XSS-Net: An Intelligent Machine Learning Model for Detecting Cross-Site Scripting (XSS) Attack in Web Application

Emmanuel Osaze Oshoiribhor, Adetokunbo MacGregor John-Otumu · Machine Learning Research · 2025

This research paper focuses on detecting Cross-Site Scripting (XSS) attacks, a prevalent web security threat where attackers inject malicious scripts into web applications to steal sensitive user data, hijack sessions, and execute unauthorized actions. Traditional rule-based and signature-based detection methods often fail against sophisticated and obfuscated XSS payloads, necessitating more advanced solutions. To address this, a machine learning-based model is developed to enhance XSS detection accuracy while minimizing false positives. The proposed approach utilizes feature extraction techniques, including Term Frequency-Inverse Document Frequency (TF-IDF) and n-grams, to analyze JavaScript payloads, while Principal Component Analysis (PCA) is employed for feature selection, reducing dimensionality and improving computational efficiency. A Logistic Regression classifier is trained on an XSS payload dataset from Kaggle, with data split into 80% for training and 20% for testing to ensure a robust evaluation. Hyperparameter tuning is performed using GridSearchCV, optimizing the model’s predictive capabilities. Experimental results demonstrate a 99.70% accuracy, with 100% recall and 99.36% precision, highlighting the model’s effectiveness in detecting XSS attacks while minimizing false alarms. The high recall score ensures all malicious payloads are identified, while the strong precision rate enhances reliability for real-world deployment. These findings underscore the potential of machine learning in strengthening web security frameworks, offering a scalable and efficient alternative to conventional detection systems. Future research should focus on enhancing resilience against adversarial attacks by integrating deep learning models such as Bidirectional LSTMs (BiLSTMs) and Transformer-based architectures. Additionally, deploying the model in real-time web security solutions could provide proactive defense mechanisms, ensuring robust protection against evolving XSS threats.

Read the paper · More papers on PaperTik