<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="review-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMES</journal-id>
<journal-id journal-id-type="nlm-ta">CMES</journal-id>
<journal-id journal-id-type="publisher-id">CMES</journal-id>
<journal-title-group>
<journal-title>Computer Modeling in Engineering &#x0026; Sciences</journal-title>
</journal-title-group>
<issn pub-type="epub">1526-1506</issn>
<issn pub-type="ppub">1526-1492</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">78774</article-id>
<article-id pub-id-type="doi">10.32604/cmes.2026.078774</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Review</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Privacy-Preserving Phishing Detection: A Systematic Review of LLMs, Federated Learning, and Blockchain Integration</article-title>
<alt-title alt-title-type="left-running-head">Privacy-Preserving Phishing Detection: A Systematic Review of LLMs, Federated Learning, and Blockchain Integration</alt-title>
<alt-title alt-title-type="right-running-head">Privacy-Preserving Phishing Detection: A Systematic Review of LLMs, Federated Learning, and Blockchain Integration</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Almaktoom</surname><given-names>Ghadi</given-names></name></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Aladhadh</surname><given-names>Suliman</given-names></name></contrib>
<contrib id="author-3" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Khediri</surname><given-names>Salim El</given-names></name><xref rid="cor1" ref-type="corresp">&#x002A;</xref><email>s.elkhediri@qu.edu.sa</email></contrib>
<aff id="aff-1"><institution>Department of Information Technology, College of Computer, Qassim University</institution>, <addr-line>Buraydah</addr-line>, <country>Saudi Arabia</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Salim El Khediri. Email: <email>s.elkhediri@qu.edu.sa</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2026</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>27</day><month>5</month><year>2026</year>
</pub-date>
<volume>147</volume>
<issue>2</issue>
<elocation-id>7</elocation-id>
<history>
<date date-type="received">
<day>07</day>
<month>01</month>
<year>2026</year>
</date>
<date date-type="accepted">
<day>01</day>
<month>04</month>
<year>2026</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2026 The Authors. Published by Tech Science Press.</copyright-statement>
<copyright-year>2026</copyright-year>
<copyright-holder>The Authors</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMES_78774.pdf"></self-uri>
<abstract>
<p>The rapid growth of phishing attempts in the enterprise could potentially lead to bankruptcy. The primary focus of the research is on detecting phishing attacks, with no interest in how the data is processed. Attackers use fraudulent methods to obtain valuable, confidential information, resulting in billions of dollars in financial losses for enterprises. In our review, we examined the methods used in phishing-detection studies. We concluded that the two main sections, centralized and decentralized methods, were the centralized ones, which aggregate data in a central server and thus violate data protection regulations, such as GDPR. In order to properly investigate the field, we put four main questions to give the reader a proper understanding of the field: what are the major detection approaches, what are their limitations and gaps, which datasets are most commonly used and trusted across different studies, and which privacy-preserving detection approaches are used and investigated in the field of phishing detection. To address these questions, we examined 105 different papers published from 2015 to 2024. Our review covers machine learning, deep learning, hybrid methods, large language models (LLMs), federated learning, and blockchain-based detection. Our investigation led to centralized approaches that achieved more than 95% accuracy but raised privacy concerns. Keeping data local on user devices offers privacy protection, as in decentralized strategies such as federated learning, at the cost of an accuracy trade-off of 1%&#x2013;3%. Other decentralized methods, such as blockchain-based systems, enhance security and transparency in the pricing of computational challenges.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Phishing detection</kwd>
<kwd>federated learning</kwd>
<kwd>blockchain</kwd>
<kwd>privacy-preserving</kwd>
<kwd>deep learning</kwd>
<kwd>BERT</kwd>
<kwd>natural language processing</kwd>
<kwd>smart contracts</kwd>
<kwd>decentralized machine learning</kwd>
<kwd>cybersecurity</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Deanship of Graduate Studies and Scientific Research at Qassim University</funding-source>
<award-id>QU-APC-2026</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>Phishing attacks seek to obtain personal information through complex techniques, strategies, and tools, including content insertion, social engineering, and more. The Anti-Phishing Working Group (APWG) offers the following description of phishing, despite other existing interpretations [<xref ref-type="bibr" rid="ref-1">1</xref>]. &#x201C;Phishing employs social engineering and technical misdirection for obtaining users&#x2019; identities and bank account information&#x201D; [<xref ref-type="bibr" rid="ref-1">1</xref>]. These attacks can cause up to $16.6 billion in losses, as the FBI Internet Crime Complaint Center (IC3) has stated in its annual reports [<xref ref-type="bibr" rid="ref-2">2</xref>], including breaches, ransomware incidents, and substantial financial losses [<xref ref-type="bibr" rid="ref-3">3</xref>]. The International Association for Information Technology Asset Managers (IAITAM) warned that remote work could increase the risk of data breaches [<xref ref-type="bibr" rid="ref-4">4</xref>,<xref ref-type="bibr" rid="ref-5">5</xref>]. The simplicity, low cost, and reduced risk associated with phishing attacks facilitate their execution. The only conditions for performing cybercrime are an Internet connection and a computer. The anonymous nature of the Internet hinders the identification and prosecution of offenders [<xref ref-type="bibr" rid="ref-6">6</xref>,<xref ref-type="bibr" rid="ref-7">7</xref>]. Among the methods for identifying malicious and fraudulent websites, URL analysis is the most common. In machine learning, one of the most critical domains is the classification of phishing URLs. To obtain machine-learning-based security systems and train the model on features associated with genuine and phishing website labels, a large amount of data is required. Because of their exceptional performance, machine learning algorithms can swiftly identify attacks that are hidden from users or performed for the first time and are not included on a blacklist [<xref ref-type="bibr" rid="ref-8">8</xref>]. In the last decade, a mechanism called deep learning has emerged as a robust tool for detection, particularly effective for training large-scale systems or systems lacking defined features, leading to a move towards deep learning methodologies [<xref ref-type="bibr" rid="ref-9">9</xref>]. In a typical phishing scenario, an attacker emails a phishing link; the target visits a spoofed site and unknowingly submits credentials; and the attacker then reuses those stolen credentials to access the legitimate service [<xref ref-type="bibr" rid="ref-10">10</xref>]. <xref ref-type="fig" rid="fig-1">Fig. 1</xref> shows the two main detection types: centralized and decentralized. The target visits a spoofed site and unknowingly submits credentials, and the attacker then reuses those stolen credentials to access the legitimate service. Misuse of individual data for central learning, exposing client data to third-party risks [<xref ref-type="bibr" rid="ref-11">11</xref>], thereby violating the regulation. That is why enterprises can reach 20 million EUR, or 4% of global revenue, if they do not comply [<xref ref-type="bibr" rid="ref-11">11</xref>,<xref ref-type="bibr" rid="ref-12">12</xref>]. The underlying conflict between efficient, centralized methods for phishing detection cannot adequately address privacy concerns. Blockchain technology offers promising potential for data protection across various domains. The authors Zhu et al. [<xref ref-type="bibr" rid="ref-13">13</xref>] proposed user data protection mechanism, which, combined with distributed hash tables and cryptography, allows users to control their data through web applications. In similar situations, Nwaiku et al. [<xref ref-type="bibr" rid="ref-14">14</xref>] considered cloud security and proposed an AI-driven anomaly detection system that leverages authentication protocols such as SAML and OAuth 2.0. They aimed to detect potential security breaches in real time using unsupervised machine learning algorithms, such as Isolation Forest.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Comparison of centralized and decentralized phishing detection approaches.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-1.tif"/>
</fig>
<sec id="s1_1">
<label>1.1</label>
<title>Motivation</title>
<p>Usually, researchers in the field of phishing detection concentrate on achieving high accuracy. However, in the real world, maintaining the security of user data is far more important; it is about how we handle it. Different studies on this matter do not address this issue. Technologies such as federated learning and blockchain have garnered tremendous attention for enabling us to build detection systems without collecting user data in a single location. However, there is no single review that compares them with traditional methods. Highlighting what truly works is what motivates us to work in this paper.</p>
</sec>
<sec id="s1_2">
<label>1.2</label>
<title>Contribution</title>
<p>Our review contributes to the field of phishing detection by offering the first comprehensive analysis of the main approaches to detect traditional phishing, with privacy methods. Second, in order to distinguish between centralized and decentralized techniques, we introduce a novel classification framework. Third, our review presents the most commonly used datasets across different studies, offering their limitations and features. Fourth, we represent our view on the best method for studying privacy requirements by evaluating adversarial robustness.</p>
</sec>
<sec id="s1_3">
<label>1.3</label>
<title>Paper Structure</title>
<p>The paper is structured as follows: <xref ref-type="sec" rid="s2">Section 2</xref> presents related work. <xref ref-type="sec" rid="s3">Section 3</xref> describes our review methodology. <xref ref-type="sec" rid="s4">Section 4</xref> analyzes the literature on centralized approaches (machine learning, deep learning, hybrid, and LLMs) and decentralized approaches (federated learning, blockchain, and federated learning with blockchain integration). <xref ref-type="sec" rid="s5">Section 5</xref> discusses key findings, including statistical analysis of detection approaches, dataset distribution, and research gaps. <xref ref-type="sec" rid="s6">Section 6</xref> concludes the review with the main insights and recommendations. <xref ref-type="fig" rid="fig-1">Fig. 1</xref> illustrates the two main approaches to phishing detection examined in this review.</p>
</sec>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>Existing studies dedicated to detecting phishing fall short in both content and scope. While aiming for high-accuracy results and seeking the right model, they fail to address privacy and security issues. Various surveys have examined aspects of phishing detection. Here, the authors Do et al. [<xref ref-type="bibr" rid="ref-15">15</xref>] examined the ability of deep learning algorithms to detect phishing emails, focusing mainly on their strengths and limitations in this context. Similarly, Saleh and &#x015E;ahin [<xref ref-type="bibr" rid="ref-16">16</xref>] review focused on detection methods, including system architectures and algorithms, and, at the end, they develop recommender systems; however, there is no mention of any security suggestions. Alkawaz et al. [<xref ref-type="bibr" rid="ref-17">17</xref>] focus specifically on developing a functional AI algorithm that outperforms other models. Also, this review did not discuss any security matters. Kytidou et al. [<xref ref-type="bibr" rid="ref-18">18</xref>] aim to investigate phishing detection approaches, such as machine learning, and the most widely used publicly accessible datasets. Kavya and Sumathi [<xref ref-type="bibr" rid="ref-19">19</xref>] (2024) survey covers traditional centralized learning, mainly machine learning and deep learning. To determine the benefits and fundamental constraints of each technique. Furthermore, Wilk-Jakubowski et al. [<xref ref-type="bibr" rid="ref-20">20</xref>] (2025) focused on identifying phishing techniques using sophisticated machine learning modelling. Alghenaim et al. [<xref ref-type="bibr" rid="ref-21">21</xref>] (2024) emphasized the use of various feature sets and classifiers to improve detection reliability, despite the ongoing challenges posed by the dynamic nature of phishing attacks and dataset imbalance.</p>
<p>Furthermore, Gupta et al. [<xref ref-type="bibr" rid="ref-22">22</xref>] used two main deep learning models: BERT and CNN, leveraging BERT&#x2019;s extraction of linguistic features and CNNs&#x2019; ability to classify organizational systems. They ultimately achieve 97.5% accuracy. Synthetic Minority Over-sampling Technique (SMOTE) was used to address dataset imbalance. Bari et al. [<xref ref-type="bibr" rid="ref-23">23</xref>] provided a framework for selecting features using filters to detect phishing URLs. This framework uses several preprocessing methods, including removing constant and correlated features, using mutual information, and performing ANOVA testing. Their method used a stacking ensemble of classifiers, achieving 98.17% accuracy and a very low false-positive rate of 1.31%. That shows how important systematic feature selection is for enhancing phishing detection performance.</p>
<p><xref ref-type="table" rid="table-1">Table 1</xref> compares our review with other accessible surveys. None of the previous surveys addressed federated learning, blockchain-based detection, or privacy protection. Our review aims to fill the gap by addressing these drawbacks by investigating privacy-preserving phishing detection methodologies with their classification framework to allow us differentiates between centralized and decentralized strategies.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Comparison of related work based on various criteria.</title>
</caption>
<table>
<colgroup>
<col align="center" width="38mm"/>
<col align="center" width="10mm"/>
<col align="center" width="11mm"/>
<col align="center" width="11mm"/>
<col align="center" width="11mm"/>
<col align="center" width="14mm"/>
<col align="center" width="12mm"/>
<col align="center" width="11mm"/>
<col align="center" width="11mm"/> </colgroup>
<thead>
<tr>
<th>Criteria</th>
<th>Do et al. [<xref ref-type="bibr" rid="ref-15">15</xref>]</th>
<th>Saleh and &#x015E;ahin [<xref ref-type="bibr" rid="ref-16">16</xref>]</th>
<th>Alkawaz et al. [<xref ref-type="bibr" rid="ref-17">17</xref>]</th>
<th>Kytidou et al. [<xref ref-type="bibr" rid="ref-18">18</xref>]</th>
<th>Kavya and Sumathi [<xref ref-type="bibr" rid="ref-19">19</xref>]</th>
<th>Wilk-Jakubowski et al. [<xref ref-type="bibr" rid="ref-20">20</xref>]</th>
<th>Alghenaim et al. [<xref ref-type="bibr" rid="ref-21">21</xref>]</th>
<th>Our Review</th>
</tr>
</thead>
<tbody>
<tr>
<td>Machine Learning</td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
</tr>
<tr>
<td>Deep Learning</td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
</tr>
<tr>
<td>Hybrid Approaches</td>
<td><inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
<td><inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
</tr>
<tr>
<td>Large Language Models (LLMs)</td>
<td><inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
<td><inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
</tr>
<tr>
<td>Federated Learning</td>
<td><inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
</tr>
<tr>
<td>Blockchain-based Detection</td>
<td><inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
</tr>
<tr>
<td>Privacy-Preserving Methods</td>
<td><inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
</tr>
<tr>
<td>Centralized vs. Decentralized</td>
<td><inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
</tr>
<tr>
<td>GDPR/Privacy Regulations</td>
<td><inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
</tr>
<tr>
<td>Dataset Analysis</td>
<td><inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td>Partial</td>
<td><inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
<td><inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
</tr>
<tr>
<td>Feature Engineering</td>
<td><inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
<td><inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
<td><inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
<td><bold>&#x2713;</bold></td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-1fn1" fn-type="other">
<p>Note: <bold>&#x2713;</bold> &#x003D; Covered, <inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mo>&#x00D7;</mml:mo></mml:math></inline-formula> &#x003D; Not Covered, Partial &#x003D; Partially Covered.</p>
</fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec id="s3">
<label>3</label>
<title>Methodology</title>
<p>This review examines phishing detection approaches published between 2015 and 2025. We searched major databases, including IEEE Xplore, ScienceDirect, and Google Scholar, using keywords such as &#x201C;phishing detection&#x201D;, &#x201C;machine learning&#x201D;, &#x201C;deep learning&#x201D;, &#x201C;federated learning&#x201D;, and &#x201C;blockchain security&#x201D;. We selected 105 peer-reviewed studies that focus on AI-driven phishing detection methods. To properly investigate and facilitate the search for relevant research papers, we have determined the publication years to be 2015&#x2013;2025. We used datasets from IEEE Xplore, ScienceDirect, and Google Scholar, using keywords such as &#x201C;phishing detection&#x201D;, &#x201C;machine learning&#x201D;, &#x201C;deep learning&#x201D;, &#x201C;federated learning&#x201D;, and &#x201C;blockchain security&#x201D;. We selected 105 peer-reviewed studies with a main focus on phishing detection methods. We divide the research we examined into two main groups: centralized approaches (such as machine learning, deep learning, hybrid methods, and large language models) and decentralized approaches (like federated learning and blockchain-based solutions). <xref ref-type="fig" rid="fig-2">Fig. 2</xref> shows the several types of phishing-detection methods examined in this evaluation. Our classification has helped us focus on traditional technologies and distributions that provide privacy.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Phishing detection taxonomy.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-2.tif"/>
</fig>
<sec id="s3_1">
<label>3.1</label>
<title>Search Strategy</title>
<p>To cover as many relevant papers as possible, we used IEEE Xplore, ScienceDirect, and Google Scholar, concentrating on papers published between 2015 and 2025. The selected datasets were mostly known and popular among researchers. IEEE Xplore provides access to computer science journals and many conferences, while ScienceDirect covers a broader range in many computer-related fields. On the other hand, Google Scholar is a well-known search engine that primarily facilitates the search for scholarly publications. Utilizing an exclusive search engine, one can explore a wide range of disciplines and sources, including articles, theses, books, abstracts, and judicial opinions from academic publishers, professional organizations, online repositories, universities, and other sources. We searched for keywords such as phishing detection, machine learning, deep learning, federated learning, blockchain, and privacy-preserving methods. The complete search string is shown in Algorithm 1. After removing duplicates and filtering based on our inclusion and exclusion criteria, we ended up with 105 studies. <xref ref-type="fig" rid="fig-2">Fig. 2</xref> shows how we organized these studies into categories.</p>

<fig id="fig-14">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-14.tif"/>
</fig>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Research Questions</title>
<p>This review is guided by four research questions, as summarized in <xref ref-type="table" rid="table-2">Table 2</xref>.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Research questions for the review.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center" width="70mm"/>
<col align="center" width="80mm"/> </colgroup>
<thead>
<tr>
<th>#</th>
<th>Research Question</th>
<th>Aims to Answer</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>1</bold></td>
<td>What are the major approaches for phishing detection?</td>
<td>To investigate the phishing detection approaches</td>
</tr>
<tr>
<td><bold>2</bold></td>
<td>What are the limitations of centralized and decentralized approaches?</td>
<td>To identify the commonly used techniques for identifying the phishing attempts in centralized and decentralized environments.</td>
</tr>
<tr>
<td><bold>3</bold></td>
<td>What are the most used datasets in phishing detection studies?</td>
<td>To investigate the most used dataset in phishing detection research, also identify their type, size, and balance.</td>
</tr>
<tr>
<td><bold>4</bold></td>
<td>What are the current research gaps and future directions in privacy-preserving phishing detection?</td>
<td>To identify recent research gaps and outline future research directions for privacy-preserving phishing detection methods.</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Inclusion and Exclusion Criteria</title>
<p><xref ref-type="table" rid="table-3">Table 3</xref> presents the inclusion and exclusion criteria applied during the study selection process.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Inclusion and exclusion criteria for paper selection.</title>
</caption>
<table>
<colgroup>
<col align="center" width="90mm"/>
<col align="center" width="70mm"/> </colgroup>
<thead>
<tr>
<th>Inclusion Criteria (IC)</th>
<th>Exclusion Criteria (EC)</th>
</tr>
</thead>
<tbody>
<tr>
<td>IC1: The papers are in the field of Phishing detection</td>
<td>EC1: Papers that are not conducted in the context of phishing detection.</td>
</tr>
<tr>
<td>IC2: The papers study phishing detection using centralized or decentralized approaches</td>
<td>EC2: Publications not peer-reviewed, an abstract, an editorial letter, a book review, and a scientific report.</td>
</tr>
<tr>
<td>IC3: The paper should be published in reputable journals or recognized conference proceedings</td>
<td>EC3: MSc and Ph.D. thesis, Posters, and Seminar.</td>
</tr>
<tr>
<td>IC4: The studies should be written in English.</td>
<td>EC4: Studies that are published before 2015.</td>
</tr>
<tr>
<td>IC5: Published between 2015&#x2013;2025.</td>
<td></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>Study Selection Process (PRISMA)</title>
<p>The study selection process followed PRISMA 2020 guidelines (<xref ref-type="fig" rid="fig-3">Fig. 3</xref>). The PRISMA checklists are available in the supplementary files. We began with 500 entries, removed 180 duplicates, and ended up with 320 unique records. We then screened these records based on their title and abstract, leaving us with 135 full-text articles to analyze for eligibility. After disposal of 30 publications (12 that were published before 2015, 8 that weren&#x2019;t peer-reviewed, as well as 10 review papers), the final informal synthesis included 105 studies.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>PRISMA 2020 flow diagram of the study selection process.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-3.tif"/>
</fig>
