Machine Learning-Based Detection of Cross-Site Scripting (XSS) Attacks Using Classification Algorithms

Authors

  • Anupama Mishra
  • Pramod Kumar School of Science & Technology, Swami Rama Himalayan University

Keywords:

Cross site scripting, Cyber Security, Machine learning, Web Security

Abstract

Cross-Site Scripting (XSS) attack is the most dominant attack in web applications. Its empowering attackers to inject malicious scripts into trusted web environments. The research paper proposed a machine learning-based framework for the detection and classification of XSS attacks. We use the dataset from Kaggle that contains textual web request patterns labeled as normal and malicious instances. Experimental analysis was performed to evaluate the effectiveness of multiple supervised learning algorithms including Logistic Regression, Random Forest, and Support Vector Machine. The methodology involved preprocessing, feature extraction, model training, testing, and performance evaluation parameters for binary classification.

Downloads

Download data is not yet available.

References

Ayoubi, A., Laaouina, L., Jeghal, A., & Tairi, H. (2026). An improved detection of cross-site scripting (XSS) attacks using a hybrid approach combining convolutional neural networks and support vector machine. Journal of Cybersecurity and Privacy, 6, 18.

Babaey, V., & Ravindran, A. (2025). GenXSS: An AI-driven framework for automated detection of XSS attacks in WAFs. In Proceedings of SoutheastCon 2025 (pp. 1519–1524). IEEE.

Bakır, R. (2025). UniEmbed: A novel approach to detect XSS and SQL injection attacks leveraging multiple feature fusion with machine learning techniques. Arabian Journal for Science and Engineering, 50, 15591–15604.

Cheng, S., et al. (2025). Machine learning for modelling unstructured grid data in computational physics: A review. Information Fusion, 123, 103255.

Deng, J., et al. (2025). So you’ve got a high AUC, now what? An overview of important considerations when bringing machine-learning models from computer to bedside. Medical Decision Making, 45, 640–653.

Gharai, C., et al. (2025). Enhancing web security through machine learning-based feature selection for cross-site scripting (XSS) attacks classification. In 2025 IEEE 6th India Council International Subsections Conference (INDISCON). IEEE.

Hu, T., Xu, C., Zhang, S., Tao, S., & Li, L. (2023). Cross-site scripting detection with two-channel feature fusion embedded in self-attention mechanism. Computers & Security, 124, 102990.

Hussain, S. S. (2023). Cross-site scripting (XSS) dataset. Kaggle. https://www.kaggle.com/datasets/syedsaqlainhussain/cross-site-scripting-xss-dataset

Kshetri, N., Kumar, D., Hutson, J., Kaur, N., & Osama, O. F. (2024). AlgoXSSF: Detection and analysis of cross-site request forgery (XSRF) and cross-site scripting (XSS) attacks via machine learning algorithms. arXiv. https://arxiv.org/abs/2402.01012

Li, Z., Liu, F., Gu, Z., & Liu, Y. (2025). XSS attack detection method based on CNN-BiLSTM-attention. Applied Sciences, 15, 8924.

Meze, M., Bolojan, O. M., & Costea, F. M. (2025). Comparison of machine learning algorithms used for detecting XSS attacks. In 2025 18th International Conference on Engineering of Modern Electric Systems (EMES). IEEE.

Miczek, D., Gabbireddy, D., & Saha, S. (2025). Leveraging LLM to strengthen ML-based cross-site scripting detection. In Proceedings of the 2025 ACM Workshop on Wireless Security and Machine Learning (pp. 14–19).

Mishra, A., & Colace, F. (2022). Cyber security traits of a future-ready organization. Cyber Security Insights Magazine, Insights2Techinfo, 1, 16–19.

Mishra, A., Gupta, B. B., Santaniello, D., & Mishra, K. (2024). Secure web applications based on moving target defense: Challenges, solutions, and new trends. In Digital forensics and cyber crime investigation (pp. 1–16). CRC Press.

Mishra, A., Hsu, C. H., Arya, V., Chaurasia, P., & Li, P. (2021). A hybrid approach for protection against rumours in an IoT-enabled smart city environment. In International Conference on Cyber Security, Privacy and Networking (pp. 101–109). Springer.

OWASP Foundation. (2024). Cross site scripting (XSS). https://owasp.org/www-community/attacks/xss/

Rathore, S., & Sharma, P. K. (2017). XSSClassifier: An efficient XSS attack detection approach based on machine learning classifier on SNSs. Journal of Information Processing Systems, 13.

Riesthuis, P., Otgaar, H., & Bücken, C. (2025). Ready to ROC? A tutorial on simulation-based power analyses for null hypothesis significance, minimum-effect, and equivalence testing for ROC curve analyses. Behavior Research Methods, 57, 120.

Sant, L. (2025). ROC curves. In International Encyclopedia of Statistical Science (pp. 2212–2215). Springer.

Santithanmanan, K., Kirimasthong, K., & Boongoen, T. (2023). Machine learning based XSS attacks detection method. In UK Workshop on Computational Intelligence (pp. 418–429). Springer.

Shaisob, M. H., et al. (2025). XSS-SafeNet: A bidirectional LSTM architecture for high-precision cross-site scripting detection. In 2025 28th International Conference on Computer and Information Technology (ICCIT). IEEE.

Thajeel, I. K., Samsudin, K., Hashim, S. J., & Hashim, F. (2023). Machine and deep learning-based XSS detection approaches: A systematic literature review. Journal of King Saud University - Computer and Information Sciences, 35, 101628.

Wali, S., Farrukh, Y. A., & Khan, I. (2025). Explainable AI and random forest based reliable intrusion detection system. Computers & Security, 157, 104542.

Younas, F., Raza, A., Thalji, N., Abualigah, L., Zitar, R. A., & Jia, H. (2024). An efficient artificial intelligence approach for early detection of cross-site scripting attacks. Decision Analytics Journal, 11, 100466.

Zeng, G. (2025). Invariance properties and evaluation metrics derived from the confusion matrix in multiclass classification. Mathematics, 13, 2609.

Downloads

Published

2026-01-31