-title":"Proc. USENIX Secur. Symp.","author":"Lin Yun","year":"2021","unstructured":"Yun Lin , Ruofan Liu , Dinil\u00a0Mon Divakaran , Jun\u00a0Yang Ng , Qing\u00a0Zhou Chan , Yiwen Lu , Yuxuan Si , Fan Zhang , and Jin\u00a0Song Dong . 2021 . Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing Webpages . In Proc. USENIX Secur. Symp. Yun Lin, Ruofan Liu, Dinil\u00a0Mon Divakaran, Jun\u00a0Yang Ng, Qing\u00a0Zhou Chan, Yiwen Lu, Yuxuan Si, Fan Zhang, and Jin\u00a0Song Dong. 2021. Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing Webpages. In Proc. USENIX Secur. Symp."},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"crossref","unstructured":"Rami\u00a0M Mohammad Fadi Thabtah and Lee McCluskey. 2014. Intelligent rule-based phishing websites classification. IET Inf. Secur. (2014).  Rami\u00a0M Mohammad Fadi Thabtah and Lee McCluskey. 2014. Intelligent rule-based phishing websites classification. IET Inf. Secur. (2014).","DOI":"10.1049\/iet-ifs.2013.0202"},{"key":"e_1_3_2_2_61_1","volume-title":"The economics of cybersecurity: Principles and policy options","author":"Moore Tyler","year":"2010","unstructured":"Tyler Moore . 2010. The economics of cybersecurity: Principles and policy options . Elsevier Int. J. Critical Infrastructure Protection ( 2010 ). Tyler Moore. 2010. The economics of cybersecurity: Principles and policy options. Elsevier Int. J. Critical Infrastructure Protection (2010)."},{"key":"e_1_3_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484796"},{"key":"e_1_3_2_2_63_1","volume-title":"USENIX Security Symposium.","author":"Nasr Milad","year":"2021","unstructured":"Milad Nasr , Alireza Bahramali , and Amir Houmansadr . 2021 . Defeating {DNN-Based} Traffic Analysis Systems in {Real-Time} With Blind Adversarial Perturbations . In USENIX Security Symposium. Milad Nasr, Alireza Bahramali, and Amir Houmansadr. 2021. Defeating {DNN-Based} Traffic Analysis Systems in {Real-Time} With Blind Adversarial Perturbations. In USENIX Security Symposium."},{"key":"e_1_3_2_2_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2018.8587410"},{"key":"e_1_3_2_2_65_1","unstructured":"Adam Oest Yeganeh Safaei Penghui Zhang Brad Wardman Kevin Tyers Yan Shoshitaishvili and Adam Doup\u00e9. 2020. PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing Blacklists. In USENIX Sec.  Adam Oest Yeganeh Safaei Penghui Zhang Brad Wardman Kevin Tyers Yan Shoshitaishvili and Adam Doup\u00e9. 2020. PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing Blacklists. In USENIX Sec."},{"key":"e_1_3_2_2_66_1","volume-title":"Proc. USENIX Secur. Symp.","author":"Oest Adam","year":"2020","unstructured":"Adam Oest , Penghui Zhang , Brad Wardman , Eric Nunes , Jakub Burgis , Ali Zand , Kurt Thomas , Adam Doup\u00e9 , and Gail-Joon Ahn . 2020 . Sunrise to sunset: Analyzing the end-to-end life cycle and effectiveness of phishing attacks at scale . In Proc. USENIX Secur. Symp. Adam Oest, Penghui Zhang, Brad Wardman, Eric Nunes, Jakub Burgis, Ali Zand, Kurt Thomas, Adam Doup\u00e9, and Gail-Joon Ahn. 2020. Sunrise to sunset: Analyzing the end-to-end life cycle and effectiveness of phishing attacks at scale. In Proc. USENIX Secur. Symp."},{"key":"e_1_3_2_2_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISPA-BDCloud-SocialCom-SustainCom52081.2021.00222"},{"key":"e_1_3_2_2_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403241"},{"key":"e_1_3_2_2_69_1","volume-title":"Proc. USENIX Workshop Cyber Security Exp. Test.","author":"Panum Thomas\u00a0Kobber","year":"2020","unstructured":"Thomas\u00a0Kobber Panum , Kaspar Hageman , Ren\u00e9\u00a0Rydhof Hansen , and Jens\u00a0Myrup Pedersen . 2020 . Towards adversarial phishing detection . In Proc. USENIX Workshop Cyber Security Exp. Test. Thomas\u00a0Kobber Panum, Kaspar Hageman, Ren\u00e9\u00a0Rydhof Hansen, and Jens\u00a0Myrup Pedersen. 2020. Towards adversarial phishing detection. In Proc. USENIX Workshop Cyber Security Exp. Test."},{"key":"e_1_3_2_2_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_2_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"e_1_3_2_2_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_2_73_1","volume-title":"Intriguing Properties of Adversarial ML Attacks in the Problem Space. In IEEE Symp. Secur. Privacy.","author":"Pierazzi Fabio","year":"2020","unstructured":"Fabio Pierazzi , Feargus Pendlebury , Jacopo Cortellazzi , and Lorenzo Cavallaro . 