CANLI
Yükleniyor Veriler getiriliyor…
SCI-Expanded JCR Q2 Özgün Makale Scopus
A comparative evaluation of large language models for detecting SQL injection vulnerabilities in web applications
PeerJ Computer Science 2026 Cilt 12 Sayı 1
Scopus Eşleşmesi Bulundu
0
Atıf
12
Cilt
🔓
Açık Erişim
Özet
Structured Query Language (SQL) injection is considered to be one of the most intractable and harmful threats to the security of web applications, as SQL injection is a technique that allows hackers to manipulate queries and steal confidential information. Even though traditional methods of defense have been used, emerging attack techniques continue to circumvent them, and it requires stronger mechanisms of detection. As the concept of Large Language Models (LLMs) has become prominent in the field of cybersecurity, the idea of assessing their capability to detect and address such threats in practical contexts is gaining more and more popularity. This article provides a comparative evaluation of five pre-trained LLMs on the capability of detecting SQL injection attacks. To induce more realistic conditions, a Flask-based web application that linked to an SQLite database was created, which was able to support both benign queries and SQL injection payloads using Boolean-based, Union-based, and Error-based methods. These models were put to the test in the zero-shot settings, and their performance was evaluated by accuracy, precision, recall, and F1-score. Findings indicate that Mixtral-8x7B-Instruct achieved the best results, with an average F1-score of 87.52% and an accuracy of 86.67%. The second-best performance was achieved by LLaMA-3-70B-Instruct, which demonstrated consistently high recall across all attack categories. Deep Seek and CodeLLaMA both performed well in some form of attacks, but not overall. In contrast, Qwen2.5-Coder-7B-Instruct produced the lowest average detection metrics among all evaluated models. These findings indicate that advanced LLMs are potentially promising to enhance the detection of SQL injection and complementary web application security.
Web of Science Eşleşmesi Bulundu
0
WoS Atıf
12
Cilt
Article
Belge Türü
Kaynak: PEERJ COMPUTER SCIENCE
Anahtar Kelimeler (WoS)

Havuzumuzdaki Atıflar 0

Bu makaleye, sistemimizdeki Scopus veritabanında bulunan 0 makale atıf yapmıştır.

Bu makaleye, kendi Scopus havuzumuzdaki başka bir makaleden atıf kaydı bulunmuyor.

Anahtar Kelimeler

WoS | Bir kelimeye tıklayıp ilgili kaynaktaki yayınları görün.

Makale Bilgileri

Dergi PeerJ Computer Science
ISSN 2376-5992
Yıl 2026 / 7. ay
Cilt / Sayı 12 / 1
Sayfalar 1 – 26
Makale Türü Özgün Makale
Hakemlik Hakemli
Endeks SCI-Expanded
JCR Quartile Q2
Yayın Dili Türkçe
Kapsam Uluslararası
Toplam Yazar 2 kişi
Erişim Türü Elektronik
Alan Mühendislik Temel Alanı Bilgisayar Bilimleri ve Mühendisliği Yapay Zeka Algoritmalar ve Hesaplama Kuramı Bilgisayar Yazılımı ve Yazılım Mühendisliği

YÖKSİS Yazar Kaydı

Yazar Adı Hairan Borhanullah,ŞAHMAN MEHMET AKİF
YÖKSİS ID 9654307

Metrikler

Havuz Atıfları 0
JCR Quartile Q2
Yazar Sayısı 2