IP Library › Granted Patent US 12,641,119
Granted Patent B2
US 12,641,119 · App. 18/651,332 · Granted May 26, 2026

Systems and methods for detection of phishing webpages through autoencoder techniques

Inventors: Glory Emmanuel Avina (Brentwood, CA); Abhinav Mishra (San Francisco, CA); Kumar Sharad (Dresden, DE)
Assignee: Cisco Technology, Inc.
H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,641,119
App. No.
18/651,332
Filed
Apr 30, 2024
Granted
May 26, 2026
Kind
B2
Examiner
NIPA, WASIKA
Art Unit
2433
USPC
726/22
Abstract

One implementation is directed to a phishing detection methodology including operations of obtaining an image of a candidate phishing webpage having a login screen component, where encoder is deployed on the image resulting in the generation of a latent representation corresponding to the login screen component. The login screen component may then be classified as one of a defined set of classes by deploying a machine learning model taking the latent representation as input. Further, an additional operation may include obtaining allow/deny lists of account authentication providers for the domain of the URL of the candidate phishing webpage. Finally, a determination may be made as to whether the candidate phishing webpage is a phishing webpage when the login class assigned by the classifying machine learning model does not appear on the allow list.

Claims (52)

1 . A computer-implemented method, comprising:

obtaining an image of a candidate phishing webpage that includes a login screen component, wherein a login screen component includes one or more user interface (UI) elements configured to receive confidential information of an individual;

deploying an encoder configured to take the image of the candidate phishing webpage as input, identify the login screen component within the image of the candidate phishing webpage and generate a latent representation corresponding the login screen component, wherein the encoder is a neural network that includes an input layer that receive the image of the candidate phishing webpage and one or more hidden layers that reduce a dimensionality of the image of the candidate phishing webpage resulting in the latent representation;

deploying a machine learning model trained and configured to classify the login screen component into one of a predefined set of classes through analysis of the latent representation corresponding the login screen component;

correlating a class assigned to the login screen component with an allow/deny list pertaining to a domain of the candidate phishing webpage; and

identifying the candidate phishing webpage as either a phishing webpage or a non-phishing webpage based on the correlating of the class assigned to the login screen component with the allow/deny list.

2 . The computer-implemented method of claim 1 , wherein the domain of the candidate phishing webpage is determined through parsing of a uniform resource locator (URL) of the candidate phishing webpage.

3 . The computer-implemented method of claim 1 , wherein the candidate phishing webpage includes the login screen component and additional text or imagery, and wherein identifying the login screen component within the image of the candidate phishing webpage includes differentiating the login screen component from the additional text or imagery.

4 . The computer-implemented method of claim 1 , wherein the encoder is a component of an autoencoder, wherein the autoencoder includes both the encoder and a decoder, wherein both the encoder and the decoder are separate neural networks.

5 . The computer-implemented method of claim 4 , further comprising:

training the autoencoder on training data comprising sample webpage images, wherein at least a portion of the sample webpage images include login screen components, and iteratively performing a set of operations for each of the sample webpage images including:

providing a first sample webpage image to the encoder resulting in generation of a first sample latent representation,

decoding the first sample latent representation by the decoder thereby producing a reconstructed version of a sample login component of the first sample webpage image,

comparing the reconstructed version of the sample login component of the first sample webpage image with an original version of the sample login component of the first sample webpage image resulting in computation of a loss, and

adjusting a set of parameters of one or more of the encoder or the decoder based on the loss.

6 . The computer-implemented method of claim 5 , wherein, following training, the encoder is stored for subsequent deployment and the decoder is discarded.

7 . The computer-implemented method of claim 5 , wherein layers of the encoder are asymmetrical to layers of the decoder.

8 . A computing device, comprising:

a processor; and

a non-transitory computer-readable medium having stored thereon instructions that, when executed by the processor, cause the processor to perform operations including:

obtaining an image of a candidate phishing webpage that includes a login screen component, wherein a login screen component includes one or more user interface (UI) elements configured to receive confidential information of an individual;

deploying an encoder configured to take the image of the candidate phishing webpage as input, identify the login screen component within the image of the candidate phishing webpage and generate a latent representation corresponding the login screen component, wherein the encoder is a neural network that includes an input layer that receive the image of the candidate phishing webpage and one or more hidden layers that reduce a dimensionality of the image of the candidate phishing webpage resulting in the latent representation;

deploying a machine learning model trained and configured to classify the login screen component into one of a predefined set of classes through analysis of the latent representation corresponding the login screen component;

correlating a class assigned to the login screen component with an allow/deny list pertaining to a domain of the candidate phishing webpage; and

identifying the candidate phishing webpage as either a phishing webpage or a non-phishing webpage based on the correlating of the class assigned to the login screen component with the allow/deny list.