<p>The following paper offers a comprehensive taxonomy of phishing detection approaches across seven fundamental parameters. s is provided in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>. The taxonomy gives a short overview of major papers from 2019 to 2025 on Machine Learning, Deep Learning, Hybrid methods, Federated Learning, Blockchain, and FL&#x002B;Blockchain approaches. Color coding shows how private each approach is.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Privacy-preserving phishing detection: comprehensive analysis.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-4.tif"/>
</fig>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Literature Review</title>
<sec id="s4_1">
<label>4.1</label>
<title>Centralized Approaches</title>
<p>In this section, we will cover the centralized approach. Usually, this type of data processing handles data in a single server, allowing the model to be trained and aggregated. The simplicity and high accuracy have led many researchers to adopt this approach. We divided this section into four parts. The first covers machine learning, in which the model identifies the main characteristics of a phishing attempt. Deep learning derives insights from patterns stored in raw data. The hybrid approach leverages mixing different techniques, and large language models can learn in a deeper context. All of them have their own suitable context and applications, as well as the domain that best accommodates them. On the other hand, each of them has disadvantages. Access to user data is required, compromising privacy and potentially violating regulations such as the General Data Protection Regulation (GDPR).</p>
<sec id="s4_1_1">
<label>4.1.1</label>
<title>Machine Learning Techniques</title>
<p>Shahrivari et al. [<xref ref-type="bibr" rid="ref-24">24</xref>] examined 12 classifiers on a phishing website dataset comprising 6157 authentic websites and 4898 fraudulent websites. The classifiers investigated include Logistic Regression, Decision Tree, Support Vector Machine, AdaBoost, Random Forest, Neural Networks, K-Nearest Neighbors, Gradient Boosting, and XGBoost. The study finds that integrating multiple classification methods yields higher accuracy results. Tan et al. [<xref ref-type="bibr" rid="ref-25">25</xref>] introduced an approach, PhishWHO, for identifying phishing websites in three phases. Initially, keywords are retrieved from the websites utilizing the N-gram approach. In the second stage, these keywords are used in a web browser to identify the target domain name. Eventually, they used the same technique to verify the website&#x2019;s legitimacy. Chiew et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] The proposed method can detect whether a web page is a phishing site. Utilize a logo image to evaluate the consistency of identification between a website&#x2019;s actual and represented identity. The suggested approach includes techniques for logo extraction and identity verification. The logo extraction procedure employs a machine learning technique. The identity verification technique uses Google Image Search to identify the image. Efficacy of experimental results. A graphical element, such as a logo, is more beneficial than a textual element. Harikrishnan et al. [<xref ref-type="bibr" rid="ref-27">27</xref>] used TF-IDF combined with SVD and Non-negative Matrix Factorization (NMF) representations, followed by machine learning, to categorize emails as authentic or phishing. The study concluded that decision trees and random forests achieved the highest training accuracy. We have summarized the reviewed studies in <xref ref-type="table" rid="table-4">Table 4</xref>.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Summary of research papers on machine learning techniques.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center" width="25mm"/>
<col align="center"/>
<col align="center" width="18mm"/>
<col align="center" width="44mm"/>
<col align="center" width="34mm"/> </colgroup>
<thead>
<tr>
<th>Ref.</th>
<th>Method</th>
<th>Data</th>
<th>Result</th>
<th>Innovations</th>
<th>Limitations</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td>XGBoost</td>
<td>PhishTank</td>
<td>Accuracy: 98.3%</td>
<td>Examined twelve classifiers</td>
<td>Noise has a higher impact on the result</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td>PhishWHO</td>
<td>PhishTank</td>
<td>Accuracy: 96.10%</td>
<td>Identify fake web pages by searching the keywords</td>
<td>Image-based only</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-26">26</xref>]</td>
<td>Support Vector Machine</td>
<td>PhishTank</td>
<td>Accuracy: 93.4%</td>
<td>Identifies the legitimate logos machine learning</td>
<td>Image-based only</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-27">27</xref>]</td>
<td>Support Vector Machine</td>
<td>IWSPA</td>
<td>Accuracy: 99.9%</td>
<td>Compared multiple ML models</td>
<td>Overfitting due to an unbalanced dataset</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Studies [<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-27">27</xref>] show that machine learning approaches can achieve high accuracy, while this high performance comes at the cost of more sophisticated techniques. Usually, these models learn threat patterns over time. The model identifies patterns in order to detect attacks. Making a model depend on a single feature to detect an attack can easily be countered. To identify fake logos in brand names, the research study [<xref ref-type="bibr" rid="ref-24">24</xref>] uses an XGBoost model with 98.3% accuracy. The cycle continues: researchers develop their tools while attackers find ways to circumvent them. Moreover, the cycle continues indefinitely without achieving lasting protection.</p>
</sec>
<sec id="s4_1_2">
<label>4.1.2</label>
<title>Deep Learning Techniques</title>
<p>Deep learning and machine learning can learn structures and patterns from raw data and assist in detection. According to that pattern, a study by Kumar et al. [<xref ref-type="bibr" rid="ref-28">28</xref>] showed that both methods are capable of identifying intricate patterns. The main focus of the study is on using convolutional layers to detect patterns and identify links between the related content of data, enabling the model to achieve greater autonomy and efficiency on the training dataset. Sharmin et al. [<xref ref-type="bibr" rid="ref-29">29</xref>] compare CNNs to other machine learning methods. They used CNNs with a novel feature set that integrates the raw picture and Canny edges to improve earlier studies. The Support Vector Machine (SVM), Multilayer Perceptron (MLP), and CNN models outperformed conventional machine learning models with an accuracy of 99.02%. In Zavrak and Yilmaz [<xref ref-type="bibr" rid="ref-30">30</xref>], the authors&#x2019; main contribution is the integration of a convolutional layer into a deep learning model to identify the most relevant components of email content for phishing. Stratification enables the model to identify patterns in the data. Their technique obtained an overall accuracy score of 0.9926. They also investigated image fraud using convolutional neural networks to compare suspicious images with the original reference image and detect potential fraud. Sharmin et al. [<xref ref-type="bibr" rid="ref-29">29</xref>] proposed a CNN model that works with SVM and MLP. Their methodology led to a high accuracy of 99.02%. Their study compares the outcomes of CNNs with those of alternative machine learning methodologies; their findings yield raw images with novel features. Ansari et al. [<xref ref-type="bibr" rid="ref-31">31</xref>] studied how well employees can spot phishing emails. They used AI-based training to test and improve employees&#x2019; ability to detect phishing and strengthen security. This training utilizes AI to demonstrate how to identify phishing attempts effectively. Using AIs is an effective tool to mitigate cyberattacks. The authors Eze and Shamir [<xref ref-type="bibr" rid="ref-32">32</xref>] studied AI&#x2019;s ability to generate phishing emails that effectively deceive individuals. They used DeepAI to generate 865 emails containing only text. The tools, such as MALLET, Universal Data Analysis of Text (UDAT) tool, were used to recognize phrases that detect phishing patterns and to identify phishing tactics. They used the CoreNLP library with a deep neural network and Long Short-Term Memory (LSTM) to enhance the detection of phishing. Furthermore, Md et al. [<xref ref-type="bibr" rid="ref-33">33</xref>] employed a Dynamic Phishing Safeguard System (DPSS) to detect phishing emails using two main components, Anti-Phishing Neural Algorithm (APNA) and the Anti-Phishing Boosting Algorithm (APBA), to identify suspicious IP addresses, protecting user privacy through safe and timely phishing detection. The APNA results achieved 97.82% and 97.10% accuracy, respectively. In the case of Zaimi et al. [<xref ref-type="bibr" rid="ref-34">34</xref>], a two-dimensional CNN architecture is also used to detect fraudulent webpages. Their methodology consisted of three main approaches: first, analyze the text in URLs; second, extract useful features from the text; third, use third party services to detect phishing websites. They focused on using CNN models for user protection. Their results show that 1D CNN performs better for phishing detection (96.76% accuracy), while 2D CNN is more suitable for image tasks. We have summarized the reviewed studies in <xref ref-type="table" rid="table-5">Table 5</xref>.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Summary of research papers on deep learning techniques.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center" width="17mm"/>
<col align="center" width="24mm"/>
<col align="center" width="17mm"/>
<col align="center" width="40mm"/>
<col align="center" width="40mm"/> </colgroup>
<thead>
<tr>
<th>Ref.</th>
<th>Method</th>
<th>Data</th>
<th>Result</th>
<th>Innovations</th>
<th>Limitations</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-29">29</xref>]</td>
<td>CNN</td>
<td>Enron, SpamAssassin</td>
<td>Accuracy: 99.2%</td>
<td>Utilized CNN for word identification</td>
<td>High computational power</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
<td>CNN</td>
<td>ISH</td>
<td>Accuracy: 99.02%</td>
<td>The CNN model excels in identifying phishing imagery</td>
<td>Image-based only</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-32">32</xref>]</td>
<td>LSTM</td>
<td>AI-generated</td>
<td>Accuracy: 99.5%</td>
<td>Identifies AI phishing emails</td>
<td>Phishing tactics may not be fully covered</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-33">33</xref>]</td>
<td>APBA-APNA</td>
<td>UCI</td>
<td>Accuracy: 97.82%</td>
<td>Able to identify phishing emails and analyze URLs</td>
<td>High computational power</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-34">34</xref>]</td>
<td>CNN</td>
<td>Web Page Phishing</td>
<td>Accuracy: 96.76%</td>
<td>1D CNN excels over 2D CNN</td>
<td>Does not include HTML pages</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>These results may seem impressive and have achieved a great deal in exposing traditional phishing, except that they present a dilemma due to their potential for real-world application. If we looked closely at studies that use the same CNN model, we found that [<xref ref-type="bibr" rid="ref-29">29</xref>] reported 99.2% accuracy on the Enron dataset, which is an email dataset. In comparison, the study [<xref ref-type="bibr" rid="ref-30">30</xref>] achieved 99.02% accuracy in image-based phishing detection on the ISH dataset. Even though CNN can detect phishing easily, it yet lacks the robustness for crafted, designed phishing emails, and that is a gap in most studies [<xref ref-type="bibr" rid="ref-28">28</xref>&#x2013;<xref ref-type="bibr" rid="ref-34">34</xref>] that lack testing their models against adversarial attacks.</p>
</sec>
<sec id="s4_1_3">
<label>4.1.3</label>
<title>Hybrid Approaches</title>
<p>The authors here, Bountakas and Xenakis [<xref ref-type="bibr" rid="ref-35">35</xref>], proposed HELPED, a phishing email detection method. It analyzes linguistic characteristics of emails to enhance detection accuracy. It combines two ways: ensemble learning and hybrid attributes to improve detection. To process the hybrid features separately. They proposed two approaches for HELPED: first, an ensemble learning approach, and second, a soft voting ensemble. In each approach, they used different Machine Learning algorithms. Combining the two methods, the soft voting ensemble gives better detection results than a single-feature focus. using only content-based or text-based features. The result also shows that using the Soft Voting Ensemble method on the imbalanced email dataset achieves an F1-score of 0.9942, surpassing those of traditional machine learning and deep learning models. Additionally, Alhogail and Alsabih [<xref ref-type="bibr" rid="ref-36">36</xref>] combined deep learning, graph convolutional networks (GCNs), and natural language processing to enhance detection accuracy; they achieved 98.2% accuracy. We have summarized the reviewed studies in <xref ref-type="table" rid="table-6">Table 6</xref>.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Summary of research papers on hybrid approaches.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center" width="25mm"/>
<col align="center"/>
<col align="center" width="32mm"/>
<col align="center" width="39mm"/> </colgroup>
<thead>
<tr>
<th>Ref.</th>
<th>Method</th>
<th>Data</th>
<th>Result</th>
<th>Innovations</th>
<th>Limitations</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-35">35</xref>]</td>
<td>HELPED</td>
<td>Combined dataset</td>
<td>Accuracy: 99.43%</td>
<td>Novel layered technique</td>
<td>High computational power</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-36">36</xref>]</td>
<td>GCN-NLP</td>
<td>CLAIR Fraud Dataset</td>
<td>Accuracy: 98.2%</td>
<td>Utilizing GCN with NLP</td>
<td>Text-based only</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In these two studies, the main constraint is that they focus solely on combining features, even though both use ensemble learning, which requires training multiple models. In the first study [<xref ref-type="bibr" rid="ref-35">35</xref>], the combination leads to a high computational cost of hybrid methods, while the second study [<xref ref-type="bibr" rid="ref-36">36</xref>] does not justify this cost. We notice that neither study shows that the high computational cost was worth it; neither explains further practical or functional challenges.</p>
</sec>
<sec id="s4_1_4">
<label>4.1.4</label>
<title>Large Language Models (LLMs)</title>
<p>In phishing, attackers aim to exploit human weaknesses by tricking them into trusting something unauthentic. That is what Heiding et al. [<xref ref-type="bibr" rid="ref-37">37</xref>] studied in their paper. They tested the two models&#x2019; ability to trick human participants. They used the two models to generate nearly 112 emails, which they presented to volunteers. The criterion was the number of clicks on the links in the emails. The GPT-generated emails had success rates of 30%&#x2013;44%, while V-Triad emails achieved success rates of 69%&#x2013;79%. Beyond that, they tested the model: both methods combined achieved success rates ranging from 43%&#x2013;81%. Additionally, models GPT, Claude, PaLM, and LLaMA were used to detect phishing email intentions, as well as their ability to detect phishing from non-harmful emails. The results showed that LLMs outperformed human participants, especially in detecting subtle phishing attempts. Kulkarni et al. [<xref ref-type="bibr" rid="ref-38">38</xref>] developed <italic>PhishOracle</italic> to test how well detection systems resist attacks, which add fake and harmful web pages to legitimate ones. They used the Stack model and Phishpedia to estimate the Gemini Pro Vision performance. They put it to the test by calling for 52 participants to test whether users could recognize fake brand logos on PhishOracle-generated websites. Their results demonstrated humans can easily be deceived, while the LLM Gemini Pro showed stronger resistance to these attacks. Hua et al. [<xref ref-type="bibr" rid="ref-39">39</xref>] Phishing attackers usually aim to exploit vulnerabilities by impersonating trusted entities; this study covers both text and visual elements using ChatGPT-4 and Gemini to detect them. ChatGPT-4 shows lower recall, and also has a hard time detecting more sophisticated phishing emails with hidden malicious links. Overall, it achieved high accuracy without generating false positives. Koide et al. [<xref ref-type="bibr" rid="ref-40">40</xref>] aim to investigate how LLM contextual understanding can improve the detection of different phishing techniques. They proposed a system called ChatSpamDetector that converts email content into organized prompts. They used GPT-4 as their LLM model. Their system achieved 99.70% accuracy. Additionally, Lee et al. [<xref ref-type="bibr" rid="ref-41">41</xref>] proposed a two-stage approach to phishing detection: first, analyze the original web pages and their features, such as logos, visual themes, and brand-related elements. The second stage here is the URL classification to determine whether this web page is legitimate or malicious. Using the GPT and Claude 3 models, the results show similar precision and recall; meanwhile, Gemini performed worse, with a drop of more than 15%. The examination involved modified logos and HTML content; GPT and Claude 3 maintained strong detection performance. Furthermore, Jamal and Wimmer [<xref ref-type="bibr" rid="ref-42">42</xref>] achieved satisfactory results on both balanced and imbalanced datasets; they proposed the IPSDM, a fine-tuned transformer-based model for phishing detection, based on BERT. The IPSDM model achieved 97.50% validation accuracy and 97.10% test accuracy. Their approach improves pre-trained DistilBERT and RoBERTa models. In Mittal et al. [<xref ref-type="bibr" rid="ref-43">43</xref>], a framework based on machine learning called DARTH, their method model handles single-phishing features, and evaluation is done separately using natural language processing and neural network techniques. Their examination shows high performance in detection with an F-score of 99.98%, trained on 150,000 emails. A summary of the reviewed LLM-based approaches is presented in <xref ref-type="table" rid="table-7">Table 7</xref>.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Summary of research papers on large language models (LLMs).</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center" width="27mm"/>
<col align="center" width="23mm"/>
<col align="center" width="23mm"/>
<col align="center" width="42mm"/>
<col align="center" width="32mm"/> </colgroup>
<thead>
<tr>
<th>Ref.</th>
<th>Method</th>
<th>Data</th>
<th>Result</th>
<th>Innovations</th>
<th>Limitations</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-37">37</xref>]</td>
<td>GPT-4 &#x002B; V-Triad</td>
<td>112 volunteers</td>
<td>Success rate: 43%&#x2013;81%</td>
<td>Combined GPT-4 with V-Triad psychological framework for phishing generation and detection</td>
<td>Relies on commercial LLMs; limited participant pool</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-38">38</xref>]</td>
<td>PhishOracle/<break/> Gemini Pro Vision</td>
<td>PhishOracle-generated pages</td>
<td>Gemini showed resilience</td>
<td>Generates adversarial phishing pages to test detection robustness</td>
<td>No standardized accuracy metric reported</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-39">39</xref>]</td>
<td>ChatGPT-4/Gemini</td>
<td>Brand impersonation emails</td>
<td>High accuracy, zero FP</td>
<td>Evaluated LLMs on brand impersonation with textual and visual features</td>
<td>Reduced recall for ChatGPT-4; struggles with concealed malicious links</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-40">40</xref>]</td>
<td>ChatSpam<break/> Detector (GPT-4)</td>
<td>Email dataset</td>
<td>Accuracy: 99.70%</td>
<td>Transforms email content into structured prompts for LLM analysis</td>
<td>Dependent on GPT-4 API availability and cost</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-41">41</xref>]</td>
<td>GPT/Claude3/<break/> Gemini</td>
<td>Phishing webpages</td>
<td>GPT &#x0026; Claude3: high recall/precision</td>
<td>Two-phase framework: brand identification &#x002B; phishing classification; adversarial evaluation</td>
<td>Gemini performance &#x003E;15% lower; requires multimodal input</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-42">42</xref>]</td>
<td>IPSDM (DistilBERT/RoBERTa)</td>
<td>Balanced &#x0026; imbalanced datasets</td>
<td>Accuracy: 97.50%</td>
<td>Fine-tuned BERT-family transformers for phishing and spam detection</td>
<td>Limited to text-based features only</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-43">43</xref>]</td>
<td>DARTH (NLP &#x002B; NN)</td>
<td>150,000 emails</td>
<td>F-score: 99.98%</td>
<td>Dedicated models for individual composite phishing attributes</td>
<td>High computational cost; email-only</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In related studies we reviewed, we noticed that cloud-based commercial models such as GPT-4, Gemini, and Claude were the fundamental concern. However, locally implemented models are more appropriate for applications that care about privacy, such as LLaMA and Mistral. Allowing models to train in a decentralized way, with fine-tuning and running on-premises. The model can adjust and operate locally, which eliminates the need to send sensitive email or URL data to external servers. The method supports a decentralized approach and could be combined with federated learning to allow collaborative training without sharing raw data. Future research should focus on integrating the local LLM deployment with federated learning for phishing detection, especially in high-value data sectors such as healthcare and finance.</p>
</sec>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Decentralized Approaches</title>
<p>In this section, we will conduct a review. methods that reduce the privacy risks of centralized systems, such as single-server storage, by spreading data across different nodes in a decentralized approach. This approach provides a better solution for enterprises that need to maintain high detection performance while protecting data privacy. We started this section by reviewing the general use of these technologies in security applications, and then focused on their role in phishing detection.</p>
<sec id="s4_2_1">
<label>4.2.1</label>
<title>Federated Learning</title>
<p>Korkmaz et al. [<xref ref-type="bibr" rid="ref-44">44</xref>] found that Federated Learning (FL) is a form of Distributed machine learning, first introduced by Google, to support collaborative, decentralized, and multi-device model training. The most important difference from centralization is that a server trains the model for security, rather than each individual device training it. Each device can train its own model at home using its own data, and the model does not have to expose data it doesn&#x2019;t need to other devices. The benefits of FL include improved performance, increased scalability, cost savings, and faster development time. Applications of federated learning span many fields, including healthcare [<xref ref-type="bibr" rid="ref-45">45</xref>&#x2013;<xref ref-type="bibr" rid="ref-47">47</xref>], industrial cyber-physical systems [<xref ref-type="bibr" rid="ref-48">48</xref>], IoT anomaly detection [<xref ref-type="bibr" rid="ref-49">49</xref>], cybersecurity [<xref ref-type="bibr" rid="ref-50">50</xref>], and privacy-preserving systems [<xref ref-type="bibr" rid="ref-51">51</xref>]. As noted by Guo et al. [<xref ref-type="bibr" rid="ref-52">52</xref>], FL generally operates in an environment with multiple users or participants; therefore, a coordinator is sometimes needed to compile the insights gathered from users. This is also one reason why FL is attractive, as it can mitigate privacy issues because users&#x2019; private data is never shared when training is centralized [<xref ref-type="bibr" rid="ref-53">53</xref>]. Zeng et al. [<xref ref-type="bibr" rid="ref-54">54</xref>] reported that when using FL, the centralized global model can be created on a server and distributed to clients for local training.</p>
