A Comparative Study of LSTM and CNN Models in SQL Injection Attack Detection
DOI:
https://doi.org/10.56705/ijodas.v7i2.460Keywords:
SQL Injection, Deep Learning, Long Short-Term Memory, Convolutional Neural Network, EmbeddingAbstract
Introduction: SQL Injection (SQLi) remains a critical cybersecurity threat because it exploits vulnerabilities in user input validation and can compromise the confidentiality, integrity, and availability of information systems. This study compares Long Short-Term Memory (LSTM) and Convolutional Neural Network (CNN) architectures for detecting malicious SQL queries under identical experimental conditions. Method: A publicly available dataset containing 148,327 malicious and benign SQL query instances was preprocessed through missing-value removal, label encoding, tokenization, sequence transformation, padding, and embedding representation. LSTM and CNN models were evaluated using three train-test split scenarios of 70:30, 80:20, and 90:10. Performance was assessed using accuracy, precision, recall, F1-score, and confusion matrices, with the 80:20 split selected for detailed evaluation. Results and Discussion: LSTM consistently achieved higher accuracy across the evaluated splits, ranging from 97.84% to 98.00%. Under the 80:20 configuration, LSTM achieved 97.86% accuracy, 99.34% precision, 96.55% recall, and a 97.92% F1-score, compared with CNN at 97.00%, 97.68%, 96.56%, and 97.12%, respectively. LSTM also reduced false positives from 356 to 99, demonstrating better discrimination between legitimate and malicious queries. Conclusion: LSTM provides more reliable SQL Injection detection than CNN by better capturing sequential dependencies within SQL query structures, making it a promising approach for practical cybersecurity systems
Downloads
References
[1] M. Nasereddin, A. ALKhamaiseh, M. Qasaimeh, and R. Al-Qassas, “A Systematic Review of Detection and Prevention Techniques of SQL Injection Attacks,” Information Security Journal: A Global Perspective, vol. 32, no. 4, pp. 252–265, 2023.
[2] Y. Chen, G. Liang, and Q. Wang, “Research on SQL Injection Detection Technology Based on Content Matching and Deep Learning,” Comput. Mater. Contin., vol. 84, no. 1, pp. 1145–1167, 2025, doi: https://doi.org/10.32604/cmc.2025.063319.
[3] R. T. Lo, W. J. Hwang, and T. M. Tai, “SQL Injection Detection Based on Lightweight Multi-Head Self-Attention,” Appl. Sci., vol. 15, no. 2,pp. 1–17, 2025, doi: https://doi.org/10.3390/app15020571.
[4] A. G. Kakisim, “A Deep Learning Approach Based on Multi-View Consensus for SQL Injection Detection,” International Journal of Information Security, vol. 23, no. 2, pp. 1541–1556, 2024, doi: https://doi.org/10.1007/s10207-023-00791-y.
[5] Y. Liu, “Deep Learning in Cybersecurity: A Hybrid BERT–LSTM Network for SQL Injection Attack Detection,” IET Information Security, 2024, doi: https://doi.org/10.1049/2024/5565950.
[6] N. Thalji, A. Raza, M. S. Islam, N. Abdel Samee, and M. M. Jamjoom, “AE-Net: Novel Autoencoder-Based Deep Features for SQL Injection Attack Detection,” IEEE Access, vol. 11, pp. 135507–135516, 2023.
[7] D. Lu, J. Fei, and L. Liu, “A Semantic Learning-Based SQL Injection Attack Detection Technology,” Electronics, vol. 12, no. 6, p. 1344, 2023.
[8] B. Arasteh et al., “Detecting SQL Injection Attacks by Binary Gray Wolf Optimizer and Machine Learning Algorithms,” Neural Computing and Applications, vol. 36, pp. 6771–6792, 2024.
[9] R. Bakır, “UniEmbed: A Novel Approach to Detect XSS and SQL Injection Attacks Leveraging Multiple Feature Fusion with Machine Learning Techniques,” Arabian Journal for Science and Engineering, 2025.
[10] J.Triloka, H. Hartono, and S. Sutedi, “Detection of SQL Injection Attack Using Machine Learning Based On Natural Language Processing,” Int. J. Artif. Intell. Res., vol. 6, no. 2, 2022, doi: https://doi.org/10.29099/ijair.v6i2.355.
[11] S R. Menaka, G. Dharani, P. Kalaivani, S. R. Basha, S. K. S. Hareeth, and V. Kalaiyarasan, “An Efficient SQL Injection Detection with a Hybrid CNN & Random Forest Approach,” J. Inf. Syst. Eng. Manag., vol. 10, pp. 664–673, 2025, doi: https://doi.org/10.52783/jisem.v10i18s.2979.
[12] A. Alazzawi, “Sql Injection Detection Using Rnn Deep Learning Model,” Sql Inject. Detect. Using Rnn Deep Learn. Model, vol. 5, no. 1, pp. 531–541, 2023, doi: https://doi.org/10.37385/jaets.v5i1.2864.
[13] C. S. Datasets, “Enhancing Cyber Security : A Study of Data Preprocessing Techniques for Enhancing Cyber Security : A Study of Data Preprocessing Techniques for Cyber Security Datasets,” no. September, 2024, doi: https://doi.org/10.32628/IJSRST2411427.
[14] T. Sabri, S. Bahassine, O. El Beggar, and M. Kissi, “An improved Arabic text classification method using word embedding,” Int. J. Electr. Comput. Eng., vol. 14, no. 1, pp. 721–731, 2024, doi: https://doi.org/10.11591/ijece.v14i1.pp721.
