{"id":"https://openalex.org/W4387068228","doi":"https://doi.org/10.1109/tdsc.2023.3319352","title":"An Automatic XSS Attack Vector Generation Method Based on the Improved Dueling DDQN Algorithm","display_name":"An Automatic XSS Attack Vector Generation Method Based on the Improved Dueling DDQN Algorithm","publication_year":2023,"publication_date":"2023-09-26","ids":{"openalex":"https://openalex.org/W4387068228","doi":"https://doi.org/10.1109/tdsc.2023.3319352"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2023.3319352","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2023.3319352","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101290598","display_name":"Yuan Yao","orcid":"https://orcid.org/0000-0003-1473-8201"},"institutions":[{"id":"https://openalex.org/I24185976","display_name":"Sichuan University","ror":"https://ror.org/011ashp19","country_code":"CN","type":"education","lineage":["https://openalex.org/I24185976"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yuan Yao","raw_affiliation_strings":["School of Cyber Science and Engineering, Sichuan University, Chengdu, China"],"raw_orcid":"https://orcid.org/0000-0003-1473-8201","affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China","institution_ids":["https://openalex.org/I24185976"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047196217","display_name":"Junjiang He","orcid":"https://orcid.org/0000-0001-7040-2425"},"institutions":[{"id":"https://openalex.org/I24185976","display_name":"Sichuan University","ror":"https://ror.org/011ashp19","country_code":"CN","type":"education","lineage":["https://openalex.org/I24185976"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Junjiang He","raw_affiliation_strings":["School of Cyber Science and Engineering, Sichuan University, Chengdu, China"],"raw_orcid":"https://orcid.org/0000-0001-7040-2425","affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China","institution_ids":["https://openalex.org/I24185976"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100654634","display_name":"Tao Li","orcid":"https://orcid.org/0000-0002-8608-9776"},"institutions":[{"id":"https://openalex.org/I24185976","display_name":"Sichuan University","ror":"https://ror.org/011ashp19","country_code":"CN","type":"education","lineage":["https://openalex.org/I24185976"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Tao Li","raw_affiliation_strings":["School of Cyber Science and Engineering, Sichuan University, Chengdu, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China","institution_ids":["https://openalex.org/I24185976"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102819863","display_name":"Yunpeng Wang","orcid":"https://orcid.org/0000-0002-9607-4885"},"institutions":[{"id":"https://openalex.org/I24185976","display_name":"Sichuan University","ror":"https://ror.org/011ashp19","country_code":"CN","type":"education","lineage":["https://openalex.org/I24185976"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yunpeng Wang","raw_affiliation_strings":["School of Cyber Science and Engineering, Sichuan University, Chengdu, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China","institution_ids":["https://openalex.org/I24185976"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035587625","display_name":"Xiaolong Lan","orcid":"https://orcid.org/0000-0003-3483-1710"},"institutions":[{"id":"https://openalex.org/I24185976","display_name":"Sichuan University","ror":"https://ror.org/011ashp19","country_code":"CN","type":"education","lineage":["https://openalex.org/I24185976"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaolong Lan","raw_affiliation_strings":["School of Cyber Science and Engineering, Sichuan University, Chengdu, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China","institution_ids":["https://openalex.org/I24185976"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100718648","display_name":"Yuan Li","orcid":"https://orcid.org/0000-0002-8336-4840"},"institutions":[{"id":"https://openalex.org/I24185976","display_name":"Sichuan University","ror":"https://ror.org/011ashp19","country_code":"CN","type":"education","lineage":["https://openalex.org/I24185976"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuan Li","raw_affiliation_strings":["School of Cyber Science and Engineering, Sichuan University, Chengdu, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China","institution_ids":["https://openalex.org/I24185976"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5101290598"],"corresponding_institution_ids":["https://openalex.org/I24185976"],"apc_list":null,"apc_paid":null,"fwci":2.5578,"has_fulltext":false,"cited_by_count":13,"citation_normalized_percentile":{"value":0.90222161,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":"21","issue":"4","first_page":"2852","last_page":"2868"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9939000010490417,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9939000010490417,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9860000014305115,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.984000027179718,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/cross-site-scripting","display_name":"Cross-site scripting","score":0.9599640369415283},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.868412971496582},{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.4691416621208191},{"id":"https://openalex.org/keywords/convergence","display_name":"Convergence (economics)","score":0.42382803559303284},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.41869738698005676},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.35664600133895874},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.34505656361579895},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.22776710987091064},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.15597766637802124},{"id":"https://openalex.org/keywords/web-application-security","display_name":"Web application security","score":0.1540595293045044},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.12382188439369202},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.08990353345870972}],"concepts":[{"id":"https://openalex.org/C39569185","wikidata":"https://www.wikidata.org/wiki/Q371199","display_name":"Cross-site