论文

基于 YOLOv8 的网页截图视觉识别钓鱼网站研究

A Computer Vision Approach to Visual Fraud Detection in Phishing Websites Using YOLOv8

精选理由

有人用 YOLOv8 直接看网页截图来抓钓鱼页面,准确率 92%,一张截图 100 毫秒出结果,思路挺新,做安全检测的可以看看。

一篇 arXiv 论文提出用视觉方法检测钓鱼网站,把渲染后的整页截图当作图像来分类,而非分析 URL 或 HTML。研究者训练 YOLOv8 卷积神经网络,依据页面布局、Logo 位置、配色和登录表单结构判断页面是否仿冒可信品牌。系统在留出测试集上达到 92% 分类准确率,单张截图处理耗时约 100 毫秒;针对光照、压缩和缩放变化做数据增强后,误报率相比增强前基线降低 11%。论文还讨论了这类视觉检测器与现有 URL 和内容检测方案如何配合使用。

原文 · arXiv cs.AI

A Computer Vision Approach to Visual Fraud Detection in Phishing Websites Using YOLOv8

Phishing remains one of the most common vectors for financial and identity fraud, and most detection systems still rely on inspecting a page's URL, HTML markup, or domain registration history. These signals are easy for an attacker to rotate or obfuscate, and they say very little about what actually convinces a victim to hand over a password or a card number: the way the page looks. This paper describes a visual, image-based approach to phishing detection that treats a rendered webpage the same way a human eye would, as a picture that either matches a trusted brand or doesn't. A YOLOv8 convolutional neural network was trained to classify full-page website screenshots as phishing or legitimate based on layout, logo placement, color scheme, and login-form structure, rather than on text extracted from the page. The system reached 92% classification accuracy on a held-out test set, processed a single screenshot in roughly 100 milliseconds, and, after a round of data augmentation aimed specifically at lighting, compression, and scaling variation, cut the false-positive rate by 11% relative to the pre-augmentation baseline. The paper walks through the dataset construction, the augmentation strategy, the model architecture and training setup, and the resulting performance, and closes with a discussion of where this kind of visual detector fits alongside, rather than instead of, existing URL- and content-based defenses.