<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Iranian Society of Cryptology</PublisherName>
				<JournalTitle>The ISC International Journal of Information Security</JournalTitle>
				<Issn>2008-2045</Issn>
				<Volume>18</Volume>
				<Issue>3</Issue>
				<PubDate PubStatus="epublish">
					<Year>2026</Year>
					<Month>07</Month>
					<Day>01</Day>
				</PubDate>
			</Journal>
<ArticleTitle>Genetic Algorithms in Action: Adversarial Attacks on Machine Learning-Based XSS Detection Systems</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage>277</FirstPage>
			<LastPage>286</LastPage>
			<ELocationID EIdType="pii">248360</ELocationID>
			
<ELocationID EIdType="doi">10.22042/isecure.2026.248360</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Mohammadreza</FirstName>
					<LastName>Safi</LastName>
<Affiliation>Faculty of Electrical and Computer Engineering, Malek Ashtar University of Technology, Iran</Affiliation>

</Author>
<Author>
					<FirstName>Mohammad Ali</FirstName>
					<LastName>Hadavi</LastName>
<Affiliation>Faculty of Electrical and Computer Engineering, Malek Ashtar University of Technology, Iran</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
		<Abstract>Cross-Site Scripting (XSS) remains a critical web application vulnerability, consistently ranking among the OWASP Top 10 security risks. Although machine learning and deep learning techniques have improved XSS detection, these models are susceptible to adversarial attacks — carefully crafted inputs designed to evade detection. This paper proposes a novel adversarial attack framework that leverages a Genetic Algorithm to generate adversarial XSS payloads targeting machine learning-based detection systems automatically. Our framework is designed to achieve high transferability, enabling adversarial samples to bypass a wide range of detection models, even those with different architectures. By employing genetic operators such as selection, crossover, and mutation, the framework systematically optimizes payloads to maximize their ability to evade detection while preserving syntactic validity. Experimental results demonstrate that the generated adversarial samples consistently evade multiple state-of-the-art detection models, revealing significant vulnerabilities in current XSS defences. This work underscores the urgent need for more robust machine learning-based security solutions and provides a foundation for developing improved defences against adaptive adversarial threats.</Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">IMachine learning</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Adversarial attack</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Genetic Algorithms</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">XSS detection</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Cross-Site Scripting</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.isecure-journal.com/article_248360_dbfa5440c1b25025783d77cfde98f97e.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
