SQL Injection in LLM-Generated Queries: Systematic Analysis of Detection Gaps and Security Risks

Citations

WEB OF SCIENCE

1
Citations

SCOPUS

1

초록

Large language models (LLMs) are being woven into software systems at a remarkable pace. When these systems include a back-end database, LLM integration opens new attack surfaces for SQL injection (SQLi). We present the first systematic security evaluation of LLM-generated SQL across 14 models-four accessed via web-based chat interfaces and ten via direct APIs. Using 100 expert-crafted attack prompts spanning three complexity tiers (basic, medium, advanced), we generated queries from each model and executed them on SQLite, MySQL, and PostgreSQL. The results expose pronounced security disparities. Web-interface models rejected 41.5% of potentially malicious prompts, whereas API-access models blocked only 13.4%, a difference in protective behavior. Cross-database testing showed MySQL to be most susceptible (12.1% successful attacks), SQLite moderately vulnerable (8.1%), and PostgreSQL the most resilient (1.7%). We further assessed four popular SQLi-detection techniques-regular-expression matching, classical machine learning, a convolutional neural network, and a RoBERTa-based contextual model. All experienced severe performance degradation when confronted with LLM-generated queries: overall accuracy plummeted from roughly 98% on standard SQLi benchmarks to just 60% on our test set. Even the context-aware embedding model failed to reliably flag malicious patterns in LLM outputs. Our work contributes (i) the first comprehensive characterization of SQLi risks posed by LLMs, (ii) a publicly released evaluation framework with expert-validated test cases, and (iii) evidence of critical blind spots in current SQLi-detection mechanisms that must be addressed to secure next-generation LLM applications.

키워드

Security; SQL injection; Codes; Structured Query Language; Databases; Filters; Benchmark testing; Accuracy; Systematics; Passwords; Large language models; database security; security analysis; machine learning; deep learning
제목
SQL Injection in LLM-Generated Queries: Systematic Analysis of Detection Gaps and Security Risks
저자
Kim, Eunyoung; Lee, Sangkyun
DOI
10.1109/ACCESS.2026.3654822
발행일
2026
유형
Article
저널명
IEEE Access
권
14
페이지
12797 ~ 12815