YangYang-Research/web-attack-detection
032
Web Attack Detection (Hybrid CNN-GRU)
Binary classifier for HTTP request / payload strings. Detects common web attacks (SQLi, XSS, CMDi, and related patterns) for RASP / WAF-style offline scoring.
Paper: Research and Development of a Smart Solution for Runtime Web Application Self-Protection (SOICT '23).
Note: Hub Inference Widgets / Inference Providers do not run this model end-to-end. Input must be a 384-d SentenceTransformer embedding (all-MiniLM-L6-v2), not raw text. Use the code below locally.Model Details
Architecture
- Input:
(batch, 384)— MiniLM sentence embedding - Reshape:
(batch, 384, 1)for Conv1D - CNN branch: Conv1D 32→64→128→256 + MaxPool + GlobalMaxPool →
(batch, 256) - GRU branch: stacked GRU 32→64→128→256 →
(batch, 256) - Fusion: element-wise multiply of CNN × GRU outputs
- Head: Dense 256→128→64→32→1 (sigmoid) — attack probability

Uses
Direct use
- Offline / online scoring of HTTP query strings, body snippets, or path segments
- Research on ML-based RASP / WAF detection
- Complement (not replace) signature WAF / IDS rules
Out of scope
- Standalone production gate without threshold tuning + human review
- Image, audio, or non-sequential tabular classification
- Guaranteed detection of novel / obfuscated zero-days
- Direct use with Hub
pipeline("text-classification")(no transformersconfig.json)
Bias, Risks, and Limitations
- Performance depends on training payload distribution; new frameworks / encodings may drift.
- Overfitting risk on smaller or unbalanced subsets.
- Black-box CNN-GRU: hard to explain individual decisions.
- False positives can block legitimate traffic if threshold is too low.
Recommendations
- Calibrate decision threshold on your traffic.
- Keep signature rules + allowlists alongside the model.
- Retrain / evaluate on domain-specific logs before production.
- Prefer explainability tools (SHAP/LIME on embeddings) for audits.
How to Get Started
pip install -U "keras>=3" tensorflow huggingface_hub sentence-transformersimport os
os.environ["KERAS_BACKEND"] = "tensorflow"
import keras
from huggingface_hub import hf_hub_download
from sentence_transformers import SentenceTransformer
REPO_ID = "YangYang-Research/web-attack-detection"
model_path = hf_hub_download(repo_id=REPO_ID, filename="model.h5")
model = keras.saving.load_model(model_path)
encoder = SentenceTransformer("sentence-transformers/all-MiniLM-L6-v2")
payload = "1' OR '1'='1 --"
embedding = encoder.encode(payload).reshape(1, 384)
score = float(model.predict(embedding, verbose=0)[0][0])
print(f"attack_probability={score:.4f}")Keras Hub-style path (weights still loaded from model.h5 via download):
# Equivalent one-liner once weights are local:
# model = keras.saving.load_model("hf://YangYang-Research/web-attack-detection")
# Only works if the repo follows Keras 3 Hub layout (config.json + model.weights.h5).
# This repo currently ships legacy `model.h5` — use hf_hub_download as above.Training Details
Training data
- Dataset: `YangYang-Research/web-attack-detection` (~626k labeled payloads; ~295k attack / ~331k benign)
- Split: ~70% train / ~30% test
Hyperparameters
Compute
- Google Colab Pro
- Jupyter Notebook
Evaluation
Test split (~30%) of `YangYang-Research/web-attack-detection`.
Reported metrics: precision, recall, F1, accuracy (see paper / figures below).


Repository layout
Previous Hub layout shipped a ~98 MBconfig.jsonthat embedded raw weight arrays and claimedlibrary_name: transformers. That file is removed — it broke Hub config parsing (Config file config.json cannot be fetched (too big)).
Citation
@inproceedings{10.1145/3628797.3628901,
author = {Le-Thanh, Phuc and Le-Anh, Tuan and Le-Trung, Quan},
title = {Research and Development of a Smart Solution for Runtime Web Application Self-Protection},
year = {2023},
isbn = {9798400708916},
publisher = {Association for Computing Machinery},
address = {New York, NY, USA},
url = {https://doi.org/10.1145/3628797.3628901},
doi = {10.1145/3628797.3628901},
booktitle = {Proceedings of the 12th International Symposium on Information and Communication Technology},
pages = {304–311},
numpages = {8},
location = {Ho Chi Minh, Vietnam},
series = {SOICT '23}
}Model Card Authors / Contact
- YangYang Research — org: YangYang-Research
- Original author: noobpk
