<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN"
  "https://jats.nlm.nih.gov/publishing/1.2/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink"
         xmlns:mml="http://www.w3.org/1998/Math/MathML"
         article-type="research-article"
         dtd-version="1.2">

  <!-- ============================================================ FRONT -->
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">IJLTEMAS</journal-id>
      <journal-title-group>
        <journal-title>International Journal of Latest Technology in Engineering, Management &amp; Applied Science (IJLTEMAS)</journal-title>
        <abbrev-journal-title abbrev-type="publisher">IJLTEMAS</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="epub">2278-2540</issn>
      <publisher>
        <publisher-name>IJLTEMAS</publisher-name>
      </publisher>
    </journal-meta>

    <article-meta>
      <!-- IDs -->
      <article-id pub-id-type="publisher-id">375</article-id>
            <article-id pub-id-type="doi">10.51583/IJLTEMAS.2026.150900024</article-id>
      
      <!-- Categories -->
            <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Machine Learning</subject>
        </subj-group>
      </article-categories>
      
      <!-- Title -->
      <title-group>
        <article-title>Hybrid Ensemble Learning For Malicious URL Detection: A Literature Review of Machine Learning, Deep Learning, and Feature-Fusion Approaches</article-title>
      </title-group>

      <!-- Authors -->
      <contrib-group>
                <contrib contrib-type="author">
                    <name>
            <surname>Sable</surname>
            <given-names>Ashwini</given-names>
          </name>
                              <aff>
            Independent Researcher                        <country>India</country>
                      </aff>
                    
        </contrib>
                <contrib contrib-type="author">
                    <name>
            <surname>More</surname>
            <given-names>Vijay</given-names>
          </name>
                              <aff>
            Independent Researcher                        <country>India</country>
                      </aff>
                    
        </contrib>
              </contrib-group>

      <!-- Volume / Issue / Pages -->
            <volume>15</volume>
                  <issue>9</issue>
                        <fpage>289</fpage>
            <lpage>307</lpage>
            
      <!-- Dates -->
      <history>
                <date date-type="received">
          <day>11</day>
          <month>09</month>
          <year>2026</year>
        </date>
                        <date date-type="accepted">
          <day>16</day>
          <month>09</month>
          <year>2026</year>
        </date>
              </history>

            <pub-date pub-type="epub">
        <day>01</day>
        <month>10</month>
        <year>2026</year>
      </pub-date>
      
      <!-- DOI Self-URI -->
            <self-uri xlink:href="https://doi.org/10.51583/IJLTEMAS.2026.150900024"/>
      
      <!-- Keywords -->
            <kwd-group kwd-group-type="author">
                <kwd>malicious URL detection</kwd>
                <kwd>phishing detection</kwd>
                <kwd>ensemble learning</kwd>
                <kwd>hybrid learning</kwd>
                <kwd>machine learning</kwd>
                <kwd>deep learning</kwd>
                <kwd>BERT</kwd>
                <kwd>Random Forest</kwd>
                <kwd>boosting</kwd>
                <kwd>cybersecurity</kwd>
              </kwd-group>
      
    </article-meta>
  </front>

  <!-- ============================================================ BODY (Abstract) -->
  <body>
        <sec>
      <title>Abstract</title>
      <p>The rapid evolution of phishing, malware distribution, and other web-based attacks has made malicious Uniform Resource Locator (URL) detection an important cybersecurity research problem. Traditional blacklist and rule-based mechanisms provide efficient protection against known malicious addresses but may fail when attackers generate previously unseen URLs, employ URL shortening, manipulate lexical structures, or rapidly change domains. Consequently, machine learning and deep learning approaches have increasingly been investigated for detecting malicious URLs using lexical, structural, host-based, contextual, and semantic information. More recently, hybrid and ensemble learning architectures have emerged as promising alternatives to individual classifiers because they combine complementary representations and learning mechanisms. This structured review synthesizes twenty studies published primarily between 2020 and 2026 across IEEE, Elsevier, Springer, and related peer-reviewed venues. The analysis is organized around representation diversity rather than reported accuracy alone and covers handcrafted lexical and structural features, sparse character n-grams, convolutional and recurrent neural representations, transformer-based contextual models, graph neural networks, and heterogeneous ensemble or fusion architectures. The evidence indicates a clear transition from single-representation classifiers toward multi-branch models that combine complementary statistical, sequential, contextual, and relational signals. However, reported benchmark performance is not directly comparable across studies because datasets, class distributions, preprocessing, temporal splits, and operating thresholds vary substantially. Persistent research challenges include cross-dataset generalization, temporal drift, domain-level leakage, class imbalance, false-positive control, adversarial robustness, explainability, and deployment latency. Based on these gaps, the review proposes a four-branch hybrid ensemble architecture and a formal evaluation plan emphasizing ablation, temporal and cross-dataset validation, adversarial testing, low-false-positive operating points, and computational efficiency.</p>
    </sec>
      </body>

