Skip to content

SOFTWARE ENGINEER · PHD CANDIDATE SZCZECIN, PL

Milosz Misiek

Code that ships. Research that's published.

* main

Software Engineer

Elastic Email 2023 — Present 3 years

Full Stack Development & AI Integration

  • Implementing AI-powered features using RAG architecture and large language models
  • Core engineer on Inbox — owning features across frontend, backend, and data layers
  • Building shared component library and reusable patterns adopted across product teams
  • Diagnosing and resolving performance bottlenecks across the full stack
TypeScript
React.js
Node.js
Express.js

PhD Candidate

West Pomeranian University of Technology 2024 — 2028 4-year program

Cybersecurity & Phishing Detection

  • Published 2 papers (HICSS 2025, IEEE Access 2026), 3rd accepted for CISIM 2026
  • Built browser extension for real-time phishing URL detection using XGBoost
  • Developing multi-layer detection pipeline combining NLP and computer vision
Python
PyTorch
Deep Learning
NLP

Web Developer

Maritime University of Szczecin 2023 — 2023 3 months

Procurement System Development

  • Built and delivered the first version of a full-stack procurement system (NDA project)
  • Deployed and configured on Debian server with secure database management
  • Led development across the entire project lifecycle to on-time delivery
React.js
Redux
Express.js
TypeScript
Accepted
2026

Phishing protection model based on machine learning vision detection approach

authors:Miłosz Misiek, Tomasz Hyla

Detects phishing pages from screenshots by fusing frozen SigLIP 2 and DINOv2 embeddings, with no fine-tuning. Evaluated on 70,785 web-page screenshots, the fused MLP reaches an F1 score of 0.9474 and an AUC of 0.9839.

Time: 15 mindoi:TBA
Available once the conference proceedings are published
Abstract

Phishing protection model based on machine learning vision detection approach

{ author(s): Miłosz Misiek, Tomasz Hyla }

Phishing attacks increasingly rely on visual deception to steal user data. Because attackers copy the exact appearance of legitimate websites, text-based and URL-based detectors often fail to identify the threat.

This paper presents a visual phishing detection approach that exploits the semantic knowledge of large pretrained vision models without the computational cost of fine-tuning. We extract embeddings from frozen SigLIP 2 and DINOv2 encoders and concatenate them into a single multimodal representation. We then train a lightweight Multi-Layer Perceptron (MLP) classifier on these fused features and compare its performance against XGBoost.

Evaluated on a dataset of 70,785 web-page screenshots, our fused MLP model achieves an F1 score of 0.9474 and an AUC of 0.9839. The results demonstrate that multimodal fusion of image-text and purely visual embeddings consistently outperforms single-encoder representations. Furthermore, a simple MLP is highly competitive with gradient boosting when trained on rich pretrained embeddings.

2026doi:TBA
Available once the conference proceedings are published
Published
2026

XGBoost-Based URL Phishing Detection Method With Cross-Dataset Validation

authors:Milosz Misiek, Tomasz Hyla

Conducted comprehensive cross-dataset validation of XGBoost for phishing URL detection across over 760,000 samples. The model achieved 90.7% accuracy, training 12.6x faster and using 3.6x less memory than comparable neural networks.

Time: 30 mindoi:10.1109/access.2026.3672690
VIEW PAPER
Abstract

XGBoost-Based URL Phishing Detection Method With Cross-Dataset Validation

{ author(s): Milosz Misiek, Tomasz Hyla }

This article analyses the performance characteristics of XGBoost models across multiple datasets for phishing URL detection, extending our previous conference paper with comprehensive cross-dataset validation and comparative analysis.

Using a validation framework with three distinct datasets — a custom phishing dataset (75,738 samples), the large-scale GramBeddings dataset (639,723 samples), and the PhiUSIIL dataset (47,103 samples)—we demonstrate that XGBoost delivers robust performance across diverse data sources. Our approach addresses the issue of feature instability, showing how balanced feature engineering is crucial for reliable detection.

The model achieves 90.7% accuracy and 91.2% F1 score on the custom dataset, with a solid 77.8% average accuracy across three independent test sets. In comparative benchmarks against Neural Networks, XGBoost proved superior in training efficiency and detection quality, achieving 2.1% higher accuracy and training 12.6 times faster (0.95s vs 12.01s) with 3.6 times less memory. Although Neural Networks offered faster inference (7.51ms vs 20.6ms) and smaller model sizes, XGBoost’s balance of high accuracy and rapid training makes it highly effective for practical, real-world phishing detection systems.

2026doi:10.1109/access.2026.3672690
VIEW PAPER
Published
2025

Preventing Phishing Attacks with Browser-Based URL Detection

authors:Miłosz Misiek, Tomasz Hyla

Built and evaluated a machine-learning browser extension using XGBoost to detect phishing attacks in real-time. The solution accurately identifies malicious URLs while offering an exceptional balance of computational efficiency and interpretability.

Time: 15 mindoi:10.24251/hicss.2025.874
VIEW PAPER
Abstract

Preventing Phishing Attacks with Browser-Based URL Detection

{ author(s): Miłosz Misiek, Tomasz Hyla }

One way to protect users from clicking on a malicious URL is to continuously check all URLs displayed on the website and notify them when a suspicious URL is detected.

This paper presents a browser plug-in to detect malicious web addresses facilitating phishing attacks. The plug-in leverages a machine-learning model, specifically the Extreme Gradient Boosting decision tree model. The results indicate high performance in accurately identifying malicious URLs.

Although the XGBoost model does not achieve the highest possible accuracy, it offers an exceptional balance between various performance metrics. It provides practical benefits in terms of computational efficiency and interpretability. These features make it a solid foundation for further development and potential implementation in phishing detection systems on social networking sites. The plug-in identifies and flags all external URLs on a given page, providing users with information regarding the potential maliciousness of a URL.

2025doi:10.24251/hicss.2025.874
VIEW PAPER
00
NDA2025

Inbox: Communication Platform

Core Engineer

Built a real-time communication system as a core contributor. Unified multiple messaging protocols into a single app, delivering a seamless cross-channel experience.

Next.jsNodeJSMongoDBGraphQLTypeScriptWebSocket
Inbox: Communication Platform
01
NDA2024

Home Page: Elastic Email

Engineer

Contributed to the Elastic Email marketing website. Focused on performance and rendering efficiency to improve user experience.

Next.jsTypeScriptTailwindCSS
Home Page: Elastic Email
02
NDA2023

Template Editor: Elastic Email

Engineer

Worked on a complex, client-heavy email template editor, addressing drag-and-drop integration, state synchronization challenges, and rendering performance for complex layouts.

ReactTypeScriptStyled ComponentsWordPress Gutenberg
Template Editor: Elastic Email

Let’s connect.

Have an idea or interesting problem? I’d love to hear about it.