Loading…
10th WorldS4 2026 has ended
Tuesday July 28, 2026 2:30pm - 2:45pm BST
Authors - Saltanat Adilzhanova, Gulshat Amirkanova, Bauyrzhan Amirkhanov, Dana Sybanova, Anas Salem
Abstract - The increasing adoption of large language models (LLMs) by adversarial actors has introduced a critical threat to web application security: AI-mutated malicious payloads - injection attacks automatically rewritten by LLMs to preserve malicious functionality while evading signaturebased detection. Existing intrusion detection approaches, including classical machine learning classifiers and deep learning architectures trained on static historical corpora, do not address this threat class and degrade severely when confronted with LLM-obfuscated variants of known attacks. This paper presents a three-component framework for detecting and explaining AImutated malicious API payloads. First, a novel three-class labelled dataset is constructed by applying a controlled GPT-4o-mini mutation pipeline, spanning five structurally distinct obfuscation strategies, to payloads drawn from three established attack corpora, with validation against a sandboxed DVWA instance. Second, a CodeBERT encoder is fine-tuned for three-class classification distinguishing benign traffic, classically malicious payloads, and AI-mutated payloads, achieving a macro-F1 of 0.9472 and an AUC-ROC of 0.9990 on the held-out test set, with a class-specific F1 of 0.8627 on AI-mutated samples - an improvement of 27.18 points over the strongest baseline. Third, a dual-layer explainability module combining attention visualisation and SHAP-based token attribution is evaluated through a faithfulness deletion test, confirming that both methods identify decision-relevant tokens and revealing distinct detection strategies for classical versus AI-mutated payloads. A controlled ablation study demonstrates that AI-mutated training data is a necessary condition for detecting this class, with class-specific F1 collapsing to zero when such data is withheld. The dataset and model are released publicly to support reproducible research.
Paper Presenters
Tuesday July 28, 2026 2:30pm - 2:45pm BST
Bishopsgate 1 America Square, London, United Kingdom

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link