{"id":"https://openalex.org/W4224317173","doi":"https://doi.org/10.1145/3485447.3512234","title":"Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement Learning","display_name":"Link: Black-Box Detection of Cross-Site Scripting Vulnerabilities Using Reinforcement Learning","publication_year":2022,"publication_date":"2022-04-25","ids":{"openalex":"https://openalex.org/W4224317173","doi":"https://doi.org/10.1145/3485447.3512234"},"language":"en","primary_location":{"id":"doi:10.1145/3485447.3512234","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3485447.3512234","pdf_url":null,"source":{"id":"https://openalex.org/S4363608783","display_name":"Proceedings of the ACM Web Conference 2022","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2022","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5103932380","display_name":"Soyoung Lee","orcid":"https://orcid.org/0000-0002-3023-249X"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":true,"raw_author_name":"Soyoung Lee","raw_affiliation_strings":["School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea"],"affiliations":[{"raw_affiliation_string":"School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084848487","display_name":"Seongil Wi","orcid":"https://orcid.org/0000-0001-8081-4386"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Seongil Wi","raw_affiliation_strings":["School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea"],"affiliations":[{"raw_affiliation_string":"School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5082893706","display_name":"Sooel Son","orcid":"https://orcid.org/0000-0003-0904-2875"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Sooel Son","raw_affiliation_strings":["School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea"],"affiliations":[{"raw_affiliation_string":"School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea","institution_ids":["https://openalex.org/I157485424"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5103932380"],"corresponding_institution_ids":["https://openalex.org/I157485424"],"apc_list":null,"apc_paid":null,"fwci":3.2106,"has_fulltext":false,"cited_by_count":24,"citation_normalized_percentile":{"value":0.9341052,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"743","last_page":"754"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9858999848365784,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9842000007629395,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/cross-site-scripting","display_name":"Cross-site scripting","score":0.9509338736534119},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8225204944610596},{"id":"https://openalex.org/keywords/scripting-language","display_name":"Scripting language","score":0.6578149795532227},{"id":"https://openalex.org/keywords/false-positive-paradox","display_name":"False positive paradox","score":0.6202414035797119},{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.6132473945617676},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.5790235996246338},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5502630472183228},{"id":"https://openalex.org/keywords/web-application","display_name":"Web application","score":0.4448082745075226},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.4186669886112213},{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.4157242178916931},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.30326876044273376},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.28235599398612976},{"id":"https://openalex.org/keywords/web-application-security","display_name":"Web application security","score":0.28117889165878296},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.2569732666015625},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.24633321166038513},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.15128758549690247},{"id":"https://openalex.org/keywords/web-development","display_name":"Web development","score":0.08946084976196289}],"concepts":[{"id":"https://openalex.org/C39569185","wikidata":"https://www.wikidata.org/wiki/Q371199","display_name":"Cross-site scripting","level":5,"score":0.9509338736534119},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8225204944610596},{"id":"https://openalex.org/C61423126","wikidata":"https://www.wikidata.org/wiki/Q187432","display_name":"Scripting language","level":2,"score":0.6578149795532227},{"id":"https://openalex.org/C64869954","wikidata":"https://www.wikidata.org/wiki/Q1859747","display_name":"False positive paradox","level":2,"score":0.6202414035797119},{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.6132473945617676},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.5790235996246338},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5502630472183228},{"id":"https://openalex.org/C118643609","wikidata":"https://www.wikidata.org/wiki/Q189210","display_name":"Web application","level":2,"score":0.4448082745075226},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.4186669886112213},{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.4157242178916931},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.30326876044273376},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.28235599398612976},{"id":"https://openalex.org/C59241245","wikidata":"https://www.wikidata.org/wiki/Q4781497","display_name":"Web