Phishing website detection method, system and equipment based on multi-role agent debate

By employing a multi-role intelligent agent debate method, combined with URL, HTML structure, semantic content, and brand counterfeiting detection, and coordinating multi-dimensional feature analysis of phishing websites, the problems of misjudgment by single models and information silos are solved, achieving highly accurate and interpretable phishing website detection.

CN121125303APending Publication Date: 2025-12-12CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511425054.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-30
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Existing phishing website detection technologies rely on a single model or fixed rule set, resulting in a high false positive rate, insufficient robustness, difficulty in dealing with phishing attacks that are constantly evolving, and a lack of effective collaboration and information sharing, making it impossible to meet the accuracy and adaptability requirements in complex network environments.

Method used

A multi-role intelligent agent debate method is adopted, which configures professional intelligent agents (URL analysis, HTML structure analysis, semantic content analysis, brand counterfeiting detection) to conduct multi-dimensional feature analysis. The moderator intelligent agent distributes tasks and coordinates the debate, and the judge intelligent agent makes arbitration decisions to generate a structured chain of evidence.

Benefits of technology

It significantly improves the accuracy and anti-interference ability of phishing website detection, provides interpretable judgment results, and adapts to the detection needs in complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125303A_ABST
    Figure CN121125303A_ABST
Patent Text Reader

Abstract

The invention relates to a phishing website detection method, system and device based on multi-role agent debate. The method comprises the following steps: configuring a multi-role agent, wherein the multi-role agent comprises a professional agent, a host agent and a judge agent; the method comprises the following steps: carrying out preliminary feature recognition on a to-be-detected website through a host agent, distributing a preliminary detection task to a matched professional agent, monitoring opinion divergence according to an analysis result of each professional agent, and if divergence exists, distributing a debate task to the corresponding professional agent to carry out dynamic debate. After debate is finished, an analysis result of the professional agent is submitted to the judge agent as a debate result; and performing classification judgment on the to-be-detected website and outputting a judgment result through the judge agent according to the debate result, a preset arbitration rule and a confidence coefficient threshold, and generating a structured evidence chain corresponding to the judgment result. By adopting the method, the accuracy, the anti-interference capability and the interpretability of phishing website detection can be remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to a phishing website detection method, system and device based on multi-role agent debate. BACKGROUND

[0002] With the rapid popularization of Internet technology and the deepening of digital transformation in various industries, the threats in the field of network security are becoming increasingly complex. As a typical attack form that uses social engineering and technical means to implement fraud, phishing websites not only steal sensitive information and property of individual users, but also pose a serious threat to the safe and stable operation of enterprises, financial institutions and government systems.

[0003] To address this challenge, phishing website detection technology has gradually developed and formed multiple technical directions. For example, some technologies extract domain name reputation, character patterns and other features of URLs to achieve preliminary identification, some technologies focus on HTML structure analysis to detect abnormal link pointing and form submission behavior, some technologies use natural language processing (NLP) to analyze page text to identify fraudulent expressions, or some technologies compare the logos and texts of genuine brands to detect counterfeit phishing websites. These technologies each form a certain recognition ability around a specific detection dimension and play a protective role in specific scenarios.

[0004] However, the current mainstream phishing website detection methods mostly rely on a single model or fixed rule set. Such traditional methods have obvious shortcomings in actual application: on the one hand, a single model is prone to "model illusion" and misjudgment due to its own limitations, such as misjudging legitimate URLs with special character patterns as phishing links, or missing phishing pages with precise wording but suspicious structure. Moreover, it lacks robustness in the face of constantly updated attack strategies by phishers (such as using obfuscated JavaScript to dynamically load web page content), making it difficult to cope with new phishing methods. On the other hand, there is a lack of effective coordination and information sharing among various detection technologies, forming "information silos" and failing to leverage complementary advantages. Many models are also limited by input length, making it difficult to analyze long texts or complex script pages comprehensively, resulting in potential phishing features being overlooked. The "black box" decision-making process of a single model cannot provide clear and traceable detection evidence, which is inconvenient for fields such as finance and government that require high compliance audits. In addition, existing detection systems are mostly fixed architectures, making it difficult to dynamically configure and optimize according to specific needs such as resource constraints of mobile devices or emergency scenarios. These problems collectively result in the accuracy, adaptability and practicality of current phishing website detection being difficult to meet the increasingly complex network security protection needs. SUMMARY

[0005] Therefore, it is necessary to provide a phishing website detection method, system, and device based on multi-role intelligent agent debate to address the aforementioned technical problems.

[0006] A phishing website detection method based on multi-role agent debate, the method comprising: Configure multi-role intelligent agents, including professional intelligent agents, host intelligent agents, and judge intelligent agents; the professional intelligent agents are used to perform feature analysis of phishing websites from different dimensions, including at least URL analysis, HTML structure analysis, semantic content analysis, and brand counterfeiting detection intelligent agents; The host agent performs preliminary feature identification on the website to be tested, distributes the preliminary detection task to the matched professional agents, and monitors the differences of opinion based on the analysis results of each professional agent. If there are differences, the debate task is distributed to the corresponding professional agent to conduct dynamic debate. After the debate, the analysis results of the professional agents are submitted to the judge agent as the debate results. The analysis results are standardized analysis results including detection conclusions, confidence levels and supporting evidence. The judge agent classifies and judges the websites to be tested based on the debate results, preset arbitration rules, and confidence thresholds, and outputs the judgment results, generating a structured evidence chain corresponding to the judgment results.

