A Comparative Study of LSTM and CNN Models in SQL Injection Attack Detection
DOI:
https://doi.org/10.56705/ijodas.v7i2.460Keywords:
SQL Injection, Deep Learning, Long Short-Term Memory, Convolutional Neural Network, EmbeddingAbstract
This research focuses on evaluating and comparing the performance of two deep learning architectures, namely Long Short-Term Memory (LSTM) and Convolutional Neural Network (CNN), for detecting SQL Injection (SQLi) attacks on text-based query data. SQL Injection remains one of the most critical cybersecurity threats due to its ability to exploit vulnerabilities in user input validation and compromise the integrity, confidentiality, and availability of information systems. In this study, LSTM and CNN models were trained using a publicly available SQL Injection dataset containing malicious and benign SQL queries. Three train-test split scenarios were evaluated, namely 70:30, 80:20, and 90:10, while maintaining identical preprocessing procedures and experimental configurations. Text preprocessing was performed using tokenization, sequence transformation, padding, and embedding representation to convert SQL queries into numerical input suitable for deep learning models. Model performance was evaluated using accuracy, precision, recall, F1-score, and confusion matrix analysis. The experimental results show that the LSTM model achieved the best performance with an accuracy of 98.90% using the 80:20 train-test split scenario, while the CNN model achieved an accuracy of 97.90% under the same scenario. Although CNN is effective in extracting local textual patterns, LSTM demonstrated better capability in capturing sequential dependencies within SQL query structures. These findings indicate that deep learning approaches, particularly LSTM-based models, provide an effective and reliable solution for SQL Injection detection and support the development of adaptive cybersecurity systems
Downloads
References
[1] Y. Chen, G. Liang, and Q. Wang, “Research on SQL Injection Detection Technology Based on Content Matching and Deep Learning,” Comput. Mater. Contin., vol. 84, no. 1, pp. 1145–1167, 2025, doi: 10.32604/cmc.2025.063319.
[2] E. Lestari, N. Jannah, and J. Nasution, “Effect of Service Quality and Excellence in Islamic Insurance Products on Community Preferences in Choosing an Islamic Insurance Company in Sikara Kara 1 Village, Natal Kab. Madina,” Int. J. Financ. Res., vol. 4, no. 4, pp. 339–350, 2024, doi: 10.47747/ijfr.v4i4.1592.
[3] H. Sun, Y. Du, and Q. Li, “Deep Learning-Based Detection Technology for SQL Injection Research and Implementation,” Appl. Sci., vol. 13, no. 16, 2023, doi: 10.3390/app13169466.
[4] C. S. Datasets, “Enhancing Cyber Security : A Study of Data Preprocessing Techniques for Enhancing Cyber Security : A Study of Data Preprocessing Techniques for Cyber Security Datasets,” no. September, 2024, doi: 10.32628/IJSRST2411427.
[5] H. Sun, Y. Du, and Q. Li, “Deep Learning-Based Detection Technology for SQL Injection Research and Implementation,” Appl. Sci., vol. 13, no. 16, 2023, doi: 10.3390/app13169466.
[6] H. C. Altunay and Z. Albayrak, “A hybrid CNN + LSTMbased intrusion detection system for industrial IoT networks,” Eng. Sci. Technol. an Int. J., vol. 38, p. 101322, 2023, doi: 10.1016/j.jestch.2022.101322.
[7] S. R. Menaka, G. Dharani, P. Kalaivani, S. R. Basha, S. K. S. Hareeth, and V. Kalaiyarasan, “An Efficient SQL Injection Detection with a Hybrid CNN & Random Forest Approach,” vol. 10, 2025.
[8] M. Sajid et al., “Enhancing intrusion detection: a hybrid machine and deep learning approach,” J. Cloud Comput., vol. 13, no. 1, 2024, doi: 10.1186/s13677-024-00685-x.
[9] R. T. Lo, W. J. Hwang, and T. M. Tai, “SQL Injection Detection Based on Lightweight Multi-Head Self-Attention,” Appl. Sci., vol. 15, no. 2, pp. 1–17, 2025, doi: 10.3390/app15020571.
