A Review of Graph-Theoretic Approaches in Phishing Website Detection
Krystian Magdziarz, Damian FrąszczakGraph-based phishing website detection exploits structural relations that are more difficult for attackers to manipulate than page content alone, including URL-token dependencies, DOM structure, hyperlink neighbourhoods, user–URL interactions and hosting infrastructure. Despite the growing use of graph neural networks, belief propagation and other topology-aware methods in this area, existing phishing-detection surveys treat graph-based approaches only as one category among many and do not provide an internal taxonomy of the graph representations used. This review addresses that gap through a PRISMA 2020-based systematic review of graph-theoretic approaches to phishing website detection published between 2005 and August 2026. Searches were conducted in IEEE Xplore, ACM Digital Library, ScienceDirect and Google Scholar, and were extended through reference-list analysis; 136 records were catalogued and 21 primary studies met all six inclusion criteria. The review proposes a two-axis taxonomy that classifies methods independently by the artefact layer modelled by the graph-address, document, inter-page links, semantic relations, user behaviour, and infrastructure, and by graph type: homogeneous, multi-relational or heterogeneous. Reported accuracies range from 91.0% to 99.7%, but these figures derive from different datasets, class balances and evaluation protocols and therefore cannot be treated as directly comparable. Within-study comparisons show that adding graph structure changes accuracy by −6.1 to +3.9 percentage points, indicating that graph modelling is not uniformly beneficial and that its value depends strongly on the represented layer and deployment context. Only nine studies report processing time and only four evaluate adversarial robustness; in the most severe reported case, accuracy drops from 98.73% to 74.68% under FGSM perturbation. The main barrier to progress is the absence of a shared benchmark with fixed temporal and domain-disjoint splits, standard false-positive reporting and robustness requirements. The review concludes with a concrete benchmark specification and identifies cross-layer graph modelling as the most important unresolved research direction.