[0007] A phishing website detection system based on multi-role intelligent agent debate, the system comprising: The user configuration interface is used to receive basic system configuration parameters input by the user. The system controller, connected to the user configuration interface, is used to trigger the detection process based on the basic configuration parameters and to schedule the collaborative work of each component. The module manager, connected to the system controller, is used to manage the instantiation and interaction channels of multi-role intelligent agents, including professional intelligent agents, host intelligent agents, and judge intelligent agents; the professional intelligent agents include at least URL analysis, HTML structure analysis, semantic content analysis, and brand counterfeiting detection intelligent agents; The host agent performs preliminary feature identification on the website to be detected, distributes the preliminary detection task to the matched professional agents, and monitors the differences of opinion based on the analysis results of each professional agent. If there are differences, the host agent distributes the debate task to the corresponding professional agent to conduct dynamic debate. After the debate, the analysis results of the professional agents are submitted to the judge agent as the debate results. The analysis results are standardized analysis results including detection conclusions, confidence levels and supporting evidence. The judge agent classifies and judges the websites to be tested based on the debate results, preset arbitration rules, and confidence thresholds, and outputs the judgment results, generating a structured evidence chain corresponding to the judgment results.

[0008] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program performing the following steps: Configure multi-role intelligent agents, including professional intelligent agents, host intelligent agents, and judge intelligent agents; the professional intelligent agents are used to perform feature analysis of phishing websites from different dimensions, including at least URL analysis, HTML structure analysis, semantic content analysis, and brand counterfeiting detection intelligent agents; The host agent performs preliminary feature identification on the website to be tested, distributes the preliminary detection task to the matched professional agents, and monitors the differences of opinion based on the analysis results of each professional agent. If there are differences, the debate task is distributed to the corresponding professional agent to conduct dynamic debate. After the debate, the analysis results of the professional agents are submitted to the judge agent as the debate results. The analysis results are standardized analysis results including detection conclusions, confidence levels and supporting evidence. The judge agent classifies and judges the websites to be tested based on the debate results, preset arbitration rules, and confidence thresholds, and outputs the judgment results, generating a structured evidence chain corresponding to the judgment results.

[0009] The aforementioned phishing website detection method, system, and device based on multi-role intelligent agent debate, by configuring professional intelligent agents covering multiple dimensions such as URL features, HTML structure, semantic content, and brand imitation, can comprehensively capture the complex disguise features of phishing websites. It accurately addresses the problem of missed detection due to incomplete feature coverage in single-dimensional detection. The moderator intelligent agent distributes tasks based on initial identification and coordinates disagreements through a dynamic debate mechanism, making the detection conclusions more closely reflect the actual risks of the website. The judge intelligent agent generates a judgment based on the debate results, arbitration rules, and confidence thresholds, and outputs a structured evidence chain containing full-process analysis and reasoning. This not only avoids subjective bias through quantitative standards but also solves the pain point of untraceable decision-making in traditional black-box models. The embodiments of this invention can significantly improve the accuracy, anti-interference ability, and interpretability of phishing website detection, effectively adapting to the detection needs in complex network environments. Attached Figure Description

[0010] Figure 1 This is a flowchart illustrating a phishing website detection method based on multi-role agent debate in one embodiment. Figure 2 This is a flowchart illustrating a phishing website detection method based on multi-role agent debate in a specific embodiment. Figure 3 This is a flowchart illustrating anti-truncation content processing in one embodiment; Figure 4 This is a schematic diagram of the truncation identifier injection process in one embodiment; Figure 5 This is a diagram of a multi-role intelligent agent debate architecture in one embodiment; Figure 6 This is a schematic diagram of the modular architecture of a phishing website detection system based on multi-role intelligent agent debate in one embodiment. Figure 7 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0011] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0012] In one embodiment, such as Figure 1 As shown, a phishing website detection method based on multi-role intelligent agent debate is provided, including the following steps: Step 102: Configure multi-role intelligent agents, including professional intelligent agents, host intelligent agents, and judge intelligent agents.

[0013] Specialized intelligent agents are used to perform feature analysis of phishing websites from different dimensions, including at least URL analysis, HTML structure analysis, semantic content analysis, and brand counterfeiting detection agents.

[0014] Multi-role intelligent agents refer to a collection of intelligent agents undertaking different functions, achieving a complete process of phishing website detection through division of labor and cooperation. Specialized intelligent agents are analytical units focusing on specific characteristic dimensions of phishing websites. Among them, the URL analysis intelligent agent analyzes features such as the domain structure and character patterns of website links; the HTML structure analysis intelligent agent parses the structural features of web pages such as the DOM tree and script behavior; the semantic content analysis intelligent agent identifies content features such as the fraudulent tendencies of page text; the brand counterfeiting detection intelligent agent compares the visual and logo similarity between the page and legitimate brands; the moderator intelligent agent is responsible for coordinating the interaction and debate process among the intelligent agents; and the judge intelligent agent is responsible for the final judgment and the generation of the evidence chain. Existing solutions often rely on single-dimensional features such as URLs or text, which are prone to missed detection due to the multi-dimensional disguise of phishing websites (such as counterfeiting brands while hiding URL anomalies). The configuration of multi-role intelligent agents provides a foundation for comprehensively capturing phishing features, improving the comprehensiveness of detection from the source.

[0015] Step 104: The host agent performs preliminary feature identification on the website to be tested, distributes the preliminary detection task to the matched professional agents, and monitors the differences of opinion based on the analysis results of each professional agent. If there are differences, the debate task is distributed to the corresponding professional agent to conduct dynamic debate. After the debate, the analysis results of the professional agents are submitted to the judge agent as the debate results.

[0016] The analysis results are standardized analysis results including detection conclusions, confidence scores, and supporting evidence. These standardized results are uniformly formatted data output by specialized agents and can be stored in the debate pool, a shared data area temporarily storing the output results of all agents. The data structure must be in standardized JSON format, containing three mandatory fields: Claim: Detection conclusion category; Confidence: Confidence score; Evidence: Supporting evidence. The moderator agent continuously monitors the debate pool. When there are disagreements in the content output by agents (e.g., URL analysis considers it suspicious, but semantic analysis considers it normal), or when more in-depth information is needed, the moderator agent will coordinate relevant agents to conduct further debates or supplementary analyses. For example, if the HTML structure analysis agent detects a JavaScript function that may be used for dynamically loading content, the moderator can instruct the semantic content agent or the brand counterfeiting agent to focus on this dynamically loaded content. The moderator can also increase the depth of analysis by adjusting the debate rounds. Key output data throughout the debate process is recorded by the moderator and ultimately aggregated.

[0017] Understandably, the dynamic debate mechanism breaks down information silos through targeted supplementary analysis, making the detection results more consistent with the actual risks of websites and significantly reducing the misjudgment rate of single dimensions.

[0018] Step 106: The judge's intelligent agent classifies and judges the websites to be tested based on the debate results, preset arbitration rules and confidence thresholds, and outputs the judgment results, generating the structured evidence chain corresponding to the judgment results.

[0019] The pre-defined arbitration rules serve as the logical basis for the judge's decision (e.g., prioritizing the acceptance of conclusions reached by a majority of agents). The confidence threshold is the quantitative standard for identifying phishing websites (e.g., determining it as phishing when the overall confidence level is ≥0.8). The structured evidence chain is traceable data recording the entire detection process, including the analysis results of each agent, the debate process, and the basis for the decision. The structured evidence chain clearly presents the complete logic from multi-agent analysis to the final decision, ensuring the credibility of the judgment and providing a clear basis for subsequent manual review and risk tracing. At the same time, the quantitative threshold and arbitration rules avoid the arbitrariness of subjective judgment.

[0020] The aforementioned phishing website detection method based on multi-role intelligent agent debate, by configuring specialized intelligent agents covering multiple dimensions such as URL features, HTML structure, semantic content, and brand imitation, can comprehensively capture the complex disguise features of phishing websites. It accurately addresses the issue of missed detection due to incomplete feature coverage in single-dimensional detection. The moderator intelligent agent distributes tasks based on initial identification and coordinates disagreements through a dynamic debate mechanism, making the detection conclusions more closely reflect the actual risks of the website. The judge intelligent agent generates a judgment based on the debate results, arbitration rules, and confidence thresholds, and outputs a structured evidence chain containing full-process analysis and reasoning. This not only avoids subjective bias through quantitative standards but also solves the pain point of untraceable decision-making in traditional black-box models. This invention significantly improves the accuracy, anti-interference ability, and interpretability of phishing website detection, effectively adapting to the detection needs in complex network environments.

[0021] In one embodiment, the specialized intelligent agent is used to perform feature analysis of phishing websites across different dimensions, including: a URL analysis agent for analyzing domain reputation, character patterns, redirection chains, and subdomain structure; an HTML structure analysis agent for parsing the DOM tree, JavaScript dynamic behavior, form submission targets, and abnormal link pointers; a semantic content analysis agent for identifying fraudulent words, sentiment tendencies, and misleading expressions in the page text; and a brand counterfeiting detection agent for comparing the similarity of the logo, brand name, and contact information on the page with known brands.

[0022] In this embodiment, by covering technical features such as URL and structure, as well as semantic features such as content and brand, the system avoids missed detections due to incomplete feature coverage in single-dimensional analysis, significantly improving the comprehensiveness of detection. Combined with the hot-swappable agent mechanism implemented through modular interfaces, the configuration of the aforementioned specialized agents is not fixed or limited. In practical applications, specialized agents of other dimensions (such as agents analyzing SSL certificate anomalies, AI-based image tampering detection agents, etc.) can be flexibly added according to the evolution of phishing methods or the needs of specific detection scenarios. Furthermore, newly added agents can be quickly integrated into the system through automatic registration of feature dimensions and output formats without modifying the core architecture. This means that the system not only covers current feature dimensions such as URL, structure, content, and brand, but also has the flexibility to dynamically expand its analytical capabilities as threats change, thereby continuously adapting to new phishing methods and significantly improving the system's scenario adaptability and long-term evolutionary capabilities.

