Artificial Intelligence-Based Web Attack Detection: A Survey of Machine Learning, Deep Learning, Transformer and Large Language Model Approaches

Authors

  • Haiyang Wang Beijing Union University, Beijing, China
  • Yuejin Zhang Beijing Union University, Beijing, China

DOI:

https://doi.org/10.54097/s52rq572

Keywords:

Web Attack Detection, Artificial Intelligence, Deep Learning, Transformer, Large Language Model, Cybersecurity

Abstract

Web services are now pervasive in almost all industries, but this has made them a major target for hackers. Traditional signature-based solutions are no longer effective against zero‑day and polymorphic threats that evolve rapidly. The much heralded game‑changer is artificial intelligence (AI) particularly deep learning and more recently large language models. But the literature is fragmented: CNNs learn local features, Transformers capture long-range dependencies, and LLMs offer semantic understanding - yet each suffers from real-world limitations on interpretability, efficiency and security. In this survey we chart this progress and suggest that it's not model accuracy but trustworthiness that matters most. We carve up benchmark datasets (CSIC2010, CICIDS2017) and see a disconnect between lab and reality. Our message: the next big jump will not be driven by larger parameters, but smaller, more visible and dynamic systems that can be trusted by security analysts.

Downloads

Download data is not yet available.

References

[1] Guo, Y. (2023). A review of machine learning based zero day attack detection: Challenges and future directions. Computer Communications, 198, 175 185. https://doi.org/ 10.1016/j. comcom. 2022.11.001NIST.

[2] Yang, Y., Gu, Y. H., & Yan, Y. (2023). Machine learning based intrusion detection for rare class network attacks. Electronics, 12(18), 3911. https://doi.org/ 10.3390/ electronics 12183911.

[3] Alaoui, R. L., & Nfaoui, E. H. (2022). Deep learning for vulnerability and attack detection on web applications: A systematic literature review. Future Internet, 14(4), 118. https://doi. org/10.3390/fi14040118.

[4] Arroju, S., Adunoori, B., Jadhav, R., Jakkula, J., & Sreelakshmi, R. (2025). Detecting web attacks with end to end deep learning. Journal of Computer Allied Intelligence, 3(4), 36 46.

[5] Wu, Y. Q., Zou, B. L., & Cao, Y. F. (2024). Current status and challenges and future trends of deep learning based intrusion detection models. Journal of Imaging, 10(10), 254. https:// doi. org/10.3390/jimaging10100254.

[6] Yang, J., Wu, Y. G., Yuan, Y. P., Xue, H. Z., Bourouis, S., Abdel Salam, M., Prajapat, S., & Por, L. Y. (2025). LLM AE MP: Web attack detection using a large language model with autoencoder and multilayer perceptron. Expert Systems with Applications, 274, 126982. https://doi.org/10. 1016/j. eswa.2025.126982.

[7] Xu, Y. J., Fang, Y., Liu, Z. L., & Zhang, Q. (2023). PWAGAT: Potential web attacker detection based on graph attention network. Neurocomputing, 557, 126725. https://doi.org/10. 1016/j. neucom.2023.126725.

[8] Wu, Z. H., Zhang, H., Wang, P. H., & Sun, Z. B. (2022). RTIDS: A robust transformer based approach for intrusion detection system. IEEE Access, 10, 64375 64387. https:// doi. org/ 10.1109/ACCESS.2022.3183012.

[9] Farias Junior, E. P., De Neira, A. B., Borges, L. F., & Nogueira, M. (2025). Transformers model for DDoS attack detection: A survey. Computer Networks, 270, 111433. https://doi.org/ 10. 1016/ j. comnet.2025.111433.

[10] Xu, Y. J., Zhang, Q., Deng, H. X., Liu, Z. L., Yang, C., & Fang, Y. (2025). Unknown web attack threat detection based on large language model. Applied Soft Computing, 173, 112905. https://doi.org/10.1016/j.asoc.2025.112905.

[11] Hozouri, A., Mirzaei, A., & Effatparvar, M. (2025). A comprehensive survey on intrusion detection systems with advances in machine learning, deep learning and emerging cybersecurity challenges. Discover Artificial Intelligence, 5, 314. https://doi.org/10.1007/s44163 025 00314 8.

[12] Fasla, H., & Mehmood, A. (2026). Explainable artificial intelligence for web application threat detection: A systematic review. Artificial Intelligence Review. https://doi.org/10. 1007/ s10462 025 10987 9.

[13] Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., Kaiser, L., & Polosukhin, I. (2017). Attention is all you need. In Advances in Neural Information Processing Systems (pp. 5998 6008). https://doi.org/10.48550/ arXiv. 1706. 03762.

[14] Devlin, J., Chang, M. W., Lee, K., & Toutanova, K. (2019). BERT: Pre training of deep bidirectional transformers for language understanding. In Proceedings of NAACL HLT (pp. 4171 4186). https://doi.org/10.18653/v1/N19 1423.

[15] Liu, Y. H., Ott, M., Goyal, N., Du, J. F., Joshi, M., Chen, D. Q., Levy, O., Lewis, M., Zettlemoyer, L., & Stoyanov, V. (2019). RoBERTa: A robustly optimized BERT pretraining approach. arXiv preprint arXiv:1907.11692. https://doi.org/10. 48550/ arXiv. 1907.11692.

[16] Brown, T. B., Mann, B., Ryder, N., Subbiah, M., Kaplan, J., Dhariwal, P., Neelakantan, A., Shyam, P., Sastry, G., Askell, A., Agarwal, S., Herbert Voss, A., Krueger, G., Henighan, T., Child, R., Ramesh, A., Ziegler, D. M., Wu, J., Winter, C., … Amodei, D. (2020). Language models are few shot learners. In Advances in Neural Information Processing Systems (Vol. 33, pp. 1877 1901). https://doi.org/10.48550/arXiv.2005.14165.

[17] Lester, B., Al Rfou, R., & Constant, N. (2021). The power of scale for parameter efficient prompt tuning. In Proceedings of EMNLP (pp. 3045 3059). https://doi.org/10. 18653/v1/ 2021. emnlp main.240.

[18] Zhou, K. Y., Li, J. K., Lian, M., Wang, Z. X., Zhang, H. Y., Qiao, Y., & Li, W. (2022). Learning to prompt for vision language models. International Journal of Computer Vision, 130, 2337 2348. https://doi.org/ 10.1007/ s11 26 3 022 01632 4.

Downloads

Published

28-08-2026

Issue

Section

Articles

How to Cite

Wang, H., & Zhang, Y. (2026). Artificial Intelligence-Based Web Attack Detection: A Survey of Machine Learning, Deep Learning, Transformer and Large Language Model Approaches. Frontiers in Computing and Intelligent Systems, 17(3), 38-44. https://doi.org/10.54097/s52rq572