NORMA eResearch @NCI Library

Multi-Model Embedding Fusion for Phishing URL Detection: Combining GPT-3.5 Semantic Understanding with BERT Contextual Analysis for Enhanced Threat Classification

Raghavapurapu, Sai Raghu Ram (2025) Multi-Model Embedding Fusion for Phishing URL Detection: Combining GPT-3.5 Semantic Understanding with BERT Contextual Analysis for Enhanced Threat Classification. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (692kB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (1MB) | Preview

Abstract

Phishing attacks remain a threat to the security of cyber-space, and existing solutions to this issue are based solely on single-model designs, either focusing on semantic aspects or structural aspects but not both simultaneously. The current work aims to introduce a new model based on a cross-attention fusion structure to bridge the gap in the current techniques of embedding in identifying phishing URLs through the utilization of the GPT-3.5 semantic embeddings and the BERT structural embeddings. The approach uses the OpenAI text-embedding-3-large model to produce embeddings of size 3,072-dimensions based on the URL descriptions, in parallel with the domain-specific 'DomURLs_BERT' model creating embeddings of size 768-dimensions based on the structural information. The two embeddings are combined in a bidirectional cross-attention architecture with an adaptive fusion gate to determine the weights for the embeddings to be fused. The results of the experimentation using the PhiUSIIL dataset with a total of 235,795 URLs show that the fusion architecture has an accuracy of 97.27%, an F1-score of 97.66%, a recall value of 99.49%, and an AUC-ROC. It has been verified that both the embedding sources provide considerable complementary information through the analysis of the fusion weights learned and calculating the contribution of BERT embeddings to be 62.71% and GPT embeddings to be 17.26%, while the cross-attention components account for the remaining 20%. The cross-attention fusion has been found to successfully leverage the complementary semantic and structural representations for enhanced threat detection in the form of a GPT-BERT model application in phishing URL detection tasks in the current work, and this is a first in its area and domain.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Salahuddin, Jawad
UNSPECIFIED
Subjects: Q Science > QH Natural history > QH301 Biology > Methods of research. Technique. Experimental biology > Data processing. Bioinformatics > Artificial intelligence
Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Artificial intelligence
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 04 Sep 2026 09:30
Last Modified: 04 Sep 2026 09:30
URI: https://norma.ncirl.ie/id/eprint/9821

Actions (login required)

View Item View Item