UniEmbed: A Novel Approach to Detecting XSS and SQL Injection Attacks Using Machine Learning

In the era of web applications, security vulnerabilities expose sensitive data and organizational integrity to sophisticated attacks. Researchers from the Faculty of Engineering and Natural Sciences at Sivas University of Science and Technology have developed a novel approach, UniEmbed, to detect cross-site scripting (XSS) and SQL injection attacks using machine learning classifiers. This approach leverages natural language processing techniques, combining features from Word2Vec, the Universal Sentence Encoder (USE), and FastText to extract meaningful data from web applications. The researchers conducted extensive experiments using various machine learning classifiers on three benchmark datasets, demonstrating exceptional results.

Key Takeaways:

  • UniEmbed, a unified approach, detects XSS and SQL injection attacks using machine learning classifiers, yielding outstanding results with an accuracy of 0.9982 and an F1-score of 0.9983 for XSS attacks.
  • The Multi-Layer Perceptron (MLP) classifier achieved exceptional performance, minimizing false positives and false negatives for XSS and SQL injection attacks.
  • Comparative analysis showed that the UniEmbed method consistently outperformed individual feature extraction methods across all classifiers.
  • The research concluded that UniEmbed is highly effective in detecting both XSS and SQL injection attacks, making it a promising approach for enhancing web application security.
  • The UniEmbed method has been peer-reviewed and published in the Arabian Journal for Science and Engineering, 2025;50(19):15591-15604.
  • Rezan Bakir, a researcher from Sivas University of Science and Technology, Faculty of Engineering and Natural Sciences, is the corresponding author of the study.

Statistics:

  • Accuracy of the UniEmbed method for XSS attacks: 0.9982.
  • F1-score of the UniEmbed method for XSS attacks: 0.9983.
  • Accuracy of the UniEmbed method for SQL injection attacks: exceeding 0.9980 across two datasets.
  • F1-score of the UniEmbed method for SQL injection attacks: 0.9980.
  • True positive rate of the UniEmbed method: high.
  • False positive rate of the UniEmbed method: low.
  • The UniEmbed method was evaluated using three benchmark datasets.

Sources:

  • Uniembed: a Novel Approach To Detect Xss and Sql Injection Attacks Leveraging Multiple Feature Fusion With Machine Learning Techniques. Arabian Journal for Science and Engineering, 2025;50(19):15591-15604. Springe Heidelberg, Tiergartenstrasse 17, D-69121 Heidelberg, Germany. (Springer - www.springer.com; Arabian Journal for Science and Engineering - www.springerlink.com/content/1319-8025/)
  • Faculty of Engineering and Natural Sciences, Sivas University of Science and Technology, Department of Computer Engineering, Sivas, Turkiye.