AI-Assisted Security Testing of REST APIs: A Conceptual Framework for Vulnerability Detection and Validation

REST APIs are widely used in modern web and mobile applications, making their security an important concern. Traditional API security testing often depends on predefined test cases and vulnerability patterns, which may not adequately adapt to different API structures and contexts. Recent advances in artificial intelligence, particularly large language models, provide opportunities to support automated security test generation. However, AI-based approaches require reliable API information, contextual understanding, controlled test execution, and evidence-based vulnerability validation. This paper proposes a conceptual framework for AI-assisted security testing of REST APIs. The framework integrates an API Information Collector, API Context Analyzer, AI Security Test Generator, Dynamic Test Executor, and Vulnerability Validator. The proposed approach uses API specifications, endpoint information, parameters, authentication requirements, and response behavior to generate context-aware security tests. The framework focuses on common REST API security problems, including broken object-level authorization, broken authentication, excessive data exposure, injection, and security misconfiguration. A validation stage is included to distinguish potential vulnerabilities from false positives using observable security evidence. The framework is conceptual and has not been experimentally evaluated in this study. Therefore, no performance or accuracy claims are made. The paper provides a structured foundation for future implementation and empirical evaluation of AI-assisted REST API security testing.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-18
DOI
https://doi.org/10.5281/zenodo.22834978
Primary Topic
Web Application Security Vulnerabilities
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

AI-Assisted Security Testing of REST APIs: A Conceptual Framework for Vulnerability Detection and Validation

Muhammad Afaq
Zenodo (CERN European Organization for Nuclear Research)
Web Application Security Vulnerabilities
preprint

AI-Assisted Security Testing of REST APIs: A Conceptual Framework for Vulnerability Detection and Validation

Muhammad Afaq
preprint en

Abstract

REST APIs are widely used in modern web and mobile applications, making their security an important concern. Traditional API security testing often depends on predefined test cases and vulnerability patterns, which may not adequately adapt to different API structures and contexts. Recent advances in artificial intelligence, particularly large language models, provide opportunities to support automated security test generation. However, AI-based approaches require reliable API information, contextual understanding, controlled test execution, and evidence-based vulnerability validation. This paper proposes a conceptual framework for AI-assisted security testing of REST APIs. The framework integrates an API Information Collector, API Context Analyzer, AI Security Test Generator, Dynamic Test Executor, and Vulnerability Validator. The proposed approach uses API specifications, endpoint information, parameters, authentication requirements, and response behavior to generate context-aware security tests. The framework focuses on common REST API security problems, including broken object-level authorization, broken authentication, excessive data exposure, injection, and security misconfiguration. A validation stage is included to distinguish potential vulnerabilities from false positives using observable security evidence. The framework is conceptual and has not been experimentally evaluated in this study. Therefore, no performance or accuracy claims are made. The paper provides a structured foundation for future implementation and empirical evaluation of AI-assisted REST API security testing.

Zenodo (CERN European Organization for Nuclear Research)
University of the Punjab (PK)
Peace, Justice and strong institutions
Web Application Security Vulnerabilities
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

AI-Assisted Security Testing of REST APIs: A Conceptual Framework for Vulnerability Detection and Validation — Muhammad Afaq · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS