CFP last date
28 August 2026
Reseach Article

A Stacking Ensemble Approach for the Detection of Cross-Site Scripting and Cross-Site Request Forgery Attacks

by E.O. Oginni, A.O. Amoo, T.O. Omodunbi, A.S. Afolayan
International Journal of Applied Information Systems
Foundation of Computer Science (FCS), NY, USA
Volume 13 - Number 4
Year of Publication: 2026
Authors: E.O. Oginni, A.O. Amoo, T.O. Omodunbi, A.S. Afolayan
10.5120/ijais02bd31ac23ec

E.O. Oginni, A.O. Amoo, T.O. Omodunbi, A.S. Afolayan . A Stacking Ensemble Approach for the Detection of Cross-Site Scripting and Cross-Site Request Forgery Attacks. International Journal of Applied Information Systems. 13, 4 ( Aug 2026), 51-60. DOI=10.5120/ijais02bd31ac23ec

@article{ 10.5120/ijais02bd31ac23ec,
author = { E.O. Oginni, A.O. Amoo, T.O. Omodunbi, A.S. Afolayan },
title = { A Stacking Ensemble Approach for the Detection of Cross-Site Scripting and Cross-Site Request Forgery Attacks },
journal = { International Journal of Applied Information Systems },
issue_date = { Aug 2026 },
volume = { 13 },
number = { 4 },
month = { Aug },
year = { 2026 },
issn = { 2249-0868 },
pages = { 51-60 },
numpages = {9},
url = { https://www.ijais.org/archives/volume13/number4/a-stacking-ensemble-approach-for-the-detection-of-cross-site-scripting-and-cross-site-request-forgery-attacks/ },
doi = { 10.5120/ijais02bd31ac23ec },
publisher = {Foundation of Computer Science (FCS), NY, USA},
address = {New York, USA}
}
%0 Journal Article
%1 2026-08-24T20:50:46.266076+05:30
%A E.O. Oginni
%A A.O. Amoo
%A T.O. Omodunbi
%A A.S. Afolayan
%T A Stacking Ensemble Approach for the Detection of Cross-Site Scripting and Cross-Site Request Forgery Attacks
%J International Journal of Applied Information Systems
%@ 2249-0868
%V 13
%N 4
%P 51-60
%D 2026
%I Foundation of Computer Science (FCS), NY, USA
Abstract

The growing use of web-based applications has simultaneously increased vulnerability to security attacks, in particular Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF), which are among the most common online vulnerabilities. In this research, a stacking ensemble approach was used to detect XSS and CSRF attacks using structured web request data, with labelled datasets of normal and malicious web traffic obtained via publicly available GitHub repositories. It integrates three different base learners, such as the Random Forest (RF), Support Vector Machine (SVM), and Multilayer Perceptron (MLP) and uses an XGBoost meta-learner to boost the probabilistic outputs of the base learners to improve the detection results. The proposed model is a combination of heterogeneous classifiers, which improves the detection accuracy and robustness. The experimental results reveal that the stacking ensemble model is an effective solution for detecting web attacks and is more effective than the base learners. The model had an accuracy of 95%, and had a precision of 95%, showing increased detection reliability and a reduced false positive rate. Moreover, it has a high discriminative ability as it has an ROC-AUC score of 0.9808. The results highlight the importance of the stacking ensemble approach in enhancing the robustness and stability of machine learning-based software systems for protecting web applications from XSS and CSRF attacks. This study focuses on XSS and CSRF vulnerabilities and the application of stacking ensemble learning in the detection of attacks on web applications.

