Wegis Phishing Detection Model

URL ๋ฌธ์ž CNN + MobileBERT ๋ฉ€ํ‹ฐ๋ชจ๋‹ฌ ํ”ผ์‹ฑ ์‚ฌ์ดํŠธ ํŒ๋ณ„ ๋ชจ๋ธ์ž…๋‹ˆ๋‹ค. Wegis ๋ธŒ๋ผ์šฐ์ € ํ™•์žฅ๊ณผ Wegis Server์˜ ์‹ค์‹œ๊ฐ„ ํ”ผ์‹ฑ ํŒ๋ณ„์— ์‚ฌ์šฉ๋˜๋ฉฐ, ํ•™์Šต ํŒŒ์ดํ”„๋ผ์ธ์€ bnbong/Wegis_model์— ๊ณต๊ฐœ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

Model Architecture

URL๊ณผ ํŽ˜์ด์ง€ ๋ณธ๋ฌธ ํ…์ŠคํŠธ๋ฅผ ํ•จ๊ป˜ ์ฝ๋Š” ์ด์ง„ ๋ถ„๋ฅ˜(ํ”ผ์‹ฑ = 1) ๋ชจ๋ธ์ž…๋‹ˆ๋‹ค.

  • URL ๋ถ„๊ธฐ : ๋ฌธ์ž ๋‹จ์œ„ ํ† ํฌ๋‚˜์ด์ €(vocab 98, max 512) โ†’ Embedding(98ร—128) โ†’ Conv1d k=3/k=5 ๋ณ‘๋ ฌ(๊ฐ 256ํ•„ํ„ฐ, ReLU + ์ „์—ญ max pool) โ†’ concat(512) โ†’ Linear(512โ†’512)
  • HTML ๋ถ„๊ธฐ : ๋ณธ๋ฌธ ํ…์ŠคํŠธ ์ถ”์ถœ โ†’ MobileBERT(google/mobilebert-uncased) โ†’ last_hidden_state๋ฅผ ์‹œํ€€์Šค ์ถ• median ํ’€๋ง โ†’ (512)
  • ๊ฒฐํ•ฉ ํ—ค๋“œ : concat(1024) โ†’ Linear(1024โ†’512) โ†’ GELU โ†’ Linear(512โ†’1) โ†’ logits (์ถ”๋ก  ์‹œ sigmoid๋กœ ํ™•๋ฅ  ์ถœ๋ ฅ)
  • ํŒŒ๋ผ๋ฏธํ„ฐ 25,645,057๊ฐœ. ์†์‹ค์€ BCEWithLogitsLoss.

์„ธ๋ถ€ ๋‹ค์ด์–ด๊ทธ๋žจ๊ณผ ๋…ผ๋ฌธ ๋Œ€๋น„ ๊ตฌํ˜„ ์ฐจ์ด๋Š” ํ•™์Šต ์ €์žฅ์†Œ README๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

Performance

Metric Score
F1 0.8739
Accuracy 0.8710

Files

  • model.safetensors : ๋ชจ๋ธ ๊ฐ€์ค‘์น˜ state_dict (์•ฝ 103MB) โ€” ๋ฐฐํฌ ๊ถŒ์žฅ๋ณธ. Wegis_model์˜ ๋ชจ๋ธ ์ •์˜์— strict=True๋กœ ๋กœ๋“œ๋จ (tests/test_pretrained_compat.py๋กœ ๊ฒ€์ฆ).
  • best_acc_model.pt : ํ•™์Šต ๋‹น์‹œ ์ฒดํฌํฌ์ธํŠธ ์›๋ณธ (model + optimizer + scheduler, 206MB). ์‚ฌ์šฉ ์‹œ torch.load(path, weights_only=True)["model"]๋กœ ๋ชจ๋ธ ๋ถ€๋ถ„๋งŒ ์ทจํ•˜์„ธ์š”.

Usage

ํ•™์Šต ์ €์žฅ์†Œ CLI๋กœ ํ‰๊ฐ€

git clone https://github.com/bnbong/Wegis_model && cd Wegis_model
uv sync
uv run wegis-model evaluate --checkpoint hf://bnbong/wegis-model --data data/valid.parquet

Python

from wegis_model import QshingBertModel, load_state_dict, resolve_checkpoint

model = QshingBertModel(pretrained_html=False)  # ์ฒดํฌํฌ์ธํŠธ๋กœ ๋ฎ์–ด์“ธ ๊ฒƒ์ด๋ฏ€๋กœ ์‚ฌ์ „ํ•™์Šต ๋‹ค์šด๋กœ๋“œ ์ƒ๋žต
load_state_dict(model, resolve_checkpoint("hf://bnbong/wegis-model"))
model.eval()

ํŒจํ‚ค์ง€ ์—†์ด safetensors๋งŒ์œผ๋กœ ๋กœ๋“œํ•˜๋Š” ๊ฒฝ์šฐ (๋ชจ๋ธ ํด๋ž˜์Šค๋Š” wegis_model.model ์ฐธ๊ณ ):

from safetensors.torch import load_file
model.load_state_dict(load_file("model.safetensors"), strict=True)