  <!-- ============================================================ BACK (References) -->
    <back>
    <ref-list>
      <title>References</title>
            <ref id="ref1">
        <label>1</label>
        <mixed-citation>M. Sameen, K. Han, and S. O. Hwang, “PhishHaven—An efficient real-time AI phishing URLs detection system,” IEEE Access, vol. 8, pp. 83425–83443, 2020, doi: 10.1109/ACCESS.2020.2991403.</mixed-citation>
      </ref>
            <ref id="ref2">
        <label>2</label>
        <mixed-citation>J. Yuan, G. Chen, S. Tian, and X. Pei, “Malicious URL detection based on a parallel neural joint model,” IEEE Access, vol. 9, pp. 9464–9472, 2021, doi: 10.1109/ACCESS.2021.3049625.</mixed-citation>
      </ref>
            <ref id="ref3">
        <label>3</label>
        <mixed-citation>V. K. Nadar, B. Patel, V. Devmane, and U. Bhave, “Detection of phishing websites using machine learning approach,” Proc. 2nd Global Conf. Advancement in Technology (GCAT), 2021, pp. 1–8, doi: 10.1109/GCAT52182.2021.9587682.</mixed-citation>
      </ref>
            <ref id="ref4">
        <label>4</label>
        <mixed-citation>M. Aljabri et al., “Detecting malicious URLs using machine learning techniques: Review and research directions,” IEEE Access, vol. 10, pp. 121395–121417, 2022, doi: 10.1109/ACCESS.2022.3222307.</mixed-citation>
      </ref>
            <ref id="ref5">
        <label>5</label>
        <mixed-citation>A. Saleem Raja, R. Madhubala, N. Rajesh, L. Shaheetha, and N. Arulkumar, “Survey on malicious URL detection techniques,” in Proc. 6th Int. Conf. Trends in Electronics and Informatics (ICOEI), Tirunelveli, India, Apr. 28–30, 2022, pp. 778–781, doi: 10.1109/ICOEI53556.2022.9777221.</mixed-citation>
      </ref>
            <ref id="ref6">
        <label>6</label>
        <mixed-citation>J. A. Kumar, “Hybrid feature-based machine learning method for phishing URL detection,” Proc. 3rd Int. Conf. Secure Cyber Computing and Communication (ICSCCC), 2023, pp. 222–227, doi: 10.1109/ICSCCC58608.2023.10176901.</mixed-citation>
      </ref>
            <ref id="ref7">
        <label>7</label>
        <mixed-citation>R. Ferdaws and N. E. Majd, “Phishing URL detection using machine learning and deep learning,” Proc. IEEE World AI IoT Congress (AIIoT), 2024, pp. 485–490, doi: 10.1109/AIIoT61789.2024.10579005.</mixed-citation>
      </ref>
            <ref id="ref8">
        <label>8</label>
        <mixed-citation>B. Alaladinni et al., “A hybrid approach for malicious URL detection using ML classifiers and graph neural networks,” Proc. 6th Int. Conf. Data Intelligence and Cognitive Informatics (ICDICI), 2025, doi: 10.1109/ICDICI66477.2025.11135390.</mixed-citation>
      </ref>
            <ref id="ref9">
        <label>9</label>
        <mixed-citation>J. Lee and H. Kwon, “Hybrid ensemble learning for malicious URL detection with BERT and boosting models,” IEEE Access, vol. 14, pp. 62045–62058, 2026, doi: 10.1109/ACCESS.2025.3605302.</mixed-citation>
      </ref>
            <ref id="ref10">
        <label>10</label>
        <mixed-citation>Ü. Özmen and E. O. Yildirim, “DistilBERT-based hybrid architecture for phishing URL detection,” IEEE Access, vol. 14, pp. 71720–71737, 2026, doi: 10.1109/ACCESS.2026.3684855.</mixed-citation>
      </ref>
            <ref id="ref11">
        <label>11</label>
