Phishing Email Classification Using TF-IDF Method and Random Forest Algorithm

Authors

  • Ismi Rosia Dwianti Internet Engineering Technology Politeknik Negeri Lampung
  • Dilla regita Cahyani Internet Engineering Technology Politeknik Negeri Lampung
  • Titik Khawa Abd Rahman Asia e University
  • Muhammad Faisal Universitas Muhammadiyah Makassar
  • Aedah Abd Rahman Asia e University
  • Swa Lee Lee Asia e University
  • Nasir Usman STMIK Profesional Makassar

DOI:

https://doi.org/10.25181/rt.v3i2.4310

Keywords:

Phishing, Natural Language Processing, TF-IDF, Random Forest, Email

Abstract

Phishing attacks through email are increasingly becoming a serious threat to cybersecurity. Traditional detection methods such as blacklists and pattern matching have proven to be ineffective in addressing increasingly complex attacks. Therefore, a new approach is needed one that can analyze email content contextually and intelligently.This study develops a phishing email detection system by integrating the Term Frequency–Inverse Document Frequency (TF-IDF) method and the Random Forest algorithm. The system is designed to analyze the linguistic structure of email content and recognize common patterns frequently used in phishing attacks.The research stages include text preprocessing, feature extraction using TF-IDF, model training with Random Forest, and performance evaluation using three data splitting scenarios: 60:40, 70:30, and 80:20. The dataset was obtained from Kaggle and consists of 82,486 emails that have been adjusted to be balanced between phishing and legitimate emails. The evaluation results show that the system achieved high accuracy in all scenarios, with the highest score reaching 98.01% in the 80:20 split. The precision, recall, and F1-score metrics also indicate strong and stable performance. In addition, feature importance analysis shows that the model can identify key terms such as “click,” “money,” and “attached” that frequently appear in phishing emails. This research is expected to serve as a foundation for the development of more adaptive, intelligent, and responsive phishing detection systems in the face of evolving cyber threats.

Downloads

Download data is not yet available.

Downloads

Published

2025-07-28

Issue

Section

Articles