Training

  • ํ•™์Šต ํŒŒ์ดํ”„๋ผ์ธ : https://github.com/bnbong/Wegis_model (MIT) โ€” uv ๊ธฐ๋ฐ˜ CLI(train / evaluate / prepare-data), AdamW, early stopping, ์ธตํ™” 8:2 ๋ถ„ํ• 
  • ๋ฐ์ดํ„ฐ ์Šคํ‚ค๋งˆ : url, html, label(1 = ํ”ผ์‹ฑ) โ€” CSV / Parquet / JSONL / XLSX
  • ๊ณต๊ฐœ ๋ฐ์ดํ„ฐ์…‹ ๋กœ๋” : Kaggle guchiopara/look-before-you-leap (Opara et al., 45,373๊ฑด ๊ท ํ˜• ์ฝ”ํผ์Šค)

Provenance

๊ณต๊ฐœ๋œ ๊ฐ€์ค‘์น˜๋Š” ๋™์ผ ์•„ํ‚คํ…์ฒ˜์˜ ์ดˆ๊ธฐ ๊ตฌํ˜„์œผ๋กœ ํ•™์Šต๋˜์—ˆ์œผ๋ฉฐ, Wegis_model์˜ ๋ชจ๋ธ ์ •์˜์™€ ์™„์ „ํžˆ ํ˜ธํ™˜๋ฉ๋‹ˆ๋‹ค(strict load ๊ฒ€์ฆ ํฌํ•จ). ํ•ด๋‹น ์ €์žฅ์†Œ๋Š” ์•„๋ž˜ ๋…ผ๋ฌธ๋“ค์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•™์Šต ํŒŒ์ดํ”„๋ผ์ธ์„ ์ƒˆ๋กœ ๊ตฌํ˜„ํ•œ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

Known Behaviors

  • URL ์ž„๋ฒ ๋”ฉ์˜ padding_idx๋Š” 0์ด๊ณ  ์‹ค์ œ PAD ํ† ํฐ id๋Š” 94์ž…๋‹ˆ๋‹ค(ํ•™์Šต๋œ ๊ฐ€์ค‘์น˜์˜ quirk โ€” ๊ทธ๋Œ€๋กœ ์œ ์ง€ํ•ด์•ผ ํ˜ธํ™˜๋จ). ํŒจ๋”ฉ ์œ„์น˜๋Š” forward์—์„œ attention mask ๊ณฑ์œผ๋กœ 0 ์ฒ˜๋ฆฌ๋ฉ๋‹ˆ๋‹ค.
  • HTML median ํ’€๋ง์€ attention mask๋ฅผ ์ฐธ์กฐํ•˜์ง€ ์•Š์•„ ํŒจ๋”ฉ ์œ„์น˜ ํ‘œํ˜„๋„ ํ†ต๊ณ„์— ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.
  • URL ๋ถ„๊ธฐ์˜ ์ „์—ญ max pooling์—๋Š” ํ•ฉ์„ฑ๊ณฑ bias๋กœ ์ธํ•œ ํŒจ๋”ฉ ๊ตฌ๊ฐ„ ์ƒ์ˆ˜ ํ™œ์„ฑ๊ฐ’์ด ์œ ์ž…๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

References

๋ชจ๋ธ ์•„ํ‚คํ…์ฒ˜์™€ ํ•™์Šต ์„ค๊ณ„๋Š” ๋‹ค์Œ ๋…ผ๋ฌธ์— ๊ธฐ๋ฐ˜ํ•ฉ๋‹ˆ๋‹ค.

Ahn, J., Akhavan, D., Jung, W., Kang, K., Son, J. "Encoder-Based Multimodal Ensemble Learning for High Compatibility and Accuracy in Phishing Website Detection." In: Security and Privacy in Communication Networks (SecureComm 2024), LNICST vol. 629, pp. 347โ€“365. Springer, 2025. https://doi.org/10.1007/978-3-031-94455-0_16

Opara, C., Chen, Y., Wei, B. "Look before you leap: Detecting phishing web pages by exploiting raw URL and HTML characteristics." Expert Systems with Applications 236 (2024) 121183. https://doi.org/10.1016/j.eswa.2023.121183 (Open Access, CC BY 4.0)

@inproceedings{ahn2025encoder,
  author    = {Ahn, Jemin and Akhavan, Dorian and Jung, Woohwan and Kang, Kyungtae and Son, Junggab},
  title     = {Encoder-Based Multimodal Ensemble Learning for High Compatibility and Accuracy in Phishing Website Detection},
  booktitle = {Security and Privacy in Communication Networks (SecureComm 2024)},
  series    = {LNICST},
  volume    = {629},
  pages     = {347--365},
  publisher = {Springer},
  year      = {2025},
  doi       = {10.1007/978-3-031-94455-0_16}
}

@article{opara2024look,
  author  = {Opara, Chidimma and Chen, Yingke and Wei, Bo},
  title   = {Look before you leap: Detecting phishing web pages by exploiting raw {URL} and {HTML} characteristics},
  journal = {Expert Systems with Applications},
  volume  = {236},
  pages   = {121183},
  year    = {2024},
  doi     = {10.1016/j.eswa.2023.121183}
}

License

  • ๊ฐ€์ค‘์น˜ : Apache License 2.0 (๋ฒ ์ด์Šค ๋ชจ๋ธ MobileBERT์™€ ๋™์ผ)
  • ํ•™์Šต ์ฝ”๋“œ : MIT License (Wegis_model)

Related Projects

Downloads last month

-

Downloads are not tracked for this model. How to track
Safetensors
Model size
25.6M params
Tensor type
F32
ยท
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐Ÿ™‹ Ask for provider support

Model tree for bnbong/wegis-model

Finetuned
(53)
this model