scripting","level":5,"score":0.9599640369415283},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.868412971496582},{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.4691416621208191},{"id":"https://openalex.org/C2777303404","wikidata":"https://www.wikidata.org/wiki/Q759757","display_name":"Convergence (economics)","level":2,"score":0.42382803559303284},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.41869738698005676},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.35664600133895874},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.34505656361579895},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.22776710987091064},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.15597766637802124},{"id":"https://openalex.org/C59241245","wikidata":"https://www.wikidata.org/wiki/Q4781497","display_name":"Web application security","level":4,"score":0.1540595293045044},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.12382188439369202},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.08990353345870972},{"id":"https://openalex.org/C79373723","wikidata":"https://www.wikidata.org/wiki/Q386275","display_name":"Web development","level":3,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C50522688","wikidata":"https://www.wikidata.org/wiki/Q189833","display_name":"Economic growth","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tdsc.2023.3319352","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2023.3319352","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.6499999761581421}],"awards":[{"id":"https://openalex.org/G1963852172","display_name":null,"funder_award_id":"62101358","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2396152343","display_name":null,"funder_award_id":"62032002","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8512557549","display_name":null,"funder_award_id":"2020M683345","funder_id":"https://openalex.org/F4320321543","funder_display_name":"China Postdoctoral Science Foundation"},{"id":"https://openalex.org/G867414068","display_name":null,"funder_award_id":"U19A2068","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320321543","display_name":"China Postdoctoral Science Foundation","ror":"https://ror.org/0426zh255"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4366502726","https://openalex.org/W2511770387","https://openalex.org/W2023038964","https://openalex.org/W3120811337","https://openalex.org/W2075358766","https://openalex.org/W2766647240","https://openalex.org/W4385301282","https://openalex.org/W2990186179","https://openalex.org/W2611265297","https://openalex.org/W3072699177"],"abstract_inverted_index":{"As":[0],"one":[1],"of":[2,57,110,136,156,192,218,243,286],"the":[3,9,27,74,82,94,104,111,134,148,154,157,161,190,199,230,277,295,299],"most":[4],"common":[5],"web":[6,21],"attack":[7,14,22,28,68,84,96,137,180,195,252,258],"types,":[8],"XSS":[10,67,83,179,210,223],"(Cross":[11],"Site":[12],"Scripting)":[13],"is":[15],"an":[16,65,117,177],"important":[17],"research":[18],"topic":[19],"in":[20,30,166,241,288],"and":[23,49,100,107,133,169,248,266,280],"defense":[24,268],"technology.":[25],"However,":[26],"vectors":[29,259],"security":[31],"evaluation":[32],"methods":[33],"are":[34,45],"often":[35],"based":[36,72,146,183],"on":[37,73,147,184,198],"expert":[38],"experience":[39,126],"or":[40],"manual":[41],"testing":[42],"methods,":[43,201],"which":[44,212],"not":[46],"only":[47],"costly":[48],"time-consuming":[50],"but":[51],"also":[52],"have":[53,203],"a":[54,89,124,143,205,215,282],"large":[55],"number":[56],"false":[58],"positives.":[59],"In":[60],"this":[61],"paper,":[62],"we":[63,80,115,141,175,202],"build":[64],"automatic":[66,178,209],"vector":[69,85,97,138,253],"generation":[70,86,254],"method":[71,182,271],"improved":[75,118,231],"Dueling":[76,119,232],"DDQN":[77,120,233],"algorithm.":[78],"First,":[79],"model":[81,162,255,296],"process":[87],"as":[88],"Markov":[90],"decision":[91],"process,":[92],"mapping":[93],"initial":[95],"mutation":[98,101,172],"points":[99],"strategies":[102,304],"to":[103,129,152,188,262,305],"state":[105],"space":[106,109],"action":[108],"model,":[112],"respectively.":[113],"Second,":[114],"propose":[116,176],"algorithm":[121,131,151,234],"by":[122],"introducing":[123],"priority":[125],"replay":[127],"mechanism":[128,145],"improve":[130],"performance":[132],"speed":[135],"generation.":[139],"Third,":[140],"establish":[142],"feedback":[144],"edit":[149],"distance":[150],"define":[153],"role":[155],"reward":[158],"function,":[159],"preventing":[160],"from":[163],"getting":[164],"stuck":[165],"local":[167],"optima":[168],"achieving":[170],"better":[171],"effects.":[173],"Finally,":[174],"verification":[181],"static":[185],"semantic":[186],"analysis":[187],"validate":[189],"effectiveness":[191],"our":[193],"generated":[194],"vectors.":[196],"Based":[197],"aforementioned":[200],"developed":[204],"prototype":[206],"tool":[207],"for":[208,302],"scanning,":[211],"avoids":[213],"generating":[214],"high":[216],"proportion":[217],"invalid":[219],"samples":[220],"like":[221],"traditional":[222],"scanners.":[224],"The":[225,250],"experimental":[226],"results":[227],"demonstrate":[228],"that":[229,260],"outperforms":[235],"other":[236],"value-based":[237],"reinforcement":[238],"learning":[239,246],"algorithms":[240],"terms":[242],"convergence":[244],"speed,":[245],"efficiency,":[247],"stability.":[249],"adaptive":[251],"can":[256,297],"generate":[257],"adapt":[261],"program":[263],"context":[264],"semantics":[265],"bypass":[267,284,306],"mechanisms.":[269],"Our":[270],"performs":[272],"well":[273],"when":[274],"directly":[275],"scanning":[276],"target":[278,289],"system":[279],"exhibits":[281],"higher":[283],"rate":[285],"85.71%":[287],"systems":[290],"deployed":[291],"with":[292],"WAFs.":[293],"Furthermore,":[294],"learn":[298],"shortest":[300],"path":[301],"selecting":[303],"WAF":[307],"detection":[308]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":9},{"year":2024,"cited_by_count":2}],"updated_date":"2026-04-24T08:23:43.765630","created_date":"2025-10-10T00:00:00"}
