A MULTI-STAGE MACHINE LEARNING FRAMEWORK FOR EFFECTIVE SQL INJECTION DETECTION USING DATA AUGMENTATION AND CONTEXTUAL FEATURE EXTRACTION.

SQL Injection (SQLi) remains one of the most critical security threats to modern web applications, exploiting vulnerabilities in database query handling to gain unauthorized access to sensitive data. Traditional signature- based detection methods often fail to identify novel or obfuscated attack pat...

Descripción completa

Detalles Bibliográficos
Publicado en:Scientific Culture Vol. 12; no. 2, Part 1; pp. 781 - 797
Autores principales: Awadelkarim, Awad M., Alsamiri, Reem A., Bushnag, Anas, Chaabane, Slim Ben, Mustafa, Mohammed
Formato: Artículo
Publicado: University of the Aegean 2026
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=191995782&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 191995782
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        24080071
        I6HU
      jtl: Scientific Culture
      issn: 24080071
      maglogo: N
    pubinfo:
      dt: 2026
      vid: 12
      iid: 2, Part 1
      pid: 47715
      pub: University of the Aegean
    artinfo:
      ui:
        191995782
        10.5281/zenodo.122.12666
      ppf: 781
      ppct: 16
      formats:
      tig:
        atl: A MULTI-STAGE MACHINE LEARNING FRAMEWORK FOR EFFECTIVE SQL INJECTION DETECTION USING DATA AUGMENTATION AND CONTEXTUAL FEATURE EXTRACTION.
      aug:
        au:
          Awadelkarim, Awad M.
          Alsamiri, Reem A.
          Bushnag, Anas
          Chaabane, Slim Ben
          Mustafa, Mohammed
        affil: College of Computing and Information Technology, University of Tabuk, Tabuk 47713, Saudi Arabia.
      su:
        Generative adversarial networks
        Intrusion detection systems (Computer security)
        Computer software security
        Machine learning
        Random forest algorithms
        Long short-term memory
        Language models
        Data augmentation
      sug:
        subj:
          Generative adversarial networks
          Intrusion detection systems (Computer security)
          Computer software security
          Machine learning
          Random forest algorithms
          Long short-term memory
          Language models
          Data augmentation
      keyword:
        BERT (Bidirectional Encoder Representations from Transformers)
        Data Augmentation
        Generative Adversarial Networks (GAN)
        Hybrid Classification Model
        Long Short-Term Memory (LSTM)
        Random Forest Classifier (RF)
        SQL Injection (SQLi)
        Wasserstein GAN with Gradient Penalty (WGAN-GP)
      ab: SQL Injection (SQLi) remains one of the most critical security threats to modern web applications, exploiting vulnerabilities in database query handling to gain unauthorized access to sensitive data. Traditional signature- based detection methods often fail to identify novel or obfuscated attack patterns. This paper proposes a multi- stage hybrid machine learning framework that integrates three key components: (1) data augmentation using a Wasserstein Generative Adversarial Network with Gradient Penalty (WGAN-GP) to generate realistic malicious queries and balance class distributions; (2) contextual feature extraction using a Bidirectional Encoder Representations from Transformers (BERT) model to capture the semantic and syntactic relationships within SQL queries; and (3) classification through a hybrid Long Short-Term Memory (LSTM) and Random Forest (RF) model that refines sequential dependencies and enhances classification accuracy. Experimental evaluations demonstrate that the proposed framework achieves an accuracy of 95.1% and an area under the curve (AUC) of 0.988, outperforming conventional detection methods. The results confirm the effectiveness of integrating generative modeling, deep contextual representation, and hybrid classification for robust SQLi detection. Future work will focus on improving the generative data augmentation component and optimizing the architecture for real-time deployment in Web Application Firewalls (WAFs). The proposed framework provides a strong foundation for advancing machine learning–based SQLi detection in practical security applications.
      pubtype: Academic Journal
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2026
    holdings:
      @attributes:
        islocal: N