Detecting Obfuscated Cross-Site Scripting Attacks Using LLM-Generated Payloads and Graph Neural Networks

preprint OA: closed
Full text JSON View at publisher
AI-generated deep summary by claude@2026-07, 2026-07-06 · read from full text

This preprint studies detecting obfuscated cross-site scripting (XSS) attacks by generating complex obfuscated payloads with a fine-tuned CodeGen-350M-multi model, converting the payloads into control flow graphs (CFGs), and training a graph neural network (GNN) to classify them. On held-out test data, it reports very high performance (accuracy 99.72%, precision 99.60%, recall 100%, F1-score 99.70%) and further evaluates out-of-distribution sources, runtime feasibility, and performs ablation analysis for robustness and reproducibility. A key limitation is that the work is presented as a preprint under review and is not reported as peer-reviewed. The paper does not explicitly discuss endometriosis or adenomyosis; it was included in the corpus via a keyword match in the upstream search index.

Read from the paper's body, not the abstract. Not a substitute for reading the paper. No clinical advice. How this works

Abstract

Abstract Cross-Site Scripting (XSS) remains a persistent web security vulnerability, particularly in its obfuscated forms. Building upon recent advancements in leveraging Large Language Models (LLMs) for security, this study adopts a novel pipeline that generates complex obfuscated XSS samples using a fine-tuned code generation model \texttt{CodeGen-350M-multi}. These samples are transformed into Control Flow Graphs (CFGs) to capture their structural and behavioral semantics. We then utilize a Graph Neural Network (GNN) architecture to classify these samples. Our approach achieves high performance on held-out test data (reported accuracy: 99.72%, precision: 99.60%, recall: 100%, F1-score: 99.70%). We additionally extend the evaluation to out-of-distribution sources, runtime feasibility and ablation analysis to validate robustness and reproducibility.
Full text 11,942 characters · extracted from preprint-html · click to expand
Detecting Obfuscated Cross-Site Scripting Attacks Using LLM-Generated Payloads and Graph Neural Networks | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Detecting Obfuscated Cross-Site Scripting Attacks Using LLM-Generated Payloads and Graph Neural Networks Abdelkader TAJTIT, Mohammed Serrhini This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-9254071/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 12 You are reading this latest preprint version Abstract Cross-Site Scripting (XSS) remains a persistent web security vulnerability, particularly in its obfuscated forms. Building upon recent advancements in leveraging Large Language Models (LLMs) for security, this study adopts a novel pipeline that generates complex obfuscated XSS samples using a fine-tuned code generation model \texttt{CodeGen-350M-multi}. These samples are transformed into Control Flow Graphs (CFGs) to capture their structural and behavioral semantics. We then utilize a Graph Neural Network (GNN) architecture to classify these samples. Our approach achieves high performance on held-out test data (reported accuracy: 99.72%, precision: 99.60%, recall: 100%, F1-score: 99.70%). We additionally extend the evaluation to out-of-distribution sources, runtime feasibility and ablation analysis to validate robustness and reproducibility. Cross-Site Scripting (XSS) Large Language Models (LLMs) Code Obfuscation Graph Neural Networks Control Flow Graphs (CFG) Web Security Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Under Review Version 1 posted Reviews received at journal 12 May, 2026 Reviews received at journal 26 Apr, 2026 Reviews received at journal 26 Apr, 2026 Reviewers agreed at journal 26 Apr, 2026 Reviews received at journal 22 Apr, 2026 Reviewers agreed at journal 18 Apr, 2026 Reviewers agreed at journal 17 Apr, 2026 Reviewers agreed at journal 17 Apr, 2026 Reviewers invited by journal 17 Apr, 2026 Editor assigned by journal 30 Mar, 2026 Submission checks completed at journal 30 Mar, 2026 First submitted to journal 28 Mar, 2026 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-9254071","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":627977931,"identity":"3f6496c2-267a-464a-956a-b0435d122805","order_by":0,"name":"Abdelkader TAJTIT","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABS0lEQVRIie3RsWrCQBgH8O8ImOWk60nVvsKFgzgU9EG6XHDootDiUrBgQqAuoa4tlj5DskScGgjokgcI1CE+QOFcSgoOvaiFErF2LDT/EC4H+fG/LwEoUuQvhgCFJABkbnZYXgDaUtwcIXxL5I0ploYxEv2ayI0kOinfHRYnY9tLeNSsjU4DNUmr62oLFJdUnsOLBihLgTrNvZLFrEd53GaP9xxZzuZgpSt67YfdqVliBPntvZq4oxMuFMON5MHwhmDKK5K4AeiAfCUvzuJOI+ViYLxIYq13JCg/ZUR9l2SQJ1S2AI9Dw8WA7F2LZpbNjOCsJcwTTc5CeDRnDxGyxlXMMA5LPYXMLrtTG/eI4c/zpP5qe0LM+rWRowSrN6feUof25EPcnncn6tATK79/+HNnvwU5cv2al2YP/AewTfp9zKNvFylSpMg/ySfQ+3DrBpIKbQAAAABJRU5ErkJggg==","orcid":"","institution":"Mohamed I University","correspondingAuthor":true,"prefix":"","firstName":"Abdelkader","middleName":"","lastName":"TAJTIT","suffix":""},{"id":627977932,"identity":"4b273d0c-c4bd-41f5-875e-13e58c5c6160","order_by":1,"name":"Mohammed