[0023] In one embodiment, preliminary feature identification of the website to be detected and the distribution of preliminary detection tasks to matching professional intelligent agents include: extracting basic features of the website to be detected, determining potential risk dimensions based on a preset feature library and basic features, determining preliminary detection tasks based on potential risk dimensions, and distributing preliminary detection tasks to corresponding professional intelligent agents; basic features include URL features, page titles, and metadata. In this embodiment, basic features such as URL features, page titles, and metadata of the website to be detected are extracted, and potential risk dimensions are determined in conjunction with a preset feature library (e.g., URLs containing abnormal characters are determined as URL risk dimensions). Then, preliminary detection tasks are distributed to corresponding professional intelligent agents (e.g., URL risk dimensions correspond to URL analysis intelligent agents) based on potential risk dimensions. This avoids indiscriminate calls to all intelligent agents, reducing unnecessary computational overhead and ensuring that initial detection focuses on high-risk dimensions, thus improving detection efficiency and targeting.

[0024] In one embodiment, monitoring for disagreements based on the analysis results of each specialized agent, and if a disagreement exists, distributing debate tasks to the corresponding specialized agents for dynamic debate includes: if at least two specialized agents have contradictory detection conclusions, and the difference in their confidence levels is less than or equal to a credibility threshold, a disagreement is determined. The moderator agent sends a supplementary analysis instruction to the specialized agents involved in the disagreement, containing opposing evidence to be verified. This process is repeated until the conditions for stopping the debate are met, at which point the debate ends. In this embodiment, when at least two specialized agents have contradictory detection conclusions, and the difference in their confidence levels is ≤ a credibility threshold, a disagreement is determined. The moderator agent sends a supplementary analysis instruction containing opposing evidence (e.g., having the semantic agent verify an abnormal domain name discovered by the URL agent) to the specialized agents involved in the disagreement. This process is repeated until the conditions for stopping the debate are met (e.g., consistent conclusions or reaching the maximum number of rounds). It can be understood that by specifically verifying opposing evidence, the problem of difficulty in handling conflicts in static result integration is effectively solved, promoting the convergence of detection conclusions towards real risks and reducing the false judgment rate.

[0025] In one embodiment, classifying and outputting a judgment result for the website to be detected based on the debate results, preset arbitration rules, and a confidence threshold includes: obtaining the debate results; if the detection conclusions of each professional agent are determined to be a high-confidence consensus in the debate results, then the judgment result is output based on the consensus detection results; otherwise, the detection conclusions of each professional agent are weighted and summed using a preset weighting rule to obtain a weighted confidence sum; and the classification and judgment result is output based on the relationship between the weighted confidence sum and the confidence threshold. In this embodiment, after obtaining the debate results, if the detection conclusions of each professional agent form a high-confidence consensus (e.g., most conclusions are consistent and have high confidence), then the judgment result is directly output based on the consensus; otherwise, the detection conclusions of each agent are weighted and summed using a preset weighting rule, and the judgment result is output based on the relationship between the weighted confidence sum and the confidence threshold (e.g., if the sum ≥ the confidence threshold, it is determined to be a phishing website). Understandably, this decision-making method respects the consensus of multiple agents to reduce computational costs, while also using weights to reflect the importance of different dimensions when disagreements exist, thus balancing the value of multi-source information and improving the accuracy and rationality of the decision. In one embodiment, the structured evidence chain includes the analysis results of each professional intelligence agent, the record of debate rounds, the arbitration record, and the reasoning chain of the judgment result; the record of debate rounds includes the points of divergence, supplementary analysis instructions, and response results for each round of debate. In this embodiment, the reasoning chain of the judgment result refers to the record of the complete logical deduction process of the judge intelligence agent from receiving the debate results to outputting the final judgment, specifically including: referencing the key detection conclusions and supporting evidence of each professional intelligence agent in the debate results (such as the domain name anomaly evidence of the URL analysis intelligence agent and the high similarity evidence of the logo of the brand counterfeiting detection intelligence agent); matching and explaining the applicable preset arbitration rule clauses (such as the specific application of the majority principle or weighted rule); presenting the calculation details of the confidence level (such as the weight allocation of the conclusions of each intelligence agent and the derivation process of the weighted sum); and the correlation argument between the final judgment category (phishing / legal) and the above evidence, rules, and calculation results (such as judging it as a phishing website because the weighted confidence level exceeds the threshold τ). By fully recording the entire process logic from multi-agent analysis to debate coordination and final judgment, the problem of black box decision-making in traditional detection models is solved. This not only provides clear evidence for result traceability and meets the compliance audit needs of fields such as finance and government, but also enhances the credibility and interpretability of the judgment results.