References
  1. Dwivedi, Y., Williams, M., Mitra, A., Niranjan, S., and Weerakkody, V. (2011). Understanding advances in web technologies: evolution from web 2.0 to web 3.0.
  2. Xia, L., Baghaie, S., and Sajadi, S. M. (2024). The digital economy: Challenges and opportunities in the new era of technology and electronic communications. Ain Shams Engineering Journal, 15(2), 102411.
  3. Diwan, T. D. (2021). An investigation and analysis of cyber security information systems: latest trends and future suggestion. Information Technology in Industry, 9(2), 477-492.
  4. OWASP Foundation. (2025a). OWASP Top 10: 2025 – A05: Injection. Retrieve from https://owasp.org/Top10/2025/A05_2025-Injection/ on July 30.2025
  5. OWASP Foundation. (2025b). OWASP Top 10: 2025 – A01: Broken Access Control. Retrieve from https://owasp.org/Top10/2025/A01_2025-Broken_Access_Control/ on July 30.2025
  6. Rodriguez, G. E., Torres, J. G., Flores, P., and Benavides, D. E. (2020). Cross-site scripting (XSS) attacks and mitigation: A survey. Computer Networks, 166, 106960.
  7. Alaoui, R. L., and Nfaoui, E. H. (2022). Deep learning for vulnerability and attack detection on web applications: A systematic literature review. Future Internet, 14(4), 118.
  8. Razzaq, A., Latif, K., Ahmad, H. F., Hur, A., Anwar, Z., and Bloodsworth, P. C. (2014). Semantic security against web application attacks. Information Sciences, 254, 19-38.
  9. Ali, A. H., Charfeddine, M., Ammar, B., Hamed, B. B., Albalwy, F., Alqarafi, A., & Hussain, A. (2024). Unveiling machine learning strategies and considerations in intrusion detection systems: a comprehensive survey. Frontiers in Computer Science, 6, 1387354.
  10. Momand, A., Jan, S. U., & Ramzan, N. (2023). A systematic and comprehensive survey of recent advances in intrusion detection systems using machine learning: Deep learning, datasets, and attack taxonomy. Journal of sensors, 2023(1), 6048087.
  11. Chua, T. H., & Salam, I. (2022). Evaluation of machine learning algorithms in network-based intrusion detectionsystem. arXiv preprint arXiv:2203.05232.
  12. Pawlicki, M., Kozik, R., & Choraś, M. (2022). A survey on neural networks for (cyber-) security and (cyber-) security of neural networks. Neurocomputing, 500, 1075-1087.
  13. Hannousse, A., Yahiouche, S., and Nait-Hamoud, M. C. (2024). Twenty-two years since revealing cross-site scripting attacks: A systematic mapping and a comprehensive survey. Computer Science Review, 52, 100634.
  14. Gupta, S., and Gupta, B. B. (2017). Cross-Site Scripting (XSS) attacks and defense mechanisms: classification and state-of-the-art. International Journal of System Assurance Engineering and Management, 8(Suppl 1), 512-530
  15. Luo, A., Huang, W. and Fan, A.W. (2019). CNN-based approach to the detection of SQL injection attacks. In 2019 IEEE/ACIS 18th International Conference on Computer and Information Science (ICIS). 320-324.
  16. Herman, H., Riadi, I., and Kurniawan, Y., (2023). Vulnerability detection with K-nearest neighbor and naive Bayes method using machine learning. Int. J. Artif. Intell. Res. 7, 1
  17. Rankothge, W. H., & Randeniya, S. M. N. (2020). Identification and mitigation tool for cross-site request forgery (CSRF). In 2020 IEEE 8th R10 Humanitarian Technology Conference (R10-HTC) (pp. 1–5). IEEE. https://doi.org/10.1109/R10-HTC49770.2020.9357029
  18. Bohara, R., Arjun, V. V. J., Jaiswal, D. J., Nikhil, M., Geetha, G., Pandey, B., and Raghav, U. R. (2023). A survey paper on cross-site scripting (XSS). In Proceedings of the International Conference on Innovative Computing and Communication (ICICC) 2022 (pp. 1–5). SSRN.
  19. Abaimov, S., and Bianchi G (2021). A survey on the application of deep learning for code injection detection. Array. 11(June):100077.
  20. Ali, A. H., Charfeddine, M., Ammar, B., Hamed, B. B., Albalwy, F., Alqarafi, A., & Hussain, A. (2024). Unveiling machine learning strategies and considerations in intrusion detection systems: a comprehensive survey. Frontiers in Computer Science, 6, 1387354.
