PhishGuard: AI-Driven Graph-Based Analysis for Smarter Email Security
Harchana Ramesh ;
Noris Ismail ;
Nor Azlina Abd Rahman ;
Aitizaz Ali
Published: 2026
Abstract
This research presents a phishing detection system that integrates graph analytics and machine learning to improve email security. As phishing tactics become more sophisticated, traditional filters often fail to detect such threats effectively. This project proposes a dual-model solution: a RoBERTa-based transformer is used to classify the email body content, while a Neo4j-powered graph model analyses sender-receiver domain relationships using graph metrics such as PageRank, ArticleRank, and Degree Centrality. The rule-based system intelligently combines the predictions of the two models. Highly confident RoBERTa results are accepte d directly, whereas for the remaining cases, scores from the graph model are applied. For mid-confidence cases, a fixed rule-based thresholding logic is used to ensure robust classification. For real-time detection, a web interface was developed using Streamlit, integrating Gmail API and Google Apps Script for email quarantine. The system achieved an F1 score above 0.99 in testing, marking it as a fully stable system for spam identification. By combining content and relational signals, the work advances email security and accordingly fulfils Sustainable Development Goal 9 by fostering innovation infrastructure in digital safety.
Keywords
How to Cite the Article
Ramesh, H., Ismail, N., Abd Rahman, N. A., & Ali, A. (2026). PhishGuard: AI-Driven Graph-Based Analysis for Smarter Email Security. STAP Journal of Security Risk Management, 2026(1), 31–45. https://doi.org/10.63180/jsrm.thestap.2026.1.2
References
- Alabdan, R. (2020). Phishing attacks survey: Types, vectors, and technical approaches. Future internet, 12(10), 168.
- Adil, M., Farouk, A., Ali, A., Song, H., & Jin, Z. (2025). Securing tomorrow of next-generation technologies with biometrics, state-of-the-art techniques, open challenges, and future research directions. Computer Science Review, 57, 100750.
- Al-Maari, A. A., Abdulnabi, M., Nathan, Y., Ali, A., Ali, U., & Khan, M. (2025). Optimized credit card fraud detection leveraging ensemble machine learning methods. Engineering, Technology & Applied Science Research, 15(3), 22287–22294.
- Addula, S. R., & Ali, A. (2025). A novel permissioned blockchain approach for scalable and privacy-preserving IoT authentication. Journal of Cyber Security and Risk Auditing, 2025(4), 222–237.
- Frederick, N., & Ali, A. (2024). Enhancing DDoS attack detection and mitigation in SDN using advanced machine learning techniques. Journal of Cyber Security and Risk Auditing, 2024(1), 23–37.
- Alkhalil, Z., Hewage, C., Nawaf, L., & Khan, I. (2021). Phishing attacks: A recent comprehensive study and a new anatomy. Frontiers in Computer Science, 3, 563060.
- Basit, A., Zafar, M., Liu, X., Javed, A. R., Jalil, Z., & Kifayat, K. (2021). A comprehensive survey of AI-enabled phishing attacks detection techniques. Telecommunication Systems, 76(1), 139-154.
- Ermoshina, K., Musiani, F., & Halpin, H. (2016, August). End-to-end encrypted messaging protocols: An overview. In International Conference on Internet Science (pp. 244-254). Cham: Springer International Publishing.
- Nagel, C., Mungale, A., Kumar, V., Laghari, N., Krowczyk, A., Parker, T., ... & Serban, A. (2013). E-mail Protocols. In Pro. NET 1.1 Network Programming (pp. 393-429). Berkeley, CA: Apress.
- Upadhyay, D., Bhatia, V., & Sidharth, S. (2023, November). An in-Depth Analysis of Email Protocols Traffic Using Wireshark. In 2023 2nd International Conference on Futuristic Technologies (INCOFT) (pp. 1-5). IEEE.
- Gupta, B. B., Tewari, A., Jain, A. K., & Agrawal, D. P. (2017). Fighting against phishing attacks: state of the art and future challenges. Neural Computing and Applications, 28(12), 3629-3654.
- Basit, A., Zafar, M., Liu, X., Javed, A. R., Jalil, Z., & Kifayat, K. (2021). A comprehensive survey of AI-enabled phishing attacks detection techniques. Telecommunication Systems, 76(1), 139-154.
- Tewari, A., Jain, A. K., & Gupta, B. B. (2016). Recent survey of various defense mechanisms against phishing attacks. Journal of Information Privacy and Security, 12(1), 3-13.
- Holt, T., & Bossler, A. (2015). Cybercrime in progress: Theory and prevention of technology-enabled offenses. Routledge.
- El Naqa, I., & Murphy, M. J. (2015). What is machine learning?. In Machine learning in radiation oncology: theory and applications (pp. 3-11). Cham: Springer International Publishing.
- Xin, Y., Kong, L., Liu, Z., Chen, Y., Li, Y., Zhu, H., ... & Wang, C. (2018). Machine learning and deep learning methods for cybersecurity. Ieee access, 6, 35365-35381.
- Kaushik, D., Garg, M., Gupta, A., & Pramanik, S. (2022). Application of machine learning and deep learning in cybersecurity: An innovative approach. In An Interdisciplinary Approach to Modern Network Security (pp. 89-109). CRC Press.
- Altwaijry, N., Al-Turaiki, I., Alotaibi, R., & Alakeel, F. (2024, March 24). Advancing phishing email detection: A comparative study of deep learning models. MDPI. https://www.mdpi.com/1424-8220/24/7/2077
- Hosseinzadeh, M., Ali, U., Ali, S., Abbaszadi, R., Gharehchopogh, F. S., Khoshvaght, P., ... & Lansky, J. (2025). Improving phishing email detection performance through deep learning with adaptive optimization. Scientific Reports, 15(1), 36724.
- Salloum, S., Gaber, T., Vadera, S., & Shaalan, K. (2021). Phishing email detection using natural language processing techniques: a literature survey. Procedia Computer Science, 189, 19-28.
- Gupta, B. B., Gaurav, A., Arya, V., Attar, R. W., Bansal, S., Alhomoud, A., & Chui, K. T. (2024). Advanced bert and cnn-based computational model for phishing detection in enterprise systems. CMES-Computer Modeling in Engineering and Sciences, 141(3), 2165-2183.
- Doshi, J., Parmar, K., Sanghavi, R., & Shekokar, N. (2023). A comprehensive dual-layer architecture for phishing and spam email detection. Computers & Security, 133, 103378.
- Adil, M., Abulkasim, H., Ali, A., Song, H., Farouk, A., & Jin, Z. (2024). Role of 5G and 6G technologies in metaverse, quality of service challenges and future research directions. IEEE Network.
- Mohamed, N., Taherdoost, H., & Khashan, O. A. (2024, March). A review of AI in spear phishing defense: Detecting and thwarting advanced email threats. In International Conference on Smart Technology (pp. 177-189). Cham: Springer Nature Switzerland.
- Alsahaim, S., Almaiah, M. A., & Sulaiman, R. B. (2023). Security Threats in Mobile Phones: Challenges, Countermeasures, and the Importance of User Awareness. International Journal of Cybersecurity Engineering and Innovation, 2023(1).
- Yassin, A., & Almaiah, M. (2026). Cyber security risk assessment for determining threats and countermeasures for banking systems. International Journal of Cybersecurity Engineering and Innovation, 2026(1).
- Ibrahim, A., Kadhim, A. F., Hamzah, A. E., & Al-Shareeda, M. A. (2026). A Secure and Scalable IoT Home Automation Architecture with Web and Biometric Control. International Journal of Cybersecurity Engineering and Innovation, 2026(1).