Deteksi Sistem Cerdas Kerentanan Kode PHP Menggunakan Hybrid ML dan LLM
DOI:
https://doi.org/10.32627/internal.v9i1.2025Keywords:
Abstract Syntax Tree, LLM, PHP Security, Random Forest, TF-IDFAbstract
Security vulnerabilities in PHP programming code remain one of the major threats to the integrity of web applications, especially when software development processes are not supported by automated and adaptive security analysis mechanisms. This study aims to develop an intelligent system for vulnerability detection and automatic code remediation using a Hybrid Machine Learning (ML) and Large Language Model (LLM) approach. The system combines Term Frequency-Inverse Document Frequency (TF-IDF), Abstract Syntax Tree (AST) Parsing, and the Random Forest algorithm for vulnerability classification, while integrating the Google Gemini API as a dynamic recommendation layer to generate contextual and adaptive secure coding suggestions. The dataset consists of 320 PHP code snippets covering SQL Injection, XSS, File Inclusion, Command Injection, Unsafe File Upload, and safe code samples. Experimental evaluation using accuracy, precision, recall, F1-score, and confusion matrix shows that the model achieved an overall accuracy of 86.25% with a macro average F1-score of 0.86. This study demonstrates that integrating Hybrid ML and LLM-based remediation using the Gemini API has strong potential for developing intelligent static code analysis systems for PHP web applications.
References
Y. Fang, S. Han, C. Huang, and R. Wu, "TAP: A Static Analysis Model for PHP Vulnerabilities Based on Token and Deep Learning Technology," PLOS ONE, vol. 14, no. 11, p. e0225196, Nov. 2019, doi: 10.1371/journal.pone.0225196.
J. R. Tadhani, V. Vekariya, V. Sorathiya, S. Alshathri, and W. El-Shafai, "Securing Web Applications Against XSS and SQLi Attacks Using a Novel Deep Learning Approach," Scientific Reports, vol. 14, no. 1, p. 1897, Jan. 2024, doi: 10.1038/s41598-023-48845-4.
A. Senanayake, H. Kalutarage, and M. O. Al-Kadri, "Android Source Code Vulnerability Detection: A Systematic Literature Review," ACM Computing Surveys, vol. 55, no. 9, pp. 1-37, 2023, doi: 10.1145/3556974.
H. Pearce, B. Ahmad, B. Tan, B. Dolan-Gavitt, and R. Karri, "Asleep at the Keyboard? Assessing the Security of GitHub Copilot’s Code Contributions," in Proc. IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 2022, pp. 754-768, doi: 10.1109/SP46214.2022.9833571.
N. Shiri Harzevili, A. B. Belle, J. Wang, S. Wang, Z. M. Jiang, and N. Nagappan, "A Survey on Automated Software Vulnerability Detection Using Machine Learning and Deep Learning," ACM Computing Surveys, vol. 56, no. 9, pp. 1-39, 2024, doi: 10.1145/3652155.
C. S. Xia, Y. Wei, and L. Zhang, "Automated Program Repair in the Era of Large Language Models," in Proc. IEEE/ACM 46th International Conference on Software Engineering (ICSE), Lisbon, Portugal, 2024, pp. 1-13, doi: 10.1145/3597503.3639187.
D. Cao, Y. Liao, and X. Shang, "RealVul: Can We Detect Vulnerabilities in Web Applications with LLM?" in Proc. 39th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2024, pp. 1-13, doi: 10.1145/3691620.3695063.
H. Yuan, Y. Tang, W. Sun, and L. Liu, "A Detection Method for Android Application Security Based on TF-IDF and Machine Learning," PLOS ONE, vol. 15, no. 9, p. e0238694, Sep. 2020, doi: 10.1371/journal.pone.0238694.
X. Li, W. Wang, and X. Li, "Research on Intrusion Detection Based on an Enhanced Random Forest Algorithm," Applied Sciences, vol. 14, no. 2, p. 714, Jan. 2024, doi: 10.3390/app14020714.
A. Alzahrani, "Structural Detection of Security Vulnerabilities in PHP Code Using AST and Graph-Based Techniques," Journal of Systems and Software, vol. 153, pp. 190-203, 2019, doi: 10.1016/j.jss.2019.03.064.
A. Semasaba, W. Zheng, X. Wu, and S. Agyemang, "An Empirical Evaluation of Deep Learning-Based Source Code Vulnerability Detection: Representation Versus Models," Journal of Software: Evolution and Process, vol. 35, no. 6, p. e2422, Jan. 2023, doi: 10.1002/smr.2422.
J. Wang, L. Cao, X. Luo, Z. Zhou, J. Xie, A. Jatowt, and Y. Cai, "Enhancing Large Language Models for Secure Code Generation: A Dataset-driven Study on Vulnerability Mitigation," in Proc. IEEE/ACM 46th International Conference on Software Engineering (ICSE), 2024, pp. 1-12, doi: 10.1145/3597503.3608134.
M. E. Habiby, "Deteksi Kerentanan Kode PHP Menggunakan TF-IDF, AST Parsing, dan Random Forest," INTERNAL (Information System Journal), vol. 8, no. 1, pp. 1-9, Jun. 2025, doi: 10.32627/internal.v8i1.1411.
O. Cetin, E. Ekmekcioglu, B. Arief, and J. Hernandez-Castro, "An Empirical Evaluation of Large Language Models in Static Code Analysis for PHP Vulnerability Detection," Journal of Universal Computer Science (JUCS), vol. 30, no. 9, pp. 1163-1183, Sep. 2024, doi: 10.3897/jucs.134739.
M. Bascara, A. Fass, K. Rieck, and T. Holz, "DeepTective: A Hybrid Graph Neural Network Approach for Detecting PHP Vulnerabilities," in Proc. IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), 2022, pp. 1-10, doi: 10.1109/EuroSPW55150.2022.00033.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Moh Erdda Habiby Habiby, Miki Wijana

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.