<p>As summarized in <xref ref-type="table" rid="table-8">Table 8</xref>, the federated learning studies [<xref ref-type="bibr" rid="ref-55">55</xref>,<xref ref-type="bibr" rid="ref-56">56</xref>] represent a promising direction for privacy-preserving phishing detection, directly addressing the regulatory and ethical concerns raised by centralized data collection. However, only three studies focus on phishing detection, leaving the field underdeveloped. Study [<xref ref-type="bibr" rid="ref-57">57</xref>] demonstrates that FL achieves comparable accuracy to centralized while keeping email data distributed across clients. Study [<xref ref-type="bibr" rid="ref-55">55</xref>] stated that achieving protection through best practices is better than traditional centralized detection methods. Research in this field, aimed at protecting user privacy, investigated federated learning (FL). Study [<xref ref-type="bibr" rid="ref-56">56</xref>] used an SMS dataset to detect phishing attacks, with the training process kept locally on users&#x2019; devices using a federated learning (FL) approach. The study describes this as a solution for protecting user privacy. Their examination achived 95.02% accuracy. Maintaining the data trained on a single local server creates serious privacy risks because it requires sharing sensitive communications for model training. Earlier studies demonstrated that federated learning is a privacy-preserving alternative that enables collaborative detection without sharing raw data, thereby preserving detection accuracy, which we observed varying from minimal reductions [<xref ref-type="bibr" rid="ref-56">56</xref>,<xref ref-type="bibr" rid="ref-57">57</xref>] to more noticeable decreases [<xref ref-type="bibr" rid="ref-55">55</xref>].</p>
<table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>Summary of research papers on FL for phishing detection.</title>
</caption>
<table>
<colgroup>
<col align="center" width="8mm"/>
<col align="center" width="17mm"/>
<col align="center" width="18mm"/>
<col align="center" width="17mm"/>
<col align="center" width="45mm"/>
<col align="center" width="40mm"/> </colgroup>
<thead>
<tr>
<th>Ref.</th>
<th>Method</th>
<th>Data</th>
<th>Result</th>
<th>Innovations</th>
<th>Limitations</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-57">57</xref>]</td>
<td>FL/BERT</td>
<td>Collected dataset</td>
<td>Accuracy: 96.1%</td>
<td>Integrates FL with BERT to detect phishing attempts</td>
<td>High computational power</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-56">56</xref>]</td>
<td>FL/CNN-LSTM</td>
<td>UCI SMS</td>
<td>Accuracy: 99.19%</td>
<td>Integrates CNN-LSTM with FL to detect phishing attempts</td>
<td>Lack of examination of advanced feature engineering</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-55">55</xref>]</td>
<td>FL/BiLSTM</td>
<td>Confidential</td>
<td>Accuracy: 83%</td>
<td>Integrates BiLSTM with FL to detect phishing attempts</td>
<td>Low accuracy</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_2_2">
<label>4.2.2</label>
<title>Blockchain-Based</title>
<p>Nofer et al. [<xref ref-type="bibr" rid="ref-58">58</xref>] first introduced blockchain for digital currency, such as Bitcoin, using a distributed ledger system. They also highlighted its potential for use in other applications. Swan [<xref ref-type="bibr" rid="ref-59">59</xref>] blockchain can operate across public and private environments, making it suitable for use across fields and sectors. Additionally, Esmaili and Christensen [<xref ref-type="bibr" rid="ref-60">60</xref>] clarify that public ledgers are open to all participants without restrictions. In contrast, Azaria et al. [<xref ref-type="bibr" rid="ref-61">61</xref>] explain that a private blockchain is restricted to only certain users who meet specific conditions and are authenticated and allowed to participate. Islam et al. [<xref ref-type="bibr" rid="ref-62">62</xref>] define Blockchain as a distributed ledger containing multiple blocks that hold information, where each block is linked to the previous one to maintain a historical record. Additionally, Zheng et al. [<xref ref-type="bibr" rid="ref-63">63</xref>] noted that each block has a pointer to the preceding block, using a link that is merely a hash of that block. <xref ref-type="fig" rid="fig-5">Fig. 5</xref> below clarifies the application of Blockchain in security.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>An example series of blocks.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-5.tif"/>
</fig>
</sec>
<sec id="s4_2_3">
<label>4.2.3</label>
<title>Blockchain with Deep Learning</title>
<p>Scicchitano et al. [<xref ref-type="bibr" rid="ref-64">64</xref>] propose an anomaly detection system that uses an encoder-decoder deep learning model trained on aggregated data from tracking blockchain incidents. The results demonstrate the model&#x2019;s effectiveness in detecting publicly disclosed attacks.</p>
<p>Ashfaq et al. [<xref ref-type="bibr" rid="ref-65">65</xref>] blockchain technology using XGBoost and Random Forest (RF) to detect fraudulent transactions. inonther study.</p>
<p>Yan et al. [<xref ref-type="bibr" rid="ref-66">66</xref>] ropose ADA-Spear-an automatic phishing detection model utilizing adversarial domain adaptive learning which symbolizes the method&#x2019;s ability to penetrate various heterogeneous blockchains for phishing detection. Du et al. [<xref ref-type="bibr" rid="ref-67">67</xref>] Designed DeepPhishDetect, which used deep learning with blockchain to detect fraudulent nodes in blockchain networks. Their novel approach, DMFD, for node feature learning, and GAT for label dependency modeling</p>
<p>Nouman et al. [<xref ref-type="bibr" rid="ref-68">68</xref>] used a Histogram-based Gradient Boosting (HGB) classifier to detect the malicious node; they proposed this approach using a blockchain-based method. Their approach resulted in speed detection. Saveetha and Maragatham [<xref ref-type="bibr" rid="ref-69">69</xref>] integrated both deep learning and blockchain to detect network intrusion. Their experiment led to high accuracy and enabled the detection of security threats. Furthermore, in a review study, Afaq and Manocha [<xref ref-type="bibr" rid="ref-70">70</xref>] highlighted that combining blockchain and deep learning improves decision-making. In other studies, both technologies were integrated.</p>
<p>In Hamdan et al. [<xref ref-type="bibr" rid="ref-71">71</xref>], the author proposed a solution for fraud detection that can enable risk-free, secure transactions. They propose a Deep Learning-based Blockchain Framework for Fraud Detection using Multilevel Supervision in Hierarchical Generative Hashing. Chen et al. [<xref ref-type="bibr" rid="ref-72">72</xref>] introduces a blockchain-based anti-phishing authentication protocol that enhances the security and efficiency of virtual game recharge orders. The proposed protocol integrates elliptic curve cryptography. Furthermore, Sheng et al. [<xref ref-type="bibr" rid="ref-73">73</xref>] proposed blockchain phishing detection method leveraging a dynamic feature fusion model that combines graph-based representation learning and semantic feature extraction. Varma et al. [<xref ref-type="bibr" rid="ref-74">74</xref>] proposes a novel framework, AI-MCAGCN-B-DIFCS, which integrates a Multi-Component Attention Graph Convolutional Neural Network (MCAGCN) with blockchain technology for secure and precise fraud detection. Darwish et al. [<xref ref-type="bibr" rid="ref-75">75</xref>] explores the integration of lightweight blockchain technology and deep learning for robust fraud detection in financial transactions. Lightweight blockchain ensures transaction immutability. Ref. [<xref ref-type="bibr" rid="ref-76">76</xref>] present an approach for detecting medical insurance fraud utilizing a consortium blockchain and deep learning, capable of identifying suspect medical records through an explainable model. BERT-LE is intended to assess the validity of ICD illness codes.</p>
<p>Zhang et al. [<xref ref-type="bibr" rid="ref-76">76</xref>] present an approach for detecting medical insurance fraud utilizing a consortium blockchain and deep learning, capable of identifying suspect medical records through an explainable model. BERT-LE is intended to assess the validity of ICD illness codes.</p>
<p>Ghnemat and Mosa [<xref ref-type="bibr" rid="ref-77">77</xref>] Decentralized blockchain networks are designed to make it hard to intervene in or alter records; therefore, individuals on the network can send transactions, rendering traditional fraud prevention methods ineffective. Ertam [<xref ref-type="bibr" rid="ref-78">78</xref>] This study shows that using XGBoost, LightGBM, and CatBoost can achieve 95.83%&#x2013;96.46% accuracy to detect phishing attempts in Ethereum wallets. Shevchuk et al. [<xref ref-type="bibr" rid="ref-79">79</xref>] Due to increased attacks, fraud, and threat complexity, blockchain security is gaining popularity. Machine learning is replacing fundamental protection approaches as the area becomes more sophisticated. Karthika et al. [<xref ref-type="bibr" rid="ref-80">80</xref>] The proposed Phish Block on a private Ethereum blockchain has kept homographic phishing URLs. Liu et al. [<xref ref-type="bibr" rid="ref-81">81</xref>] The first effort to characterize and detect Ethereum phishing gangs was this paper. They examine phishing gang transaction habits from people&#x2019;s viewpoints. Bayan et al. [<xref ref-type="bibr" rid="ref-82">82</xref>] The evolution of Permissionless blockchains has become the foundation for Web3 applications, as well as decentralized finance (DeFi), resulting in privacy vulnerabilities. Vanna et al. [<xref ref-type="bibr" rid="ref-83">83</xref>] The study highlights the need for an advanced phishing detection hybrid approach to enhance the accuracy Gao et al. [<xref ref-type="bibr" rid="ref-84">84</xref>] Proposed AHGT-DFD is designed to detect phishing in blockchain-based on four categories: Feature, Encoding, Graph, and Continuous Learning there result shows 95.58% F1. Farrukh et al. [<xref ref-type="bibr" rid="ref-85">85</xref>] argued that centralized ML is more efficient than FL but might put privacy at risk. FL-blockchain hybrids reduce false positives.</p>
<p>Blockchain provides transparency and a decentralized ledger, as Refs. [<xref ref-type="bibr" rid="ref-80">80</xref>&#x2013;<xref ref-type="bibr" rid="ref-84">84</xref>] demonstrate. However, there is no mention of how these studies address the privacy concerns. The Ethereum transaction analysis studies [<xref ref-type="bibr" rid="ref-86">86</xref>&#x2013;<xref ref-type="bibr" rid="ref-89">89</xref>] focus on cryptocurrency phishing rather than email or web phishing. They rely on public blockchain data, where transaction privacy is already limited. However, these studies do not discuss privacy-preserving analysis methods or consider that fraud detection models might unintentionally reveal sensitive transaction patterns. Study [<xref ref-type="bibr" rid="ref-90">90</xref>] used a permissioned system called a &#x201C;private Ethereum blockchain&#x201D;, which is a proposed system that can control access in the network, yet there is no evidence to support their claim. Critically, none of the blockchain studies evaluate privacy implications of their proposed systems, compare privacy properties against centralized or federated alternatives, or implement privacy-enhancing techniques such as zero-knowledge proofs, confidential transactions, or encrypted on-chain data. Main strengths of blockchain technology are its immutability and transparency, which conflict with the privacy concept, and prior studies do not clearly show how to balance transparency and privacy without harming either. In several studies [<xref ref-type="bibr" rid="ref-86">86</xref>&#x2013;<xref ref-type="bibr" rid="ref-89">89</xref>], the Ethereum transaction data used for phishing detection was collected from publicly available platforms such as Etherscan [<xref ref-type="bibr" rid="ref-91">91</xref>].</p>
</sec>
<sec id="s4_2_4">
<label>4.2.4</label>
<title>Federated Learning and Blockchain Integration</title>
<p>A combination of secure technology blockchain and federated learning can offer several solutions that are substantial to immutability and collaboratively train among different local devices. At the same time, blockchain functions as a secure, immutable ledger that documents and authenticates each model update. Together, they provide a remarkable blend of privacy and trust [<xref ref-type="bibr" rid="ref-92">92</xref>,<xref ref-type="bibr" rid="ref-93">93</xref>]. <xref ref-type="fig" rid="fig-6">Fig. 6</xref> demonstrates that the generalized blockchain-based federated learning paradigm incorporates blockchain as a decentralized ledger to facilitate model aggregation among distributed clients.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>A generalized blockchain-based federated learning paradigm.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-6.tif"/>
</fig>
<p>Many recent surveys have studied how these two technologies can function together. Research by Qammar et al. [<xref ref-type="bibr" rid="ref-94">94</xref>] investigated how blockchain can enhance the robustness of federated learning. <xref ref-type="fig" rid="fig-7">Fig. 7</xref> illustrates the architecture of FL members&#x2019; interaction with the blockchain network via smart contracts and consensus procedures. They noted improvements in model fidelity and in protection against poisoning. Issa et al. [<xref ref-type="bibr" rid="ref-95">95</xref>] examined blockchain-based federated learning for IoT security, and Ali et al. [<xref ref-type="bibr" rid="ref-96">96</xref>] examined blockchain and FL-based intrusion detection for industrial IoT networks. Orabi et al. [<xref ref-type="bibr" rid="ref-97">97</xref>] organized current research through data partitioning to demonstrate how blockchain could enhance the security and knowledge sharing of FL systems. In blockchain-based FL setups, Sameera et al. [<xref ref-type="bibr" rid="ref-98">98</xref>] reviewed differential privacy, homomorphic encryption, and safe multiparty computation.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Architecture of a blockchain-integrated federated learning system.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-7.tif"/>
</fig>
<p>One of the studies, Ren et al. [<xref ref-type="bibr" rid="ref-99">99</xref>], proposed a system that uses FL with a smart contract to automate model verification. As shown in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>, the FLCoin framework uses a composed two-layer model with blocks and update blocks. Here, it records every system event, the size of the training data, contribution metrics, and validation proofs.</p>
<fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Structure of model and update blocks in the FLCoin framework.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-8.tif"/>
</fig>
<p>Abou El Houda et al. [<xref ref-type="bibr" rid="ref-100">100</xref>] proposed using explainable AI, a blockchain, and a federated system to detect IoT intrusions. Yang and Li [<xref ref-type="bibr" rid="ref-101">101</xref>] proposed a solution to the free-rider problem, in which a system participant does not contribute to their own data. Here, the solution consists of Federated Learning (FL), Blockchain, and Incentive mechanisms to reward the participants. Li et al. [<xref ref-type="bibr" rid="ref-102">102</xref>] introduced BLADE-FL, which is in <xref ref-type="fig" rid="fig-9">Fig. 9</xref>. Its decentralized FL blockchain framework encompasses performance evaluation metrics and resource allocation strategies. Mainly replacing the central server with a blockchain network for aggregation and verification.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>Architecture of the BLADE-FL framework for blockchain-assisted decentralized federated learning.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-9.tif"/>
</fig>
<p>Liu et al. [<xref ref-type="bibr" rid="ref-103">103</xref>] used both blockchain and federated learning in detection. Their approach highlighted that accuracy can be improved while safeguarding the data.</p>
<p>The combination of decentralized technologies has driven the attention of researchers. Zhao et al. [<xref ref-type="bibr" rid="ref-104">104</xref>] developed a privacy-preserving approach specifically designed for IoT devices that have limited computing power. Lu et al. [<xref ref-type="bibr" rid="ref-105">105</xref>] designed a platform for secure data sharing in the industrial internet of things that employs the Use of a blockchain and federated learning. <xref ref-type="fig" rid="fig-10">Fig. 10</xref> shows the combination of blockchain technology with federated learning to enable secure data exchange among industrial IoT devices. Hallaji et al. [<xref ref-type="bibr" rid="ref-106">106</xref>] examined the security and privacy vulnerabilities of decentralized federated learning, particularly the potential of blockchain to mitigate model poisoning and data inference attacks. Han et al. [<xref ref-type="bibr" rid="ref-107">107</xref>] simultaneously provided a comprehensive examination of methodologies for ensuring both privacy and reliability in federated learning, including blockchain-based methods. Manzoor et al. [<xref ref-type="bibr" rid="ref-108">108</xref>] surveyed various defense strategies in FL, categorizing them according to what occurs before, during, and after model aggregation. Ngoupayou Limbepe et al. [<xref ref-type="bibr" rid="ref-109">109</xref>] focused on effective healthcare and examined how blockchain technology could enhance privacy in Florida-based medical systems.</p>
<fig id="fig-10">
<label>Figure 10</label>
<caption>
<title>Blockchain-based federated learning architecture for privacy-preserving intrusion detection in Industrial IoT.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-10.tif"/>
</fig>
<p>Wu et al. [<xref ref-type="bibr" rid="ref-110">110</xref>] and Ning et al. [<xref ref-type="bibr" rid="ref-111">111</xref>] have provided significant surveys that classify blockchain-based federated learning solutions according to consensus mechanisms and model aggregation methods. Cao et al. [<xref ref-type="bibr" rid="ref-112">112</xref>] have identified privacy and trust concerns given from the integration of blockchain and federated learning in intrusion detection systems. Phishing detection research is nascent yet demonstrates significant potential. Ghosh et al. [<xref ref-type="bibr" rid="ref-113">113</xref>] demonstrated that it is feasible to train phishing-detection models collaboratively across distributed nodes using FL and blockchain, while keeping transaction data private on the Ethereum network. The FedPhishLLM framework [<xref ref-type="bibr" rid="ref-114">114</xref>] took things even further by combining FL with fine-tuned multimodal large language models for phishing detection, representing one of the first attempts to merge all three technologies.</p>
<p>To further phishing detection, blockchain-enabled federated learning is emerging, with many recent studies presenting frameworks to address security, privacy, and scalability challenges. In an early comprehensive taxonomy of blockchain-enabled federated learning, Qu et al. [<xref ref-type="bibr" rid="ref-92">92</xref>] classified techniques by architectural frameworks and consensus mechanisms, Jiang et al. [<xref ref-type="bibr" rid="ref-115">115</xref>] conducted a comprehensive survey of blockchain-based federated learning in IoT settings, examining interactions among blockchain participants throughout the federated learning process and categorizing frameworks into three classes based on the level of integration between blockchain and federated learning. In addition, Cai et al. [<xref ref-type="bibr" rid="ref-116">116</xref>] investigated the uses of both benefits, challenges, and possible solutions; they stress model verification strategies.</p>
<p>Multiple frameworks have shown that combining federated learning with blockchain is effective in real-world applications. Vijay Anand et al. [<xref ref-type="bibr" rid="ref-117">117</xref>] integrated federated learning with LSTM autoencoders to safeguard blockchain network transactions, enabling diverse datasets across nodes to contribute to a global model without exchanging raw data. Their framework achieved strong anomaly detection performance while maintaining data Privacy through decentralized training. Shalan et al. [<xref ref-type="bibr" rid="ref-118">118</xref>] use knowledge distillation, transfer learning, and blockchain-enhanced FL to enable multiple IoT devices with different computing capabilities to collaborate while ensuring security via blockchain-based role-based access control.</p>
<p>The preservation of privacy in blockchain-enabled federated learning systems has caused increased interest among the research communities. Abuzied et al. [<xref ref-type="bibr" rid="ref-119">119</xref>] proposed FLoBC, a distributed ledger-based expandable privacy-preserving FL framework, and explored node update synchronization algorithms and associated performance trade-offs. Chen et al. [<xref ref-type="bibr" rid="ref-120">120</xref>] proposed a blockchain-based federated learning framework that establishes trust and fairness while counteracting poisoning attacks through federated computation. In study [<xref ref-type="bibr" rid="ref-121">121</xref>], the BPRFL framework was proposed to detect malicious clients and eliminate their intrusions. Their approach uses federated learning with differential privacy. Their framework consists of tracking each client&#x2019;s behavior, setting two rules they must pass, and accepting updates only from participants. Their methodology achieved high accuracy.</p>
<p>In the study by Ali et al. FL-BCID: A Lightweight and Smart Model-Update System for Industrial IoT Systems in Decentralized Environments [<xref ref-type="bibr" rid="ref-122">122</xref>]. This paper proposes an FL-based intrusion detection system for industrial IoT environments; it uses a lightweight technique that updates the model via smart contracts and the Blockchain. Odeh and Taleb [<xref ref-type="bibr" rid="ref-123">123</xref>] proposed another combination of the two technologies, integrating federated learning with Blockchain and smart contracts, leveraging the Merkle tree to enhance integrity and eliminate unauthorized access to the network. In addition, a dual-layer hybrid blockchain&#x2013;SecureChainFL&#x2013;was proposed [<xref ref-type="bibr" rid="ref-124">124</xref>]. The public Blockchain ensures cryptographic auditability, and the private Blockchain (or, in some cases, a federated ledger) is used for model validation and aggregation. Moreover, for privacy protection, zero-knowledge proofs and homomorphic encryption are used.</p>
<p>However, several substantial obstacles persist. On public networks [<xref ref-type="bibr" rid="ref-94">94</xref>,<xref ref-type="bibr" rid="ref-97">97</xref>], transaction fees and consensus latency on blockchains can significantly delay model updates. Due to storage constraints, model parameters cannot be stored entirely on the Blockchain; as a result, systems depend on off-chain storage using IPFS [<xref ref-type="bibr" rid="ref-95">95</xref>,<xref ref-type="bibr" rid="ref-98">98</xref>]. In addition, the communication overhead inherent in federated learning, combined with blockchain verification costs, is a major stumbling block to large-scale real-time phishing detection [<xref ref-type="bibr" rid="ref-96">96</xref>,<xref ref-type="bibr" rid="ref-106">106</xref>]. Participating clients generally have non-identical data distributions, which constitute a substantial statistical challenge that blockchain technology cannot solve on its own [<xref ref-type="bibr" rid="ref-107">107</xref>,<xref ref-type="bibr" rid="ref-110">110</xref>]. Furthermore, most proposed frameworks are only evaluated in controlled lab settings, leaving many open questions about their capacity and performance in practical phishing detection [<xref ref-type="bibr" rid="ref-108">108</xref>,<xref ref-type="bibr" rid="ref-112">112</xref>]. Most importantly, the field lacks standardized benchmarks, which makes it difficult to compare various approaches fairly and consistently [<xref ref-type="bibr" rid="ref-109">109</xref>]. <xref ref-type="table" rid="table-9">Table 9</xref> summarizes the key studies on federated learning and blockchain integration.</p>
