arXiv:2412.02084cs.CRcs.AI2024-12被引 3

对比黑盒与白盒模型在钓鱼检测中的表现,选对模型关键看是否要可解释性。

Comparative Analysis of Black-Box and White-Box Machine Learning Model in Phishing Detection

  • 比较黑盒与白盒模型在钓鱼检测中的优劣,分析其适用场景。
  • 白盒模型如EBM在可解释性上更优,但整体性能相近。
  • 需根据是否需要可解释性来选择模型,无绝对优劣。

背景:钓鱼检测模型的可解释性有助于提升信任度并理解检测机制,从而支持攻击缓解。目标:确定并推荐能满足关键需求的方法。方法:分析黑盒与白盒模型在钓鱼检测中的优缺点,通过使用知名算法和公开钓鱼数据集进行实验验证。评估指标包括预测准确率和可解释性指标。结论:两类模型在可解释性和一致性方面表现相当,但在多样化数据集上仍有改进空间。以EBM为代表的白盒模型更适合需要可解释性及可操作洞察的应用。白盒与黑盒模型在性能与可解释性上各有优劣,应根据使用目标进行选择。

原文摘要 · Abstract (English)

Background: Explainability in phishing detection model can support a further solution of phishing attack mitigation by increasing trust and understanding how phishing can be detected. Objective: The aims of this study to determine and best recommendation to apply an approach which has several components with abilities to fulfil the critical needs Methods: A methodology starting with analyzing both black-box and white-box models to get the pros and cons specifically in phishing detection. The conclusion of the analysis will be validated by experiment using a set of well-known algorithms and public phishing datasets. Experimental metrics covers 3 measurements such as predictive accuracy and explainability metrics. Conclusion: Both models are comparable in terms of interpretability and consistency, with room for improvement in diverse datasets. EBM as an example of white-box model is generally better suited for applications requiring explainability and actionable insights. Finally, each model, white-box and black-box model has positive and negative aspects both for performance metric and for explainable metric. It is important to consider the objective of model usage.

钓鱼检测可解释性模型对比

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。