{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T06:17:55Z","timestamp":1772000275001,"version":"3.50.1"},"reference-count":53,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2026,2,14]],"date-time":"2026-02-14T00:00:00Z","timestamp":1771027200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Phishing remains one of the most pervasive social engineering threats, exploiting human vulnerabilities and continuously evolving to bypass static detection mechanisms. Existing machine learning models achieve high accuracy but often act as opaque systems that lack robustness to evolving tactics and explainability, limiting trust and real-world deployment. In this research, we propose a dynamic Explainable AI (XAI) approach for phishing detection that integrates temporally aware feature extraction with dual interpretability through LIME and SHAP applied to the resulting window-level features. The novelty of this research lies in a temporally dynamic feature framework that simulates a plausible email reading progression using a heuristic temporal model and employs a sliding window aggregation method to capture behavioural and temporal patterns within email content. Using an aggregated dataset of 82,500 phishing and legitimate emails, dynamic features were extracted and used to train four classifiers: Random Forest, XGBoost, Multi-Layer Perceptron, and Logistic Regression. Ensemble models demonstrated strong performance with XGBoost achieving 94% accuracy and Random Forest 93%. This research addresses an important gap by combining dynamically constructed temporal features with transparent explanations, achieving high detection performance while preserving interpretability. These findings demonstrate that dynamic temporal modelling with explainable learning can enhance the trustworthiness and practicality of phishing detection systems, highlighting that temporally structured features and explainable learning can enhance the trustworthiness and practical deployability of phishing detection systems without incurring excessive computational overhead.<\/jats:p>","DOI":"10.3390\/fi18020101","type":"journal-article","created":{"date-parts":[[2026,2,16]],"date-time":"2026-02-16T08:38:39Z","timestamp":1771231119000},"page":"101","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A Temporally Dynamic Feature-Extraction Framework for Phishing Detection with LIME and SHAP Explanations"],"prefix":"10.3390","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-2630-045X","authenticated-orcid":false,"given":"Chris","family":"Mayo","sequence":"first","affiliation":[{"name":"School of Computing and Creative Technologies, University of the West of England, Bristol BS16 1QY, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-7703-9911","authenticated-orcid":false,"given":"Michael","family":"Tchuindjang","sequence":"additional","affiliation":[{"name":"School of Computing and Creative Technologies, University of the West of England, Bristol BS16 1QY, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3463-0484","authenticated-orcid":false,"given":"Sarfraz","family":"Brohi","sequence":"additional","affiliation":[{"name":"School of Computing and Creative Technologies, University of the West of England, Bristol BS16 1QY, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7699-9998","authenticated-orcid":false,"given":"Nikolaos","family":"Ersotelos","sequence":"additional","affiliation":[{"name":"School of Computing and Creative Technologies, University of the West of England, Bristol BS16 1QY, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,2,14]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Singh, P., Hasija, T., and Ramkumar, K. (2024, January 28\u201330). Machine Learning Algorithms for Phishing Detection: A Comparative Analysis of SVM, Random Forest, and CatBoost Models. Proceedings of the 2024 Second International Conference on Intelligent Cyber Physical Systems and Internet of Things (ICoICI), Coimbatore, India.","DOI":"10.1109\/ICoICI62503.2024.10696365"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1930002","DOI":"10.1142\/S0218213019300023","article-title":"Machine Learning and Nature Inspired Based Phishing Detection: A Literature Survey","volume":"28","author":"Akinyelu","year":"2019","journal-title":"Int. J. Artif. Intell. Tools"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Wilk-Jakubowski, J., Pawlik, \u0141., Wilk-Jakubowski, G., and Sikora, A. (2025). Machine Learning and Neural Networks for Phishing Detection: A Systematic Review (2017\u20132024). Electronics, 14.","DOI":"10.3390\/electronics14183744"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"935","DOI":"10.1016\/j.icte.2024.05.007","article-title":"Explainable AI for cybersecurity automation, intelligence and trustworthiness in digital twin: Methods, taxonomy, challenges and prospects","volume":"10","author":"Sarker","year":"2024","journal-title":"ICT