SQL Injection Detection Using Character-Level Embedding with Convolutional Neural Network and Gated Recurrent Unit

Authors

  • Ahmad Andri Alfian Universitas Negeri Semarang Author
  • Subhan Subhan Universitas Negeri Semarang Author

DOI:

https://doi.org/10.15294/rji.v4i2.62096

Keywords:

Character-level Embedding, Convolutional Neural Network, SQL Injection Detection, Gated Recurrent Unit

Abstract

Abstract. SQL Injection is one of the most common cyberattacks targeting web applications by exploiting malicious SQL queries to gain unauthorized access to database systems. Conventional SQL Injection detection methods generally rely on manually engineered features or word-level representations, which may overlook fine-grained syntactic characteristics contained in SQL queries.

Purpose: This study aims to develop and evaluate a SQL Injection detection model based on Character-level Embedding, Convolutional Neural Network (CNN), and Gated Recurrent Unit (GRU). The proposed model is expected to preserve character-level information while improving the capability to distinguish legitimate SQL queries from SQL Injection attacks.

Methods/Study design/approach: The proposed model combines Character-Level Embedding, CNN, and GRU for binary classification of SQL queries. The dataset used is the SQL Injection Dataset obtained from the Kaggle website, consisting of 30,907 SQL queries with 19,529 legitimate queries and 11,378 SQL Injection queries. Before model training, the dataset was preprocessed using character-level tokenization, sequence padding, and dataset splitting with a ratio of 80:10:10 for training, validation, and testing. The model was implemented using TensorFlow and Keras, trained with the Adam optimizer and Binary Cross-entropy loss function, and evaluated using Accuracy, Precision, Recall, F1-score, and Confusion Matrix.

Result/Findings: The proposed CNN-GRU model achieved an Accuracy of 99.64%, Precision of 100%, Recall of 99.03%, and F1-score of 99.51% indicating that the model effectively classifies legitimate SQL queries and SQL Injection attacks with high performance.

Novelty/Originality/Value: It can be concluded that integrating Character-Level Embedding with hybrid CNN-GRU architecture enables the proposed model to learn both local character patterns and long-term sequential dependencies without requiring manual feature engineering. Therefore, the proposed approach provides an effective alternative for SQL Injection detection and has the potential to improve web application security.

References

[1] European Union Agency for Cybersecurity., ENISA threat landscape 2023: July 2022 to June 2023. LU: Publications Office, 2023. doi: 10.2824/782573.

[2] A. I. Mallick and R. Nath, “Navigating the Cyber security Landscape: A Comprehensive Review of Cyber-Attacks, Emerging Trends, and Recent Developments,” 2024.

[3] T. Li et al., “A Survey on Web Application Testing: A Decade of Evolution,” Apr. 25, 2025, arXiv: arXiv:2412.10476. doi: 10.48550/arXiv.2412.10476.

[4] W. Zhang et al., “Deep Neural Network-Based SQL Injection Detection Method,” Secur. Commun. Netw., vol. 2022, pp. 1–9, Mar. 2022, doi: 10.1155/2022/4836289.

[5] “OWASP Top 10:2025.” Accessed: Feb. 23, 2026. [Online]. Available: https://owasp.org/Top10/2025/

[6] D. Muduli et al., “SIDNet: A SQL Injection Detection Network for Enhancing Cybersecurity,” IEEE Access, vol. 12, pp. 176511–176526, 2024, doi: 10.1109/ACCESS.2024.3502293.

[7] H. Sun, Y. Du, and Q. Li, “Deep Learning-Based Detection Technology for SQL Injection Research and Implementation,” Appl. Sci., vol. 13, no. 16, p. 9466, Aug. 2023, doi: 10.3390/app13169466.

[8] P. Roy, R. Kumar, and P. Rani, “SQL Injection Attack Detection by Machine Learning Classifier,” in 2022 International Conference on Applied Artificial Intelligence and Computing (ICAAIC), Salem, India: IEEE, May 2022, pp. 394–400. doi: 10.1109/ICAAIC53929.2022.9792964.

