{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:M5LEU4YVQKOATRJCQEJKCS3ZU7","short_pith_number":"pith:M5LEU4YV","schema_version":"1.0","canonical_sha256":"67564a7315829c09c5228112a14b79a7c63f82077e4091495951e7eef627ff7f","source":{"kind":"arxiv","id":"2504.08176","version":1},"attestation_state":"computed","paper":{"title":"GenXSS: an AI-Driven Framework for Automated Detection of XSS Attacks in WAFs","license":"http://creativecommons.org/publicdomain/zero/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Arun Ravindran, Vahid Babaey","submitted_at":"2025-04-11T00:13:59Z","abstract_excerpt":"The increasing reliance on web services has led to a rise in cybersecurity threats, particularly Cross-Site Scripting (XSS) attacks, which target client-side layers of web applications by injecting malicious scripts. Traditional Web Application Firewalls (WAFs) struggle to detect highly obfuscated and complex attacks, as their rules require manual updates. This paper presents a novel generative AI framework that leverages Large Language Models (LLMs) to enhance XSS mitigation. The framework achieves two primary objectives: (1) generating sophisticated and syntactically validated XSS payloads u"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2504.08176","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/publicdomain/zero/1.0/","primary_cat":"cs.CR","submitted_at":"2025-04-11T00:13:59Z","cross_cats_sorted":[],"title_canon_sha256":"6a5d7f88eecdfbe9d49920ab64c5b2e9be2d926d40aa31a91a50493fe64d8eba","abstract_canon_sha256":"92531993623aa0119a35b5dc067e9d9e2a2356494fb0ffa6d3e119b29c9aec8a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:47:44.350226Z","signature_b64":"4WiYCPE+2UH9nbkxsQGP3JQesBTfRGXxpJxhLgPb6jLC146bui4RybwUPei1ONlUmwWn+U1s5C+Y892bAM4CAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"67564a7315829c09c5228112a14b79a7c63f82077e4091495951e7eef627ff7f","last_reissued_at":"2026-07-05T10:47:44.349748Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:47:44.349748Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"GenXSS: an AI-Driven Framework for Automated Detection of XSS Attacks in WAFs","license":"http://creativecommons.org/publicdomain/zero/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Arun Ravindran, Vahid Babaey","submitted_at":"2025-04-11T00:13:59Z","abstract_excerpt":"The increasing reliance on web services has led to a rise in cybersecurity threats, particularly Cross-Site Scripting (XSS) attacks, which target client-side layers of web applications by injecting malicious scripts. Traditional Web Application Firewalls (WAFs) struggle to detect highly obfuscated and complex attacks, as their rules require manual updates. This paper presents a novel generative AI framework that leverages Large Language Models (LLMs) to enhance XSS mitigation. The framework achieves two primary objectives: (1) generating sophisticated and syntactically validated XSS payloads u"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2504.08176","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2504.08176/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2504.08176","created_at":"2026-07-05T10:47:44.349806+00:00"},{"alias_kind":"arxiv_version","alias_value":"2504.08176v1","created_at":"2026-07-05T10:47:44.349806+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2504.08176","created_at":"2026-07-05T10:47:44.349806+00:00"},{"alias_kind":"pith_short_12","alias_value":"M5LEU4YVQKOA","created_at":"2026-07-05T10:47:44.349806+00:00"},{"alias_kind":"pith_short_16","alias_value":"M5LEU4YVQKOATRJC","created_at":"2026-07-05T10:47:44.349806+00:00"},{"alias_kind":"pith_short_8","alias_value":"M5LEU4YV","created_at":"2026-07-05T10:47:44.349806+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2504.14122","citing_title":"Detecting Zero-Day Web Attacks with an Ensemble of LSTM, GRU, and Stacked Autoencoders","ref_index":49,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/M5LEU4YVQKOATRJCQEJKCS3ZU7","json":"https://pith.science/pith/M5LEU4YVQKOATRJCQEJKCS3ZU7.json","graph_json":"https://pith.science/api/pith-number/M5LEU4YVQKOATRJCQEJKCS3ZU7/graph.json","events_json":"https://pith.science/api/pith-number/M5LEU4YVQKOATRJCQEJKCS3ZU7/events.json","paper":"https://pith.science/paper/M5LEU4YV"},"agent_actions":{"view_html":"https://pith.science/pith/M5LEU4YVQKOATRJCQEJKCS3ZU7","download_json":"https://pith.science/pith/M5LEU4YVQKOATRJCQEJKCS3ZU7.json","view_paper":"https://pith.science/paper/M5LEU4YV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2504.08176&json=true","fetch_graph":"https://pith.science/api/pith-number/M5LEU4YVQKOATRJCQEJKCS3ZU7/graph.json","fetch_events":"https://pith.science/api/pith-number/M5LEU4YVQKOATRJCQEJKCS3ZU7/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/M5LEU4YVQKOATRJCQEJKCS3ZU7/action/timestamp_anchor","attest_storage":"https://pith.science/pith/M5LEU4YVQKOATRJCQEJKCS3ZU7/action/storage_attestation","attest_author":"https://pith.science/pith/M5LEU4YVQKOATRJCQEJKCS3ZU7/action/author_attestation","sign_citation":"https://pith.science/pith/M5LEU4YVQKOATRJCQEJKCS3ZU7/action/citation_signature","submit_replication":"https://pith.science/pith/M5LEU4YVQKOATRJCQEJKCS3ZU7/action/replication_record"}},"created_at":"2026-07-05T10:47:44.349806+00:00","updated_at":"2026-07-05T10:47:44.349806+00:00"}