UPM Institutional Repository

Adaptive cross-site scripting detection using multi- agent deep Q-network and hybrid method for tempo- spatial dynamic feature selection


Citation

Thajeel, Isam Kareem Thajeel (2024) Adaptive cross-site scripting detection using multi- agent deep Q-network and hybrid method for tempo- spatial dynamic feature selection. Doctoral thesis, Universiti Putra Malaysia.

Abstract

The ubiquity of modern web applications has deeply integrated them into daily life, but this also exposes them to significant cybersecurity threats, particularly cross-site scripting (XSS) attacks. XSS involves embedding malicious scripts within legitimate webpage code, leading to potential compromise of sensitive information and system integrity. Recent researches have increasingly turned to artificial intelligence (AI) and machine learning (ML) methods to enhance the detection of XSS attacks. However, existing approaches face significant challenges. First, they struggle to address the evolving nature of XSS, where attackers continually refine their tactics to bypass detection systems. This results in temporal feature drift, where the relevance of features changes over time. Second, traditional feature extraction methods often rely on static representations, neglecting the dynamic nature of raw text data, which leads to spatial drift—differences in feature relevance even within the same time period. Consequently, selecting relevant features should be addressed not only at the chunk level of data (as seen in temporal dynamic feature selection) but also at the data group level for all samples that arrive within a specific time interval. Finally, existing models lack the capacity to handle the diverse types of XSS attacks, which can occur across various data types such as JavaScript, payloads, and statistical features, under different scenarios. To address these challenges, this research proposes the DQN-MAFS (Deep Q-Network Multi-Agent Feature Selection) model, designed to handle temporal feature drift in the numerical representation of XSS data. In this model, each agent is responsible for selecting or deselecting a specific feature, with rewards distributed fairly through the Fair Agent Reward Distribution (FARD-DFS) mechanism. Additionally, the spatial and temporal feature drifts in raw text XSS data are tackled using the Tabu Search-Based Tempo-Spatial Dynamic Feature Selection (2TS-DFS). This model employs dynamic word embedding method that consist of Word2Vec and Bi-LSTM models. To handle the issue of model capacity, both DQN-MAFS and 2TS-DFS are integrated into a unified framework capable of processing two types of XSS data: numerical and text-based (including JavaScript and payloads). The proposed models were evaluated on six distinct XSS datasets: four numerical datasets (D1-N66, D2-N167, D3-N30, and D4-N30) and two raw text datasets (D5-JS, a JavaScript dataset, and D6-PL, a payload dataset). Furthermore, the proposed models outperformed benchmark methods designed for XSS attack detection and dynamic feature selection, including those utilizing reinforcement learning, genetic algorithms, multi-agent reinforcement learning, JSContana and static word embedding techniques,in terms of accuracy, precision, recall, and F1-score. The DQN-MAFS and 2TS-DFS models demonstrated superior performance, achieving a mean accuracy of 99.59% and an F1-score of 98.42%. The results affirm the framework's efficacy in enhancing cybersecurity measures by providing a scalable, adaptable, and efficient adaptive approach to the evolving nature of XSS attack.


Download File

[img] Text
FK 2024 46 - Declaration Form.pdf
Restricted to Repository staff only
Available under License Creative Commons Attribution Non-commercial No Derivatives.

Download (687kB)
[img] Text
FK 2024 46 - Full Text.pdf
Available under License Creative Commons Attribution Non-commercial No Derivatives.

Download (6MB)
[img] Text
FK 2024 46.pdf
Restricted to Repository staff only
Available under License Creative Commons Attribution Non-commercial No Derivatives.

Download (6MB)
Official URL or Download Paper: http://ethesis.upm.edu.my/id/eprint/19011

Additional Metadata

Item Type: Thesis (Doctoral)
Subject: Reinforcement learning
Subject: Multiagent systems
Subject: Computer security
Call Number: FK 2024 46
Chairman Supervisor: Khairulmizam bin Samsudin
Divisions: Faculty of Engineering
Keywords: Cyber security; Dynamic feature selection; Feature drift; Machine learning; Web application security.
Sustainable Development Goals (SDGs): GOAL 9: Industry, Innovation and Infrastructure
Depositing User: Pelajar Latihan Industri
Date Deposited: 15 Jul 2026 02:50
Last Modified: 15 Jul 2026 02:50
URI: http://psasir.upm.edu.my/id/eprint/125944
Statistic Details: View Download Statistic

Actions (login required)

View Item View Item