2020 . Intriguing Properties of Adversarial ML Attacks in the Problem Space. In IEEE Symp. Secur. Privacy. Fabio Pierazzi, Feargus Pendlebury, Jacopo Cortellazzi, and Lorenzo Cavallaro. 2020. Intriguing Properties of Adversarial ML Attacks in the Problem Space. In IEEE Symp. Secur. Privacy."},{"key":"e_1_3_2_2_74_1","volume-title":"Phishnet: predictive blacklisting to detect phishing attacks","author":"Prakash Pawan","unstructured":"Pawan Prakash , Manish Kumar , Ramana\u00a0Rao Kompella , and Minaxi Gupta . 2010. Phishnet: predictive blacklisting to detect phishing attacks . In IEEE InfoCOM. Pawan Prakash, Manish Kumar, Ramana\u00a0Rao Kompella, and Minaxi Gupta. 2010. Phishnet: predictive blacklisting to detect phishing attacks. In IEEE InfoCOM."},{"key":"e_1_3_2_2_75_1","volume-title":"USENIX Secur. Symp.","author":"Quiring Erwin","year":"2020","unstructured":"Erwin Quiring , David Klein , Daniel Arp , Martin Johns , and Konrad Rieck . 2020 . Adversarial Preprocessing: Understanding and Preventing {Image-Scaling} Attacks in Machine Learning . In USENIX Secur. Symp. Erwin Quiring, David Klein, Daniel Arp, Martin Johns, and Konrad Rieck. 2020. Adversarial Preprocessing: Understanding and Preventing {Image-Scaling} Attacks in Machine Learning. In USENIX Secur. Symp."},{"key":"e_1_3_2_2_76_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-04780-1_28"},{"key":"e_1_3_2_2_77_1","volume-title":"An evasion attack against ML-based phishing URL detectors. arXiv:2005.08454","author":"Sabir Bushra","year":"2020","unstructured":"Bushra Sabir , M\u00a0Ali Babar , and Raj Gaire . 2020. An evasion attack against ML-based phishing URL detectors. arXiv:2005.08454 ( 2020 ). Bushra Sabir, M\u00a0Ali Babar, and Raj Gaire. 2020. An evasion attack against ML-based phishing URL detectors. arXiv:2005.08454 (2020)."},{"key":"e_1_3_2_2_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/CONECCT50063.2020.9198349"},{"key":"e_1_3_2_2_79_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22479-0_5"},{"key":"e_1_3_2_2_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420987"},{"key":"e_1_3_2_2_81_1","doi-asserted-by":"crossref","unstructured":"Fu Song Yusi Lei Sen Chen Lingling Fan and Yang Liu. 2021. Advanced evasion attacks and mitigations on practical ML-based phishing website classifiers. Int. J. Intell. Syst.(2021).  Fu Song Yusi Lei Sen Chen Lingling Fan and Yang Liu. 2021. Advanced evasion attacks and mitigations on practical ML-based phishing website classifiers. Int. J. Intell. Syst.(2021).","DOI":"10.1002\/int.22510"},{"key":"e_1_3_2_2_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"e_1_3_2_2_83_1","volume-title":"PhishWHO: Phishing webpage detection via identity keywords extraction and target domain name finder","author":"Tan Choon\u00a0Lin","year":"2016","unstructured":"Choon\u00a0Lin Tan , Kang\u00a0Leng Chiew , KokSheik Wong , 2016. PhishWHO: Phishing webpage detection via identity keywords extraction and target domain name finder . Elsevier Decis . Support Syst.( 2016 ). Choon\u00a0Lin Tan, Kang\u00a0Leng Chiew, KokSheik Wong, 2016. PhishWHO: Phishing webpage detection via identity keywords extraction and target domain name finder. Elsevier Decis. Support Syst.(2016)."},{"key":"e_1_3_2_2_84_1","doi-asserted-by":"crossref","unstructured":"Lizhen Tang and Qusay\u00a0H Mahmoud. 2021. A survey of machine learning-based solutions for phishing website detection. Machine Learning and Knowledge Extraction(2021).  Lizhen Tang and Qusay\u00a0H Mahmoud. 2021. A survey of machine learning-based solutions for phishing website detection. Machine Learning and Knowledge Extraction(2021).","DOI":"10.3390\/make3030034"},{"key":"e_1_3_2_2_85_1","doi-asserted-by":"publisher","DOI":"10.1145\/3278532.3278569"},{"key":"e_1_3_2_2_86_1","volume-title":"USENIX Secur. Symp.","author":"Tong Liang","year":"2019","unstructured":"Liang Tong , Bo Li , Chen Hajaj , Chaowei Xiao , Ning Zhang , and Yevgeniy Vorobeychik . 2019 . Improving robustness of ML classifiers against realizable evasion attacks using conserved features . In USENIX Secur. Symp. Liang Tong, Bo Li, Chen Hajaj, Chaowei Xiao, Ning Zhang, and Yevgeniy Vorobeychik. 