Explainable Machine-Learning Models for Detecting Phishing URLs Targeting Healthcare Organizations: A Systematic Technical Review and Deployment Framework
DOI:
https://doi.org/10.66687/JMRISKeywords:
Phishing, URL, Explainable MLAbstract
Background: Phishing remains a major cybersecurity threat to healthcare organizations because successful attacks may expose employee credentials, protected health information, clinical systems and critical network infrastructure. Conventional blacklist-based controls are effective against known malicious domains but may fail against newly created or rapidly changing phishing URLs. Machine-learning models using lexical, domain, host and webpage characteristics offer an opportunity for earlier detection, although highly accurate black-box predictions may provide limited operational insight to security analysts.
Objective: To synthesize high-quality evidence published through 2021 concerning machine-learning detection of phishing URLs and develop an explainable deployment framework tailored to healthcare organizations.
Methods: A structured technical evidence synthesis was conducted using peer-reviewed literature published no later than 31 December 2021. References were restricted to Q1 journals in cybersecurity, artificial intelligence, information systems, medical informatics and digital health. Evidence concerning URL classification, phishing detection, feature engineering, benchmark construction, explainable artificial intelligence and healthcare phishing vulnerability was reviewed. No novel classifier performance was fabricated because a healthcare-specific labeled URL dataset was not available.
Results: Pre-2022 studies demonstrated strong performance of machine-learning URL classifiers. A large URL-based study reported 97.98% accuracy using Random Forest, while a 2021 lexical approach using only nine URL features reported accuracy of 99.57%. Benchmark research demonstrated that Random Forest remained highly competitive, with feature selection producing accuracy of approximately 96.83% while reducing computational burden. However, performance varied according to dataset construction, feature availability and temporal sampling. Explainability is particularly important in healthcare because security teams must distinguish actionable indicators from spurious correlations. A tiered architecture using inexpensive lexical features for initial screening, domain and host characteristics for uncertain cases, and content-based analysis for secondary inspection offers a practical balance among speed, accuracy and interpretability.
Conclusion: Explainable machine learning can provide a practical additional defense layer against phishing URLs in healthcare organizations. Systems should prioritize reproducible datasets, temporally separated validation, low-latency lexical features, interpretable model outputs and human security-operations oversight rather than relying on headline accuracy alone.
References
Gordon WJ, Wright A, Aiyagari R, Corbo L, Glynn RJ, Kadakia J, et al. Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Netw Open. 2019;2(3):e190393. doi:10.1001/jamanetworkopen.2019.0393.
Williams CM, Chaturvedi R, Chakravarthy K. Cybersecurity risks in a pandemic. J Med Internet Res. 2020;22(9):e23692. doi:10.2196/23692.
He Y, Aliyu A, Evans M, Luo C. Health care cybersecurity challenges and solutions under the climate of COVID-19: scoping review. J Med Internet Res. 2021;23(4):e21747. doi:10.2196/21747.
Sahingoz OK, Buber E, Demir O, Diri B. Machine learning based phishing detection from URLs. Expert Syst Appl. 2019;117:345-357.
Gupta BB, Yadav K, Razzak I, Psannis K, Castiglione A, Chang X. A novel approach for phishing URLs detection using lexical based machine learning in a real-time environment. Comput Commun. 2021;175:47-57. doi:10.1016/j.comcom.2021.04.023.
Hannousse A, Yahiouche S. Towards benchmark datasets for machine learning based website phishing detection: an experimental study. Eng Appl Artif Intell. 2021;104:104347. doi:10.1016/j.engappai.2021.104347.
Barraclough PA, Fehringer G, Woodward J. Intelligent cyber-phishing detection for online. Comput Secur. 2021;104:102123. doi:10.1016/j.cose.2020.102123.
Alhogail A, Alsabih A. Applying machine learning and natural language processing to detect phishing email. Comput Secur. 2021;110:102414. doi:10.1016/j.cose.2021.102414.
Chiew KL, Yong KSC, Tan CL. A survey of phishing attacks: their types, vectors and technical approaches. Expert Syst Appl. 2018;106:1-20.
Arrieta AB, Díaz-Rodríguez N, Del Ser J, Bennetot A, Tabik S, Barbado A, et al. Explainable artificial intelligence (XAI): concepts, taxonomies, opportunities and challenges toward responsible AI. Inf Fusion. 2020;58:82-115.
Rudin C. Stop explaining black box machine learning models for high stakes decisions and use interpretable models instead. Nat Mach Intell. 2019;1:206-215. doi:10.1038/s42256-019-0048-x.
Jiang JX, Bai G. Evaluation of causes of protected health information breaches. JAMA Intern Med. 2019;179(2):265-267.
Gordon WJ, Wright A, Glynn RJ, Kadakia J, Mazzone C, Leinbach E, et al. Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system. J Am Med Inform Assoc. 2019;26(6):547-552. doi:10.1093/jamia/ocz005.