- Conference Article
- 10.1117/12.3107369
Research on XSS malicious code detection method based on LSTM-LLM cascade architecture
- Mar 19, 2026
- Cheng Wei + 3 more +3
Cross site scripting (XSS) attacks are still one of the key threats to the security of web applications. With the increasingly evolving attack methods, traditional detection methods have a high false positive rate of detection results. This article proposes a new model: a cascaded detection architecture that combines Long Short Term Memory (LSTM) networks with Large Language Models (LLM) for detecting XSS malicious code attacks. This method first uses Word2vec for code vectorization, turning the malicious code into vector data predictable by LSTM. Then, LSTM detects the vectorized malicious code and classifies the samples as malicious , benign , or suspicious. The malicious code samples classified as suspicious will be sent to LLM for detailed analysis again. The experimental results obtained show that compared to independent LSTM for malicious code detection, the cascaded method of LSTM and LLM has an accuracy rate of up to 97.8% and a 42% reduction in false positive rate, especially for some Base64 and URL encoded malicious code detection with higher accuracy. At the same time, to ensure detection speed, only 8.3% of the malicious code samples were extracted for detection.
Read more