Express"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Brohi, S., and Mastoi, Q.u.a. (2025). AI Under Attack: Metric-Driven Analysis of Cybersecurity Threats in Deep Learning Models for Healthcare Applications. Algorithms, 18.","DOI":"10.3390\/a18030157"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"93104","DOI":"10.1109\/ACCESS.2022.3204051","article-title":"Explainable Artificial Intelligence Applications in Cyber Security: State-of-the-Art in Research","volume":"10","author":"Zhang","year":"2022","journal-title":"IEEE Access"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Brohi, S., and Mastoi, Q.u.a. (2025). From Accuracy to Vulnerability: Quantifying the Impact of Adversarial Perturbations on Healthcare AI Models. Big Data Cogn. Comput., 9.","DOI":"10.3390\/bdcc9050114"},{"key":"ref_8","unstructured":"Srivastava, G., Jhaveri, R.H., Bhattacharya, S., Pandya, S., Maddikunta, P.K.R., Yenduri, G., Hall, J.G., Alazab, M., and Gadekallu, T.R. (2022). XAI for Cybersecurity: State of the Art, Challenges, Open Issues and Future Directions. arXiv."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Yakandawala, Y.L.D.H., Madushanka, M.K.P., and Ilmini, W.M.K.S. (2024, January 19). Explainable AI for Transparent Phishing Email Detection. Proceedings of the 2024 International Conference on Advances in Technology and Computing (ICATC), Kelaniya, Sri Lanka.","DOI":"10.1109\/ICATC64549.2024.11025302"},{"key":"ref_10","unstructured":"Fajar, A., Yazid, S., and Budi, I. (2024). Enhancing phishing detection through feature importance analysis and explainable ai: A comparative study of catboost, xgboost, and ebm models. arXiv."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Alam, R., Khune, A., Kalal, T.V., and Nautiyal, A. (2024, January 6\u20138). E2Phish: Explainable Ensemble Machine Learning Model for Enhanced Phishing URL Detection. Proceedings of the 2024 IEEE 8th International Conference on Information and Communication Technology (CICT), Prayagraj UP, India.","DOI":"10.1109\/CICT64037.2024.10899721"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Makkar, A., Kumar, N., Sama, L., Mishra, S., and Samdani, Y. (2020, January 18\u201320). An intelligent phishing detection scheme using machine learning. Proceedings of the Sixth International Conference on Mathematics and Computing: ICMC 2020, Gangtok, India.","DOI":"10.1007\/978-981-15-8061-1_13"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Maturure, P., Ali, A., and Gegov, A. (2024, January 9). Hybrid machine learning model for phishing detection. Proceedings of the 2024 IEEE 12th International Conference on Intelligent Systems (IS), Varna, Bulgaria.","DOI":"10.1109\/IS61756.2024.10705257"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"120","DOI":"10.1016\/j.procs.2023.12.067","article-title":"Phishing Detection using Gradient Boosting Classifier","volume":"230","author":"Omari","year":"2023","journal-title":"Procedia Comput. Sci."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Roshinta, T.A., and G\u00e1bor, S. (2024, January 12\u201314). A Comparative Study of LIME and SHAP for Enhancing Trustworthiness and Efficiency in Explainable AI Systems. Proceedings of the 2024 IEEE International Conference on Computing (ICOCO), Kuala Lumpur, Malaysia.","DOI":"10.1109\/ICOCO62848.2024.10928183"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Desai, B., Patil, K., Mehta, I., and Patil, A. (2024, January 21\u201322). Explainable AI in Cybersecurity: A Comprehensive Framework for enhancing transparency, trust, and Human-AI Collaboration. Proceedings of the 2024 International Seminar on Application for Technology of Information and Communication (iSemantic), Semarang, Indonesia.","DOI":"10.1109\/iSemantic63362.2024.10762690"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Fan, Z., Li, W., Laskey, K.B., and Chang, K.C. (2024, January 6\u201310). Towards Personalized Anti-Phishing: Counterfactual Explanation Approach-Extended Abstract. Proceedings of the 2024 IEEE 11th International Conference on Data Science and Advanced Analytics (DSAA), San Diego, CA, USA.","DOI":"10.1109\/DSAA61799.2024.10722801"},{"key":"ref_18","unstructured":"Arthy, S., and Sakthi Priya, G. (2025, January 4\u20135). A Hybrid Machine Learning Approach for Securing Emails: Phishing Detection and Prevention. Proceedings of the 2025 3rd International Conference on Advancements in Electrical, Electronics, Communication, Computing and Automation (ICAECA), Coimbatore, India."