[9] M. Zivkovic et al., “Optimizing SQL injection detection using BERT encoding and AdaBoost Classification,” in Proceedings of the 2nd International Conference on Innovation in Information Technology and Business (ICIITB 2024), vol. 113, N. Bacanin and H. Shaker, Eds., in Advances in Computer Science Research, vol. 113. , Dordrecht: Atlantis Press International BV, 2024, pp. 137–154. doi: 10.2991/978-94-6463-482-2_10.

[10] A. ALAzzawi, “SQL Injection Detection Using RNN Deep Learning Model,” J. Appl. Eng. Technol. Sci. JAETS, vol. 5, no. 1, pp. 531–541, Dec. 2023, doi: 10.37385/jaets.v5i1.2864.

[11] M. Alghawazi, D. Alghazzawi, and S. Alarifi, “Deep Learning Architecture for Detecting SQL Injection Attacks Based on RNN Autoencoder Model,” Mathematics, vol. 11, no. 15, p. 3286, Jul. 2023, doi: 10.3390/math11153286.

[12] S.-J. Bu and S.-B. Cho, “Deep Character-Level Anomaly Detection Based on a Convolutional Autoencoder for Zero-Day Phishing URL Detection,” Electronics, vol. 10, no. 12, p. 1492, Jun. 2021, doi: 10.3390/electronics10121492.

[13] Y. Tian, Y. Jia, J. Sun, Y. Wang, Z. Liu, and X. Ling, “URL2Graph++: Unified semantic-structural-character learning for malicious URL detection,” Inf. Fusion, 2026.

[14] J. Choi, Y.-A. Jung, and H. Ko, “Comparative Analysis of SQL Injection Defense Mechanisms Based on Three Approaches: PDO, PVT, and ART,” Appl. Sci., vol. 15, no. 23, p. 12351, Nov. 2025, doi: 10.3390/app152312351.

[15] T. Burzykowski, M. Geubbelmans, A.-J. Rousseau, and D. Valkenborg, “Validation of machine learning algorithms,” Am. J. Orthod. Dentofacial Orthop., vol. 164, no. 2, pp. 295–297, Aug. 2023, doi: 10.1016/j.ajodo.2023.05.007.

[16] “SQL Injection Dataset.” Accessed: Jul. 20, 2026. [Online]. Available: https://www.kaggle.com/datasets/sajid576/sql-injection-dataset

[17] S. J. Mielke et al., “Between words and characters: A Brief History of Open-Vocabulary Modeling and Tokenization in NLP,” Dec. 20, 2021, arXiv: arXiv:2112.10508. doi: 10.48550/arXiv.2112.10508.

[18] I. Goodfellow, Y. Bengio, and A. Courville, Deep Learning. in Adaptive Computation and Machine Learning series. MIT Press, 2016. [Online]. Available: https://books.google.co.id/books?id=omivDQAAQBAJ

[19] V. Nair and G. E. Hinton, “Rectified linear units improve restricted boltzmann machines,” in Proceedings of the 27th International Conference on International Conference on Machine Learning, in ICML’10. Madison, WI, USA: Omnipress, 2010, pp. 807–814.

[20] I. D. Mienye, T. G. Swart, and G. Obaido, “Recurrent Neural Networks: A Comprehensive Review of Architectures, Variants, and Applications,” Information, vol. 15, no. 9, p. 517, Aug. 2024, doi: 10.3390/info15090517.

[21] K. Cho et al., “Learning Phrase Representations using RNN Encoder-Decoder for Statistical Machine Translation,” Sep. 03, 2014, arXiv: arXiv:1406.1078. doi: 10.48550/arXiv.1406.1078.

[22] Y. Hu, H. Jin, X. Chu, and Y. Yi, “Transfer Learning-Based Piezoelectric Actuators Feedforward Control with GRU-CNN,” Appl. Sci., vol. 16, no. 3, p. 1305, Jan. 2026, doi: 10.3390/app16031305.

[23] M. Grandini, E. Bagli, and G. Visani, “Metrics for Multi-Class Classification: an Overview,” Aug. 13, 2020, arXiv: arXiv:2008.05756. doi: 10.48550/arXiv.2008.05756.

Downloads

Published

2026-09-30

Article ID

62096

How to Cite

SQL Injection Detection Using Character-Level Embedding with Convolutional Neural Network and Gated Recurrent Unit. (2026). Recursive Journal of Informatics, 4(2), 92-101. https://doi.org/10.15294/rji.v4i2.62096