<table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Summary of research papers on federated learning and blockchain integration.</title>
</caption>
<table>
<colgroup>
<col align="center" width="8mm"/>
<col align="center" width="27mm"/>
<col align="center" width="22mm"/>
<col align="center" width="20mm"/>
<col align="center" width="40mm"/>
<col align="center" width="27mm"/> </colgroup>
<thead>
<tr>
<th>Ref.</th>
<th>Method</th>
<th>Data</th>
<th>Result</th>
<th>Innovations</th>
<th>Limitations</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-99">99</xref>]</td>
<td>FL &#x002B; Blockchain &#x002B; smart contracts</td>
<td>Edge computing data</td>
<td>Improved efficiency</td>
<td>Scalable architecture with smart contract model verification</td>
<td>Tested only in controlled environment</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-100">100</xref>]</td>
<td>FL &#x002B; Blockchain &#x002B; explainable AI</td>
<td>IoT network traffic</td>
<td>Improved detection</td>
<td>Combined blockchain, FL, and XAI for intrusion detection</td>
<td>High computational overhead</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-113">113</xref>]</td>
<td>FL &#x002B; Blockchain phishing detection</td>
<td>Ethereum transactions</td>
<td>Accuracy: 95.8%</td>
<td>Decentralized defense for Ethereum phishing using FL</td>
<td>Limited to Ethereum transactions</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-114">114</xref>]</td>
<td>FL &#x002B; LLM &#x002B; Blockchain</td>
<td>Multimodal phishing data</td>
<td>Improved accuracy</td>
<td>First framework combining FL with multimodal LLMs for phishing detection</td>
<td>High resource requirements for LLM fine-tuning</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-102">102</xref>]</td>
<td>BLADE-FL decentralized</td>
<td>Distributed datasets</td>
<td>Improved convergence</td>
<td>Blockchain-assisted decentralized FL with resource allocation</td>
<td>Communication overhead from blockchain</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-103">103</xref>]</td>
<td>FL &#x002B; Blockchain vehicular</td>
<td>Vehicular network traffic</td>
<td>Accuracy: 97.5%</td>
<td>Collaborative intrusion detection preserving vehicle privacy</td>
<td>Limited to vehicular networks</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-104">104</xref>]</td>
<td>FL &#x002B; Blockchain for IoT</td>
<td>IoT device data</td>
<td>Accuracy: 96.2%</td>
<td>Privacy-preserving FL for resource-limited IoT devices</td>
<td>Constrained by IoT device capabilities</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-105">105</xref>]</td>
<td>FL &#x002B; Blockchain industrial IoT</td>
<td>Industrial IoT data</td>
<td>Improved privacy</td>
<td>Privacy-preserved data sharing in industrial IoT environments</td>
<td>Scalability not fully evaluated</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-101">101</xref>]</td>
<td>FL &#x002B; Blockchain fair incentives</td>
<td>Distributed datasets</td>
<td>Improved fairness</td>
<td>Fair incentive mechanism and secure aggregation</td>
<td>Free-rider issue partially addressed</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-117">117</xref>]</td>
<td>FL &#x002B; LSTM autoencoder</td>
<td>Blockchain transactions</td>
<td>Strong anomaly detection</td>
<td>FL with LSTM autoencoders for blockchain transaction security</td>
<td>Limited to anomaly detection</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-118">118</xref>]</td>
<td>Knowledge distillation &#x002B; blockchain FL</td>
<td>Smart home IoT data</td>
<td>Improved security</td>
<td>Knowledge distillation and transfer learning with blockchain RBAC</td>
<td>Limited to smart home environments</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-119">119</xref>]</td>
<td>FLoBC framework</td>
<td>Distributed datasets</td>
<td>Improved privacy</td>
<td>Distributed ledger-based scalable privacy-preserving FL</td>
<td>Node synchronization trade-offs</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-120">120</xref>]</td>
<td>Credible FL framework</td>
<td>Distributed datasets</td>
<td>Improved trust</td>
<td>Blockchain-based FL with trust and fairness against poisoning</td>
<td>Computational overhead of verification</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-123">123</xref>]</td>
<td>BETAC-IoT</td>
<td>IoT network data</td>
<td>Improved security</td>
<td>Blockchain, smart contracts, FL, and Merkle tree verification</td>
<td>Complexity of multi-technology integration</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-122">122</xref>]</td>
<td>FL-BCID</td>
<td>Industrial IoT traffic</td>
<td>Improved detection</td>
<td>Lightweight FL with smart contract-enabled blockchain for IDS</td>
<td>Limited to industrial IoT scenarios</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-121">121</xref>]</td>
<td>BPRFL</td>
<td>Distributed datasets</td>
<td>Higher accuracy</td>
<td>Noise-separated differential privacy with reputation consensus</td>
<td>Performance under extreme non-IID data unclear</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-124">124</xref>]</td>
<td>SecureChainFL</td>
<td>Distributed datasets</td>
<td>Enhanced privacy</td>
<td>Hybrid dual-layer blockchain with zero-knowledge proofs and homomorphic encryption</td>
<td>Scalability of ZKP verification not tested</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Discussion</title>
<sec id="s5_1">
<label>5.1</label>
<title>Dataset Distribution and Analysis</title>
<p>This paper delivered an exhaustive analysis of phishing detection techniques (and their privacy-preserving extensions). The literature was categorized into seven approaches: Machine learning (ML), deep learning (DL), hybrid (Hybrid), large language models (LLM), federated learning (FL), FL &#x002B; blockchain (FL &#x002B; Blockchain), and blockchain (Blockchain). Our results show a substantial increase in the number of publications on phishing detection from 2022 onwards, with 2023&#x2013;2025 accounting for more than 52% of all papers we have reviewed in this area. The substantial increase in the number of papers from 2020 to 2021 is due to the COVID-19 pandemic, which led to a massive migration of the world&#x2019;s workforce to remote work environments and a corresponding increase in phishing attacks. The current high rate of publication on phishing detection is driven mainly by growing interest in privacy-preserving methods.</p>
<p>We provide a statistical evaluation of the detection performance of the respective methods using the mean accuracy and the standard deviation (see <xref ref-type="table" rid="table-4">Tables 4</xref>&#x2013;<xref ref-type="table" rid="table-9">9</xref>). <xref ref-type="fig" rid="fig-11">Fig. 11</xref> illustrates that centralized methods outperform decentralized methods concerning their average accuracy. While large language models achieve an average accuracy of 99.1 99.1% (<inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula>1.1%) followed by deep learning with 98.5% (<inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula>1.0%), the average accuracy of federated learning (FL) is slightly lower at 92.8% (<inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula>7.0%). However, the combination of federated learning with blockchain improves the average accuracy to 96.5% (<inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula>0.7%) and thus exceeds the average accuracy of federated learning alone by 3.7%. Furthermore, the use of blockchain reduces the variance of average accuracy, i.e., it leads to more consistent detection. Finally, the difference in average accuracy between centralized and privacy-preserving methods is only 2.6%, indicating further improvement in decentralized methods. In <xref ref-type="fig" rid="fig-12">Fig. 12</xref> shows the research papers from 2015 to 2025.</p>
<fig id="fig-11">
<label>Figure 11</label>
<caption>
<title>Statistical comparison of phishing detection approaches showing mean accuracy with standard deviation.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-11.tif"/>
</fig><fig id="fig-12">
<label>Figure 12</label>
<caption>
<title>Yearly distribution of reviewed research papers.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-12.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-13">Fig. 13</xref> shows the datasets used by all of the studies we reviewed. The &#x201C;Not Specified/Distributed&#x201D; dataset was the most frequently used. It was used in 11 of the studies we reviewed. The second-most-frequently used dataset was the IoT dataset, which was used in 8 of the studies. The Etherscan, self-collected datasets, and other single-use datasets were each used in 7 of the studies. Six of the studies used the PhishTank dataset, indicating moderate use of this dataset for phishing detection research. Nevertheless, Sven of the studies used private or personally collected forms from others for privacy reasons; they cannot access them. In order for us to verify the result, we need the dataset to be available; not identifying them is a major limitation.</p>
<fig id="fig-13">
<label>Figure 13</label>
<caption>
<title>Dataset distribution.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_78774-fig-13.tif"/>
</fig>
<p>As shown <xref ref-type="table" rid="table-10">Table 10</xref> previously in our review, the traditional centralized model in LLM and deep learning section can achieve an accuracy rate (up to 99.70%), while the decentralized model with the aggregated models can achieve (95.80%) at a cost, providing privacy. Our report shows the accuracy of phishing detection, privacy, and the trade-off between the two.</p>
<table-wrap id="table-10">
<label>Table 10</label>
<caption>
<title>Comparative analysis of phishing detection approaches across centralized and decentralized categories.</title>
</caption>
<table>
<colgroup>
<col align="center" width="17mm"/>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/>
<col align="center" width="17mm"/>
<col align="center" width="30mm"/>
<col align="center" width="30mm"/> </colgroup>
<thead>
<tr>
<th>Ref.</th>
<th>Method</th>
<th>Data</th>
<th>Result</th>
<th>Innovations</th>
<th>Limitations</th>
</tr>
</thead>
<tbody>
<tr>
<td align="center" colspan="6"><italic><bold>Machine Learning</bold></italic></td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td>XGBoost</td>
<td>PhishTank</td>
<td>Accuracy: 98.3%</td>
<td>Examined 12 classifiers</td>
<td>Noise impact on results</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-27">27</xref>]</td>
<td>SVM</td>
<td>IWSPA</td>
<td>Accuracy: 99.9%</td>
<td>Compared multiple ML models</td>
<td>Overfitting due to unbalanced dataset</td>
</tr>
<tr>
<td align="center" colspan="6"><italic><bold>Deep Learning</bold></italic></td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-29">29</xref>]</td>
<td>CNN</td>
<td>Enron, SpamAssassin</td>
<td>Accuracy: 99.2%</td>
<td>CNN for word identification</td>
<td>High computational power</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-32">32</xref>]</td>
<td>LSTM</td>
<td>AI-generated</td>
<td>Accuracy: 99.5%</td>
<td>Identifies AI phishing emails</td>
<td>Phishing tactics may not be fully covered</td>
</tr>
<tr>
<td align="center" colspan="6"><italic><bold>Hybrid Approaches</bold></italic></td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-35">35</xref>]</td>
<td>HELPED</td>
<td>Combined dataset</td>
<td>Accuracy: 99.43%</td>
<td>Novel layered technique</td>
<td>High computational power</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-36">36</xref>]</td>
<td>GCN-NLP</td>
<td>CLAIR Fraud</td>
<td>Accuracy: 98.2%</td>
<td>Utilizing GCN with NLP</td>
<td>Text-based only</td>
</tr>
<tr>
<td align="center" colspan="6"><italic><bold>Large Language Models (LLMs)</bold></italic></td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-40">40</xref>]</td>
<td>ChatSpam<break/> Detector (GPT-4)</td>
<td>Email dataset</td>
<td>Accuracy: 99.70%</td>
<td>Structured prompts for LLM analysis</td>
<td>Dependent on GPT-4 API cost</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-42">42</xref>]</td>
<td>IPSDM (DistilBERT/RoBERTa)</td>
<td>Balanced &#x0026; imbalanced datasets</td>
<td>Accuracy: 97.50%</td>
<td>Fine-tuned BERT-family transformers</td>
<td>Text-based features only</td>
</tr>
<tr>
<td align="center" colspan="6"><italic><bold>Federated Learning</bold></italic></td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-56">56</xref>]</td>
<td>FL/CNN-LSTM</td>
<td>UCI SMS</td>
<td>Accuracy: 99.19%</td>
<td>CNN-LSTM integrated with FL</td>
<td>Lack of advanced feature engineering</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-57">57</xref>]</td>
<td>FL/BERT</td>
<td>Collected dataset</td>
<td>Accuracy: 96.1%</td>
<td>FL integrated with BERT</td>
<td>High computational power</td>
</tr>
<tr>
<td align="center" colspan="6"><italic><bold>FL &#x002B; Blockchain</bold></italic></td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-113">113</xref>]</td>
<td>FL &#x002B; Blockchain</td>
<td>Ethereum transactions</td>
<td>Accuracy: 95.8%</td>
<td>Decentralized defense for Ethereum phishing</td>
<td>Limited to Ethereum transactions</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-114">114</xref>]</td>
<td>FL &#x002B; LLM &#x002B; Blockchain</td>
<td>Multimodal phishing data</td>
<td>Improved accuracy</td>
<td>First FL &#x002B; multimodal LLM framework</td>
<td>High resource requirements for LLM fine-tuning</td>
</tr>
<tr>
<td align="center" colspan="6"><italic><bold>Blockchain</bold></italic></td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-125">125</xref>]</td>
<td>Blockchain/CNN-LSTM, Bi-LSTM</td>
<td>Ethereum-lists</td>
<td>Accuracy: 99.72%</td>
<td>Different DL methods with blockchain</td>
<td>Imbalanced dataset</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-89">89</xref>]</td>
<td>Blockchain/GCN</td>
<td>Etherscan, XBlock</td>
<td>Accuracy: 98.11%</td>
<td>Double-layer graph convolutional network</td>
<td>Limited dataset</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>One of the most notable conclusions derived from this analysis is that, while data-set imbalance is prevalent across the studies we analyzed, it was rarely fully addressed. In many studies reporting proportions of each sample type, the number of legitimate samples greatly outnumbered the number of phishing samples, typically 2:1 or more. The major problem is the overrated accuracy of term detection of legitimate samples, rather than the ability to detect phishing attacks. If we used the term accuracy, it reflects the system&#x2019;s ability to detect and classify. In the Study [<xref ref-type="bibr" rid="ref-35">35</xref>], the problem was investigated using a learning technique to handle class imbalance. while study [<xref ref-type="bibr" rid="ref-34">34</xref>] applied data sanitization and class balancing through randomization. Although the majority of reviewed studies did not use methods for reducing class imbalance, including oversampling (SMOTE), undersampling, cost-sensitive learning, and/or data augmentation; it seems this is an area that needs attention as accuracy, the most frequently used metric in the field to assess the performance of the detection system, is not always the best measure of performance when dealing with unbalanced datasets. Therefore, future studies should evaluate detection systems using additional measures (<xref ref-type="table" rid="table-11">Table 11</xref>), e.g., precision, recall, F1 score, and false positive rate (FPR), in addition to accuracy, to better reflect how well detection systems perform when operating with large differences in sample sizes between classes.</p>
<table-wrap id="table-11">
<label>Table 11</label>
<caption>
<title>Summary of main datasets used in phishing detection studies.</title>
</caption>
<table>
<colgroup>
<col align="center" width="32mm"/>
<col align="center" width="12mm"/>
<col align="center" width="23mm"/>
<col align="center" width="11mm"/>
<col align="center" width="9mm"/>
<col align="center" width="8mm"/>
<col align="center" width="8mm"/>
<col align="center" width="17mm"/>
<col align="center" width="14mm"/> </colgroup>
<thead>
<tr>
<th>Dataset</th>
<th>Type</th>
<th>Features</th>
<th>Phishing</th>
<th>Benign</th>
<th>Ratio (P:B)</th>
<th>Avail.</th>
<th>Used in Study</th>
<th>Ref.</th>
</tr>
</thead>
<tbody>
<tr>
<td>PhishTank</td>
<td>Webpage</td>
<td>Logo extraction</td>
<td>N/S</td>
<td>N/S</td>
<td>Unk.</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-25">25</xref>,<xref ref-type="bibr" rid="ref-26">26</xref>,<xref ref-type="bibr" rid="ref-35">35</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-21">21</xref>]</td>
</tr>
<tr>
<td>Alexa</td>
<td>Webpage</td>
<td>Logo extraction</td>
<td>N/A</td>
<td>N/S</td>
<td>N/A</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-26">26</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-21">21</xref>]</td>
</tr>
<tr>
<td>IWSPA Email Dataset</td>
<td>Email</td>
<td>Headers, content</td>
<td>1113</td>
<td>9170</td>
<td>1:8.2</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-9">9</xref>,<xref ref-type="bibr" rid="ref-54">54</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-126">126</xref>]</td>
</tr>
<tr>
<td>Phishing Dataset</td>
<td>Webpage</td>
<td>URL extraction</td>
<td>4898</td>
<td>6157</td>
<td>1:1.3</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-9">9</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-127">127</xref>]</td>
</tr>
<tr>
<td>OpenPhish</td>
<td>Webpage</td>
<td>URL extraction</td>
<td>N/S</td>
<td>N/S</td>
<td>Unk.</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-8">8</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-128">128</xref>]</td>
</tr>
<tr>
<td>AI-generated emails</td>
<td>Email</td>
<td>Email content</td>
<td>N/S</td>
<td>N/S</td>
<td>Unk.</td>
<td>N/A</td>
<td>[<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>ISH Dataset</td>
<td>Image</td>
<td>Image extraction</td>
<td>920</td>
<td>810</td>
<td>1:0.9</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-128">128</xref>]</td>
</tr>
<tr>
<td>Challenge dataset 1,2</td>
<td>Image</td>
<td>Image extraction</td>
<td>N/D</td>
<td>N/D</td>
<td>Unk.</td>
<td>N/D</td>
<td>[<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>UCI</td>
<td>Webpage</td>
<td>URL extraction</td>
<td>N/S</td>
<td>N/S</td>
<td>Unk.</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-25">25</xref>,<xref ref-type="bibr" rid="ref-34">34</xref>,<xref ref-type="bibr" rid="ref-35">35</xref>,<xref ref-type="bibr" rid="ref-50">50</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-129">129</xref>]</td>
</tr>
<tr>
<td>MillerSmiles</td>
<td>Webpage</td>
<td>URL extraction</td>
<td>N/S</td>
<td>N/S</td>
<td>Unk.</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-130">130</xref>]</td>
</tr>
<tr>
<td>TREC</td>
<td>Email</td>
<td>Email content</td>
<td>50071</td>
<td>25217</td>
<td>2:1</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-16">16</xref>,<xref ref-type="bibr" rid="ref-32">32</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-131">131</xref>]</td>
</tr>
<tr>
<td>GenSpam</td>
<td>Email</td>
<td>Email content</td>
<td>30761</td>
<td>9186</td>
<td>3.3:1</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-16">16</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>SpamAssassin</td>
<td>Email</td>
<td>Email content</td>
<td>1892</td>
<td>4144</td>
<td>1:2.2</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-16">16</xref>,<xref ref-type="bibr" rid="ref-32">32</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-132">132</xref>,<xref ref-type="bibr" rid="ref-133">133</xref>]</td>
</tr>
<tr>
<td>Enron</td>
<td>Email</td>
<td>Email content</td>
<td>17110</td>
<td>16544</td>
<td>1:0.97</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-16">16</xref>,<xref ref-type="bibr" rid="ref-30">30</xref>,<xref ref-type="bibr" rid="ref-32">32</xref>,<xref ref-type="bibr" rid="ref-50">50</xref>,<xref ref-type="bibr" rid="ref-54">54</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-134">134</xref>]</td>
</tr>
<tr>
<td>Ling spam</td>
<td>Email</td>
<td>Email content</td>
<td>481</td>
<td>2412</td>
<td>1:5.0</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-16">16</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-135">135</xref>]</td>
</tr>
<tr>
<td>spam.csv</td>
<td>Email</td>
<td>Email content</td>
<td>N/S</td>
<td>N/S</td>
<td>Unk.</td>
<td>N/S</td>
<td>[<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>emails.csv</td>
<td>Email</td>
<td>Email content</td>
<td>N/S</td>
<td>N/S</td>
<td>Unk.</td>
<td>N/S</td>
<td>[<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>Fraud dataset</td>
<td>Email</td>
<td>Email content</td>
<td>3685</td>
<td>4894</td>
<td>1:1.3</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-28">28</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>NapierOne</td>
<td>Email, URL</td>
<td>Email content</td>
<td>N/S</td>
<td>N/S</td>
<td>Unk.</td>
<td>N/S</td>
<td>[<xref ref-type="bibr" rid="ref-35">35</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>PhishingEmailData</td>
<td>Email</td>
<td>Email content</td>
<td>N/S</td>
<td>N/S</td>
<td>Unk.</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-34">34</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>Open Phish Webpages</td>
<td>Webpage</td>
<td>Webpage content</td>
<td>1500</td>
<td>3000</td>
<td>1:2.0</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-33">33</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-128">128</xref>]</td>
</tr>
<tr>
<td>Ethereum Dataset</td>
<td>Transaction</td>
<td>TX details</td>
<td>N/S</td>
<td>N/S</td>
<td>Unk.</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-88">88</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-91">91</xref>]</td>
</tr>
<tr>
<td>PhishBlock</td>
<td>URL</td>
<td>Phishing URL</td>
<td>N/D</td>
<td>N/D</td>
<td>Unk.</td>
<td>Private</td>
<td>[<xref ref-type="bibr" rid="ref-80">80</xref>,<xref ref-type="bibr" rid="ref-86">86</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>Microsoft 365</td>
<td>Email</td>
<td>Email content</td>
<td>N/D</td>
<td>N/D</td>
<td>Unk.</td>
<td>Private</td>
<td>[<xref ref-type="bibr" rid="ref-50">50</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>CLAIR Fraud Dataset</td>
<td>Email</td>
<td>Email content</td>
<td>3685</td>
<td>4894</td>
<td>1:1.3</td>
<td>Restr.</td>
<td>[<xref ref-type="bibr" rid="ref-36">36</xref>]</td>
<td>&#x2013;</td>
</tr>
<tr>
<td>Ethereum Wallet (LGBM)</td>
<td>Transaction</td>
<td>Behavioral &#x0026; TX</td>
<td>2179</td>
<td>7662</td>
<td>1:3.5</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-78">78</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-136">136</xref>]</td>
</tr>
<tr>
<td>Ethereum Ponzi &#x0026; Phishing (Xblock)</td>
<td>Transaction</td>
<td>Graph-based</td>
<td>2708</td>
<td>1397</td>
<td>1.9:1</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-84">84</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-137">137</xref>]</td>
</tr>
<tr>
<td>Etherscan Phishing Gangs</td>
<td>Transaction</td>
<td>On-chain TX</td>
<td>5363</td>
<td>330000&#x002B;</td>
<td>1:62</td>
<td>Public</td>
<td>[<xref ref-type="bibr" rid="ref-81">81</xref>]</td>
<td>[<xref ref-type="bibr" rid="ref-138">138</xref>]</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>As demonstrated by the numbers in <xref ref-type="table" rid="table-11">Table 11</xref>, an overwhelming class imbalance issue is apparent through all of the studies contained within this review. All but two of the datasets examined contain a significant level of imbalance. The worst example of imbalance is found with the Etherscan Phishing Gangs dataset where only one percent (1.6%) of all entries (5363 phishing out of 335,000&#x002B;) are labeled as phishing. On the other hand, balanced datasets have been identified in studies on the Enron Corpus (ratio 1:0.97), and in studies using the UCI Phishing Dataset (ratio 1:1.3). The class imbalance present in these highly unbalanced datasets will significantly affect how classifiers can be evaluated. It&#x2019;s possible for a classifier to predict all benign and still reach an accuracy greater than ninety-five percent while not finding even a single phishing entry. Therefore, it would be beneficial for researchers to include precision, recall, F1-Score, and false positive rate (FPR) along side accuracy when evaluating their models. Also, several datasets&#x2013;particularly those from federated learning studies&#x2013;do not provide information about the count of either phishing or benign examples, nor do they provide conditions under which they can be accessed, preventing independent verification. At a minimum, researchers conducting federated learning studies should provide the aggregate count of phishing vs. benign examples as well as the number of client participants so that others can reproduce the results without having to compromise data security.</p>