[15] H. Darwis, Z. Ali, Purnawansyah, H. Lahuddin, and H. Azis, “Deep Dive Into Pubmed Rct: Leveraging Tribrid Embedding Recurrent Neural Network Model,” ICIC Express Lett., vol. 19, no. 1, pp. 111–118, 2025, doi: https://doi.org/10.24507/icicel.19.01.111.
[16] M. Alazab, S. Srinivasan, S. Venkatraman, V. Quoc Pham, V. Ravi, and Q.-V. Pham, “Deep learning for cyber security applications: A comprehensive survey,” Techrxiv.Org, no. October, pp. 0–34, 2023, doi: https://doi.org/10.36227/techrxiv.16748161.
[17] H. C. Altunay and Z. Albayrak, “A hybrid CNN + LSTMbased intrusion detection system for industrial IoT networks,” Eng. Sci. Technol. an Int. J., vol. 38, p. 101322, 2023, doi: https://doi.org/10.1016/j.jestch.2022.101322.
[18] M. Sajid et al., “Enhancing intrusion detection: a hybrid machine and deep learning approach,” J. Cloud Comput., vol. 13, no. 1, 2024, doi: https://doi.org/10.1186/s13677-024-00685-x.
[19] H. Sun, Y. Du, and Q. Li, “Deep Learning-Based Detection Technology for SQL Injection Research and Implementation,” Appl. Sci., vol. 13, no. 16, 2023, doi: https://doi.org/10.3390/app13169466.
[20] R. Amanda and J. Aulia, “Hybrid CNN-LSTM and Cox Model for Bipolar Risk Analysis Using Social Media Data,” Indonesian Journal of Data and Science, vol. 6, no. 2, pp. 222–231, 2025, doi: https://doi.org/10.56705/ijodas.v6i2.265.
[21] M. I. Abidin, I. Nurtanio, and A. Achmad, “Deepfake Detection in Videos Using Long Short-Term Memory and CNN ResNext,” ILKOM Jurnal Ilmiah, vol. 14, no. 3, pp. 178–185, Dec. 2022, doi: https://doi.org/10.33096/ilkom.v14i3.1254.178-185.
[22] R. Satra, I. A. Dahlan, H. Darwis, Purnawansyah, S. Mujaddid, and F. Fattah, “A Comparison of Accuracy: KNN, TabNet, and Wide & Deep Learning for DDoS Attack Detection in Software Defined Network,” Proc. 2025 19th Int. Conf. Ubiquitous Inf. Manag. Commun. IMCOM 2025, 2025, doi: https://doi.org/10.1109/IMCOM64595.2025.10857511.
[23] B. Gegeleso and O. Ebiesuwa, "Comparative Analysis of Random Forest and LSTM Models for Customer Churn Prediction Based on Customer Satisfaction and Retention," Indones. J. Data Sci., vol. 6, no. 2, pp. 313–323, 2025, doi: https://doi.org/10.56705/ijodas.v6i2.244.
[24] P. Romadloni, B. Adhi Kusuma, and W. Maulana Baihaqi, “Komparasi Metode Pembelajaran Mesin Untuk Implementasi Pengambilan Keputusan Dalam Menentukan Promosi Jabatan Karyawan,” JATI (Jurnal Mhs. Tek. Inform., vol. 6, no. 2, pp. 622–628, 2022, doi: https://doi.org/10.36040/jati.v6i2.5238.
[25] Z. Jin, B. Yu, and T. Zhou, “The Mechanism of Employee Characteristics on Promotion: Building the Predictive Machine Learning Model,” Applied and Computational Engineering, vol. 134, pp. 123–137, 2025, doi: https://doi.org/10.54254/2755-2721/2025.22254.
[26] A. Rattrout, M. Jaradat, and R. Jayousi, "Machine Learning Advancements in SQL Injection Detection: NLP and Feature Engineering Strategies," 2023. doi: https://doi.org/10.21203/rs.3.rs-3446830/v1.
[27] C. Li, H. Li, Z. Liu, B. Li, and Y. Huang, “SeedSortNet: a rapid and highly effificient lightweight CNN based on visual attention for seed sorting,” PeerJ Comput. Sci., vol. 7, pp. 1–21, 2021, doi: https://doi.org/10.7717/peerj-cs.639.
[28] L. Hochreiter and J. Schmidhuber, “Long Short-Term Memory,” Neural Computation, vol. 9, no. 8, pp. 1735–1780, 1997.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Abdul Rachman Manga', Wahyu Kadri Rahmat Suat Suat, Huzain Azis

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Authors retain copyright and full publishing rights to their articles. Upon acceptance, authors grant Indonesian Journal of Data and Science a non-exclusive license to publish the work and to identify itself as the original publisher.
Self-archiving. Authors may deposit the submitted version, accepted manuscript, and version of record in institutional or subject repositories, with citation to the published article and a link to the version of record on the journal website.
Commercial permissions. Uses intended for commercial advantage or monetary compensation are not permitted under CC BY-NC 4.0. For permissions, contact the editorial office at ijodas.journal@gmail.com.
Legacy notice. Some earlier PDFs may display “Copyright © [Journal Name]” or only a CC BY-NC logo without the full license text. To ensure clarity, the authors maintain copyright, and all articles are distributed under CC BY-NC 4.0. Where any discrepancy exists, this policy and the article landing-page license statement prevail.










