INTERNAL (Information System Journal)
Vol. 9 No. 1 (2026)

Deteksi Sistem Cerdas Kerentanan Kode PHP Menggunakan Hybrid ML dan LLM

Moh Erdda Habiby Habiby (Universitas Bina Nusantara)
Miki Wijana (Universitas Ma'soem)



Article Info

Publish Date
08 Jul 2026

Abstract

Security vulnerabilities in PHP programming code remain one of the major threats to the integrity of web applications, especially when software development processes are not supported by automated and adaptive security analysis mechanisms. This study aims to develop an intelligent system for vulnerability detection and automatic code remediation using a Hybrid Machine Learning (ML) and Large Language Model (LLM) approach. The system combines Term Frequency-Inverse Document Frequency (TF-IDF), Abstract Syntax Tree (AST) Parsing, and the Random Forest algorithm for vulnerability classification, while integrating the Google Gemini API as a dynamic recommendation layer to generate contextual and adaptive secure coding suggestions. The dataset consists of 320 PHP code snippets covering SQL Injection, XSS, File Inclusion, Command Injection, Unsafe File Upload, and safe code samples. Experimental evaluation using accuracy, precision, recall, F1-score, and confusion matrix shows that the model achieved an overall accuracy of 86.25% with a macro average F1-score of 0.86. This study demonstrates that integrating Hybrid ML and LLM-based remediation using the Gemini API has strong potential for developing intelligent static code analysis systems for PHP web applications.

Copyrights © 2026






Journal Info

Abbrev

internal

Publisher

Subject

Computer Science & IT Education Other

Description

INTERNAL (Information System Journal) is a scientific journal published by the Information Systems Study Program, Masoem University. This journal is a forum for publication of scientific papers in the form of writings by academics, researchers and practitioners on pure and applied research in the ...