application security","level":4,"score":0.28117889165878296},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.2569732666015625},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.24633321166038513},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.15128758549690247},{"id":"https://openalex.org/C79373723","wikidata":"https://www.wikidata.org/wiki/Q386275","display_name":"Web development","level":3,"score":0.08946084976196289}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3485447.3512234","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3485447.3512234","pdf_url":null,"source":{"id":"https://openalex.org/S4363608783","display_name":"Proceedings of the ACM Web Conference 2022","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2022","raw_type":"proceedings-article"},{"id":"pmh:oai:scholarworks.unist.ac.kr:201301/65874","is_oa":false,"landing_page_url":"https://scholarworks.unist.ac.kr/handle/201301/65874","pdf_url":null,"source":{"id":"https://openalex.org/S4306401118","display_name":"Scholarworks@UNIST (Ulsan National Institute of Science and Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I48566637","host_organization_name":"Ulsan National Institute of Science and Technology","host_organization_lineage":["https://openalex.org/I48566637"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"CONFERENCE"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.7300000190734863,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":33,"referenced_works":["https://openalex.org/W1969518293","https://openalex.org/W2057769218","https://openalex.org/W2070218579","https://openalex.org/W2077204203","https://openalex.org/W2080803678","https://openalex.org/W2111487235","https://openalex.org/W2118278564","https://openalex.org/W2130107753","https://openalex.org/W2134646643","https://openalex.org/W2145339207","https://openalex.org/W2148211687","https://openalex.org/W2169384417","https://openalex.org/W2169868363","https://openalex.org/W2296241649","https://openalex.org/W2512971201","https://openalex.org/W2529831505","https://openalex.org/W2534610146","https://openalex.org/W2583993537","https://openalex.org/W2794232705","https://openalex.org/W2915117209","https://openalex.org/W2963079995","https://openalex.org/W2967963259","https://openalex.org/W3000351562","https://openalex.org/W3022702682","https://openalex.org/W3080269550","https://openalex.org/W3095708133","https://openalex.org/W3100944043","https://openalex.org/W3108270739","https://openalex.org/W3110888614","https://openalex.org/W3125321227","https://openalex.org/W3156952258","https://openalex.org/W3183794086","https://openalex.org/W3188417193"],"related_works":["https://openalex.org/W4366502726","https://openalex.org/W2511770387","https://openalex.org/W2150889667","https://openalex.org/W2611265297","https://openalex.org/W3190536237","https://openalex.org/W4233984944","https://openalex.org/W1976299830","https://openalex.org/W195300121","https://openalex.org/W2017602249","https://openalex.org/W2022927028"],"abstract_inverted_index":{"Black-box":[0],"web":[1,22,123],"scanners":[2,23,124],"have":[3],"been":[4],"a":[5,36,58,66,78,86,97],"prevalent":[6],"means":[7],"of":[8,48,61,127,148],"performing":[9],"penetration":[10],"testing":[11,27,37,132],"to":[12,50,65,91],"find":[13,92],"reflected":[14,68,93,153],"cross-site":[15],"scripting":[16],"(XSS)":[17],"vulnerabilities.":[18,52,155],"Unfortunately,":[19],"off-the-shelf":[20],"black-box":[21,98],"suffer":[24],"from":[25,35],"unscalable":[26],"as":[28,30],"well":[29],"false":[31,112],"negatives":[32],"that":[33,39],"stem":[34],"strategy":[38],"employs":[40],"fixed":[41],"attack":[42,63],"payloads,":[43],"thus":[44],"disregarding":[45],"the":[46,145],"exploitation":[47],"contexts":[49],"trigger":[51],"To":[53],"this":[54],"end,":[55],"we":[56],"propose":[57],"novel":[59],"method":[60],"adapting":[62],"payloads":[64],"target":[67],"XSS":[69,94,154],"vulnerability":[70],"using":[71,149],"reinforcement":[72],"learning":[73],"(RL).":[74],"We":[75],"present":[76],"Link,":[77],"general":[79],"RL":[80,150],"framework":[81],"whose":[82],"states,":[83],"actions,":[84],"and":[85,99,107,117,130],"reward":[87],"function":[88],"are":[89],"designed":[90],"vulnerabilities":[95,109,129,139],"in":[96,114,125,140,151],"fully":[100],"automatic":[101],"manner.":[102],"Link":[103,135],"finds":[104,137],"45,":[105],"213,":[106],"60":[108],"with":[110],"no":[111],"positives":[113],"Firing-Range,":[115],"OWASP,":[116],"WAVSEP":[118],"benchmarks,":[119],"respectively,":[120],"outperforming":[121],"state-of-the-art":[122],"terms":[126],"finding":[128,152],"ending":[131],"campaigns":[133],"earlier.":[134],"also":[136],"43":[138],"12":[141],"real-world":[142],"applications,":[143],"demonstrating":[144],"promising":[146],"efficacy":[147]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":8},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":5}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
