Wahyu Kadri Rahmat Suat Suat
Universitas Muslim Indonesia

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

A Comparative Study of LSTM and CNN Models in SQL Injection Attack Detection Abdul Rachman Manga'; Wahyu Kadri Rahmat Suat Suat; Huzain Azis
Indonesian Journal of Data and Science Vol. 7 No. 2 (2026): Indonesian Journal of Data and Science
Publisher : Yocto Brain

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.56705/ijodas.v7i2.460

Abstract

Introduction: SQL Injection (SQLi) remains a critical cybersecurity threat because it exploits vulnerabilities in user input validation and can compromise the confidentiality, integrity, and availability of information systems. This study compares Long Short-Term Memory (LSTM) and Convolutional Neural Network (CNN) architectures for detecting malicious SQL queries under identical experimental conditions. Method: A publicly available dataset containing 148,327 malicious and benign SQL query instances was preprocessed through missing-value removal, label encoding, tokenization, sequence transformation, padding, and embedding representation. LSTM and CNN models were evaluated using three train-test split scenarios of 70:30, 80:20, and 90:10. Performance was assessed using accuracy, precision, recall, F1-score, and confusion matrices, with the 80:20 split selected for detailed evaluation. Results and Discussion: LSTM consistently achieved higher accuracy across the evaluated splits, ranging from 97.84% to 98.00%. Under the 80:20 configuration, LSTM achieved 97.86% accuracy, 99.34% precision, 96.55% recall, and a 97.92% F1-score, compared with CNN at 97.00%, 97.68%, 96.56%, and 97.12%, respectively. LSTM also reduced false positives from 356 to 99, demonstrating better discrimination between legitimate and malicious queries. Conclusion: LSTM provides more reliable SQL Injection detection than CNN by better capturing sequential dependencies within SQL query structures, making it a promising approach for practical cybersecurity systems