Interdisciplinary Journal of Management Studies

Interdisciplinary Journal of Management Studies

Sharable Device-Aware Phishing Attack Detection in Cloud Environments Using VAE with Clustering Mechanism and SVM

Document Type : SI: BDDEP-2026

Authors
1 Innosoft, Windsor Mill, Maryland,USA
2 Tata Consultancy Services, Milford, Ohio, USA
3 Uber Technologies Inc, San Francisco, California, USA
4 Cognizant Technology Solution, College Station, Texas, USA
5 Tekzone Systems Inc, Rancho Cordova, California, USA
6 Associate Professor, Department of Economic Theory, Faculty of Economics, Tashkent State University of Economics, Uzbekistan
Abstract
Phishing attacks pose a significant risk to cybersecurity and are especially troublesome in cloud-based settings as the risk is heightened due to shared and multi-device access. To counteract this, the current paper presents a Sharable Device-Aware Phishing Attack Detection system that integrates Variational Autoencoder (VAE) with a Clustering Mechanism and Support Vector Machine (SVM) to make the detection of phishing attacks more effective. The VAE is employed for feature extraction and to facilitate the unsupervised learning of phishing behavior. This approach enables the clustering mechanism to group threats effectively, after which the SVM model is applied to accurately classify the phishing cases. The presented model is evaluated on a dataset of phishing behaviors collected from cloud-based IoT environments, demonstrating strong performance in terms of detection accuracy, recall, and F1-score. Results show 99.5% accuracy, 99% precision, 98.5% recall, and 99.95% F1-score, outperforming the current phishing detection algorithms. The combination of device-aware learning with more sophisticated machine learning concepts offers an effective, scalable, and flexible phishing detection algorithm for cloud security.
Keywords
Subjects

