Real-Time Phishing Attack Detection in A Chrome Extension Using Hybrid Gwo-Pso Feature Selection and Optimized Xgboost
Abstract
Phishing remains one of the most prevalent and damaging cyber-attack techniques, and traditional detection methods such as blacklisting and static heuristics increasingly fail to identify sophisticated, zero-day deceptive websites. This study proposes a real-time phishing detection system balancing accuracy with the low-latency requirements of browser-side deployment. Website data was acquired from the UCI Phishing Websites repository and the PhishTank repository, after which raw lexical, HTML/DOM structural, and visual features were engineered from each URL. Class imbalance was addressed using a SMOTE-Tomek hybrid sampling technique, while an Isolation Forest model and Z-score standardization cleaned and scaled the feature space. Feature selection and classifier hyperparameter tuning were jointly optimized using a Hybrid Grey Wolf Optimizer-Particle Swarm Optimization (GWO-PSO) algorithm, reducing the input space from 30 candidate features to 9 high-impact indicators used to train an eXtreme Gradient Boosting (XGBoost) classifier. On a held-out test set of 2,463 samples, the GWO-PSO-XGBoost framework achieved 95.0% accuracy, 94% precision, 95% recall, and an AUC-ROC of 0.9897. The trained model was implemented and deployed as a working Google Chrome browser extension, whose source code and live-site test cases are presented as direct evidence of implementation; the deployed extension achieved an average inference latency of 210ms and a false positive rate of 1.7%, outperforming Google Safe Browsing, the PhishTank extension, and the Netcraft toolbar under identical test conditions. These findings demonstrate that hybrid metaheuristic optimization combined with gradient-boosted classification provides an efficient, lightweight, and empirically verifiable solution for real-time phishing defense at the browser edge.