A NOVEL DEEP LEARNING APPROACH USING AUTOENCODER-BASED FEATURE LEARNING FOR CROSS-SITE SCRIPTING DETECTION

Authors

  • Imtiaz Ali Khoso Author
  • Anika Joyo Author
  • Ghulam Yasin Khoso Author
  • Muhammad Rafiue Author
  • Muzamil Sabir Bozdar Author
  • Nadar Hussain Author

Keywords:

Cross-Site Scripting (XSS), Machine Learning, Deep Learning, Web Security, Intrusion Detection System, RNN, LSTM, Autoencoder, ANN, Support Vector Machine

Abstract

Client and server-side scripting plays an important role in contemporary web applications to deliver interactive content and customize it along with attracting more users. The same scripting power, however, provides an opportunity for Cross-Site Scripting (XSS), a malicious attack where the attacker embeds malicious script in pages to which the visitor has already given trust which is then used to harvest sensitive data. This mechanism is used by threat actors, either directly or via a set of intermediaries to attack normal Internet users. Usual targets are to gain access to the remote system, capture user's login information, access personal records, steal session cookies and deliver malware; stealing cookies is a common secondary motive. XSS is one of the most common and dangerous web application attacks and is also one of the OWASP Top 10 (2021) attacks. In 2023, XSS is the most critical most vulnerability with 19.10% of the cases, reported Alhamyani and Alshammari (2024). The present study compares a set of classifiers to detect XSS: Logistic Regression, Gradient Boosting, Naive Bayes, K-Means, Random Forest, Artificial Neural Network and Support Vector Machine. The accuracy of the model was the highest for the ANN (98.98%) model, which shows the significance of the deep-learning based method for separating malicious traffic from benign traffic.

Downloads

Published

2026-08-17