[10] M. Alazab, S. Srinivasan, S. Venkatraman, V. Quoc Pham, V. Ravi, and Q.-V. Pham, “Deep learning for cyber security applications: A comprehensive survey,” Techrxiv.Org, no. October, pp. 0–34, 2023, doi: 10.36227/techrxiv.16748161.
[11] H. Darwis, Z. Ali, Purnawansyah, H. Lahuddin, and H. Azis, “Deep Dive Into Pubmed Rct: Leveraging Tribrid Embedding Recurrent Neural Network Model,” ICIC Express Lett., vol. 19, no. 1, pp. 111–118, 2025, doi: 10.24507/icicel.19.01.111.
[12] H. Darwis, Z. Ali, Purnawansyah, H. Lahuddin, and H. Azis, “Deep Dive Into Pubmed Rct: Leveraging Tribrid Embedding Recurrent Neural Network Model,” ICIC Express Lett., vol. 19, no. 1, pp. 111–118, 2025, doi: 10.24507/icicel.19.01.111.
[13] T. Sabri, S. Bahassine, O. El Beggar, and M. Kissi, “An improved Arabic text classification method using word embedding,” Int. J. Electr. Comput. Eng., vol. 14, no. 1, pp. 721–731, 2024, doi: 10.11591/ijece.v14i1.pp721-731.
[14] A. Alazzawi, “Sql Injection Detection Using Rnn Deep Learning Model,” Sql Inject. Detect. Using Rnn Deep Learn. Model, vol. 5, no. 1, pp. 531–541, 2023, doi: 10.37385/jaets.v5i1.2864.
[15] M. Indra, I. Nurtanio, and A. Achmad, “Deepfake detection in videos using Long Short-Term Memory and CNN ResNext,” vol. 14, no. 3, pp. 178–185, 2022.
[16] I. M. Mahmud, P. S. Informatika, F. Sains, U. Jenderal, and A. Yani, “Klasifikasi Frame Bahasa Isyarat Huruf Sibi Menggunakan Fitur Landmark dan Long Short-Term Memory ( LSTM ),” vol. 07, no. 02, pp. 43–49, 2025.
[17] A. P. Wibawa and T. Widiyaningtyas, “Congestion Predictive Modelling on Network Dataset Using Ensemble Deep Learning,” vol. 5, no. 4, pp. 1597–1613, 2024.
[18] A. Bachir, A. Sultan, and S. S. Abu-naser, “Predictive Modeling of Breast Cancer Diagnosis Using Neural Networks : A Kaggle Dataset Analysis,” vol. 7, no. 9, pp. 1–9, 2023.
[19] M. R. Yusuf, “Penerapan Deep Learning untuk Deteksi Anomali dalam Jaringan Keamanan Siber Menggunakan Recurrent Neural Networks ( RNNs ),” 2025, doi: doi.org/10.56211/blendsains.v3i4.800.
[20] A. Farizi, “Sistem Deteksi Intrusi Berbasis Deep Learning untuk Mitigasi Serangan Zero-Day pada Jaringan Komputer,” no. I, 2025
Published
Issue
Section
License
Copyright (c) 2026 Abdul Rachman Manga', Wahyu Kadri Rahmat Suat Suat, Huzain Azis

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Authors retain copyright and full publishing rights to their articles. Upon acceptance, authors grant Indonesian Journal of Data and Science a non-exclusive license to publish the work and to identify itself as the original publisher.
Self-archiving. Authors may deposit the submitted version, accepted manuscript, and version of record in institutional or subject repositories, with citation to the published article and a link to the version of record on the journal website.
Commercial permissions. Uses intended for commercial advantage or monetary compensation are not permitted under CC BY-NC 4.0. For permissions, contact the editorial office at ijodas.journal@gmail.com.
Legacy notice. Some earlier PDFs may display “Copyright © [Journal Name]” or only a CC BY-NC logo without the full license text. To ensure clarity, the authors maintain copyright, and all articles are distributed under CC BY-NC 4.0. Where any discrepancy exists, this policy and the article landing-page license statement prevail.










