Jul 2026· International journal of computer information systems and industrial management applications· Vol 18, pp. 713-723· 0 citations
TL;DR
Threshold transfer, false-alarm behavior, and reproducibility are central deployment concerns for flow-based SQLi detection.
Abstract
Machine-learning detectors for SQL injection (SQLi) may perform well under internal evaluation yet fail to preserve a usable decision threshold across traffic scenarios. This study evaluates that transfer risk using two independently generated NetFlow V5 datasets. D1 (400,003 flows) is used only for training, preprocessing, feature selection, hyperparameter selection, and threshold calibration; D2 (57,229 flows) is reserved for final cross-scenario testing. Six classifiers are evaluated with corrected FAR = FP/(FP+TN), confusion-matrix consistency checks, with-IP/without-IP ablation, and computational timing. In the primary baseline, Logistic Regression with IP features yields 85.25% accuracy, 87.09% F1-score, 99.46% recall, and 28.96% FAR. Under a D1-validation operating point that minimizes FAR subject to recall of at least 95%, LinearSVC with IP features yields the strongest D2 result (91.96% accuracy, 92.52% F1-score, 99.54% recall, and 15.63% FAR), whereas Random Forest thresholds collapse to all-benign predictions. Removing IP-address features reduces calibrated LinearSVC accuracy to 89.88% and raises FAR to 19.78%, although its ROC-AUC and PR-AUC remain high. A controlled audit also fails to reproduce the approximately 98% Logistic Regression result reported in the earlier preprint. Threshold transfer, false-alarm behavior, and reproducibility are therefore central deployment concerns for flow-based SQLi detection.
This research study has resulted in an optimised hybrid BERT-GNN pipeline with improved detection accuracy and robustness while reducing false-positive and false-negative rates.
Lilliane Linnet Musoke, A. Badii, A. Ashlam· 0 citations
A DistilBERT-Stacked Ensemble pipeline to improve detection efficiency and robustness while reducing false-positive and false-negative rates is designed and optimised to highlight the value of adversarial training and stacked meta-learning in building robust Web Application Firewalls for SQLi detection.
Lilliane Linnet Musoke, A. Badii, A. Ashlam· 0 citations
Enterprise data platforms lose substantial value to poor data quality, and database migrations routinely overrun, because integrity validation and query translation are treated as disconnected problems. We present DataFlow AI, a deployment-oriented framework coupling a stacked anomaly-detection ensemble with an audit-g...
Upasana Bhaumik, M. Berlin· IEEE Access· 0 citations
Resource pressure is a recurring issue in SQL Server performance management because users only notice it when they experience slow response times, blocking, timeouts, or service instability. Manual interpretation of Dynamic Management Views (DMVs) is typically reactive and requires specialist database-administration ex...
K. Thiruvengadam, Yousef Elsheikh, F. Rossi· Journal of Intelligent Decis...· 0 citations
Random Forest and other tree-ensemble classifiers achieve high accuracy in network intrusion detection; however, their aggregate decision logic prevents analysts from auditing or deploying individual predictions as operational rules. Post hoc explanation methods introduce latencies incompatible with security operation...
Saloua Bellouch, Mostapha Zbakh, S. Aouad et al.· Future Internet· 0 citations
Machine-learning intrusion detectors are usually reported with accuracy or F1 on a single train and test split, and their confidence scores are often read operationally as probabilities without an explicit calibration check. We test that assumption. We measure the reliability of the predicted probabilities of three cla...
Khalid Alalawi· International Journal of Adv...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.