DOI: 10.3390/electronics15184303 ISSN: 2079-9292

A Lightweight Feature Engineering Approach for Efficient and Accurate XSS Attack Classification

Durmuş Özkan Şahin, Simge Şengül

This study proposes a lightweight and computationally efficient feature engineering approach for improving the detection of increasingly prevalent Cross-Site Scripting (XSS) attacks in web applications. High-dimensional feature representations commonly used in the literature, such as Term Frequency-Inverse Document Frequency (TFIDF), Bag-of-Words (BoW), and URL-based features, often introduce significant computational overhead and may negatively impact model efficiency. To address this issue, the proposed method identifies the common features obtained from five different feature selection techniques—Correlation Coefficient, CfsSubset, Information Gain, Gain Ratio, and OneR—and constructs a compact feature subset based on their intersection. This approach reduces the feature space from over 5000 features to a minimal set of critical attributes while maintaining high classification performance. The resulting feature set was evaluated using various machine learning algorithms, achieving accuracy levels of approximately 99%, particularly with Random Forest (RF), XGBoost (XGB), and Logistic Regression (LR), while significantly reducing training time. To ensure the reliability of the results, a 10 × 10 repeated stratified cross-validation strategy was employed, and statistical validation was conducted using confidence intervals and the Wilcoxon signed-rank test. Although statistically significant differences were observed between the full feature set and the reduced feature subset, the performance degradation remained limited (approximately 0.77–0.78%). These findings demonstrate that the proposed approach achieves a favorable balance between predictive performance and computational efficiency, making it a strong candidate for real-time and resource-constrained XSS detection systems.