{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,24]],"date-time":"2025-08-24T01:31:06Z","timestamp":1755999066064,"version":"3.41.0"},"reference-count":17,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2024,3,21]],"date-time":"2024-03-21T00:00:00Z","timestamp":1710979200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2024,3,31]]},"abstract":"<jats:p>Although machine learning-based anti-phishing detectors have provided promising results in phishing website detection, they remain vulnerable to evasion attacks. The Machine Learning Security Evasion Competition 2022 (MLSEC 2022) provides researchers and practitioners with the opportunity to deploy evasion attacks against anti-phishing machine learning models in real-world settings. In this field note, we share our experience participating in MLSEC 2022. We manipulated the source code of ten phishing HTML pages provided by the competition using obfuscation techniques to evade anti-phishing models. Our evasion attacks employing a benign overlap strategy achieved third place in the competition with 46 out of a potential 80 points. The results of our MLSEC 2022 performance can provide valuable insights for research seeking to robustify machine learning-based anti-phishing detectors.<\/jats:p>","DOI":"10.1145\/3603507","type":"journal-article","created":{"date-parts":[[2023,6,15]],"date-time":"2023-06-15T12:08:48Z","timestamp":1686830928000},"page":"1-8","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Evading Anti-Phishing Models: A Field Note Documenting an Experience in the Machine Learning Security Evasion Competition 2022"],"prefix":"10.1145","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5638-5489","authenticated-orcid":false,"given":"Yang","family":"Gao","sequence":"first","affiliation":[{"name":"Indiana University, Bloomington, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0603-0270","authenticated-orcid":false,"given":"Benjamin M.","family":"Ampel","sequence":"additional","affiliation":[{"name":"University of Arizona, Tucson, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4513-805X","authenticated-orcid":false,"given":"Sagar","family":"Samtani","sequence":"additional","affiliation":[{"name":"Indiana University, Bloomington, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,3,21]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417233"},{"key":"e_1_3_1_3_2","first-page":"1","volume-title":"Proceedings of the 2019 11th International Conference on Cyber Conflict (CyCon\u201919)","volume":"900","author":"Apruzzese Giovanni","year":"2019","unstructured":"Giovanni Apruzzese, Michele Colajanni, Luca Ferretti, and Mirco Marchetti. 2019. Addressing adversarial attacks against security systems based on machine learning. In Proceedings of the 2019 11th International Conference on Cyber Conflict (CyCon\u201919), Vol. 900. ieeexplore.ieee.org, 1\u201318."},{"key":"e_1_3_1_4_2","article-title":"SpacePhish: The evasion-space of adversarial attacks against phishing website detectors using machine learning","author":"Apruzzese Giovanni","year":"2022","unstructured":"Giovanni Apruzzese, Mauro Conti, and Ying Yuan. 2022. SpacePhish: The evasion-space of adversarial attacks against phishing website detectors using machine learning. arXiv preprint arXiv:2210.13660 (2022).","journal-title":"arXiv preprint arXiv:2210.13660"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3545574"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"e_1_3_1_7_2","unstructured":"CUJOAI. 2021. Announcing the Winners of the 2021 MLSEC. https:\/\/cujo.com\/announcing-the-winners-of-the-2021-machine-learning-security-evasion-competition\/."},{"key":"e_1_3_1_8_2","unstructured":"CUJOAI. 2022. MLSEC 2022-The Winners and Some Closing Comments. https:\/\/cujo.com\/mlsec-2022-the-winners-and-some-closing-comments\/."},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/2872427.2883060"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3355369.3355585"},{"key":"e_1_3_1_11_2","unstructured":"Pinterest. 2022. Pinterest Homepage. https:\/\/www.pinterest.com\/."},{"key":"e_1_3_1_12_2","unstructured":"RobustIntelligence. 2022. ML Security Evasion Competition 2022. https:\/\/www.robustintelligence.com\/blog-posts\/ml-security-evasion-competition-2022."},{"key":"e_1_3_1_13_2","unstructured":"Similarweb. 2022. Top Website Ranking. https:\/\/www.similarweb.com\/top-websites\/."},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1002\/int.22510"},{"key":"e_1_3_1_15_2","unstructured":"Zhejiang University. 2020. Library Website of Zhejiang University. https:\/\/libweb.zju.edu.cn\/."},{"key":"e_1_3_1_16_2","article-title":"Classification of Web Phishing Kits for early detection by platform providers","author":"Venturi Andrea","year":"2022","unstructured":"Andrea Venturi, Michele Colajanni, Marco Ramilli, and Giorgio Valenziano Santangelo. 2022. Classification of Web Phishing Kits for early detection by platform providers. arXiv preprint arXiv:2210.08273 (2022).","journal-title":"arXiv preprint arXiv:2210.08273"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/2019599.2019606"},{"key":"e_1_3_1_18_2","doi-asserted-by":"crossref","first-page":"1109","DOI":"10.1109\/SP40001.2021.00021","volume-title":"Proceedings of the2021 IEEE Symposium on Security and Privacy (SP\u201921)","author":"Zhang Penghui","year":"2021","unstructured":"Penghui Zhang, Adam Oest, Haehyun Cho, Zhibo Sun, R. C. Johnson, Brad Wardman, Shaown Sarker, Alexandros Kapravelos, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doup\u00e9, and Gail-Joon Ahn. 2021. CrawlPhish: Large-scale analysis of client-side cloaking techniques in phishing. In Proceedings of the2021 IEEE Symposium on Security and Privacy (SP\u201921). ieeexplore.ieee.org, 1109\u20131124."}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3603507","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3603507","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:26Z","timestamp":1750178786000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3603507"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,3,21]]},"references-count":17,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,3,31]]}},"alternative-id":["10.1145\/3603507"],"URL":"https:\/\/doi.org\/10.1145\/3603507","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"type":"print","value":"2692-1626"},{"type":"electronic","value":"2576-5337"}],"subject":[],"published":{"date-parts":[[2024,3,21]]},"assertion":[{"value":"2022-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-05-18","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-03-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}