  21. Mokbal, F. M. M., Dan, W., Imran, A., Jiuchuan, L., Akhtar, F., and Xiaoxi, W. (2019). MLPXSS: an integrated XSS-based attack detection scheme in web applications using multilayer perceptron technique. IEEE Access, 7, 100567-100580
  22. Stency, V. S., and Mohanasundaram, N. (2021). A study on XSS attacks: Intelligent detection methods. Journal of Physics: Conference Series, 1767(1), 012047. IOP Publishing
  23. Mokbal, F.M.M., Dan, W., Xiaoxi, W., Wenbin, Z., and Lihua, F (2021). XGBXSS: An Extreme Gradient Boosting Detection Framework for Cross-Site Scripting Attacks Based on Hybrid Feature Selection Approach and Parameters Optimization. J. Inf. Secur. Appl. 2021,58, 102813.
  24. Kumar J, Santhanavijayan A, Rajendran B. (2022) Cross site scripting attacks classification using convolutional neural network. IEEE ICCCI; 2022:1-6.
  25. Alaoui, R.L. (2022). Web attacks detection using stacked generalization ensemble for LSTMs and word embedding. Procedia Computer Science, 215, 687–696.
  26. Tadhani, J. R., Vekariya, V., Sorathiya, V., Alshathri, S., and El-Shafai, W. (2024). Securing web applications against XSS and SQLi attacks using a novel deep learning approach. Scientific Reports, 14(1), 1803.
  27. Muralitharan, R., Torres, J. G., Flores and Alshammari, M. (2024). Hybrid stacking ensemble deep neural network (DNN) model to detect XSS, combining traditional ML classifiers. Information, 15(7), 424.
  28. Alhamyani, R., and Alshammari, M. (2024). Machine learning-driven detection of cross-site scripting attacks. Information, 15(7), 420.
  29. Nagpal, B., Chauhan, N., and Singh, N. (2017). SECSIX: security engine for CSRF, SQL injection and XSS attacks. International Journal of System Assurance Engineering and Management, 8, 631-644.
  30. Pellegrino, G., Johns, M., Koch, S., Backes, M., and Rossow, C. (2017). Deemon: Detecting CSRF with dynamic analysis and property graphs. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 1757-1771).
  31. Calzavara. S, M. Conti, R. Focardi, A. Rabitti, and G. Tolomei, (2019) “Mitch: A Machine Learning Approach to the Black-Box Detection of CSRF Vulnerabilities,” in 2019 IEEE European Symposium on Security and Privacy (EuroSandP), Stockholm, Sweden, pp. 528–543.
  32. Hadavi, M. A., and Sadeghi, S. (2021). Automatic black box detection of resistance against CSRF vulnerabilities in web applications. Journal of Computer Science, 8(1).
  33. Ismail, M. A., and Hassan, M. M. (2021). An automated detection system of cross site request forgery (CSRF) vulnerability in web applications. International Journal of Innovative Science and Research Technology, 6(10), 582–586
  34. Sravani, N., Raju, O. S., Harish, C., Kumar, B. A., and Anirudh (2024), S. Machine Learning for Web Vulnerability Detection: The Case of Cross-Site Request Forgery. International Journal of Information Technology and Computer Engineering, 12(1), 162–171.
  35. Kshetri, N., Kumar, D., Hutson, J., Kaur, N., and Osama, O. F. (2024). algoXSSF: Detection and analysis of cross-site request forgery (XSRF) and cross-site scripting (XSS) attacks via Machine learning algorithms. In 2024 12th International Symposium on Digital Forensics and Security (ISDFS) (pp. 1-8). IEEE.
  36. Liu, Y., Zhou, Y., Wen, S., and Tang, C. (2014). A strategy on selecting performance metrics for classifier evaluation. International Journal of Mobile Computing and Multimedia Communications, 6(4), 20–35. https://doi.org/10.4018/IJMCMC.2014100102
  37. Tasnim, A., Saiduzzaman, M., Rahman, M. A., Akhter, J., and Rahaman, A. S. M. M. (2022). Performance evaluation of multiple classifiers for predicting fake news. Journal of Computer and Communications, 10(9), 1–21. https://doi.org/10.4236/jcc.2022.109001.
Index Terms

Computer Science
Information Sciences

Keywords

Cross-Site Scripting (XSS) Cross-Site Request Forgery (CSRF) Stacking Ensemble Learning Web Application Security Machine Learning-Based Attack Detection