Serrhini","email":"","orcid":"","institution":"Mohamed I University","correspondingAuthor":false,"prefix":"","firstName":"Mohammed","middleName":"","lastName":"Serrhini","suffix":""}],"badges":[],"createdAt":"2026-03-28 16:08:43","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-9254071/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-9254071/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":107708111,"identity":"94ecb6be-17ad-43fd-9abe-4330b6d7e198","added_by":"auto","created_at":"2026-04-24 09:21:58","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":471948,"visible":true,"origin":"","legend":"","description":"","filename":"JournalofComputerVirologyandHackingTechniques.pdf","url":"https://assets-eu.researchsquare.com/files/rs-9254071/v1_covered_4b9537db-58f4-4075-89b9-cf08ba9e23c9.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Detecting Obfuscated Cross-Site Scripting Attacks Using LLM-Generated Payloads and Graph Neural Networks","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"journal-of-computer-virology-and-hacking-techniques","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"jicv","sideBox":"Learn more about [Journal of Computer Virology and Hacking Techniques](http://link.springer.com/journal/11416)","snPcode":"11416","submissionUrl":"https://submission.springernature.com/new-submission/11416/3","title":"Journal of Computer Virology and Hacking Techniques","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"Cross-Site Scripting (XSS), Large Language Models (LLMs), Code Obfuscation, Graph Neural Networks, Control Flow Graphs (CFG), Web Security","lastPublishedDoi":"10.21203/rs.3.rs-9254071/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-9254071/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eCross-Site Scripting (XSS) remains a persistent web security vulnerability, particularly in its obfuscated forms. Building upon recent advancements in leveraging Large Language Models (LLMs) for security, this study adopts a novel pipeline that generates complex obfuscated XSS samples using a fine-tuned code generation model \\texttt{CodeGen-350M-multi}. These samples are transformed into Control Flow Graphs (CFGs) to capture their structural and behavioral semantics. We then utilize a Graph Neural Network (GNN) architecture to classify these samples. Our approach achieves high performance on held-out test data (reported accuracy: 99.72%, precision: 99.60%, recall: 100%, F1-score: 99.70%). We additionally extend the evaluation to out-of-distribution sources, runtime feasibility and ablation analysis to validate robustness and reproducibility.\u003c/p\u003e","manuscriptTitle":"Detecting Obfuscated Cross-Site Scripting Attacks Using LLM-Generated Payloads and Graph Neural Networks","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-04-24 04:48:06","doi":"10.21203/rs.3.rs-9254071/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"editorInvitedReview","content":"","date":"2026-05-13T01:11:53+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-04-26T15:17:58+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-04-26T04:52:12+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"158773247823164871494899312620006066236","date":"2026-04-26T04:23:39+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-04-22T19:58:04+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"165086076613311812243820997282913208903","date":"2026-04-19T02:27:47+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"226337677974588353016273537745326898401","date":"2026-04-17T05:43:32+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"294567667425648084870017250922682307126","date":"2026-04-17T04:55:36+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2026-04-17T04:39:36+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2026-03-30T13:37:48+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2026-03-30T13:37:13+00:00","index":"","fulltext":""},{"type":"submitted","content":"Journal of Computer Virology and Hacking Techniques","date":"2026-03-28T16:02:56+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"journal-of-computer-virology-and-hacking-techniques","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"jicv","sideBox":"Learn more about [Journal of Computer Virology and Hacking Techniques](http://link.springer.com/journal/11416)","snPcode":"11416","submissionUrl":"https://submission.springernature.com/new-submission/11416/3","title":"Journal of Computer Virology and Hacking Techniques","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"8af60990-0baa-44d9-9fb4-e09303f362dc","owner":[],"postedDate":"April 24th, 2026","published":true,"recentEditorialEvents":[{"type":"editorInvitedReview","content":"","date":"2026-05-13T01:11:53+00:00","index":17,"fulltext":""}],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[],"tags":[],"updatedAt":"2026-04-24T04:48:06+00:00","versionOfRecord":[],"versionCreatedAt":"2026-04-24 04:48:06","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-9254071","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-9254071","identity":"rs-9254071","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2026) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00