Machine Learning and Deep Learning Approaches to SQL Injection Detection in Web Application Firewalls: A Comparative Empirical Synthesis

Authors

  • Sabil Shrestha Polytech Nantes, Nantes Université Nantes, France
  • Sulakshyana Ghimire Nantes Université, Nantes, France
  • Krishiyana Bhakta Polytech Nantes, Nantes Université Nantes, France

DOI:

https://doi.org/10.65091/icicset.v3i1.110

Abstract

Web application firewalls (WAFs) remain the primary
application-layer defense against SQL injection (SQLi),
cross-site scripting (XSS), and distributed denial-of-service
(DDoS) traffic, yet traditional signature-based WAFs are structurally
unable to generalize to zero-day or obfuscated payloads.
Over the past three years, researchers have proposed replacing or
augmenting signature matching with learned classifiers—models
like recurrent deep networks, classical artificial neural networks
(ANNs), and, most recently, transformer-embedding ensembles.
This paper synthesizes three representative studies spanning
this progression: a layered long short-term memory (LSTM)
architecture for combined DDoS/XSS/SQLi detection (Dawadi,
Adhikari & Srivastava, 2023); an ANN-based Web Application
Firewall using Artificial Neural Networks (WAFANN) targeted
specifically at SQLi (Elegbeleye, Chris & Koranteng, 2022);
and a DistilBERT-Stacked Ensemble hardened with adversarial
training for real-time SQLi detection (Musoke, Badii & Ashlam,
n.d.). We define a standardized comparative framework—
detection accuracy, precision, recall, F1-score, training time,
inference latency, and resource utilization (CPU and memory
consumption)—and map every metric each study actually reports
onto that framework. The central empirical finding is that
accuracy across modern approaches has become nearly saturated
(89.3%–99.8% depending on task and dataset), so the differentiating
variable for production deployment is now latency and
robustness rather than raw accuracy: the DistilBERT-Stacked
Ensemble matches the best single transformer-embedded classifier’s
accuracy (99.81% vs. 99.82%, not statistically distinguishable
by McNemar’s test) while executing roughly 140× faster and
retaining 99.77% accuracy under single-step FGSM adversarial
perturbation. A second, equally important finding is a gap in
the literature: none of the three reviewed studies measures CPU
or memory utilization at inference time, a metric essential for
capacity planning in a real-time WAF; this paper flags that gap
explicitly rather than estimating it, and proposes a standardized
control-dataset protocol for closing it in future work.We conclude
with concrete recommendations for engineering teams selecting
between layered sequence models, classical ANN pipelines, and
transformer-embedding ensembles.

Downloads

Published

2026-10-02

How to Cite

[1]
S. Shrestha, S. Ghimire, and K. Bhakta, “Machine Learning and Deep Learning Approaches to SQL Injection Detection in Web Application Firewalls: A Comparative Empirical Synthesis”, ICICSET2025, vol. 3, no. 1, Oct. 2026.