[0026] In one embodiment, the method further includes: dynamically loading or unloading specialized intelligent agents using a modular interface, wherein the feature analysis dimensions and output format corresponding to the specialized intelligent agent are automatically registered during loading. In this embodiment, the dynamic loading or unloading of specialized intelligent agents is achieved through a modular interface. During loading, the feature analysis dimensions and output format corresponding to the intelligent agent are automatically registered, and unloading does not affect the core logic of the system. This improves the system's flexibility and scalability, allowing for flexible addition or removal of intelligent agents based on detection scenario requirements (such as lightweight mobile detection or deep server-side detection). This avoids redundant functions consuming resources and facilitates the integration of new dimension analysis capabilities (such as adding AI image recognition intelligent agents), reducing system maintenance and upgrade costs.

[0027] In one embodiment, the method further includes: if the length of the webpage content to be analyzed exceeds a preset threshold, intelligently truncating the content based on the nearest HTML tag boundary in the located content, and injecting a truncation marker at the truncation position; when the professional intelligent agent detects the truncation marker, marking the content as incomplete in the analysis results, and reducing the confidence weight of features that depend on the complete structure.

[0028] In this embodiment, intelligent truncation solves the structural damage problem caused by long webpage content exceeding the analysis length limit. It preserves the partial integrity of the content while clarifying the content status by adjusting the weights of content with truncation markers, avoiding misjudgments due to incomplete information and improving the adaptability and accuracy of long webpage detection. Furthermore, when a specialized intelligent agent detects a truncation marker, it can also attempt backtracking analysis.

[0029] In one specific embodiment, such as Figure 2 The diagram illustrates a flowchart of a phishing website detection method based on multi-role intelligent agent debate, comprising the following steps: S101: Receive the URL to be detected: Obtain the website link to be detected as input for the detection process.

[0030] S102: Initialize all agents: Start multi-role agents (including professional agents such as URL analysis, HTML structure, semantic content, brand imitation, etc., as well as host agent and judge agent) and put them into a working state.

[0031] Four specialized intelligent agents perform feature analysis in parallel (demonstrating the advantages of multi-dimensional coverage detection): URL Analysis (S103): Analyze URL dimension features such as domain reputation and character patterns. S104 determines whether to output standardized JSON results containing detection conclusions, confidence levels, and supporting evidence. HTML structure analysis (S105): Parse structural features such as DOM tree and JavaScript behavior, and determine whether to output standardized JSON in S106; Semantic content analysis (S107): Identify content features such as fraudulent words and sentiment, and determine whether to output standardized JSON in S108; Brand counterfeiting analysis (S109): Compare counterfeiting features such as logo and brand name, and determine whether to output standardized JSON through S110.

[0032] (A "no" branch indicates an abnormal result generation, requiring retry or processing; a "yes" branch proceeds to the next step to ensure effective transmission of analysis results across all dimensions.) S111: Moderator coordinates debate: The moderator agent collects the analysis results of various professional agents and monitors whether there are any disagreements; if there are disagreements, it distributes debate tasks to the corresponding agents to promote dynamic debate.

[0033] S112: JSON of the debate process submitted by the agent: records supplementary analysis instructions, response results, new evidence, etc. during the debate, providing a more comprehensive basis for subsequent judgments.

[0034] S113: The judge's intelligent agent integrates all JSON: summarizing the initial analysis results and the results of the debate process to obtain complete multi-dimensional evidence.

[0035] S114: Judges make JSON-based decisions: Based on preset arbitration rules (such as majority consensus, weighted average) and confidence thresholds, they determine whether the website to be detected is a phishing website.

[0036] S115: Generate a structured chain of evidence: Organize the evidence throughout the entire process of multi-agent analysis → debate coordination → judge's judgment into a structured form to ensure that the results are traceable and interpretable.

[0037] S116: Output detection results and evidence chain: Complete the detection and provide the final judgment (whether it is a phishing website) and the corresponding structured evidence chain.

[0038] In S101-S103, when a URL to be detected (refer to...) Figure 1 When the two-tiered coordination mechanism is input into the system, the host intelligence first receives the URL. The host is responsible for making an initial judgment and distributing the task to one or more relevant agents. For example, it will hand over the URL itself to the URL analysis agent, the HTML content of the webpage to the HTML structure analysis agent and the semantic content agent, and the visual elements (such as the logo) and text in the webpage to the brand counterfeiting agent.

[0039] In steps S104, S106, S108, and S110, each agent independently performs its analysis task. For example, the URL analysis agent checks for domain name suspiciousness, path structure, parameter obfuscation, etc. The HTML structure analysis agent parses the DOM tree, looking for suspicious links, form submission behavior (such as submission to unrelated domains), and obfuscation or malicious behavior in JavaScript code. The semantic content agent analyzes the page text for fraudulent language such as urgent appeals or requests for sensitive information. The brand counterfeiting agent identifies brand elements on the page and determines whether they are counterfeit. After completing the analysis, each agent outputs its conclusions to the debate pool in a standardized JSON format. This JSON object contains `Claim` (e.g., abnormal characters in the URL), `Confidence` (e.g., 0.85 indicates high confidence), and `Evidence` (e.g., the URL string itself or a piece of HTML code).