</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Answering Research Questions</title>
<p>This study identified four key research inquiries regarding methods for phishing detection, the need to identify additional data resources to improve the current dataset, and the need to provide a guide for future investigations.</p>
<sec id="s5_2_1">
<label>5.2.1</label>
<title>What Are the Major Approaches for Phishing Detection?</title>
<p>In this review, we looked at studies that applied traditional machine learning methods (Naive Bayes, Random Forests, SVMs) to identify and extract attributes of phishing content [<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-27">27</xref>]. In addition, we evaluated the application of a deep learning method [<xref ref-type="bibr" rid="ref-29">29</xref>,<xref ref-type="bibr" rid="ref-30">30</xref>,<xref ref-type="bibr" rid="ref-32">32</xref>&#x2013;<xref ref-type="bibr" rid="ref-34">34</xref>] using CNNs and LSTMs, as well as a hybrid method combining machine learning and deep learning. In [<xref ref-type="bibr" rid="ref-35">35</xref>,<xref ref-type="bibr" rid="ref-36">36</xref>], we identified two hybrid approaches that combine both methods for improved detection performance. Federated learning and blockchain were the focus of studies [<xref ref-type="bibr" rid="ref-55">55</xref>&#x2013;<xref ref-type="bibr" rid="ref-57">57</xref>,<xref ref-type="bibr" rid="ref-80">80</xref>,<xref ref-type="bibr" rid="ref-86">86</xref>&#x2013;<xref ref-type="bibr" rid="ref-89">89</xref>,<xref ref-type="bibr" rid="ref-125">125</xref>,<xref ref-type="bibr" rid="ref-139">139</xref>,<xref ref-type="bibr" rid="ref-140">140</xref>], whereas studies [<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-27">27</xref>,<xref ref-type="bibr" rid="ref-29">29</xref>,<xref ref-type="bibr" rid="ref-30">30</xref>,<xref ref-type="bibr" rid="ref-32">32</xref>&#x2013;<xref ref-type="bibr" rid="ref-34">34</xref>, <xref ref-type="bibr" rid="ref-37">37</xref>&#x2013;<xref ref-type="bibr" rid="ref-43">43</xref>] were focused on improving detection results. The large language models (BERT and GPT) described in [<xref ref-type="bibr" rid="ref-37">37</xref>&#x2013;<xref ref-type="bibr" rid="ref-43">43</xref>] demonstrate exceptional capabilities for understanding semantic content, exceeding expectations for BERT&#x2019;s ability to understand context and GPT&#x2019;s ability to generate a comprehensive representation of the content.</p>
</sec>
<sec id="s5_2_2">
<label>5.2.2</label>
<title>What Are the Limitations of Centralized and Decentralized Approaches?</title>
<p>The European Union EU designed the GDPR to protect individuals from unauthorized use of their personal data. Although it was developed to provide legal protections for individuals&#x2019; rights with regard to data privacy, centralized approaches [<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-27">27</xref>,<xref ref-type="bibr" rid="ref-29">29</xref>,<xref ref-type="bibr" rid="ref-30">30</xref>,<xref ref-type="bibr" rid="ref-32">32</xref>&#x2013;<xref ref-type="bibr" rid="ref-34">34</xref>,<xref ref-type="bibr" rid="ref-37">37</xref>&#x2013;<xref ref-type="bibr" rid="ref-43">43</xref>] rely on model training on a central server, which creates legal challenges when deploying those models. Decentralized methodologies [<xref ref-type="bibr" rid="ref-55">55</xref>&#x2013;<xref ref-type="bibr" rid="ref-57">57</xref>,<xref ref-type="bibr" rid="ref-80">80</xref>, <xref ref-type="bibr" rid="ref-86">86</xref>&#x2013;<xref ref-type="bibr" rid="ref-89">89</xref>,<xref ref-type="bibr" rid="ref-125">125</xref>,<xref ref-type="bibr" rid="ref-139">139</xref>,<xref ref-type="bibr" rid="ref-140">140</xref>] have exhibited potential advantages over centralized methods, as they can incur 1%&#x2013;3% accuracy loss due to trade-offs made to preserve user data at the device level. However, the greatest challenge for methodologies that can preserve accuracy is the lack of production-ready implementations. In addition, although blockchain-based studies [<xref ref-type="bibr" rid="ref-80">80</xref>,<xref ref-type="bibr" rid="ref-86">86</xref>&#x2013;<xref ref-type="bibr" rid="ref-89">89</xref>,<xref ref-type="bibr" rid="ref-125">125</xref>,<xref ref-type="bibr" rid="ref-139">139</xref>&#x2013;<xref ref-type="bibr" rid="ref-141">141</xref>] demonstrate high levels of security, they do not address computational inefficiencies.</p>
</sec>
<sec id="s5_2_3">
<label>5.2.3</label>
<title>What Are the Most Used Datasets in Phishing Detection Studies?</title>
<p>We researched many of the major datasets that have been studied, namely those related to URLs (such as PhishTank, Alexa, and OpenPhish) and email data (such as IWSPA, Enron, and Nazario). Despite their importance, we found that phishing techniques have changed over time, yet these established datasets do not reflect that change. The fact that so many studies use this same data set, which is well-balanced between actual and phishing examples, will provide the best possible accuracy and effectiveness for our study. Existing datasets differ in format; some include URLs, email content, and IP addresses.</p>
</sec>
<sec id="s5_2_4">
<label>5.2.4</label>
<title>What Are the Current Research Gaps and Future Directions in Privacy-Preserving Phishing Detection?</title>
<p>The key findings from our review include a major gap in combining blockchain and federated learning in production-ready systems, along with other gaps. We noticed that most of the papers we reviewed focused mainly on accuracy; they neglected other metrics such as precision, recall, F1-score, and false positives. Furthermore, large language models with federated learning were not used to detect phishing in a privacy-preserving manner. Additionally, there is a need for standardized multilingual benchmarks to evaluate phishing detection and to broaden its scope to include new and emerging types of phishing (e.g., mobile, voice, and IoT-based phishing). Further, the issue of class imbalance needs to be systematically addressed across all phishing detection studies using techniques such as SMOTE, cost-sensitive learning, and generative data augmentation to guarantee dependable, generalizable results.</p>
</sec>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Conclusions</title>
<p>The goal of this study was to analyze the detection of Phishing and the privacy concerns of users of the above categories, i.e., (1) Centralized Detection Methods (Machine Learning, Deep Learning, Hybrid Systems, Large Language Models), and (2) Decentralized Detection Methods (Federated Learning and Blockchain Technologies). The results of our study show that central training achieves very high accuracy; however, it also enables the exploitation of user data, raising serious privacy concerns and legal obligations. We investigated other available solutions, such as Federated Learning, in which the training process is executed locally while the weights are stored on the server. At the same time, the model parameters are stored on the server. However, we found that there is currently a lack of understanding of how these systems function under intentional attacks. Therefore, we suggest that future studies create an expanded dataset of the most recent phishing attempts and incorporate multiple privacy-preserving techniques.</p>
</sec>
<sec sec-type="supplementary-material" id="s7">
<title>Supplementary Materials</title>
<supplementary-material id="SD1">
<media xlink:href="CMES_78774-s001.docx"/>
</supplementary-material>
<supplementary-material id="SD2">
<media xlink:href="CMES_78774-s002.docx"/>
</supplementary-material>
</sec>
</body>
<back>
<ack>
<p>The Researchers would like to thank the Deanship of Graduate Studies and Scientific Research at Qassim University for financial support (QU-APC-2026).</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>The Researchers would like to thank the Deanship of Graduate Studies and Scientific Research at Qassim University for financial support (QU-APC-2026).</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>Ghadi Almaktoom: Conceptualization, methodology, data collection, writing&#x2014;original draft. Suliman Aladhadh: Supervision, validation, writing&#x2014;review &#x0026; editing. Salim El Khediri: Supervision, validation, writing&#x2014;review &#x0026; editing. All authors reviewed and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>This is a review article. All data analyzed in this study are from previously published studies, which are cited in the reference list. No new datasets were generated.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable. This study is a literature review and did not involve human participants, animal subjects, or personal data collection.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest.</p>
</sec>
<sec>
<title>Supplementary Materials</title>
<p>The supplementary material is available online at <ext-link ext-link-type="uri" xlink:href="https://www.techscience.com/doi/10.32604/cmes.2026.078774/s1">https://www.techscience.com/doi/10.32604/cmes.2026.078774/s1</ext-link>. The PRISMA checklists are available in the supplementary files.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>APWG</collab></person-group>. <article-title>APWG phishing activity trends reports</article-title>. <year>2020 [cited 2026 Jan 1]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://apwg.org/trendsreports/">https://apwg.org/trendsreports/</ext-link>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Federal Bureau of Investigation</collab></person-group>. <article-title>2024 Internet crime report. Internet crime complaint center (IC3)</article-title>; <comment>2024 [cited 2026 Jan 1]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf">https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf</ext-link>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hijji</surname> <given-names>M</given-names></string-name>, <string-name><surname>Alam</surname> <given-names>G</given-names></string-name></person-group>. <article-title>A multivocal literature review on growing social engineering based cyber-attacks/threats during the COVID-19 pandemic: challenges and prospective solutions</article-title>. <source>IEEE Access</source>. <year>2021</year>;<volume>9</volume>:<fpage>7152</fpage>&#x2013;<lpage>69</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2020.3048839</pub-id>; <pub-id pub-id-type="pmid">34786300</pub-id></mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Di Pietro</surname> <given-names>R</given-names></string-name>, <string-name><surname>Raponi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Caprolu</surname> <given-names>M</given-names></string-name>, <string-name><surname>Cresci</surname> <given-names>S</given-names></string-name></person-group>. <source>New dimensions of information warfare</source>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2020</year>. p. <fpage>1</fpage>&#x2013;<lpage>4</lpage>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al-Qahtani</surname> <given-names>AF</given-names></string-name>, <string-name><surname>Cresci</surname> <given-names>S</given-names></string-name></person-group>. <article-title>The COVID-19 scamdemic: a survey of phishing attacks and their countermeasures during COVID-19</article-title>. <source>IET Inf Secur</source>. <year>2022</year>;<volume>16</volume>(<issue>5</issue>):<fpage>324</fpage>&#x2013;<lpage>45</lpage>; <pub-id pub-id-type="pmid">35942004</pub-id></mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Atlam</surname> <given-names>HF</given-names></string-name>, <string-name><surname>Oluwatimilehin</surname> <given-names>O</given-names></string-name></person-group>. <article-title>Business E-mail compromise phishing detection based on machine learning: a systematic literature review</article-title>. <source>Electronics</source>. <year>2022</year>;<volume>12</volume>(<issue>1</issue>):<fpage>42</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics12010042</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Nisha</surname> <given-names>T</given-names></string-name>, <string-name><surname>Bakari</surname> <given-names>D</given-names></string-name>, <string-name><surname>Shukla</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Business E-mail compromise&#x2014;techniques and countermeasures</article-title>. In: <conf-name>Proceedings of the 2021 International Conference on Advance Computing and Innovative Technologies in Engineering (ICACITE); 2021 Mar 4&#x2013;5</conf-name>; <publisher-loc>Greater Noida, India</publisher-loc>. p. <fpage>217</fpage>&#x2013;<lpage>22</lpage>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Karim</surname> <given-names>A</given-names></string-name>, <string-name><surname>Shahroz</surname> <given-names>M</given-names></string-name>, <string-name><surname>Mustofa</surname> <given-names>K</given-names></string-name>, <string-name><surname>Belhaouari</surname> <given-names>SB</given-names></string-name>, <string-name><surname>Joga</surname> <given-names>SRK</given-names></string-name></person-group>. <article-title>Phishing detection system through hybrid machine learning based on URL</article-title>. <source>IEEE Access</source>. <year>2023</year>;<volume>11</volume>(<issue>3</issue>):<fpage>36805</fpage>&#x2013;<lpage>22</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2023.3252366</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sahingoz</surname> <given-names>OK</given-names></string-name>, <string-name><surname>Bube</surname> <given-names>E</given-names></string-name>, <string-name><surname>Kugu</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Dephides: deep learning based phishing detection system</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>:<fpage>8052</fpage>&#x2013;<lpage>70</lpage>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Drainakis</surname> <given-names>G</given-names></string-name>, <string-name><surname>Katsaros</surname> <given-names>KV</given-names></string-name>, <string-name><surname>Pantazopoulos</surname> <given-names>P</given-names></string-name>, <string-name><surname>Sourlas</surname> <given-names>V</given-names></string-name>, <string-name><surname>Amditis</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Federated vs. centralized machine learning under privacy-elastic users: a comparative analysis</article-title>. In: <conf-name>Proceedings of the 2020 IEEE 19th International Symposium on Network Computing and Applications (NCA); 2020 Nov 24&#x2013;27; Online</conf-name>. p. <fpage>1</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>G</given-names></string-name>, <string-name><surname>Raghu</surname> <given-names>T</given-names></string-name>, <string-name><surname>Shi</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>Impact of the general data protection regulation on the global mobile app market: digital trade implications of data protection and privacy regulations</article-title>. <source>Inf Syst Res</source>. <year>2025</year>;<volume>36</volume>(<issue>2</issue>):<fpage>669</fpage>&#x2013;<lpage>89</lpage>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Frey</surname> <given-names>CB</given-names></string-name>, <string-name><surname>Presidente</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Privacy regulation and firm performance: estimating the GDPR effect globally</article-title>. <source>Econ Inq</source>. <year>2024</year>;<volume>62</volume>(<issue>3</issue>):<fpage>1074</fpage>&#x2013;<lpage>89</lpage>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhu</surname> <given-names>R</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>M</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Peng</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Investigation of personal data protection mechanism based on blockchain technology</article-title>. <source>Sci Rep</source>. <year>2023</year>;<volume>13</volume>(<issue>1</issue>):<fpage>21918</fpage>. doi:<pub-id pub-id-type="doi">10.1038/s41598-023-48661-w</pub-id>; <pub-id pub-id-type="pmid">38081862</pub-id></mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Nwaiku</surname> <given-names>M</given-names></string-name>, <string-name><surname>Diyan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Almakdi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Asghar</surname> <given-names>I</given-names></string-name>, <string-name><surname>Olugbenga</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Enhancing cloud security through anomaly detection: an artificial intelligence driven approach to secure authentication and authorization in SAML and OAuth 2.0 protocols</article-title>. In: <conf-name>Proceedings of the International Conference on Smart Systems and Emerging Technologies</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2024</year>. p. <fpage>432</fpage>&#x2013;<lpage>43</lpage>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Do</surname> <given-names>NQ</given-names></string-name>, <string-name><surname>Selamat</surname> <given-names>A</given-names></string-name>, <string-name><surname>Krejcar</surname> <given-names>O</given-names></string-name>, <string-name><surname>Herrera-Viedma</surname> <given-names>E</given-names></string-name>, <string-name><surname>Fujita</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Deep learning for phishing detection: taxonomy, current challenges and future directions</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>:<fpage>36429</fpage>&#x2013;<lpage>63</lpage>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Saleh</surname> <given-names>M</given-names></string-name>, <string-name><surname>&#x015E;ahin</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Phishing detection using machine learning and deep learning techniques: a review</article-title>. <source>J Comput Anal Appl</source>. <year>2024</year>;<volume>33</volume>(<issue>8</issue>):<fpage>894</fpage>&#x2013;<lpage>902</lpage>. doi:<pub-id pub-id-type="doi">10.52783/pst.1643</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Alkawaz</surname> <given-names>MH</given-names></string-name>, <string-name><surname>Steven</surname> <given-names>SJ</given-names></string-name>, <string-name><surname>Hajamydeen</surname> <given-names>AI</given-names></string-name>, <string-name><surname>Ramli</surname> <given-names>R</given-names></string-name></person-group>. <article-title>A comprehensive survey on identification and analysis of phishing website based on machine learning methods</article-title>. In: <conf-name>Proceedings of the 2021 IEEE 11th IEEE Symposium on Computer Applications &#x0026; Industrial Electronics (ISCAIE); 2021 Apr 3&#x2013;4</conf-name>; <publisher-loc>Penang, Malaysia</publisher-loc>. p. <fpage>82</fpage>&#x2013;<lpage>7</lpage>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kytidou</surname> <given-names>E</given-names></string-name>, <string-name><surname>Tsikriki</surname> <given-names>T</given-names></string-name>, <string-name><surname>Drosatos</surname> <given-names>G</given-names></string-name>, <string-name><surname>Rantos</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Machine learning techniques for phishing detection: a review of methods, challenges, and future directions</article-title>. <source>Intell Decis Technol</source>. <year>2025</year>;<volume>19</volume>(<issue>6</issue>):<fpage>4356</fpage>&#x2013;<lpage>79</lpage>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kavya</surname> <given-names>S</given-names></string-name>, <string-name><surname>Sumathi</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Staying ahead of phishers: a review of recent advances and emerging methodologies in phishing detection</article-title>. <source>Artif Intell Rev</source>. <year>2024</year>;<volume>58</volume>(<issue>2</issue>):<fpage>50</fpage>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wilk-Jakubowski</surname> <given-names>JL</given-names></string-name>, <string-name><surname>Pawlik</surname> <given-names>L</given-names></string-name>, <string-name><surname>Wilk-Jakubowski</surname> <given-names>G</given-names></string-name>, <string-name><surname>Sikora</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Machine learning and neural networks for phishing detection: a systematic review (2017&#x2013;2024)</article-title>. <source>Electronics</source>. <year>2025</year>;<volume>14</volume>(<issue>18</issue>):<fpage>3744</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics14183744</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alghenaim</surname> <given-names>M</given-names></string-name>, <string-name><surname>Alkawsi</surname> <given-names>G</given-names></string-name>, <string-name><surname>Barnhart</surname> <given-names>CR</given-names></string-name></person-group>. <article-title>the state of the art in AI-based phishing detection: a systematic literature review</article-title>. <source>Curr Future Trends AI Appl</source>. <year>2025</year>;<volume>1178</volume>:<fpage>431</fpage>&#x2013;<lpage>58</lpage>. doi:<pub-id pub-id-type="doi">10.1007/978-3-031-75091-5_23</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gupta</surname> <given-names>BB</given-names></string-name>, <string-name><surname>Gaurav</surname> <given-names>A</given-names></string-name>, <string-name><surname>Arya</surname> <given-names>V</given-names></string-name>, <string-name><surname>Attar</surname> <given-names>RW</given-names></string-name>, <string-name><surname>Bansal</surname> <given-names>S</given-names></string-name>, <string-name><surname>Alhomoud</surname> <given-names>A</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Advanced BERT and CNN-based computational model for phishing detection in enterprise systems</article-title>. <source>Comput Model Eng Sci</source>. <year>2024</year>;<volume>141</volume>(<issue>3</issue>):<fpage>2165</fpage>&#x2013;<lpage>83</lpage>. doi:<pub-id pub-id-type="doi">10.32604/cmes.2024.056473</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bari</surname> <given-names>N</given-names></string-name>, <string-name><surname>Saleem</surname> <given-names>T</given-names></string-name>, <string-name><surname>Shah</surname> <given-names>M</given-names></string-name>, <string-name><surname>Algarni</surname> <given-names>A</given-names></string-name>, <string-name><surname>Patel</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ullah</surname> <given-names>I</given-names></string-name></person-group>. <article-title>A filter-based feature selection framework to detect phishing URLs using stacking ensemble machine learning</article-title>. <source>Comput Model Eng Sci</source>. <year>2025</year>;<volume>145</volume>(<issue>1</issue>):<fpage>1167</fpage>&#x2013;<lpage>87</lpage>. doi:<pub-id pub-id-type="doi">10.32604/cmes.2025.070311</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Shahrivari</surname> <given-names>V</given-names></string-name>, <string-name><surname>Darabi</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Izadi</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Phishing detection using machine learning techniques</article-title>. <comment>arXiv:2009.11116. 