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Chien, A., and Khethavath, P. (2023, January 4\u20136). Email Feature Classification and Analysis of Phishing Email Detection Using Machine Learning Techniques. Proceedings of the 2023 IEEE Asia-Pacific Conference on Computer Science and Data Engineering (CSDE), Nadi, Fiji.","DOI":"10.1109\/CSDE59766.2023.10487729"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1145\/2019599.2019606","article-title":"CANTINA+: A Feature-Rich Machine Learning Framework for Detecting Phishing Web Sites","volume":"14","author":"Xiang","year":"2011","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"ref_21","unstructured":"Roy, S., and Nilizadeh, S. (2024). PhishLang: A Lightweight, Client-Side Phishing Detection Framework Using MobileBERT for Real-Time, Explainable Threat Mitigation. arXiv."},{"key":"ref_22","unstructured":"Kose, U., Gupta, D., de Albuquerque, V.H.C., and Khanna, A. (2021). 29-Sliding window time series forecasting with multilayer perceptron and multiregression of COVID-19 outbreak in Malaysia. Data Science for COVID-19, Academic Press."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Ndungi, R., and Stanislavovich, L.I. (2025, January 29\u201331). Improving time series forecasting by applying the sliding window approach. Proceedings of the International Conference on Intelligent and Fuzzy Systems (INFUS 2025), Istanbul, Turkey.","DOI":"10.1007\/978-3-031-98304-7_34"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1016\/j.dss.2018.01.001","article-title":"Detection of online phishing email using dynamic evolving neural network based on reinforcement learning","volume":"107","author":"Smadi","year":"2018","journal-title":"Decis. Support Syst."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"112540","DOI":"10.1016\/j.asoc.2024.112540","article-title":"Detection of malicious URLs using Temporal Convolutional Network and Multi-Head Self-Attention mechanism","volume":"169","author":"Do","year":"2025","journal-title":"Appl. Soft Comput."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Mythili, J., Deebeshkumar, B., Eshwaramoorthy, T., and Ajay, J.N. (2024, January 17\u201318). Enhancing Email Spam Detection with Temporal Naive Bayes Classifier. Proceedings of the 2024 International Conference on Communication, Computing and Internet of Things (IC3IoT), Chennai, India.","DOI":"10.1109\/IC3IoT60841.2024.10550229"},{"key":"ref_27","unstructured":"Hernandes, P.R.G., Floret, C.P., De Almeida, K.F.C., Da Silva, V.C., Papa, J.P., and Da Costa, K.A.P. (2021, January 24). Phishing detection using URL-based XAI techniques. Proceedings of the 2021 IEEE Symposium Series on Computational Intelligence (SSCI), Orlando, FL, USA."},{"key":"ref_28","unstructured":"Lim, B., Huerta, R., Sotelo, A., Quintela, A., and Kumar, P. (2025). EXPLICATE: Enhancing Phishing Detection through Explainable AI and LLM-Powered Interpretability. arXiv."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"26478","DOI":"10.48084\/etasr.11595","article-title":"Explainable AI for IOT Devices and Robotic Communication Phishing Detection: A Machine Learning Approach Using LIME and SHAP","volume":"15","author":"Fatima","year":"2025","journal-title":"Eng. Technol. Appl. Sci. Res."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Uddin, M.A., Mahiuddin, M., and Sarker, I.H. (2025). An Explainable Transformer-based Model for Phishing Email Detection: A Large Language Model Approach. arXiv.","DOI":"10.2139\/ssrn.4785953"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.aej.2024.06.077","article-title":"Explainable artificial intelligence in web phishing classification on secure IoT with cloud-based cyber-physical systems","volume":"110","author":"Alotaibi","year":"2024","journal-title":"Alex. Eng. J."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Brohi, S., Mastoi, Q.u.a., Jhanjhi, N.Z., and Pillai, T.R. (2025). A Research Landscape of Agentic AI and Large Language Models: Applications, Challenges and Future Directions. Algorithms, 18.","DOI":"10.3390\/a18080499"},{"key":"ref_33","unstructured":"Alam, N.A. (2025, May 16). Phishing Email Dataset. Available online: https:\/\/www.kaggle.com\/ds\/5074342."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"109625","DOI":"10.1016\/j.compeleceng.2024.109625","article-title":"Novel interpretable and robust web-based AI platform for phishing email detection","volume":"120","author":"Antora","year":"2024","journal-title":"Comput. Electr. Eng."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Gonzalez Zelaya, C.V. (2019, January 8\u201311). Towards Explaining the Effects of Data Preprocessing on Machine Learning. Proceedings of the 2019 IEEE 35th International Conference on Data Engineering (ICDE), Macao, China.","DOI":"10.1109\/ICDE.2019.00245"},{"key":"ref_36","first-page":"431","article-title":"A Comparative Study Between Various Preprocessing Techniques for Machine Learning","volume":"5","author":"Rao","year":"2020","journal-title":"Int. J. Eng. Appl. Sci. Technol."},{"key":"ref_37","unstructured":"Peng, T.Q., and Zhu, J.J.H. (2023). Understanding Online Behaviors through a Temporal Lens. arXiv."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"104047","DOI":"10.1016\/j.jml.2019.104047","article-title":"How many words do we read per minute? A review and meta-analysis of reading rate","volume":"109","author":"Brysbaert","year":"2019","journal-title":"J. Mem. Lang."