9 . The computing device of claim 8 , wherein the domain of the candidate phishing webpage is determined through parsing of a uniform resource locator (URL) of the candidate phishing webpage.

10 . The computing device of claim 8 , wherein the candidate phishing webpage includes the login screen component and additional text or imagery, and wherein identifying the login screen component within the image of the candidate phishing webpage includes differentiating the login screen component from the additional text or imagery.

11 . The computing device of claim 8 , wherein the encoder is a component of an autoencoder, wherein the autoencoder includes both the encoder and a decoder, wherein both the encoder and the decoder are separate neural networks.

12 . The computing device of claim 11 , further comprising:

training the autoencoder on training data comprising sample webpage images, wherein at least a portion of the sample webpage images include login screen components, and iteratively performing a set of operations for each of the sample webpage images including:

providing a first sample webpage image to the encoder resulting in generation of a first sample latent representation,

decoding the first sample latent representation by the decoder thereby producing a reconstructed version of a sample login component of the first sample webpage image,

comparing the reconstructed version of the sample login component of the first sample webpage image with an original version of the sample login component of the first sample webpage image resulting in computation of a loss, and

adjusting a set of parameters of one or more of the encoder or the decoder based on the loss.

13 . The computing device of claim 11 , wherein, following training, the encoder is stored for subsequent deployment and the decoder is discarded.

14 . The computing device of claim 11 , wherein layers of the encoder are asymmetrical to layers of the decoder.

15 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processor to perform operations including:

obtaining an image of a candidate phishing webpage that includes a login screen component, wherein a login screen component includes one or more user interface (UI) elements configured to receive confidential information of an individual;

deploying an encoder configured to take the image of the candidate phishing webpage as input, identify the login screen component within the image of the candidate phishing webpage and generate a latent representation corresponding the login screen component, wherein the encoder is a neural network that includes an input layer that receive the image of the candidate phishing webpage and one or more hidden layers that reduce a dimensionality of the image of the candidate phishing webpage resulting in the latent representation;

deploying a machine learning model trained and configured to classify the login screen component into one of a predefined set of classes through analysis of the latent representation corresponding the login screen component;

correlating a class assigned to the login screen component with an allow/deny list pertaining to a domain of the candidate phishing webpage; and

identifying the candidate phishing webpage as either a phishing webpage or a non-phishing webpage based on the correlating of the class assigned to the login screen component with the allow/deny list.

16 . The non-transitory computer-readable medium of claim 15 , wherein the domain of the candidate phishing webpage is determined through parsing of a uniform resource locator (URL) of the candidate phishing webpage.

17 . The non-transitory computer-readable medium of claim 15 , wherein the candidate phishing webpage includes the login screen component and additional text or imagery, and wherein identifying the login screen component within the image of the candidate phishing webpage includes differentiating the login screen component from the additional text or imagery.

18 . The non-transitory computer-readable medium of claim 15 , wherein the encoder is a component of an autoencoder, wherein the autoencoder includes both the encoder and a decoder, wherein both the encoder and the decoder are separate neural networks.

19 . The non-transitory computer-readable medium of claim 18 , wherein the operations further include:

training the autoencoder on training data comprising sample webpage images, wherein at least a portion of the sample webpage images include login screen components, and iteratively performing a set of operations for each of the sample webpage images including:

providing a first sample webpage image to the encoder resulting in generation of a first sample latent representation,

decoding the first sample latent representation by the decoder thereby producing a reconstructed version of a sample login component of the first sample webpage image,

comparing the reconstructed version of the sample login component of the first sample webpage image with an original version of the sample login component of the first sample webpage image resulting in computation of a loss, and

adjusting a set of parameters of one or more of the encoder or the decoder based on the loss.

20 . The non-transitory computer-readable medium of claim 18 , wherein layers of the encoder are asymmetrical to layers of the decoder.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2026
From: SHARAD, KUMAR; MISHRA, ABHINAV; AVINA, GLORY EMMANUEL
To: CISCO TECHNOLOGY, INC.
Reel/Frame 073770/0806 →
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
Continuity (1)
Related Publication 20250337777A1 · Oct 30, 2025
References Cited (19)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 11438377B1 · Azarafrooz · 2022 [cited by examiner]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20200358819A1 · Bowditch et al. · 2020 [cited by applicant]
US 20210344711A1 · Cleveland · 2021 [cited by examiner]
CA 3068953A1 · 2019 [cited by applicant]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
G. E. Avina, et al. “Systems and Methods for Detection of Typosquatting Domain Names Through Deployment of Language Models and Generation Of Targeted Training Data Therefore,” filed Apr. 30, 2024, U.S. Appl. No. 18/651,… [cited by applicant]
PCT/US2025/026691 filed Apr. 28, 2025, International Search Report and Written Opinion dated Jun. 17, 2025. [cited by applicant]