2020</comment>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tan</surname> <given-names>CL</given-names></string-name>, <string-name><surname>Chiew</surname> <given-names>KL</given-names></string-name>, <string-name><surname>Wong</surname> <given-names>K</given-names></string-name>, <string-name><surname>Sze</surname> <given-names>SN</given-names></string-name></person-group>. <article-title>PhishWHO: phishing webpage detection via identity keywords extraction and target domain name finder</article-title>. <source>Decis Support Syst</source>. <year>2016</year>;<volume>88</volume>:<fpage>18</fpage>&#x2013;<lpage>27</lpage>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chiew</surname> <given-names>KL</given-names></string-name>, <string-name><surname>Chang</surname> <given-names>EH</given-names></string-name>, <string-name><surname>Sze</surname> <given-names>SN</given-names></string-name>, <string-name><surname>Tiong</surname> <given-names>WK</given-names></string-name></person-group>. <article-title>Utilisation of website logo for phishing detection</article-title>. <source>Comput Secur</source>. <year>2015</year>;<volume>54</volume>(<issue>1</issue>):<fpage>16</fpage>&#x2013;<lpage>26</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2015.07.006</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Harikrishnan</surname> <given-names>NB</given-names></string-name>, <string-name><surname>Vinayakumar</surname> <given-names>R</given-names></string-name>, <string-name><surname>Soman</surname> <given-names>KP</given-names></string-name></person-group>. <article-title>A machine learning approach towards phishing email detection: CEN-Security@IWSPA 2018</article-title>. In: <conf-name>Proceedings of the 1st Anti-Phishing Shared Task Pilot at 4th ACM IWSPA Co-Located with 8th ACM Conference on Data and Application Security and Privacy (CODASPY 2018); 2018 Mar 21</conf-name>; <publisher-loc>Tempe, AZ, USA</publisher-loc>. p. <fpage>21</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Kumar</surname> <given-names>N</given-names></string-name>, <string-name><surname>Sonowal</surname> <given-names>S</given-names></string-name>, <collab>Nishant</collab></person-group>. <article-title>Email spam detection using machine learning algorithms</article-title>. In: <conf-name>Proceedings of the 2020 Second International Conference on Inventive Research in Computing Applications (ICIRCA); 2020 Jul 15&#x2013;17</conf-name>; <publisher-loc>Coimbatore, India</publisher-loc>. p. <fpage>108</fpage>&#x2013;<lpage>13</lpage>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sharmin</surname> <given-names>T</given-names></string-name>, <string-name><surname>Di Troia</surname> <given-names>F</given-names></string-name>, <string-name><surname>Potika</surname> <given-names>K</given-names></string-name>, <string-name><surname>Stamp</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Convolutional neural networks for image spam detection</article-title>. <source>Inf Secur J A Glob Perspect</source>. <year>2020</year>;<volume>29</volume>(<issue>3</issue>):<fpage>103</fpage>&#x2013;<lpage>17</lpage>. doi:<pub-id pub-id-type="doi">10.1080/19393555.2020.1722867</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zavrak</surname> <given-names>S</given-names></string-name>, <string-name><surname>Yilmaz</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Email spam detection using hierarchical attention hybrid deep learning method</article-title>. <source>Expert Syst Appl</source>. <year>2023</year>;<volume>233</volume>(<issue>2</issue>):<fpage>120977</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.eswa.2023.120977</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ansari</surname> <given-names>MF</given-names></string-name>, <string-name><surname>Sharma</surname> <given-names>PK</given-names></string-name>, <string-name><surname>Dash</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Prevention of phishing attacks using AI-based cybersecurity awareness training</article-title>. <source>Prevention</source>. <year>2022</year>;<volume>3</volume>(<issue>6</issue>):<fpage>61</fpage>&#x2013;<lpage>72</lpage>. doi:<pub-id pub-id-type="doi">10.47893/ijssan.2022.1221</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Eze</surname> <given-names>CS</given-names></string-name>, <string-name><surname>Shamir</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Analysis and prevention of AI-based phishing email attacks</article-title>. <source>Electronics</source>. <year>2024</year>;<volume>13</volume>(<issue>10</issue>):<fpage>1839</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics13101839</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Md</surname> <given-names>AQ</given-names></string-name>, <string-name><surname>Jaiswal</surname> <given-names>D</given-names></string-name>, <string-name><surname>Daftari</surname> <given-names>J</given-names></string-name>, <string-name><surname>Haneef</surname> <given-names>S</given-names></string-name>, <string-name><surname>Iwendi</surname> <given-names>C</given-names></string-name>, <string-name><surname>Jain</surname> <given-names>SK</given-names></string-name></person-group>. <article-title>Efficient dynamic phishing safeguard system using neural boost phishing protection</article-title>. <source>Electronics</source>. <year>2022</year>;<volume>11</volume>(<issue>19</issue>):<fpage>3133</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics11193133</pub-id>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zaimi</surname> <given-names>R</given-names></string-name>, <string-name><surname>Hafidi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Lamia</surname> <given-names>M</given-names></string-name></person-group>. <article-title>A deep learning approach to detect phishing websites using CNN for privacy protection</article-title>. <source>Intell Decis Technol</source>. <year>2023</year>;<volume>17</volume>(<issue>3</issue>):<fpage>713</fpage>&#x2013;<lpage>28</lpage>. doi:<pub-id pub-id-type="doi">10.3233/idt-220307</pub-id>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bountakas</surname> <given-names>P</given-names></string-name>, <string-name><surname>Xenakis</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Helphed: hybrid ensemble learning phishing email detection</article-title>. <source>J Netw Comput Appl</source>. <year>2023</year>;<volume>210</volume>:<fpage>103545</fpage>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alhogail</surname> <given-names>A</given-names></string-name>, <string-name><surname>Alsabih</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Applying machine learning and natural language processing to detect phishing email</article-title>. <source>Comput Secur</source>. <year>2021</year>;<volume>110</volume>(<issue>8</issue>):<fpage>102414</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2021.102414</pub-id>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Heiding</surname> <given-names>F</given-names></string-name>, <string-name><surname>Schneier</surname> <given-names>B</given-names></string-name>, <string-name><surname>Vishwanath</surname> <given-names>A</given-names></string-name>, <string-name><surname>Bernstein</surname> <given-names>J</given-names></string-name>, <string-name><surname>Park</surname> <given-names>PS</given-names></string-name></person-group>. <article-title>Devising and detecting phishing emails using large language models</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>:<fpage>42131</fpage>&#x2013;<lpage>46</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2024.3375882</pub-id>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kulkarni</surname> <given-names>A</given-names></string-name>, <string-name><surname>Balachandran</surname> <given-names>V</given-names></string-name>, <string-name><surname>Divakaran</surname> <given-names>DM</given-names></string-name>, <string-name><surname>Das</surname> <given-names>T</given-names></string-name></person-group>. <article-title>From ML to LLM: evaluating the robustness of phishing web page detection models against adversarial attacks</article-title>. <source>Digit Threat Res Pract</source>. <year>2025</year>;<volume>6</volume>(<issue>2</issue>):<fpage>1</fpage>&#x2013;<lpage>25</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3737295</pub-id>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hua</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>P</given-names></string-name>, <string-name><surname>Lutchkus</surname> <given-names>P</given-names></string-name></person-group>. <article-title>How effective are large language models in detecting phishing emails?</article-title> <source>Issues Inf Syst</source>. <year>2024</year>;<volume>25</volume>(<issue>3</issue>):<fpage>327</fpage>&#x2013;<lpage>41</lpage>. doi:<pub-id pub-id-type="doi">10.48009/3_iis_2024_125</pub-id>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Koide</surname> <given-names>T</given-names></string-name>, <string-name><surname>Fukushi</surname> <given-names>N</given-names></string-name>, <string-name><surname>Nakano</surname> <given-names>H</given-names></string-name>, <string-name><surname>Chiba</surname> <given-names>D</given-names></string-name></person-group>. <source>Chatspamdetector: leveraging large language models for effective phishing email detection</source>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2024</year>. p. <fpage>297</fpage>&#x2013;<lpage>319</lpage>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Lee</surname> <given-names>J</given-names></string-name>, <string-name><surname>Lim</surname> <given-names>P</given-names></string-name>, <string-name><surname>Hooi</surname> <given-names>B</given-names></string-name>, <string-name><surname>Divakaran</surname> <given-names>DM</given-names></string-name></person-group>. <article-title>Multimodal large language models for phishing webpage detection and identification</article-title>. In: <conf-name>Proceedings of the 2024 APWG Symposium on Electronic Crime Research (eCrime); 2024 Sep 24&#x2013;26</conf-name>; <publisher-loc>Boston, WA, USA</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>13</lpage>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Jamal</surname> <given-names>S</given-names></string-name>, <string-name><surname>Wimmer</surname> <given-names>H</given-names></string-name></person-group>. <article-title>An improved transformer-based model for detecting phishing, spam, and ham: a large language model approach</article-title>. <comment>arXiv:2311.04913. 2023</comment>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mittal</surname> <given-names>A</given-names></string-name>, <string-name><surname>Engels</surname> <given-names>D</given-names></string-name>, <string-name><surname>Kommanapalli</surname> <given-names>H</given-names></string-name>, <string-name><surname>Sivaraman</surname> <given-names>R</given-names></string-name>, <string-name><surname>Chowdhury</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Phishing detection using natural language processing and machine learning</article-title>. <source>SMU Data Sci Rev</source>. <year>2022</year>;<volume>6</volume>(<issue>2</issue>):<fpage>14</fpage>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Korkmaz</surname> <given-names>A</given-names></string-name>, <string-name><surname>Alhonainy</surname> <given-names>A</given-names></string-name>, <string-name><surname>Rao</surname> <given-names>P</given-names></string-name></person-group>. <article-title>An evaluation of federated learning techniques for secure and privacy-preserving machine learning on medical datasets</article-title>. In: <conf-name>Proceedings of the 2022 IEEE Applied Imagery Pattern Recognition Workshop (AIPR); 2022 Oct 11&#x2013;13</conf-name>; <publisher-loc>Washington, DC, USA</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>7</lpage>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Amin</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Ahmad</surname> <given-names>S</given-names></string-name>, <string-name><surname>Loh</surname> <given-names>WK</given-names></string-name></person-group>. <article-title>Federated learning for Healthcare 5.0: a comprehensive survey, taxonomy, challenges, and solutions</article-title>. <source>Soft Comput</source>. <year>2025</year>;<volume>29</volume>(<issue>2</issue>):<fpage>673</fpage>&#x2013;<lpage>700</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s00500-025-10508-z</pub-id>.</mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nasajpour</surname> <given-names>M</given-names></string-name>, <string-name><surname>Pouriyeh</surname> <given-names>S</given-names></string-name>, <string-name><surname>Parizi</surname> <given-names>RM</given-names></string-name>, <string-name><surname>Han</surname> <given-names>M</given-names></string-name>, <string-name><surname>Mosaiyebzadeh</surname> <given-names>F</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>L</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Federated learning in smart healthcare: a survey of applications, challenges, and future directions</article-title>. <source>Electronics</source>. <year>2025</year>;<volume>14</volume>(<issue>9</issue>):<fpage>1750</fpage>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Pfitzner</surname> <given-names>B</given-names></string-name>, <string-name><surname>Steckhan</surname> <given-names>N</given-names></string-name>, <string-name><surname>Arnrich</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Federated learning in a medical context: a systematic literature review</article-title>. <source>ACM Trans Internet Technol</source>. <year>2021</year>;<volume>21</volume>(<issue>2</issue>):<fpage>1</fpage>&#x2013;<lpage>31</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3412357</pub-id>.</mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>B</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Song</surname> <given-names>J</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>R</given-names></string-name>, <string-name><surname>Li</surname> <given-names>T</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>L</given-names></string-name></person-group>. <article-title>DeepFed: federated deep learning for intrusion detection in industrial cyber-physical systems</article-title>. <source>IEEE Trans Ind Inform</source>. <year>2020</year>;<volume>17</volume>(<issue>8</issue>):<fpage>5615</fpage>&#x2013;<lpage>24</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tii.2020.3023430</pub-id>.</mixed-citation></ref>
<ref id="ref-49"><label>[49]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Javaheri</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Almutairi</surname> <given-names>L</given-names></string-name>, <string-name><surname>Moghadamnejad</surname> <given-names>N</given-names></string-name>, <string-name><surname>Younes</surname> <given-names>OS</given-names></string-name></person-group>. <article-title>Federated deep learning for anomaly detection in the Internet of Things</article-title>. <source>Comput Electr Eng</source>. <year>2023</year>;<volume>108</volume>(<issue>7</issue>):<fpage>108651</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.compeleceng.2023.108651</pub-id>.</mixed-citation></ref>
<ref id="ref-50"><label>[50]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ferrag</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Friha</surname> <given-names>O</given-names></string-name>, <string-name><surname>Maglaras</surname> <given-names>L</given-names></string-name>, <string-name><surname>Janicke</surname> <given-names>H</given-names></string-name>, <string-name><surname>Shu</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Federated deep learning for cyber security in the internet of things: concepts, applications, and experimental analysis</article-title>. <source>IEEE Access</source>. <year>2021</year>;<volume>9</volume>:<fpage>138509</fpage>&#x2013;<lpage>42</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2021.3118642</pub-id>.</mixed-citation></ref>
<ref id="ref-51"><label>[51]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jimenez-Gutierrez</surname> <given-names>DM</given-names></string-name>, <string-name><surname>Falkouskaya</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Hernandez-Ramos</surname> <given-names>JL</given-names></string-name>, <string-name><surname>Anagnostopoulos</surname> <given-names>A</given-names></string-name>, <string-name><surname>Chatzigiannakis</surname> <given-names>I</given-names></string-name>, <string-name><surname>Vitaletti</surname> <given-names>A</given-names></string-name></person-group>. <article-title>On the security and privacy of federated learning: a survey with attacks, defenses, frameworks, applications, and future directions</article-title>. <source>Inf Fusion</source>. <year>2026</year>;<volume>131</volume>:<fpage>104155</fpage>.</mixed-citation></ref>
<ref id="ref-52"><label>[52]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Guo</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhuang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Tong</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Dong</surname> <given-names>J</given-names></string-name></person-group>. <article-title>A comprehensive survey of federated transfer learning: challenges, methods and applications</article-title>. <source>Front Comput Sci</source>. <year>2024</year>;<volume>18</volume>(<issue>6</issue>):<fpage>186356</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s11704-024-40065-x</pub-id>.</mixed-citation></ref>
<ref id="ref-53"><label>[53]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kairouz</surname> <given-names>P</given-names></string-name>, <string-name><surname>McMahan</surname> <given-names>HB</given-names></string-name></person-group>. <article-title>Advances and open problems in federated learning</article-title>. <source>Found Trends Mach Learn</source>. <year>2021</year>;<volume>14</volume>(<issue>1&#x2013;2</issue>):<fpage>1</fpage>&#x2013;<lpage>210</lpage>. doi:<pub-id pub-id-type="doi">10.1561/2200000083</pub-id>.</mixed-citation></ref>
<ref id="ref-54"><label>[54]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zeng</surname> <given-names>R</given-names></string-name>, <string-name><surname>Mi</surname> <given-names>B</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>D</given-names></string-name></person-group>. <article-title>A federated learning framework based on CSP homomorphic encryption</article-title>. In: <conf-name>Proceedings of the 2023 IEEE 12th Data Driven Control and Learning Systems Conference (DDCLS); 2023 May 12&#x2013;14</conf-name>; <publisher-loc>Xiangtan, China</publisher-loc>. p. <fpage>196</fpage>&#x2013;<lpage>201</lpage>.</mixed-citation></ref>
<ref id="ref-55"><label>[55]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Sun</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Chong</surname> <given-names>N</given-names></string-name>, <string-name><surname>Ochiai</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Privacy-preserving phishing email detection based on federated learning and LSTM</article-title>. <comment>arXiv:2110.06025. 2021</comment>.</mixed-citation></ref>
<ref id="ref-56"><label>[56]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Dafni Rose</surname> <given-names>J</given-names></string-name>, <string-name><surname>JN</surname> <given-names>M</given-names></string-name>, <string-name><surname>JP</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Next-gen phishing detection system based on federated learning integrated CNN-LSTM for SMS communication</article-title>. In: <conf-name>Proceedings of the 2024 5th International Conference on Intelligent Communication Technologies and Virtual Mobile Networks (ICICV); 2024 Mar 11&#x2013;12; Online</conf-name>. p. <fpage>367</fpage>&#x2013;<lpage>72</lpage>.</mixed-citation></ref>
<ref id="ref-57"><label>[57]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Thapa</surname> <given-names>C</given-names></string-name>, <string-name><surname>Tang</surname> <given-names>JW</given-names></string-name>, <string-name><surname>Abuadbba</surname> <given-names>A</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Camtepe</surname> <given-names>S</given-names></string-name>, <string-name><surname>Nepal</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Evaluation of federated learning in phishing email detection</article-title>. <source>Sensors</source>. <year>2023</year>;<volume>23</volume>(<issue>9</issue>):<fpage>4346</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s23094346</pub-id>; <pub-id pub-id-type="pmid">37177549</pub-id></mixed-citation></ref>
<ref id="ref-58"><label>[58]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nofer</surname> <given-names>M</given-names></string-name>, <string-name><surname>Gomber</surname> <given-names>P</given-names></string-name>, <string-name><surname>Hinz</surname> <given-names>O</given-names></string-name>, <string-name><surname>Schiereck</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Blockchain</article-title>. <source>Bus Inf Syst Eng</source>. <year>2017</year>;<volume>59</volume>(<issue>3</issue>):<fpage>183</fpage>&#x2013;<lpage>7</lpage>.</mixed-citation></ref>
<ref id="ref-59"><label>[59]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Swan</surname> <given-names>M</given-names></string-name></person-group>. <source>Blockchain: blueprint for a new economy</source>. <publisher-loc>Sebastopol, CA, USA</publisher-loc>: <publisher-name>O&#x2019;Reilly Media, Inc.</publisher-name>; <year>2015</year>.</mixed-citation></ref>
<ref id="ref-60"><label>[60]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Esmaili</surname> <given-names>M</given-names></string-name>, <string-name><surname>Christensen</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Performance modeling of public permissionless blockchains: a survey</article-title>. <source>ACM Comput Surv</source>. <year>2025</year>;<volume>57</volume>(<issue>7</issue>):<fpage>1</fpage>&#x2013;<lpage>35</lpage>.</mixed-citation></ref>
<ref id="ref-61"><label>[61]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Azaria</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ekblaw</surname> <given-names>A</given-names></string-name>, <string-name><surname>Vieira</surname> <given-names>T</given-names></string-name>, <string-name><surname>Lippman</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Medrec: using blockchain for medical data access and permission management</article-title>. In: <conf-name>2016 2nd International Conference on Open and Big Data (OBD); 2016 Aug 22&#x2013;24</conf-name>; <publisher-loc>Vienna, Austria</publisher-loc>. p. <fpage>25</fpage>&#x2013;<lpage>30</lpage>.</mixed-citation></ref>
<ref id="ref-62"><label>[62]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Islam</surname> <given-names>I</given-names></string-name>, <string-name><surname>Munim</surname> <given-names>KM</given-names></string-name>, <string-name><surname>Oishwee</surname> <given-names>SJ</given-names></string-name>, <string-name><surname>Islam</surname> <given-names>AN</given-names></string-name>, <string-name><surname>Islam</surname> <given-names>MN</given-names></string-name></person-group>. <article-title>A critical review of concepts, benefits, and pitfalls of blockchain technology using concept map</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>68333</fpage>&#x2013;<lpage>41</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2020.2985647</pub-id>.</mixed-citation></ref>
<ref id="ref-63"><label>[63]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zheng</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Xie</surname> <given-names>S</given-names></string-name>, <string-name><surname>Dai</surname> <given-names>HN</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Blockchain challenges and opportunities: a survey</article-title>. <source>Int J Web Grid Serv</source>. <year>2018</year>;<volume>14</volume>(<issue>4</issue>):<fpage>352</fpage>&#x2013;<lpage>75</lpage>. doi:<pub-id pub-id-type="doi">10.1504/ijwgs.2018.095647</pub-id>.</mixed-citation></ref>
<ref id="ref-64"><label>[64]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Scicchitano</surname> <given-names>F</given-names></string-name>, <string-name><surname>Liguori</surname> <given-names>A</given-names></string-name>, <string-name><surname>Guarascio</surname> <given-names>M</given-names></string-name>, <string-name><surname>Ritacco</surname> <given-names>E</given-names></string-name>, <string-name><surname>Manco</surname> <given-names>G</given-names></string-name></person-group>. <article-title>A deep learning approach for detecting security attacks on blockchain</article-title>. <source>CEUR Workshop Proc</source>. <year>2020</year>;<volume>2597</volume>:<fpage>212</fpage>&#x2013;<lpage>22</lpage>.</mixed-citation></ref>
