Return
Self-Learning Attack Generation toward Edge-Based Consumer Web Security Testing
DOI:10.1109/mce.2026.3731752.png)
Abstract
En 中文
Security evaluation of web-based services for consumer electronics (CE) applications is increasingly important, as many device management platforms, support systems, and companion services rely on PHP-based web technologies. Existing black-box fuzzing approaches often suffer from limited vulnerability coverage due to the large input space, while existing XSS datasets may be incomplete or biased toward known payload patterns. This paper presents an automated web security testing system that leverages Generative Adversarial Networks (GANs) to learn and generate diverse attack patterns from limited samples. WordPress is adopted as a practical PHP-based experimental carrier because of its widespread use in consumer-facing services, while the proposed testing process focuses on general PHP-based input handling, payload execution, and response analysis rather than WordPress-specific functions. The framework is intended to support local attack input generation as a future edge or gateway deployment option. The present experimental validation focuses on payload generation and vulnerability testing in a controlled web testbed rather than on embedded hardware. The results show that the generated payloads can support security testing of consumer web services under limited and imperfect attack data.
Keywords:
Cross-site scripting
Payloads
Testing
Training
Modeling
Security
Learning (artificial intelligence)
Sequences
Sequential analysis
Generative adversarial networks
Journal
IF:
4.1
Papers:
1.3K
Citations:
1.8K
Organization
Cited Papers
No cited papers available