        <mixed-citation>N. Reyes-Dorta, P. Caballero-Gil, and C. Rosa-Remedios, “Detection of malicious URLs using machine learning,” Wireless Networks, vol. 30, pp. 7543–7560, 2024, doi: 10.1007/s11276-024-03700-w.</mixed-citation>
      </ref>
            <ref id="ref12">
        <label>12</label>
        <mixed-citation>R. Liu, Y. Wang, Z. Guo, H. Xu, Z. Qin, W. Ma, and F. Zhang, “TransURL: Improving malicious URL detection with multi-layer Transformer encoding and multi-scale pyramid features,” Computer Networks, 2024, doi: 10.1016/j.comnet.2024.110707.</mixed-citation>
      </ref>
            <ref id="ref13">
        <label>13</label>
        <mixed-citation>R. Liu, Y. Wang, H. Xu, Z. Qin, F. Zhang, Y. Liu, and Z. Cao, “PMANet: Malicious URL detection via post-trained language model guided multi-level feature attention network,” Information Fusion, vol. 113, 102638, 2025, doi: 10.1016/j.inffus.2024.102638.</mixed-citation>
      </ref>
            <ref id="ref14">
        <label>14</label>
        <mixed-citation>N. Q. Do, A. Selamat, H. Fujita, and O. Krejcar, “An integrated model based on deep learning classifiers and pre-trained transformer for phishing URL detection,” Future Generation Computer Systems, vol. 161, pp. 269–285, 2024, doi: 10.1016/j.future.2024.06.031.</mixed-citation>
      </ref>
            <ref id="ref15">
        <label>15</label>
        <mixed-citation>N. Q. Do, A. Selamat, O. Krejcar, and H. Fujita, “Detection of malicious URLs using Temporal Convolutional Network and Multi-Head Self-Attention mechanism,” Applied Soft Computing, vol. 169, 112540, 2025, doi: 10.1016/j.asoc.2024.112540.</mixed-citation>
      </ref>
            <ref id="ref16">
        <label>16</label>
        <mixed-citation>K. Barik, S. Misra, and R. Mohan, “Web-based phishing URL detection model using deep learning optimization techniques,” International Journal of Data Science and Analytics, vol. 20, pp. 4449–4471, 2025, doi: 10.1007/s41060-025-00728-9.</mixed-citation>
      </ref>
            <ref id="ref17">
        <label>17</label>
        <mixed-citation>T. Doshi et al., “PhishHunter-XLD: An ensemble approach integrating machine learning and deep learning for phishing URL classification,” Franklin Open, vol. 12, 100349, 2025, doi: 10.1016/j.fraope.2025.100349.</mixed-citation>
      </ref>
            <ref id="ref18">
        <label>18</label>
        <mixed-citation>S. Lokesh R, “Phishing URL detection using machine learning: A comparative study,” in Proc. 6th Int. Conf. Mobile Computing and Sustainable Informatics (ICMCSI), Goathgaun, Nepal, Jan. 7–8, 2025, pp. 1524–1532, doi: 10.1109/ICMCSI64620.2025.10883082.</mixed-citation>
      </ref>
            <ref id="ref19">
        <label>19</label>
        <mixed-citation>J. D. Duarte, P. Chagas Junior, J. P. J. da Costa, E. J. da Costa, L. P. de Melo, R. R. Nunes, C. V. N. G. Soares, and T. E. da Cunha Silva, “Machine learning for early detection of phishing URLs in parked domains: An approach applied to a financial institution,” IEEE Access, vol. 13, pp. 145736–145753, 2025, doi: 10.1109/ACCESS.2025.3599454.</mixed-citation>
      </ref>
            <ref id="ref20">
        <label>20</label>
        <mixed-citation>Y. Tian, Y. Yu, J. Sun, and Y. Wang, “From past to present: A survey of malicious URL detection techniques, datasets and code repositories,” Computer Science Review, vol. 58, Art. no. 100810, 2025, doi: 10.1016/j.cosrev.2025.100810.</mixed-citation>
      </ref>
          </ref-list>
  </back>
  
</article>