<ref id="ref-65"><label>[65]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ashfaq</surname> <given-names>T</given-names></string-name>, <string-name><surname>Khalid</surname> <given-names>R</given-names></string-name>, <string-name><surname>Yahaya</surname> <given-names>AS</given-names></string-name>, <string-name><surname>Aslam</surname> <given-names>S</given-names></string-name>, <string-name><surname>Azar</surname> <given-names>AT</given-names></string-name>, <string-name><surname>Alsafari</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>A machine learning and blockchain based efficient fraud detection mechanism</article-title>. <source>Sensors</source>. <year>2022</year>;<volume>22</volume>(<issue>19</issue>):<fpage>7162</fpage>; <pub-id pub-id-type="pmid">36236255</pub-id></mixed-citation></ref>
<ref id="ref-66"><label>[66]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yan</surname> <given-names>C</given-names></string-name>, <string-name><surname>Han</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Du</surname> <given-names>D</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Phishing behavior detection on different blockchains via adversarial domain adaptation</article-title>. <source>Cybersecurity</source>. <year>2024</year>;<volume>7</volume>(<issue>1</issue>):<fpage>45</fpage>. doi:<pub-id pub-id-type="doi">10.1186/s42400-024-00237-5</pub-id>.</mixed-citation></ref>
<ref id="ref-67"><label>[67]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Du</surname> <given-names>W</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>RR</given-names></string-name></person-group>. <article-title>Follow the vine to get the melon: a deep framework for blockchain phishing fraud detection</article-title>. <source>Decis Support Syst</source>. <year>2025</year>;<volume>199</volume>:<fpage>114555</fpage>.</mixed-citation></ref>
<ref id="ref-68"><label>[68]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nouman</surname> <given-names>M</given-names></string-name>, <string-name><surname>Qasim</surname> <given-names>U</given-names></string-name>, <string-name><surname>Nasir</surname> <given-names>H</given-names></string-name>, <string-name><surname>Almasoud</surname> <given-names>A</given-names></string-name>, <string-name><surname>Imran</surname> <given-names>M</given-names></string-name>, <string-name><surname>Javaid</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Malicious node detection using machine learning and distributed data storage using blockchain in WSNs</article-title>. <source>IEEE Access</source>. <year>2023</year>;<volume>11</volume>(<issue>5</issue>):<fpage>6106</fpage>&#x2013;<lpage>21</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2023.3236983</pub-id>.</mixed-citation></ref>
<ref id="ref-69"><label>[69]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Saveetha</surname> <given-names>D</given-names></string-name>, <string-name><surname>Maragatham</surname> <given-names>G</given-names></string-name></person-group>. <article-title>Design of Blockchain enabled intrusion detection model for detecting security attacks using deep learning</article-title>. <source>Pattern Recognit Lett</source>. <year>2022</year>;<volume>153</volume>:<fpage>24</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-70"><label>[70]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Afaq</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Manocha</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Blockchain and deep learning integration for various application: a review</article-title>. <source>J Comput Inf Syst</source>. <year>2024</year>;<volume>64</volume>(<issue>1</issue>):<fpage>92</fpage>&#x2013;<lpage>105</lpage>.</mixed-citation></ref>
<ref id="ref-71"><label>[71]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hamdan</surname> <given-names>IK</given-names></string-name>, <string-name><surname>Aziguli</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>D</given-names></string-name>, <string-name><surname>Tiwari</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Deep learning-based blockchain framework for fraud detection using multilevel supervision in hierarchical generative hashing</article-title>. <source>Hum Centric Comput Inf Sci</source>. <year>2026</year>;<volume>17</volume>(<issue>1</issue>):<fpage>15</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s13042-025-02916-2</pub-id>.</mixed-citation></ref>
<ref id="ref-72"><label>[72]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>CM</given-names></string-name>, <string-name><surname>Xiong</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>TY</given-names></string-name>, <string-name><surname>Kumari</surname> <given-names>S</given-names></string-name>, <string-name><surname>Alenazi</surname> <given-names>MJ</given-names></string-name></person-group>. <article-title>Protecting virtual economies: a blockchain-based anti-phishing authentication protocol for metaverse applications</article-title>. <source>IEEE Internet Things J</source>. <year>2025</year>;<volume>12</volume>(<issue>13</issue>):<fpage>24244</fpage>&#x2013;<lpage>58</lpage>.</mixed-citation></ref>
<ref id="ref-73"><label>[73]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sheng</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Song</surname> <given-names>L</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Dynamic feature fusion: combining global graph structures and local semantics for blockchain phishing detection</article-title>. <source>IEEE Trans Netw Serv Manag</source>. <year>2025</year>;<volume>22</volume>(<issue>5</issue>):<fpage>4706</fpage>&#x2013;<lpage>18</lpage>.</mixed-citation></ref>
<ref id="ref-74"><label>[74]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Varma</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Varma</surname> <given-names>GP</given-names></string-name>, <string-name><surname>Hemalatha</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Enhanced AI methods for cheque book scam prevention using block chain and multi-component attention graph convolutional networks</article-title>. <source>J Comput Virol Hacking Tech</source>. <year>2026</year>;<volume>22</volume>(<issue>1</issue>):<fpage>33</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s11416-026-00607-2</pub-id>.</mixed-citation></ref>
<ref id="ref-75"><label>[75]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Darwish</surname> <given-names>SM</given-names></string-name>, <string-name><surname>EL-Naggar</surname> <given-names>S</given-names></string-name>, <string-name><surname>Elkaffas</surname> <given-names>SM</given-names></string-name></person-group>. <article-title>Securing financial transactions: exploring the role of lightweight blockchain-enabled deep learning for fraud detection in FinTech systems</article-title>. <source>Cybersecurity</source>. <year>2026</year>;<volume>9</volume>(<issue>1</issue>):<fpage>8</fpage>. doi:<pub-id pub-id-type="doi">10.1186/s42400-025-00436-8</pub-id>.</mixed-citation></ref>
<ref id="ref-76"><label>[76]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>G</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Bilal</surname> <given-names>M</given-names></string-name>, <string-name><surname>Dou</surname> <given-names>W</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Rodrigues</surname> <given-names>JJ</given-names></string-name></person-group>. <article-title>Identifying fraud in medical insurance based on blockchain and deep learning</article-title>. <source>Future Gener Comput Syst</source>. <year>2022</year>;<volume>130</volume>(<issue>1</issue>):<fpage>140</fpage>&#x2013;<lpage>54</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.future.2021.12.006</pub-id>.</mixed-citation></ref>
<ref id="ref-77"><label>[77]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ghnemat</surname> <given-names>R</given-names></string-name>, <string-name><surname>Mosa</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Blockchain-based fraud detection: a systematic review of Ethereum network applications</article-title>. <source>Clust Comput</source>. <year>2025</year>;<volume>28</volume>(<issue>16</issue>):<fpage>1080</fpage>.</mixed-citation></ref>
<ref id="ref-78"><label>[78]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ertam</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Near real-time Ethereum fraud detection using explainable AI in blockchain networks</article-title>. <source>Appl Sci</source>. <year>2025</year>;<volume>15</volume>(<issue>19</issue>):<fpage>10841</fpage>. doi:<pub-id pub-id-type="doi">10.3390/app151910841</pub-id>.</mixed-citation></ref>
<ref id="ref-79"><label>[79]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shevchuk</surname> <given-names>R</given-names></string-name>, <string-name><surname>Martsenyuk</surname> <given-names>V</given-names></string-name>, <string-name><surname>Adamyk</surname> <given-names>B</given-names></string-name>, <string-name><surname>Benson</surname> <given-names>V</given-names></string-name>, <string-name><surname>Melnyk</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Anomaly detection in blockchain: a systematic review of trends, challenges, and future directions</article-title>. <source>Appl Sci</source>. <year>2025</year>;<volume>15</volume>(<issue>15</issue>):<fpage>8330</fpage>. doi:<pub-id pub-id-type="doi">10.3390/app15158330</pub-id>.</mixed-citation></ref>
<ref id="ref-80"><label>[80]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Karthika</surname> <given-names>R</given-names></string-name>, <string-name><surname>Valliyammai</surname> <given-names>C</given-names></string-name>, <string-name><surname>Naveena</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Phish block: a blockchain framework for phish detection in cloud</article-title>. <source>Comput Syst Sci Eng</source>. <year>2023</year>;<volume>44</volume>(<issue>1</issue>):<fpage>777</fpage>&#x2013;<lpage>94</lpage>.</mixed-citation></ref>
<ref id="ref-81"><label>[81]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Fang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>Fishing for fraudsters: uncovering Ethereum phishing gangs with blockchain data</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2024</year>;<volume>19</volume>:<fpage>3038</fpage>&#x2013;<lpage>50</lpage>.</mixed-citation></ref>
<ref id="ref-82"><label>[82]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bayan</surname> <given-names>T</given-names></string-name>, <string-name><surname>Yazici</surname> <given-names>A</given-names></string-name>, <string-name><surname>Banach</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Permissionless blockchain recent trends, privacy concerns, potential solutions and secure development lifecycle</article-title>. <source>Future Internet</source>. <year>2025</year>;<volume>17</volume>(<issue>12</issue>):<fpage>547</fpage>. doi:<pub-id pub-id-type="doi">10.3390/fi17120547</pub-id>.</mixed-citation></ref>
<ref id="ref-83"><label>[83]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Vanna</surname> <given-names>K</given-names></string-name>, <string-name><surname>Rahaman</surname> <given-names>M</given-names></string-name>, <string-name><surname>Gaurav</surname> <given-names>A</given-names></string-name>, <string-name><surname>Arya</surname> <given-names>V</given-names></string-name>, <string-name><surname>Hsu</surname> <given-names>CH</given-names></string-name>, <string-name><surname>Gupta</surname> <given-names>BB</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Critical analysis of advanced hybrid models for mobile phishing detection through data mining and machine learning</article-title>. <source>Int J Data Warehous Min</source>. <year>2025</year>;<volume>21</volume>(<issue>1</issue>):<fpage>1</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.4018/ijdwm.394800</pub-id>.</mixed-citation></ref>
<ref id="ref-84"><label>[84]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gao</surname> <given-names>J</given-names></string-name>, <string-name><surname>Richard</surname> <given-names>BS</given-names></string-name>, <string-name><surname>Xia</surname> <given-names>H</given-names></string-name>, <string-name><surname>Victor</surname> <given-names>K</given-names></string-name>, <string-name><surname>Fabien</surname> <given-names>EB</given-names></string-name>, <string-name><surname>Xia</surname> <given-names>Q</given-names></string-name></person-group>. <article-title>AHGT-DFD: adaptive hierarchical graph transformer for dynamic fraud detection in blockchain networks</article-title>. <source>IEEE Trans Dependable Secur Comput</source>. <year>2025</year>;<volume>23</volume>(<issue>2</issue>):<fpage>2229</fpage>&#x2013;<lpage>41</lpage>.</mixed-citation></ref>
<ref id="ref-85"><label>[85]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Farrukh</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zafar</surname> <given-names>S</given-names></string-name>, <string-name><surname>Rehman</surname> <given-names>ZU</given-names></string-name>, <string-name><surname>Shah</surname> <given-names>AA</given-names></string-name>, <string-name><surname>Alshammry</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Blockchain-based fraud detection: a comparative systematic literature review of federated learning and machine learning approaches</article-title>. <source>Electronics</source>. <year>2025</year>;<volume>14</volume>(<issue>24</issue>):<fpage>4952</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics14244952</pub-id>.</mixed-citation></ref>
<ref id="ref-86"><label>[86]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>W</given-names></string-name>, <string-name><surname>Guo</surname> <given-names>X</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Phishing scam detection on Ethereum: towards financial security for blockchain ecosystem</article-title>. In: <conf-name>Proceedings of the Twenty-Ninth International Joint Conference on Artificial Intelligence (IJCAI-20); 2020 Jul 11&#x2013;17</conf-name>; <publisher-loc>Yokohama, Japan</publisher-loc>. p. <fpage>4456</fpage>&#x2013;<lpage>62</lpage>.</mixed-citation></ref>
<ref id="ref-87"><label>[87]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Yuan</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Lin</surname> <given-names>D</given-names></string-name>, <string-name><surname>You</surname> <given-names>W</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>W</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>C</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Who are the phishers? Phishing scam detection on Ethereum via network embedding</article-title>. <source>IEEE Trans Syst Man Cybern Syst</source>. <year>2020</year>;<volume>52</volume>(<issue>2</issue>):<fpage>1156</fpage>&#x2013;<lpage>66</lpage>.</mixed-citation></ref>
<ref id="ref-88"><label>[88]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Fu</surname> <given-names>B</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Feng</surname> <given-names>T</given-names></string-name></person-group>. <article-title>CT-GCN: a phishing identification model for blockchain cryptocurrency transactions</article-title>. <source>Int J Inf Secur</source>. <year>2022</year>;<volume>21</volume>(<issue>6</issue>):<fpage>1223</fpage>&#x2013;<lpage>32</lpage>.</mixed-citation></ref>
<ref id="ref-89"><label>[89]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kabla</surname> <given-names>AHH</given-names></string-name>, <string-name><surname>Anbar</surname> <given-names>M</given-names></string-name>, <string-name><surname>Manickam</surname> <given-names>S</given-names></string-name>, <string-name><surname>Karupayah</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Eth-PSD: a machine learning-based phishing scam detection approach in Ethereum</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>:<fpage>118043</fpage>&#x2013;<lpage>57</lpage>.</mixed-citation></ref>
<ref id="ref-90"><label>[90]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kumar</surname> <given-names>N</given-names></string-name>, <string-name><surname>Goel</surname> <given-names>V</given-names></string-name>, <string-name><surname>Ranjan</surname> <given-names>R</given-names></string-name>, <string-name><surname>Altuwairiqi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Alyami</surname> <given-names>H</given-names></string-name>, <string-name><surname>Asakipaam</surname> <given-names>SA</given-names></string-name></person-group>. <article-title>A blockchain-oriented framework for cloud-assisted system to countermeasure phishing for establishing secure smart city</article-title>. <source>Secur Commun Netw</source>. <year>2023</year>;<volume>2023</volume>(<issue>1</issue>):<fpage>8168075</fpage>. doi:<pub-id pub-id-type="doi">10.1155/2023/8168075</pub-id>.</mixed-citation></ref>
<ref id="ref-91"><label>[91]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Etherscan</collab></person-group>. <article-title>Ethereum blockchain data</article-title>. <year>2023 [cited 2026 Jan 1]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://etherscan.io/">https://etherscan.io/</ext-link>.</mixed-citation></ref>
<ref id="ref-92"><label>[92]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Qu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Uddin</surname> <given-names>MP</given-names></string-name>, <string-name><surname>Gan</surname> <given-names>C</given-names></string-name>, <string-name><surname>Xiang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>L</given-names></string-name>, <string-name><surname>Yearwood</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Blockchain-enabled federated learning: a survey</article-title>. <source>ACM Comput Surv</source>. <year>2022</year>;<volume>55</volume>(<issue>4</issue>):<fpage>1</fpage>&#x2013;<lpage>35</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3524104</pub-id>.</mixed-citation></ref>
<ref id="ref-93"><label>[93]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Xuan</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Decentralized federated learning based on blockchain: concepts, framework, and challenges</article-title>. <source>Comput Commun</source>. <year>2024</year>;<volume>216</volume>(<issue>1</issue>):<fpage>140</fpage>&#x2013;<lpage>50</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.comcom.2023.12.042</pub-id>.</mixed-citation></ref>
<ref id="ref-94"><label>[94]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Qammar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Karim</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ning</surname> <given-names>H</given-names></string-name>, <string-name><surname>Ding</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Securing federated learning with blockchain: a systematic literature review</article-title>. <source>Artif Intell Rev</source>. <year>2023</year>;<volume>56</volume>(<issue>5</issue>):<fpage>3951</fpage>&#x2013;<lpage>85</lpage>; <pub-id pub-id-type="pmid">36160367</pub-id></mixed-citation></ref>
<ref id="ref-95"><label>[95]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Issa</surname> <given-names>W</given-names></string-name>, <string-name><surname>Moustafa</surname> <given-names>N</given-names></string-name>, <string-name><surname>Turnbull</surname> <given-names>B</given-names></string-name>, <string-name><surname>Sohrabi</surname> <given-names>N</given-names></string-name>, <string-name><surname>Tari</surname> <given-names>Z</given-names></string-name></person-group>. <article-title>Blockchain-based federated learning for securing internet of things: a comprehensive survey</article-title>. <source>ACM Comput Surv</source>. <year>2023</year>;<volume>55</volume>(<issue>9</issue>):<fpage>1</fpage>&#x2013;<lpage>43</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3560816</pub-id>.</mixed-citation></ref>
<ref id="ref-96"><label>[96]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ali</surname> <given-names>S</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Yousafzai</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Blockchain and federated learning-based intrusion detection approaches for edge-enabled industrial IoT networks: a survey</article-title>. <source>Ad Hoc Netw</source>. <year>2024</year>;<volume>152</volume>(<issue>6</issue>):<fpage>103320</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.adhoc.2023.103320</pub-id>.</mixed-citation></ref>
<ref id="ref-97"><label>[97]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Orabi</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Emam</surname> <given-names>O</given-names></string-name>, <string-name><surname>Fahmy</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Adapting security and decentralized knowledge enhancement in federated learning using blockchain technology: literature review</article-title>. <source>J Big Data</source>. <year>2025</year>;<volume>12</volume>(<issue>1</issue>):<fpage>55</fpage>. doi:<pub-id pub-id-type="doi">10.1186/s40537-025-01099-5</pub-id>.</mixed-citation></ref>
<ref id="ref-98"><label>[98]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sameera</surname> <given-names>K</given-names></string-name>, <string-name><surname>Nicolazzo</surname> <given-names>S</given-names></string-name>, <string-name><surname>Arazzi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Nocera</surname> <given-names>A</given-names></string-name>, <string-name><surname>KA.</surname> <given-names>RR</given-names></string-name>, <string-name><surname>Vinod</surname> <given-names>P</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Privacy-preserving in blockchain-based federated learning systems</article-title>. <source>Comput Commun</source>. <year>2024</year>;<volume>222</volume>(<issue>4</issue>):<fpage>38</fpage>&#x2013;<lpage>67</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.comcom.2024.04.024</pub-id>.</mixed-citation></ref>
<ref id="ref-99"><label>[99]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ren</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>E</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>C</given-names></string-name></person-group>. <article-title>A scalable blockchain-enabled federated learning architecture for edge computing</article-title>. <source>PLoS One</source>. <year>2024</year>;<volume>19</volume>(<issue>8</issue>):<fpage>e0308991</fpage>. doi:<pub-id pub-id-type="doi">10.1371/journal.pone.0308991</pub-id>; <pub-id pub-id-type="pmid">39150937</pub-id></mixed-citation></ref>
<ref id="ref-100"><label>[100]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Abou El Houda</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Moudoud</surname> <given-names>H</given-names></string-name>, <string-name><surname>Brik</surname> <given-names>B</given-names></string-name>, <string-name><surname>Khoukhi</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Securing federated learning through blockchain and explainable AI for robust intrusion detection in IoT networks</article-title>. In: <conf-name>Proceedings of the IEEE INFOCOM 2023-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS); 2023 May 17&#x2013;20</conf-name>; <publisher-loc>Hoboken, NJ, USA</publisher-loc>; p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-101"><label>[101]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Li</surname> <given-names>T</given-names></string-name></person-group>. <article-title>A Blockchain-based federated learning framework for secure aggregation and fair incentives</article-title>. <source>Connect Sci</source>. <year>2024</year>;<volume>36</volume>(<issue>1</issue>):<fpage>2316018</fpage>. doi:<pub-id pub-id-type="doi">10.1080/09540091.2024.2316018</pub-id>.</mixed-citation></ref>
