A MULTI-STAGE MACHINE LEARNING FRAMEWORK FOR EFFECTIVE SQL INJECTION DETECTION USING DATA AUGMENTATION AND CONTEXTUAL FEATURE EXTRACTION.
SQL Injection (SQLi) remains one of the most critical security threats to modern web applications, exploiting vulnerabilities in database query handling to gain unauthorized access to sensitive data. Traditional signature- based detection methods often fail to identify novel or obfuscated attack pat...
| Publicado en: | Scientific Culture Vol. 12; no. 2, Part 1; pp. 781 - 797 |
|---|---|
| Autores principales: | , , , , |
| Formato: | Artículo |
| Publicado: |
University of the Aegean
2026
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=191995782&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 191995782 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 24080071 I6HU jtl: Scientific Culture issn: 24080071 maglogo: N pubinfo: dt: 2026 vid: 12 iid: 2, Part 1 pid: 47715 pub: University of the Aegean artinfo: ui: 191995782 10.5281/zenodo.122.12666 ppf: 781 ppct: 16 formats: tig: atl: A MULTI-STAGE MACHINE LEARNING FRAMEWORK FOR EFFECTIVE SQL INJECTION DETECTION USING DATA AUGMENTATION AND CONTEXTUAL FEATURE EXTRACTION. aug: au: Awadelkarim, Awad M. Alsamiri, Reem A. Bushnag, Anas Chaabane, Slim Ben Mustafa, Mohammed affil: College of Computing and Information Technology, University of Tabuk, Tabuk 47713, Saudi Arabia. su: Generative adversarial networks Intrusion detection systems (Computer security) Computer software security Machine learning Random forest algorithms Long short-term memory Language models Data augmentation sug: subj: Generative adversarial networks Intrusion detection systems (Computer security) Computer software security Machine learning Random forest algorithms Long short-term memory Language models Data augmentation keyword: BERT (Bidirectional Encoder Representations from Transformers) Data Augmentation Generative Adversarial Networks (GAN) Hybrid Classification Model Long Short-Term Memory (LSTM) Random Forest Classifier (RF) SQL Injection (SQLi) Wasserstein GAN with Gradient Penalty (WGAN-GP) ab: SQL Injection (SQLi) remains one of the most critical security threats to modern web applications, exploiting vulnerabilities in database query handling to gain unauthorized access to sensitive data. Traditional signature- based detection methods often fail to identify novel or obfuscated attack patterns. This paper proposes a multi- stage hybrid machine learning framework that integrates three key components: (1) data augmentation using a Wasserstein Generative Adversarial Network with Gradient Penalty (WGAN-GP) to generate realistic malicious queries and balance class distributions; (2) contextual feature extraction using a Bidirectional Encoder Representations from Transformers (BERT) model to capture the semantic and syntactic relationships within SQL queries; and (3) classification through a hybrid Long Short-Term Memory (LSTM) and Random Forest (RF) model that refines sequential dependencies and enhances classification accuracy. Experimental evaluations demonstrate that the proposed framework achieves an accuracy of 95.1% and an area under the curve (AUC) of 0.988, outperforming conventional detection methods. The results confirm the effectiveness of integrating generative modeling, deep contextual representation, and hybrid classification for robust SQLi detection. Future work will focus on improving the generative data augmentation component and optimizing the architecture for real-time deployment in Web Application Firewalls (WAFs). The proposed framework provides a strong foundation for advancing machine learning–based SQLi detection in practical security applications. pubtype: Academic Journal doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2026 holdings: @attributes: islocal: N |
|---|