Skip to content
Preprint

Enhancing Web Application Firewalls with BERT-GNN for SQL Injection Detection

Aug 2026 · 0 citations · 8 references
Computer Science

TL;DR

This research study has resulted in an optimised hybrid BERT-GNN pipeline with improved detection accuracy and robustness while reducing false-positive and false-negative rates.

Abstract

Detecting sophisticated SQL Injection (SQLi) attacks remains among the most critical challenges in web applications security. This research study has resulted in an optimised hybrid BERT-GNN pipeline with improved detection accuracy and robustness while reducing false-positive and false-negative rates. SQL queries are tokenised and encoded into contextual BERT embeddings, which then initialise the node features of a Graph Neural Network (GNN) trained to classify each query, with the architecture tuned by Optuna over accuracy, precision, recall, and F1-score. The proposed model achieved 99.67% accuracy, with 99.71% precision, 99.39% recall, and 99.55% F1-score on the attack class. A sensitivity analysis, performed by perturbing graph inputs, further assessed the model robustness and yielded a low mean sensitivity score of 0.0037, indicating stable predictions under such perturbations. The results have demonstrated the potential of a novel hybrid model that couples BERT contextual understanding with the GNN structural modelling to detect sophisticated SQLi attack vectors. For open validation, the dataset, test sets and models are made available at https://github.com/mlily2024/Final-project-SQL-injection-pipeline.

View source

Similar papers

Review Aug 2026

Enhancing Web Application Firewalls with Machine Learning for SQL Injection Detection

A DistilBERT-Stacked Ensemble pipeline to improve detection efficiency and robustness while reducing false-positive and false-negative rates is designed and optimised to highlight the value of adversarial training and stacked meta-learning in building robust Web Application Firewalls for SQLi detection.

Lilliane Linnet Musoke, A. Badii, A. Ashlam · 0 citations
Open access Jul 2026

Predictive Web Application Security Using Intelligent SQL Injection Detection

This work presents an intelligent approach for improving web application security through the prediction and detection of SQL injection attacks using machine learning techniques, enabling faster, more reliable, and automated detection of SQL injection vulnerabilities.

D. A. Reddy, G.Rajini · 0 citations
Open access 2026

TDNET: A Dual-Channel Injection Attack Detection Framework for Web Application Firewalls

This work proposes an injection attack detection framework, TDNET, that combines dual-channel feature extraction, multidimensional feature fusion, adaptive attention refinement, and time-sensitive neural architecture search optimization.

Congzhao Wen, Mingzhan Wu, Kongsheng Lin et al. · 0 citations
Open access Aug 2026

LLM-WAF: An Intelligent Web Application Firewall Powered by Large Language Models for Advanced Threat Detection

LLM-WAF is introduced, a new intelligent firewall architecture that uses Large Language Models (LLMs) to analyze HTTP traffic contextually and semantically to identify malicious payloads through natural language processing capabilities rather than static rule matching.

Y. Khalaf · 0 citations
Open access Aug 2026

A Hybrid Z-Isomorphic GNN Framework for Robust DDoS Attack Detection in Software-Defined Networks

Abstract Although SDN provides a programmable, centrally managed framework for modern networks, that same centralization leaves it exposed to attacks such as Distributed Denial of Service (DDoS). This paper proposes an intrusion detection framework that couples Z-Isomorphic Sigmoid Graph Neural Networks (ZIS-GNN) with...

Zahir Mulani, Suhasini Vijaykumar, Priya Chandran · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.