<ref id="ref-102"><label>[102]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Shao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wei</surname> <given-names>K</given-names></string-name>, <string-name><surname>Ding</surname> <given-names>M</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>C</given-names></string-name>, <string-name><surname>Shi</surname> <given-names>L</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Blockchain assisted decentralized federated learning (BLADE-FL): performance analysis and resource allocation</article-title>. <source>IEEE Trans Parallel Distrib Syst</source>. <year>2021</year>;<volume>33</volume>(<issue>10</issue>):<fpage>2401</fpage>&#x2013;<lpage>15</lpage>.</mixed-citation></ref>
<ref id="ref-103"><label>[103]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>P</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>X</given-names></string-name>, <string-name><surname>Shao</surname> <given-names>X</given-names></string-name>, <string-name><surname>Pu</surname> <given-names>G</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Blockchain and federated learning for collaborative intrusion detection in vehicular edge computing</article-title>. <source>IEEE Internet Things J</source>. <year>2021</year>;<volume>70</volume>(<issue>6</issue>):<fpage>6073</fpage>&#x2013;<lpage>84</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tvt.2021.3076780</pub-id>.</mixed-citation></ref>
<ref id="ref-104"><label>[104]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>J</given-names></string-name>, <string-name><surname>Jiang</surname> <given-names>L</given-names></string-name>, <string-name><surname>Tan</surname> <given-names>R</given-names></string-name>, <string-name><surname>Niyato</surname> <given-names>D</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Privacy-preserving blockchain-based federated learning for IoT devices</article-title>. <source>IEEE Internet Things J</source>. <year>2020</year>;<volume>8</volume>(<issue>3</issue>):<fpage>1817</fpage>&#x2013;<lpage>29</lpage>.</mixed-citation></ref>
<ref id="ref-105"><label>[105]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Huang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Dai</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Maharjan</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Blockchain and federated learning for privacy-preserved data sharing in industrial IoT</article-title>. <source>IEEE Trans Ind Inform</source>. <year>2019</year>;<volume>16</volume>(<issue>6</issue>):<fpage>4177</fpage>&#x2013;<lpage>86</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tii.2019.2942190</pub-id>.</mixed-citation></ref>
<ref id="ref-106"><label>[106]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hallaji</surname> <given-names>E</given-names></string-name>, <string-name><surname>Razavi-Far</surname> <given-names>R</given-names></string-name>, <string-name><surname>Saif</surname> <given-names>M</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>B</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>Q</given-names></string-name></person-group>. <article-title>Decentralized federated learning: a survey on security and privacy</article-title>. <source>IEEE Trans Big Data</source>. <year>2024</year>;<volume>10</volume>(<issue>2</issue>):<fpage>194</fpage>&#x2013;<lpage>213</lpage>.</mixed-citation></ref>
<ref id="ref-107"><label>[107]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Han</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Lu</surname> <given-names>S</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>W</given-names></string-name>, <string-name><surname>Qu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name>, <string-name><surname>Gao</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Privacy preserving and secure robust federated learning: a survey</article-title>. <source>Concurr Comput Pract Exp</source>. <year>2024</year>;<volume>36</volume>(<issue>13</issue>):<fpage>e8084</fpage>. doi:<pub-id pub-id-type="doi">10.1002/cpe.8084</pub-id>.</mixed-citation></ref>
<ref id="ref-108"><label>[108]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Manzoor</surname> <given-names>HU</given-names></string-name>, <string-name><surname>Shabbir</surname> <given-names>A</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>A</given-names></string-name>, <string-name><surname>Flynn</surname> <given-names>D</given-names></string-name>, <string-name><surname>Zoha</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A survey of security strategies in federated learning: defending models, data, and privacy</article-title>. <source>Future Internet</source>. <year>2024</year>;<volume>16</volume>(<issue>10</issue>):<fpage>374</fpage>. doi:<pub-id pub-id-type="doi">10.3390/fi16100374</pub-id>.</mixed-citation></ref>
<ref id="ref-109"><label>[109]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ngoupayou Limbepe</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Gai</surname> <given-names>K</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Blockchain-based privacy-enhancing federated learning in smart healthcare: a survey</article-title>. <source>Blockchains</source>. <year>2025</year>;<volume>3</volume>(<issue>1</issue>):<fpage>1</fpage>. doi:<pub-id pub-id-type="doi">10.3390/blockchains3010001</pub-id>.</mixed-citation></ref>
<ref id="ref-110"><label>[110]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Ruan</surname> <given-names>W</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>J</given-names></string-name>, <string-name><surname>He</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>A survey on blockchain-based federated learning</article-title>. <source>Future Internet</source>. <year>2023</year>;<volume>15</volume>(<issue>12</issue>):<fpage>400</fpage>. doi:<pub-id pub-id-type="doi">10.3390/fi15120400</pub-id>.</mixed-citation></ref>
<ref id="ref-111"><label>[111]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ning</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Song</surname> <given-names>C</given-names></string-name>, <string-name><surname>Li</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Xie</surname> <given-names>J</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Blockchain-based federated learning: a survey and new perspectives</article-title>. <source>Appl Sci</source>. <year>2024</year>;<volume>14</volume>(<issue>20</issue>):<fpage>9459</fpage>.</mixed-citation></ref>
<ref id="ref-112"><label>[112]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ku</surname> <given-names>CS</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>R</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Privacy and trust in blockchain-federated intrusion detection systems: taxonomy, challenges and perspectives</article-title>. <source>J Reliab Secur Comput</source>. <year>2025</year>;<volume>1</volume>(<issue>1</issue>):<fpage>4</fpage>&#x2013;<lpage>24</lpage>. doi:<pub-id pub-id-type="doi">10.62762/jrsc.2025.399812</pub-id>.</mixed-citation></ref>
<ref id="ref-113"><label>[113]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ghosh</surname> <given-names>PK</given-names></string-name>, <string-name><surname>Bhushan</surname> <given-names>A</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>D</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>AK</given-names></string-name></person-group>. <article-title>Decentralized defences from federated learning for Ethereum phishing detection</article-title>. In: <conf-name>International Conference on Advanced Network Technologies and Intelligent Computing</conf-name>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2024</year>. p. <fpage>243</fpage>&#x2013;<lpage>57</lpage>.</mixed-citation></ref>
<ref id="ref-114"><label>[114]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>W</given-names></string-name>, <string-name><surname>Manickam</surname> <given-names>S</given-names></string-name>, <string-name><surname>Chong</surname> <given-names>YW</given-names></string-name></person-group>. <article-title>FedPhishLLM: a privacy-preserving and explainable phishing detection mechanism using federated learning and LLMs</article-title>. <source>J King Saud Univ Comput Inf Sci</source>. <year>2025</year>;<volume>37</volume>(<issue>8</issue>):<fpage>252</fpage>.</mixed-citation></ref>
<ref id="ref-115"><label>[115]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jiang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>B</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>G</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>P</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>Z</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Blockchained federated learning for Internet of Things: a comprehensive survey</article-title>. <source>ACM Comput Surv</source>. <year>2024</year>;<volume>56</volume>(<issue>10</issue>):<fpage>1</fpage>&#x2013;<lpage>37</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3659099</pub-id>.</mixed-citation></ref>
<ref id="ref-116"><label>[116]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cai</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Fan</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Li</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Blockchain-empowered federated learning: benefits, challenges, and solutions</article-title>. <source>IEEE Trans Big Data</source>. <year>2025</year>;<volume>11</volume>(<issue>5</issue>):<fpage>2244</fpage>&#x2013;<lpage>63</lpage>.</mixed-citation></ref>
<ref id="ref-117"><label>[117]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Vijay Anand</surname> <given-names>R</given-names></string-name>, <string-name><surname>Magesh</surname> <given-names>G</given-names></string-name>, <string-name><surname>Alagiri</surname> <given-names>I</given-names></string-name>, <string-name><surname>Brahmam</surname> <given-names>MG</given-names></string-name>, <string-name><surname>Balusamy</surname> <given-names>B</given-names></string-name>, <string-name><surname>Selvan</surname> <given-names>CP</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Design of an improved model using federated learning and LSTM autoencoders for secure and transparent blockchain network transactions</article-title>. <source>Sci Rep</source>. <year>2025</year>;<volume>15</volume>(<issue>1</issue>):<fpage>1615</fpage>. doi:<pub-id pub-id-type="doi">10.1038/s41598-024-83564-4</pub-id>; <pub-id pub-id-type="pmid">39794364</pub-id></mixed-citation></ref>
<ref id="ref-118"><label>[118]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shalan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Hasan</surname> <given-names>MR</given-names></string-name>, <string-name><surname>Bai</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Enhancing smart home security: blockchain-enabled federated learning with knowledge distillation for intrusion detection</article-title>. <source>Smart Cities</source>. <year>2025</year>;<volume>8</volume>(<issue>1</issue>):<fpage>35</fpage>.</mixed-citation></ref>
<ref id="ref-119"><label>[119]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Abuzied</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ghanem</surname> <given-names>M</given-names></string-name>, <string-name><surname>Dawoud</surname> <given-names>F</given-names></string-name>, <string-name><surname>Gamal</surname> <given-names>H</given-names></string-name>, <string-name><surname>Soliman</surname> <given-names>E</given-names></string-name>, <string-name><surname>Sharara</surname> <given-names>H</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>A privacy-preserving federated learning framework for blockchain networks</article-title>. <source>Clust Comput</source>. <year>2024</year>;<volume>27</volume>(<issue>4</issue>):<fpage>3997</fpage>&#x2013;<lpage>4014</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s10586-024-04273-1</pub-id>.</mixed-citation></ref>
<ref id="ref-120"><label>[120]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>L</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>D</given-names></string-name>, <string-name><surname>Tao</surname> <given-names>L</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>K</given-names></string-name>, <string-name><surname>Qiao</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zeng</surname> <given-names>X</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>A credible and fair federated learning framework based on blockchain</article-title>. <source>IEEE Trans Artif Intell</source>. <year>2024</year>;<volume>6</volume>(<issue>2</issue>):<fpage>301</fpage>&#x2013;<lpage>16</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tai.2024.3355362</pub-id>.</mixed-citation></ref>
<ref id="ref-121"><label>[121]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Guo</surname> <given-names>J</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>R</given-names></string-name>, <string-name><surname>Xing</surname> <given-names>J</given-names></string-name></person-group>. <article-title>A blockchain-based privacy-preserving reputation consensus federated learning</article-title>. <source>Alex Eng J</source>. <year>2025</year>;<volume>133</volume>(<issue>8</issue>):<fpage>444</fpage>&#x2013;<lpage>60</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.aej.2025.11.016</pub-id>.</mixed-citation></ref>
<ref id="ref-122"><label>[122]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Ali</surname> <given-names>A</given-names></string-name>, <string-name><surname>Husain</surname> <given-names>M</given-names></string-name>, <string-name><surname>Hans</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Federated learning-enhanced blockchain framework for privacy-preserving intrusion detection in industrial IoT</article-title>. <comment>arXiv:2505.15376. 2025</comment>.</mixed-citation></ref>
<ref id="ref-123"><label>[123]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Odeh</surname> <given-names>A</given-names></string-name>, <string-name><surname>Taleb</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Federated learning and blockchain framework for scalable and secure IoT access control</article-title>. <source>Comput Mater Contin</source>. <year>2025</year>;<volume>84</volume>(<issue>1</issue>):<fpage>447</fpage>. doi:<pub-id pub-id-type="doi">10.32604/cmc.2025.065426</pub-id>.</mixed-citation></ref>
<ref id="ref-124"><label>[124]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Usharani</surname> <given-names>S</given-names></string-name>, <string-name><surname>Manju Bala</surname> <given-names>P</given-names></string-name>, <string-name><surname>Balachandar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Glorindal</surname> <given-names>G</given-names></string-name></person-group>. <chapter-title>Enhanced privacy preserving deep learning using blockchain and federated learning</chapter-title>. In: <source>Blockchain and federated learning synergy for privacy-focused deepfex solutions</source>. <publisher-loc>Berlin/Heidelberg, Germany</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2025</year>. p. <fpage>145</fpage>&#x2013;<lpage>64</lpage>.</mixed-citation></ref>
<ref id="ref-125"><label>[125]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ogundokun</surname> <given-names>RO</given-names></string-name>, <string-name><surname>Arowolo</surname> <given-names>MO</given-names></string-name>, <string-name><surname>Dama&#x0161;evi&#x010D;ius</surname> <given-names>R</given-names></string-name>, <string-name><surname>Misra</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Phishing detection in blockchain transaction networks using ensemble learning</article-title>. <source>Telecom</source>. <year>2023</year>;<volume>4</volume>(<issue>2</issue>):<fpage>279</fpage>&#x2013;<lpage>97</lpage>. doi:<pub-id pub-id-type="doi">10.3390/telecom4020017</pub-id>.</mixed-citation></ref>
<ref id="ref-126"><label>[126]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>IWSPA</collab></person-group>. <article-title>IWSPA-AP email dataset</article-title>. <comment>2018 [cited 2026 Jan 1]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://dasavisha.github.io/IWSPA-sharedtask/">https://dasavisha.github.io/IWSPA-sharedtask/</ext-link>.</mixed-citation></ref>
<ref id="ref-127"><label>[127]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mohammad</surname> <given-names>R</given-names></string-name>, <string-name><surname>McCluskey</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Phishing websites dataset</article-title>. <source>UCI Mach Learn Repos</source>. <year>2015</year>. doi:<pub-id pub-id-type="doi">10.24432/C51W2X</pub-id>.</mixed-citation></ref>
<ref id="ref-128"><label>[128]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>OpenPhish</collab></person-group>. <article-title>OpenPhish phishing intelligence</article-title>. <year>2023 [cited 2026 Jan 1]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://openphish.com/">https://openphish.com/</ext-link>.</mixed-citation></ref>
<ref id="ref-129"><label>[129]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Dredze</surname> <given-names>M</given-names></string-name>, <string-name><surname>Gevaryahu</surname> <given-names>R</given-names></string-name>, <string-name><surname>Elias-Bachrach</surname> <given-names>A</given-names></string-name></person-group>. <source>Learning fast classifiers for image spam</source>. <publisher-loc>Brussels, Belgium</publisher-loc>: <publisher-name>Council of European Aerospace Societies</publisher-name>; <year>2007</year>. p. <fpage>487</fpage>&#x2013;<lpage>93</lpage>.</mixed-citation></ref>
<ref id="ref-130"><label>[130]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Mohammad</surname> <given-names>RM</given-names></string-name>, <string-name><surname>Thabtah</surname> <given-names>F</given-names></string-name>, <string-name><surname>McCluskey</surname> <given-names>L</given-names></string-name></person-group>. <article-title>An assessment of features related to phishing websites using an automated technique</article-title>. In: <conf-name>Proceedings of the 2012 International Conference for Internet Technology and Secured Transactions (ICITST); 2012 Dec 10&#x2013;12</conf-name>; <publisher-loc>London, UK</publisher-loc>. p. <fpage>492</fpage>&#x2013;<lpage>7</lpage>.</mixed-citation></ref>
<ref id="ref-131"><label>[131]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>MillerSmiles</collab></person-group>. <article-title>Phishing scams archive</article-title>. <comment>2023 [cited 2026 Jan 1]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="http://www.millersmiles.co.uk/">http://www.millersmiles.co.uk/</ext-link>.</mixed-citation></ref>
<ref id="ref-132"><label>[132]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Cormack</surname> <given-names>GV</given-names></string-name></person-group>. <article-title>TREC 2007 spam track overview</article-title>. In: <conf-name>Proceedings of the Sixteenth Text REtrieval Conference (TREC 2007); 2007 Nov 6&#x2013;9</conf-name>; <publisher-loc>Gaithersburg, MD, USA</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>9</lpage>.</mixed-citation></ref>
<ref id="ref-133"><label>[133]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Apache SpamAssassin Project</collab></person-group>. <article-title>SpamAssassin public corpus</article-title>. <comment>2005 [cited 2026 Jan 1]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://spamassassin.apache.org/old/publiccorpus/">https://spamassassin.apache.org/old/publiccorpus/</ext-link>.</mixed-citation></ref>
<ref id="ref-134"><label>[134]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Cohen</surname> <given-names>WW</given-names></string-name></person-group>. <article-title>Enron email dataset</article-title>. <comment>2015 [cited 2026 Jan 1]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="http://www.cs.cmu.edu/">http://www.cs.cmu.edu/</ext-link>.</mixed-citation></ref>
<ref id="ref-135"><label>[135]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Androutsopoulos</surname> <given-names>I</given-names></string-name>, <string-name><surname>Koutsias</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chandrinos</surname> <given-names>KV</given-names></string-name>, <string-name><surname>Paliouras</surname> <given-names>G</given-names></string-name>, <string-name><surname>Spyropoulos</surname> <given-names>CD</given-names></string-name></person-group>. <article-title>Ling-spam dataset</article-title>. <comment>2000 [cited 2026 Jan 1]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/datasets/mandygu/lingspam-dataset">https://www.kaggle.com/datasets/mandygu/lingspam-dataset</ext-link>.</mixed-citation></ref>
<ref id="ref-136"><label>[136]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Aziz</surname> <given-names>RM</given-names></string-name>, <string-name><surname>Baluch</surname> <given-names>MF</given-names></string-name>, <string-name><surname>Patel</surname> <given-names>S</given-names></string-name>, <string-name><surname>Ganie</surname> <given-names>AH</given-names></string-name></person-group>. <article-title>LGBM: a machine learning approach for Ethereum fraud detection</article-title>. <source>Int J Inf Technol</source>. <year>2022</year>;<volume>14</volume>:<fpage>3321</fpage>&#x2013;<lpage>31</lpage>.</mixed-citation></ref>
<ref id="ref-137"><label>[137]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jin</surname> <given-names>C</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>J</given-names></string-name>, <string-name><surname>Xie</surname> <given-names>C</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>S</given-names></string-name>, <string-name><surname>Xuan</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Enhancing Ethereum fraud detection via generative and contrastive self-supervision</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2025</year>;<volume>20</volume>:<fpage>839</fpage>&#x2013;<lpage>53</lpage>.</mixed-citation></ref>
<ref id="ref-138"><label>[138]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>T</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>X</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>A</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>K</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>DataEther: data exploration framework for Ethereum</article-title>. In: <conf-name>Proceedings of the IEEE 39th International Conference on Distributed Computing Systems (ICDCS); 2021 Mar 4&#x2013;5</conf-name>; <publisher-loc>Greater Noida, India</publisher-loc>; <year>2021</year>. p. <fpage>1369</fpage>&#x2013;<lpage>80</lpage>.</mixed-citation></ref>
<ref id="ref-139"><label>[139]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Khalifa</surname> <given-names>O</given-names></string-name>, <string-name><surname>Nor</surname> <given-names>THSBT</given-names></string-name>, <string-name><surname>Ahmed</surname> <given-names>MZ</given-names></string-name>, <string-name><surname>El-Khazmi</surname> <given-names>E</given-names></string-name>, <string-name><surname>Esgiar</surname> <given-names>AN</given-names></string-name></person-group>. <article-title>Blockchain based email security to mitigate phishing attack</article-title>. <source>Asian J Electr Electron Eng</source>. <year>2024</year>;<volume>4</volume>(<issue>2</issue>):<fpage>77</fpage>&#x2013;<lpage>86</lpage>. doi:<pub-id pub-id-type="doi">10.69955/ajoeee.2024.v4i2.73</pub-id>.</mixed-citation></ref>
<ref id="ref-140"><label>[140]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Pitre</surname> <given-names>V</given-names></string-name>, <string-name><surname>Joshi</surname> <given-names>A</given-names></string-name>, <string-name><surname>Das</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Blockchain and machine learning based approach to prevent phishing attacks</article-title>. In: <conf-name>Proceedings of the 2023 3rd Asian Conference on Innovation in Technology (ASIANCON); 2023 Aug 25&#x2013;27</conf-name>; <publisher-loc>Pune, India</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-141"><label>[141]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rathore</surname> <given-names>S</given-names></string-name>, <string-name><surname>Pan</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Park</surname> <given-names>JH</given-names></string-name></person-group>. <article-title>BlockDeepNet: a blockchain-based secure deep learning for IoT network</article-title>. <source>Sustainability</source>. <year>2019</year>;<volume>11</volume>(<issue>14</issue>):<fpage>3974</fpage>.</mixed-citation></ref>
</ref-list>
</back></article>