[0040] In S111-S112, the moderator agent continuously monitors the debate pool. When there are discrepancies in the agents' outputs (e.g., URL analysis deems it suspicious, but semantic analysis considers it normal), or when more in-depth information is needed, the moderator agent coordinates relevant agents for further debate or supplementary analysis. For example, if the HTML structure analysis agent detects a JavaScript function that might be used for dynamically loading content, the moderator can instruct the semantic content agent or the brand counterfeiting agent to focus on this dynamically loaded content. The moderator can also increase the depth of analysis by adjusting the debate rounds. Key output data throughout the debate process is recorded by the moderator and ultimately aggregated.

[0041] In S113-S115, when the debate reaches the predetermined number of rounds, or when the moderator deems the information sufficient, the debate results (JSON outputs from all agents) are submitted to the judge agent. The judge agent, based on pre-defined arbitration rules (e.g., conclusions supported by the majority of agents, high-confidence conclusions taking precedence, and conclusions from specific agents having higher weight), and in conjunction with a pre-defined confidence threshold (τ), makes a final classification decision (fishing or legal). Simultaneously, the judge agent integrates all key agent outputs in JSON format, along with important interaction information from the debate, into a structured chain of evidence, recording the entire decision-making process to ensure its traceability and auditability.

[0042] like Figure 3The diagram illustrates a flowchart of anti-truncation content processing. When the content of the webpage to be analyzed is too long and may exceed the input length limit of the model, the system will activate the anti-truncation processing mechanism. First, the content processing module receives the original webpage content (S201). The system checks whether the content length exceeds the limit (S202). If it does not exceed the limit, the content is directly passed to the subsequent analyzer (S203). If the content exceeds the limit, the system searches for the nearest HTML tag boundary (e.g., ``) within the content. `, `, `, etc. (S204). Truncate the content at the found boundary (S205). For example... Figure 4 The diagram illustrates a process for injecting a truncation identifier, where a specific truncation identifier is injected at the truncation point, such as `<!--CONTENT_TRUNCATED--> `or`<!--CONTENT_TRUNCATED_BY_TAG_BOUNDARY--> (S206). This helps subsequent analyzers recognize that the content has been truncated. The truncated content is then passed to the subsequent analyzers (S207). When processing the content, the subsequent HTML structure analysis agent will recognize the incompleteness of the content if it encounters a truncation identifier, and may take appropriate strategies, such as trying different parsers, marking the result as an incomplete analysis, or including this information in the report (S208-S209). This approach preserves the HTML structure as completely as possible, improving the reliability of the analysis. For example, a phishing website may have a seemingly normal URL structure, but the page content uses a large amount of deceptive language and counterfeit brand logos. The URL analysis agent may give a low-risk score. The semantic content agent and the brand counterfeiting agent, however, will detect a large number of fraudulent words and highly similar brand elements, giving a high-risk score. In this case, the host agent may coordinate with the HTML structure analysis agent to further examine dynamically loaded elements on the page to confirm whether there are hidden malicious links. Ultimately, the judge's agent synthesized the opinions of various agents and found that the evidence from semantic and brand analysis was more conclusive. Even if URL analysis was low-risk, it could still be determined to be a phishing website based on the overall chain of evidence, and a detailed chain of evidence was generated to show that semantic and brand imitation led to the final judgment.

[0043] like Figure 5 As shown, a multi-role intelligent agent debate architecture diagram is provided. Figure 5This paper demonstrates the interaction logic of a two-level coordination mechanism in a phishing website detection process based on multi-role intelligent agent debate. The small diagram in the upper left corner abstracts the interaction relationship between three core roles (moderator, judge, and intelligent agent) and the debate pool: the moderator coordinates the debate process, the intelligent agents conduct multi-dimensional analysis, and the judge executes the final judgment. The three parties exchange viewpoints and converge results around the debate pool. First, in the task initiation and distribution steps, the URL to be detected is used as input and enters the task allocation stage. The detection task is distributed to four types of professional intelligent agents: URL analysis, HTML structure, brand imitation, and semantic content, allowing them to conduct feature analysis in parallel from different dimensions (links, page structure, brand identifiers, and text content). In the underlying interaction between the intelligent agents and the debate pool: after each professional intelligent agent completes its analysis, it submits a Claim (detection conclusion, such as 'suspected phishing'), Confidence (confidence level, such as 0.8), and Evidence (supporting evidence, such as abnormal URL fragments) to the debate pool. Simultaneously, the intelligent agents can update the Claim / Evidence through the debate pool to dynamically adjust their viewpoints (such as supplementing evidence for points of disagreement).

[0044] The moderator agent retrieves the conclusions and evidence from each agent in the debate pool, drives the debate process through instructions / feedback (e.g., instructing agents to supplement specific dimensions of analysis when disagreements are found), and transmits the final debate result to the judge agent. The judge agent receives the final debate result from the moderator, combines it with preset arbitration rules (such as multi-agent consensus and confidence weighting), and determines whether the website is a phishing scam or legitimate; simultaneously, it generates a structured chain of evidence (recording the entire process from agent analysis and debate interaction to the basis for the judgment), and finally outputs the detection result.