Achaal, B., Adda, M., Berger, M., Ibrahim, H., & Awde, A. (2024). Study of smart grid cyber-security, examining architectures, communication networks, cyber-attacks, countermeasure techniques, and challenges. Cybersecurity, 7(1), 10. https://doi.org/10.1186/s42400-023-00200-w
Akinade, A. O., Adepoju, P. A., Ige, A. B., & Afolabi, A. I. (2024). Cloud security challenges and solutions: A review of current best practices. International Journal of Multidisciplinary Research and Growth Evaluation, 6(1), 26–35. https://doi.org/10.54660/.IJMRGE.2025.6.1.26-35
Alissa, K., Alyas, T., Zafar, K., Abbas, Q., Tabassum, N., & Sakib, S. (2022). Botnet attack detection in IoT using machine learning. Computational Intelligence and Neuroscience, 2022(1), 4515642. https://doi.org/10.1155/2022/4515642
Almujahid, N. F., Haq, M. A., & Alshehri, M. (2024). Comparative evaluation of machine learning algorithms for phishing site detection. PeerJ Computer Science, 10, e2131. https://doi.org/10.7717/peerj-cs.2131
Azeem, M., Khan, D., Iftikhar, S., Bawazeer, S., & Alzahrani, M. (2024). Analyzing and comparing the effectiveness of malware detection: A study of machine learning approaches. Heliyon, 10(1), e23574. https://doi.org/10.1016/j.heliyon.2023.e23574
Butt, U. A., Amin, R., Aldabbas, H., Mohan, S., Alouffi, B., & Ahmadian, A. (2023). Cloud-based email phishing attack using machine and deep learning algorithm. Complex & Intelligent Systems, 9(3), 3043–3070. https://doi.org/10.1007/s40747-022-00760-3
Champa, A. I., Rabbi, M. F., & Zibran, M. F. (2024). Curated datasets and feature analysis for phishing email detection with machine learning. In 2024 IEEE 3rd International Conference on Computing and Machine Intelligence (ICMI), 1–7. https://doi.org/10.1109/ICMI60790.2024.10585821
Chen, N., Fan, J., Yuan, J., & Zheng, E. (2025). OBTPN: A vision-based network for UAV geo-localization in multi-altitude environments. Drones, 9(1), 33. https://doi.org/10.3390/drones9010033
Daengsi, T., Pornpongtechavanich, P., & Wuttidittachotti, P. (2022). Cybersecurity awareness enhancement: A study of the effects of age and gender of Thai employees associated with phishing attacks. Education and Information Technologies, 27(4), 4729–4752. https://doi.org/10.1007/s10639-021-10806-7
Færøy, F. L., Yamin, M. M., Shukla, A., & Katt, B. (2023). Automatic verification and execution of cyber attack on IoT devices. Sensors, 23(2), 733. https://doi.org/10.3390/s23020733
Hoefler, T., Copik, M., Beckman, P., Jones, A., Foster, I., Parashar, M., Reed, D., Troyer, M., Schulthess, T., Ernst, D., & Dongarra, J. (2024). XaaS: Acceleration as a service to enable productive high-performance cloud computing. Computing in Science & Engineering, 26(3), 40–51. https://doi.org/10.1109/MCSE.2024.3382154
Igwenagu, U. T. I., Salami, A. A., Arigbabu, A. S., Mesode, C. E., Oladoyinbo, T. O., & Olaniyi, O. O. (2024). Securing the digital frontier: Strategies for cloud computing security, database protection, and comprehensive penetration testing. Journal of Engineering Research and Reports, 26(6), 60–75. https://doi.org/10.9734/jerr/2024/v26i61162
James, E., & Rabbi, F. (2023). Fortifying the IoT landscape: Strategies to counter security risks in connected systems. Tensorgate Journal of Sustainable Technology and Infrastructure for Developing Countries, 6(1), 32-46. https://research.tensorgate.org/index.php/tjstidc/article/view/42
Jawad, S. K., & Alnajjar, S. H. (2024). Optimizing phishing threat detection: A comprehensive study of advanced bagging techniques and optimization algorithms in machine learning. Al-Iraqia Journal of Scientific Engineering Research, 3(1). https://doi.org/10.58564/IJSER.3.1.2024.146
Kasri, W., Himeur, Y., Alkhazaleh, H. A., Tarapiah, S., Atalla, S., Mansoor, W., & Al-Ahmad, H. (2025). From vulnerability to defense: The role of large language models in enhancing cybersecurity. Computation, 13(2), Article 2. https://doi.org/10.3390/computation13020030
King, I. J., & Huang, H. H. (2023). Euler: Detecting network lateral movement via scalable temporal link prediction. ACM Transactions on Privacy and Security, 26(3), 1–36. https://doi.org/10.1145/3588771
Kondoyanni, M., Loukatos, D., Maraveas, C., Drosos, C., & Arvanitis, K. G. (2022). Bio-Inspired robots and structures toward fostering the modernization of agriculture. Biomimetics, 7(2), Article 2. https://doi.org/10.3390/biomimetics7020069
Kumar, V., & Sinha, D. (2021). A robust intelligent zero-day cyber-attack detection technique. Complex & Intelligent Systems, 7(5), 2211–2234. https://doi.org/10.1007/s40747-021-00396-9
Kyaw, P. H., Gutierrez, J., & Ghobakhlou, A. (2024). A systematic review of deep learning techniques for phishing email detection. Electronics, 13(19), 3823. https://doi.org/10.3390/electronics13193823
Lestari, W. S., & Ulina, M. (2024). Optimizing deep neural networks using ANOVA for web phishing detection. Teknika, 13(1), 71–76. https://doi.org/10.34148/teknika.v13i1.758
Liubchenko, V. V., & Volkov, D. V. (2024). Cyber-aware threats and management strategies in cloud environments. Herald of Advanced Information Technology, 7(2), 158–170. https://doi.org/10.15276/hait.07.2024.11