2019. Improving robustness of ML classifiers against realizable evasion attacks using conserved features. In USENIX Secur. Symp."},{"key":"e_1_3_2_2_87_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354222"},{"key":"e_1_3_2_2_88_1","volume-title":"Proc. Int. Conf. Learning Representations.","author":"Tram\u00e8r Florian","year":"2018","unstructured":"Florian Tram\u00e8r , Alexey Kurakin , Nicolas Papernot , Ian Goodfellow , Dan Boneh , and Patrick McDaniel . 2018 . Ensemble adversarial training: Attacks and defenses . In Proc. Int. Conf. Learning Representations. Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2018. Ensemble adversarial training: Attacks and defenses. In Proc. Int. Conf. Learning Representations."},{"key":"e_1_3_2_2_89_1","doi-asserted-by":"publisher","DOI":"10.1145\/3465481.3470112"},{"key":"e_1_3_2_2_90_1","doi-asserted-by":"publisher","DOI":"10.1109\/BigDataSecurity-HPSC-IDS.2016.79"},{"key":"e_1_3_2_2_91_1","doi-asserted-by":"publisher","DOI":"10.1145\/2699026.2699115"},{"key":"e_1_3_2_2_92_1","volume-title":"Accurate and fast URL phishing detector: a convolutional neural network approach","author":"Wei Wei","year":"2020","unstructured":"Wei Wei , Qiao Ke , Jakub Nowak , Marcin Korytkowski , Rafa\u0142 Scherer , and Marcin Wo\u017aniak . 2020. Accurate and fast URL phishing detector: a convolutional neural network approach . Elsevier Comp . Netw.( 2020 ). Wei Wei, Qiao Ke, Jakub Nowak, Marcin Korytkowski, Rafa\u0142 Scherer, and Marcin Wo\u017aniak. 2020. Accurate and fast URL phishing detector: a convolutional neural network approach. Elsevier Comp. Netw.(2020)."},{"key":"e_1_3_2_2_93_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2014.2305658"},{"key":"e_1_3_2_2_94_1","volume-title":"Embedding training within warnings improves skills of identifying phishing webpages. Human Factors","author":"Xiong Aiping","year":"2019","unstructured":"Aiping Xiong , Robert\u00a0 W Proctor , Weining Yang , and Ninghui Li. 2019. Embedding training within warnings improves skills of identifying phishing webpages. Human Factors ( 2019 ). Aiping Xiong, Robert\u00a0W Proctor, Weining Yang, and Ninghui Li. 2019. Embedding training within warnings improves skills of identifying phishing webpages. Human Factors (2019)."},{"key":"e_1_3_2_2_95_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313551"},{"key":"e_1_3_2_2_96_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00021"},{"key":"e_1_3_2_2_97_1","doi-asserted-by":"crossref","unstructured":"Baolin Zheng Peipei Jiang Qian Wang Qi Li Chao Shen Cong Wang Yunjie Ge Qingyang Teng and Shenyi Zhang. 2021. Black-box adversarial attacks on commercial speech platforms with minimal information. In ACM CCS.  Baolin Zheng Peipei Jiang Qian Wang Qi Li Chao Shen Cong Wang Yunjie Ge Qingyang Teng and Shenyi Zhang. 2021. Black-box adversarial attacks on commercial speech platforms with minimal information. In ACM CCS.","DOI":"10.1145\/3460120.3485383"},{"key":"e_1_3_2_2_98_1","volume-title":"Proc. IEEE Symp. Secur. Privacy. 197\u2013211","author":"Pavel Laskov Nedim","year":"2014","unstructured":"Nedim \u00c5 rndic and Pavel Laskov . 2014 . Practical evasion of a learning-based classifier: A case study . In Proc. IEEE Symp. Secur. Privacy. 197\u2013211 . Nedim \u00c5 rndic and Pavel Laskov. 2014. Practical evasion of a learning-based classifier: A case study. In Proc. IEEE Symp. Secur. Privacy. 197\u2013211."}],"event":{"name":"ACSAC: Annual Computer Security Applications Conference","location":"Austin TX USA","acronym":"ACSAC"},"container-title":["Proceedings of the 38th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3567980","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3564625.3567980","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T14:09:12Z","timestamp":1750169352000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3567980"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,5]]},"references-count":95,"alternative-id":["10.1145\/3564625.3567980","10.1145\/3564625"],"URL":"https:\/\/doi.org\/10.1145\/3564625.3567980","relation":{},"subject":[],"published":{"date-parts":[[2022,12,5]]},"assertion":[{"value":"2022-12-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}