[0045] Understandably, intelligent agents freely exchange viewpoints through a debate pool, ensuring that multi-dimensional features (URL, structure, content, brand) are fully analyzed and avoiding omissions based on a single dimension. The moderator guides the debate to converge, and the judge executes the final judgment and generates a traceable chain of evidence, ensuring both process efficiency and interpretability of the test results (meeting compliance audit requirements).

[0046] It should be understood that, although Figure 1 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 1At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.

[0047] In one embodiment, a phishing website detection system based on multi-role agent debate is provided, comprising: The user configuration interface is used to receive basic system configuration parameters input by the user. The system controller connects to the user configuration interface and is used to trigger the detection process based on basic configuration parameters and schedule the collaborative work of various components. The module manager, connected to the system controller, manages the instantiation and interaction channels of multi-role intelligent agents, including professional intelligent agents, host intelligent agents, and judge intelligent agents; professional intelligent agents include at least URL analysis, HTML structure analysis, semantic content analysis, and brand counterfeiting detection intelligent agents; The host agent performs preliminary feature identification on the website to be tested, distributes the preliminary testing task to the matched professional agents, and monitors the differences of opinion based on the analysis results of each professional agent. If there are differences, the host agent distributes the debate task to the corresponding professional agent to conduct dynamic debate. After the debate, the analysis results of the professional agents are submitted to the judge agent as the debate results. The analysis results are standardized analysis results including the detection conclusion, confidence level and supporting evidence. The judge's intelligent agent classifies and judges the websites to be tested based on the debate results, preset arbitration rules and confidence thresholds, and generates a structured chain of evidence corresponding to the judgment results.

[0048] In one specific embodiment, such as Figure 6 The diagram illustrates a modular architecture for a phishing website detection system based on multi-role intelligent agent debate. The core of this system is flexible configuration and expansion achieved through hierarchical scheduling and dynamic management, including: User configuration interface: As the interaction point between the system and the user, it receives configuration requirements such as resource-constrained mode (e.g., when device resources are scarce, the detection process can be simplified).

[0049] System Controller: This is the core scheduling layer. After receiving user configuration, it distributes configuration parameters to three types of components: Agent activation status: Controls whether each functional module (corresponding agent) is enabled; Debate Rounds / Thresholds: Manages core parameters such as the maximum number of rounds and confidence thresholds for dynamic debate sessions; Module Manager: Responsible for performing dynamic management operations on each functional module.

[0050] The module manager is the central manager of the functional modules. It performs fine-grained operations (such as loading / unloading, hot-swapping, disabling / enabling) on ​​the professional intelligent agent module, the moderator module (responsible for task distribution and debate coordination), and the judge module (responsible for final judgment and evidence chain generation). When resources are sufficient, it loads / unloads all modules to achieve full-dimensional deep detection. When resources are limited (such as edge device detection), it disables some non-core modules to ensure lightweight operation. When adding a new detection dimension (such as AI image counterfeiting detection), it quickly connects the new module through hot-swapping without reconstructing the system.

[0051] In this embodiment, users can manage various modules of the system through configuration interfaces. Hot-swappable agents: Users can choose to enable or disable specific agents according to actual needs. For example, on resource-constrained mobile devices, users can choose to enable only the URL analysis module and the brand counterfeiting module to reduce computational overhead and response time. The system dynamically loads or unloads the corresponding agent modules through the module manager. Debate rounds and threshold adjustment: Users can configure the total number of debate rounds (e.g., set to 3 or 5 rounds) and the early stopping confidence threshold τ for the judge agent. This will affect the system's response speed and analysis depth. Through the logic of user configuration → controller scheduling → dynamic module management, the system supports both scenario-based customization (adapting to different resource environments and detection needs) and strong scalability (easily integrating new agent modules). Furthermore, through parameter configuration such as debate rounds / thresholds, it provides flexible rule support for core processes such as dynamic debates, ultimately achieving high efficiency, adaptability, and evolvability in phishing website detection.

[0052] Specific limitations regarding the phishing website detection system based on multi-agent debate can be found in the limitations of the phishing website detection method based on multi-agent debate mentioned above, and will not be repeated here. Each module in the aforementioned phishing website detection system based on multi-agent debate can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0053] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 7As shown, the computer device includes a processor, memory, network interface, display screen, and input system connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external terminals via a network connection. When executed by the processor, the computer program implements a phishing website detection method based on multi-role intelligent agent debate. The display screen can be an LCD screen or an e-ink screen. The input system can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.

[0054] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0055] In one embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, the processor executing the computer program to implement the steps of the method described above.

[0056] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0057] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A phishing website detection method based on multi-role intelligent agent debate, characterized in that, The method includes: Configure multi-role intelligent agents, including professional intelligent agents, host intelligent agents, and judge intelligent agents; the professional intelligent agents are used to perform feature analysis of phishing websites from different dimensions, including at least URL analysis, HTML structure analysis, semantic content analysis, and brand counterfeiting detection intelligent agents; The host agent performs preliminary feature identification on the website to be tested, distributes the preliminary detection task to the matched professional agents, and monitors the differences of opinion based on the analysis results of each professional agent. If there are differences, the debate task is distributed to the corresponding professional agent to conduct dynamic debate. After the debate, the analysis results of the professional agents are submitted to the judge agent as the debate results. The analysis results are standardized analysis results including detection conclusions, confidence levels and supporting evidence. The judge agent classifies and judges the websites to be tested based on the debate results, preset arbitration rules, and confidence thresholds, and outputs the judgment results, generating a structured evidence chain corresponding to the judgment results.