Lokesh, M., Devi, A. K., Chowdary, U. D., Lakshmi, P. D., & Rao, G. R. K. (2023). Data redundancy, data phishing, and data cloud backup. In 2023 Fifth International Conference on Electrical, Computer and Communication Technologies (ICECCT), 1–6. https://ieeexplore.ieee.org/abstract/document/10179679/
Madhavaram, C., Bauskar, S. R., Sunkara, J. R., & Gollangi, H. K. (2025). AI-Driven phishing email detection: Leveraging big data analytics for enhanced cybersecurity. SSRN Electronic Journal, 44 No.3. https://doi.org/10.2139/ssrn.5029438
Mali, S., Gujral, M., & Cherukuri, A. K. (2025). Encrypted network traffic classification using intelligent techniques. Cureus Journal of Computer Science. https://doi.org/10.7759/s44389-024-02701-2
Mohammed, Z. A., Gheni, H. Q., Hussein, Z. J., & Al-Qurabat, A. K. M. (2024). Advancing cloud image security via AES algorithm enhancement techniques. Engineering, Technology & Applied Science Research, 14(1), 12694–12701. https://doi.org/10.48084/etasr.6601
Niwa, H. (2024). Multitemporal monitoring of forest indicator species using UAV and machine learning image recognition. Environmental Monitoring and Assessment, 197(1), 4. https://doi.org/10.1007/s10661-024-13456-7
Odeleye, B., Loukas, G., Heartfield, R., Sakellari, G., Panaousis, E., & Spyridonis, F. (2023). Virtually secure: A taxonomic assessment of cybersecurity challenges in virtual reality environments. Computers & Security, 124, 102951. https://doi.org/10.1016/j.cose.2022.102951
Owa, K., & Adewole, O. (2025). Benchmarking machine learning techniques for phishing detection and secure URL classification. International Journal of Computer Science and Mobile Computing, 14(1), 20–37. https://doi.org/10.47760/ijcsmc.2025.v14i01.003
Paul, B., Sarker, A., Abhi, S. H., Das, S. K., Ali, Md. F., Islam, M. M., Islam, Md. R., Moyeen, S. I., Rahman Badal, Md. F., Ahamed, Md. H., Sarker, S. K., Das, P., Hasan, Md. M., & Saqib, N. (2024). Potential smart grid vulnerabilities to cyber attacks: Current threats and existing mitigation strategies. Heliyon, 10(19), e37980. https://doi.org/10.1016/j.heliyon.2024.e37980
Rafat, K. F., Xin, Q., Javed, A. R., Jalil, Z., Ahmad, R. Z., (2022). Evading obscure communication from spam emails. Math. Biosci. Eng, 19(2), 1926-1943. https://doi.org/10.3934/mbe.2022091
Schmitt, M., & Flechais, I. (2024). Digital deception: Generative artificial intelligence in social engineering and phishing. Artificial Intelligence Review, 57(12), 324. https://doi.org/10.1007/s10462-024-10973-2
Shaukat, M. W., Amin, R., Muslam, M. M. A., Alshehri, A. H., Xie, J., Shaukat, M. W., Amin, R., Muslam, M. M. A., Alshehri, A. H., & Xie, J. (2023). A hybrid approach for alluring ads phishing attack detection using machine learning. Sensors, 23(19). https://doi.org/10.3390/s23198070
Sicari, S., Rizzardi, A., & Coen-Porisini, A. (2022). Insights into security and privacy towards fog computing evolution. Computers & Security, 120, 102822. https://doi.org/10.1016/j.cose.2022.102822
Singh, N., Buyya, R., & k Kim, H. (2024). Securing cloud-based internet of things: challenges and mitigations. Sensors, 25(1), 79. https://www.mdpi.com/1424-8220/25/1/79
Stoleriu, R., Negru, C., & Rădulescu, D. (2023). Modern cyber security attacks, detection strategies, and countermeasures procedures. In 2023 24th International Conference on Control Systems and Computer Science (CSCS), 198–205. https://doi.org/10.1109/CSCS59211.2023.00039
Sudar, K. M., Rohan, M., & Vignesh, K. (2024). Detection of adversarial phishing attack using machine learning techniques. Sādhanā, 49(3), 232. https://doi.org/10.1007/s12046-024-02582-0
Mosa, D. T., Shams, M. Y., Abohany, A. A., El-kenawy, E. S. M., & Thabet, M. (2023). Machine learning techniques for detecting phishing URL attacks. Computers, Materials & Continua, 75(1), 1271-1290. https://doi.org/10.32604/cmc.2023.036422
Thapa, C., Tang, J. W., Abuadbba, A., Gao, Y., Camtepe, S., Nepal, S., Almashor, M., & Zheng, Y. (2023). Evaluation of federated learning in phishing email detection. Sensors, 23(9), 4346. https://doi.org/10.3390/s23094346
Torres, N., Pinto, P., & Lopes, S. I. (2021). Security vulnerabilities in LPWANs—An attack vector analysis for the IoT ecosystem. Applied Sciences, 11(7), Article 7. https://doi.org/10.3390/app11073176
Torres-Aguirre, F.-S. (2024). Semiarid mangrove species classification using machine learning algorithms and visible UAV data. Indian Journal of Geo-Marine Sciences, 53(03). https://doi.org/10.56042/ijms.v53i03.8184
Vichare, P. M., Sawant, P. P., & Parulekar, W. R. (2024). The future of cloud computing: Benefits and challenges. International Journal of Progressive Research in Engineering Management
and Science (IJPREMS), 4(5), 2233-2237.
Wilson, S., Hassan, N. A., Khor, K. K., Sinnappan, S., Abu Bakar, A. R., & Tan, S. A. (2024). A holistic qualitative exploration on the perception of scams, scam techniques and effectiveness of anti-scam campaigns in Malaysia. Journal of Financial Crime, 31(5), 1140–1155. https://doi.org/10.1108/JFC-06-2023-0151
Yaacoub, J.-P. A., Noura, H. N., Salman, O., & Chehab, A. (2022). Robotics cyber security: Vulnerabilities, attacks, countermeasures, and recommendations. International Journal of Information Security, 21(1), 115–158. https://doi.org/10.1007/s10207-021-00545-8