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"845","DOI":"10.1108\/ICS-07-2024-0163","article-title":"Persuasion under pressure: The influence of persuasion principles and time constraints on phishing email susceptibility","volume":"33","author":"Auton","year":"2025","journal-title":"Inf. Comput. Secur."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1016\/j.ijhcs.2018.12.004","article-title":"Persuasion: How phishing emails can influence users and bypass security measures","volume":"125","author":"Ferreira","year":"2019","journal-title":"Int. J. Hum.-Comput. Stud."},{"key":"ref_41","first-page":"1","article-title":"Segmenting Time Series: A Survey and Novel Approach","volume":"57","author":"Keogh","year":"2003","journal-title":"Data Min. Time Ser. Databases"},{"key":"ref_42","unstructured":"Navaneethakannan, B., Gokul, C., Swathi, R., and Mohanraj, K.C. (2025, January 5\u20137). Phishing Detection and Response System with XGBOOST Machine Learning. Proceedings of the 2025 International Conference on Emerging Smart Computing and Informatics (ESCI), Pune, India."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Sadaf, K. (2023, January 5\u20136). Phishing Website Detection using XGBoost and Catboost Classifiers. Proceedings of the 2023 International Conference on Smart Computing and Application (ICSCA), Hail, Saudi Arabia.","DOI":"10.1109\/ICSCA57840.2023.10087829"},{"key":"ref_44","unstructured":"Keerthana, B.P., Siva, A., Senthilkumar, T., Palanisamy, T., Prabhu, N., and Srinivasan, K. (2025, January 23\u201325). Web Phishing Detection Using Decision Tree Random Forest and XGBoost. Proceedings of the 2025 International Conference on Inventive Computation Technologies (ICICT), Kirtipur, Nepal."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"25","DOI":"10.32604\/jcs.2023.045859","article-title":"Sentence Level Analysis Model for Phishing Detection Using KNN","volume":"6","author":"Sawe","year":"2024","journal-title":"J. Cyber Secur."},{"key":"ref_46","unstructured":"Dasgupta, S., and Sen, J. (2024). A Comparative Study of Hyperparameter Tuning Methods. arXiv."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Ribeiro, M.T., Singh, S., and Guestrin, C. (2016, January 13\u201317). \u201cWhy Should I Trust You?\u201d: Explaining the Predictions of Any Classifier. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA.","DOI":"10.1145\/2939672.2939778"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Prayogo, R.D., Alfisyahrin, A.R., Gambetta, W., Karimah, S.A., and Nambo, H. (2024, January 5\u20136). An Explainable Machine Learning-Based Phishing Website Detection using Gradient Boosting. Proceedings of the 2024 International Conference on Information Technology Research and Innovation (ICITRI), Jakarta, Indonesia.","DOI":"10.1109\/ICITRI62858.2024.10698870"},{"key":"ref_49","first-page":"4768","article-title":"A unified approach to interpreting model predictions","volume":"30","author":"Lundberg","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Sivasankar, C., Tamilarasan, A., Christy, S., and Parthiban, S. (2025, January 28\u201330). Towards Practical Phishing Detection: Addressing Challenges with Hybrid Machine Learning Architectures. Proceedings of the 2025 International Conference on Computational Robotics, Testing and Engineering Evaluation (ICCRTEE), Virudhunagar, India.","DOI":"10.1109\/ICCRTEE64519.2025.11053024"},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Damatie, E.M., Eleyan, A., and Bejaoui, T. (2024, January 22\u201325). Real-Time Email Phishing Detection Using a Custom DistilBERT Model. Proceedings of the 2024 International Symposium on Networks, Computers and Communications (ISNCC), Washington, DC, USA.","DOI":"10.1109\/ISNCC62547.2024.10759011"},{"key":"ref_52","unstructured":"Salian, S.S. (2024). Enhancing Phishing Email Detection with Sentiment Analysis: A Hybrid Approach. [Master\u2019s Thesis, National College of Ireland]. Available online: https:\/\/norma.ncirl.ie\/8363\/."},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Bifet, A., and Gavalda, R. (2007, January 26\u201328). Learning from time-changing data with adaptive windowing. Proceedings of the 2007 SIAM International Conference on Data Mining. SIAM, Minneapolis, MN, USA.","DOI":"10.1137\/1.9781611972771.42"}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/18\/2\/101\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T05:17:35Z","timestamp":1771996655000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/18\/2\/101"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,14]]},"references-count":53,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2026,2]]}},"alternative-id":["fi18020101"],"URL":"https:\/\/doi.org\/10.3390\/fi18020101","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,14]]}}}