2. The method according to claim 1, characterized in that, The specialized intelligent agent is used to perform feature analysis of phishing websites across different dimensions, including: URL analysis agents are used to analyze domain reputation, character patterns, redirection chains, and subdomain structure. The HTML structure analysis agent is used to parse the DOM tree, JavaScript dynamic behavior, form submission targets, and abnormal link pointers; Semantic content analysis agents are used to identify deceptive words, sentiment biases, and misleading expressions in page text; The brand counterfeit detection AI is used to compare the similarity of the logo, brand name, and contact information on the page with known brands.

3. The method according to claim 1, characterized in that, The preliminary feature identification of the website to be detected and the distribution of the preliminary detection task to the matched professional intelligent agent include: The basic features of the website to be detected are extracted, and the potential risk dimensions are determined based on the preset feature library and the basic features. The preliminary detection tasks are determined based on the potential risk dimensions and distributed to the corresponding professional intelligent agents. The basic features include URL features, page titles and metadata.

4. The method according to claim 1, characterized in that, Based on the analysis results of each professional intelligent agent, the system monitors for disagreements. If disagreements exist, debate tasks are distributed to the corresponding professional intelligent agents to conduct dynamic debates, including: If at least two professional agents reach contradictory conclusions, and the difference in their confidence levels is less than or equal to the confidence threshold, a disagreement is determined. The moderator agent sends a supplementary analysis instruction to the professional agents involved in the disagreement. The supplementary analysis instruction contains opposing evidence that needs to be verified. The above process is repeated until the conditions for stopping the debate are met, at which point the debate ends.

5. The method according to claim 1, characterized in that, Based on the debate results, preset arbitration rules, and confidence thresholds, the websites to be detected are classified and the judgment results are output, including: Obtain the debate results. If the detection conclusions of each professional intelligent agent in the debate results are judged to be a high-confidence consensus, then output the judgment result based on the consensus detection results. Otherwise, the detection conclusions of each professional intelligent agent are weighted and summed using pre-set weighting rules to obtain a weighted confidence sum. Based on the relationship between the weighted confidence sum and the confidence threshold, a classification decision is made and the decision result is output.

6. The method according to claim 1, characterized in that, The structured evidence chain includes the analysis results of each professional intelligent agent, the record of the debate rounds, the arbitration record, and the reasoning chain of the judgment result; the record of the debate rounds includes the points of divergence in each round of debate, supplementary analysis instructions, and response results.

7. The method according to claim 1, characterized in that, The method further includes: The modular interface enables the dynamic loading or unloading of specialized intelligent agents. During loading, the feature analysis dimensions and output format corresponding to the specialized intelligent agent are automatically registered.

8. The method according to claim 1, characterized in that, The method further includes: If the length of the webpage content to be analyzed exceeds the preset threshold, the content will be intelligently truncated based on the nearest HTML tag boundary in the located content, and a truncation marker will be injected at the truncation position. When a specialized intelligent agent detects the truncation marker, it marks the content as incomplete in the analysis results and reduces the confidence weight of features that depend on the complete structure.

9. A phishing website detection system based on multi-role intelligent agent debate, characterized in that, The system includes: The user configuration interface is used to receive basic system configuration parameters input by the user. The system controller, connected to the user configuration interface, is used to trigger the detection process based on the basic configuration parameters and to schedule the collaborative work of each component. The module manager, connected to the system controller, is used to manage the instantiation and interaction channels of multi-role intelligent agents, including professional intelligent agents, host intelligent agents, and judge intelligent agents; the professional intelligent agents include at least URL analysis, HTML structure analysis, semantic content analysis, and brand counterfeiting detection intelligent agents; The host agent performs preliminary feature identification on the website to be detected, distributes the preliminary detection task to the matched professional agents, and monitors the differences of opinion based on the analysis results of each professional agent. If there are differences, the host agent distributes the debate task to the corresponding professional agent to conduct dynamic debate. After the debate, the analysis results of the professional agents are submitted to the judge agent as the debate results. The analysis results are standardized analysis results including detection conclusions, confidence levels and supporting evidence. The judge agent classifies and judges the websites to be tested based on the debate results, preset arbitration rules, and confidence thresholds, and outputs the judgment results, generating a structured evidence chain corresponding to the judgment results.

10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Phishing website detection method and device, equipment and computer readable storage medium

    CN111756724A

  • Retrieval enhanced reasoning method, device and equipment for multi-agent debate

    CN118246554A

  • Multi-agent debate medical student ability assessment method and system

    CN119941006A

  • Method for intelligent agent simulation court trial based on large language model and debate judgment mode

    CN120297313A

  • Multi-agent debate

    WO2025183627A1