D2ANN-RL: Defense-in-Depth ANN-Reinforcement Learning Framework for LLM Chatbot Code Injection Mitigation

Authors

DOI:

https://doi.org/10.64539/sjcs.v2i2.2026.506

Keywords:

Large Language Models (LLMs), LLM-chatbots, Code injection mitigation, Artificial Neural Networks (ANN), Reinforcement Learning (RL), Adversarial Manipulation, Chatbots, AI Conversational Agents

Abstract

The growing cybersecurity vulnerabilities in artificial intelligence (AI) service models, particularly Large Language Models (LLMs), highlight code injection as a critical threat to chatbot reliability and safe deployment. On the account that LLMs process inputs as undifferentiated token sequences, they cannot reliably distinguish trusted system prompts from untrusted user inputs. This architectural limitation enables attackers to exploit direct and indirect prompt injection channels, resulting in insecure code generation, altered execution flows, and potential data exfiltration or remote code execution. In mission critical environments such as cloud platforms, IoT ecosystems, and defense systems, these risks escalate into unauthorized access and operational compromise. To address this challenge, the present study introduced a D2ANN-RL framework that integrates input/output sanitization, context isolation, sandboxing, and secure prompt engineering, supported by hybridization of Artificial Neural Network (ANN)–Reinforcement Learning (RL) detection model. The ANN component ensures robust feature extraction, while RL dynamically adapts defense strategies to evolving adversarial vectors. Computational evaluation demonstrates the framework’s effectiveness, achieving 96.95% detection accuracy, precision of 96.9%, recall of 97%, and F-Score of 96.95%. The Defense Performance Index (DPI) reached 84.9%, validating model resilience, scalability, and balanced classification integrity. These findings highlight the broader implications of deploying transparent, adaptive, and generalizable safeguards for LLM based chatbot systems, advancing secure AI integration and mitigating systemic vulnerabilities in mission critical operations.

References

[1] D. Myers, R. Mohawesh, V. I. Chellaboina, A. L. Sathvik, P. Venkatesh, Y.-H. Ho, and Y. Jararweh, “Foundation and large language models: fundamentals, challenges, opportunities, and social impacts,” Cluster Computing, vol. 27, no. 1, pp. 1–26, 2024. https://doi.org/10.1007/s10586-023-04203-7.

[2] U. O. Matthew, K. M. Bakare, G. N. Ebong, C. C. Ndukwu, and A. C. Nwanakwaugwu, “Generative artificial intelligence (AI) educational pedagogy development: Conversational AI with user-centric ChatGPT4,” Journal of Trends in Computer Science and Smart Technology, vol. 5, no. 4, pp. 401–418, 2023. https://doi.org/10.36548/jtcsst.2023.4.003.

[3] E. Coronado, “From Large Language Models to Agentic AI in Industry 5.0 and the Post-ChatGPT Era: A Socio-Technical Framework and Review on Human–Robot Collaboration,” Robotics, vol. 15, no. 3, p. 58, 2026. https://doi.org/10.3390/robotics15030058.

[4] U. O. Matthew, J. S. Kazaure, O. Amaonwu, U. A. Adamu, I. M. Hassan, A. A. Kazaure, and C. N. Ubochi, “Role of internet of health things (IoHTs) and innovative internet of 5G medical robotic things (IIo-5GMRTs) in COVID-19 global health risk management and logistics planning,” in Intelligent Data Analysis for COVID-19 Pandemic, pp. 27–53, Singapore: Springer Singapore, 2021. https://doi.org/10.1007/978-981-16-1574-0_2.

[5] P. Kumar, “Large language models (LLMs): survey, technical frameworks, and future challenges,” Artificial Intelligence Review, vol. 57, 2024. https://doi.org/10.1007/s10462-024-10888-y.

[6] A. Zafar, V. B. Parthasarathy, C. L. Van, S. Shahid, A. I. Khan, and A. Shahid, “Building trust in conversational AI: A review and solution architecture using large language models and knowledge graphs,” Big Data and Cognitive Computing, vol. 8, no. 6, p. 70, 2024. https://doi.org/10.3390/bdcc8060070.

[7] D. Kumar and S. Singh, “Advancements in transformer architectures for large language models: From BERT to GPT-3 and beyond,” International Research Journal of Modernization in Engineering Technology and Science, vol. 6, no. 5, pp. 1889–1895, 2024. https://www.doi.org/10.56726/IRJMETS55985.

[8] F. Oscar et al., “Mitigating DoS/DDoS Cybersecurity False Data Injection on E-Healthcare Cloud Data Warehouse System,” in Smart Technologies for Sustainable Development Goals, pp. 363–389, CRC Press, 2021. http://doi.org/10.1201/9781003630685-19.

[9] E. E. Akpan et al., “Distributed Cybersecurity Preemptiveness on Industrial IoT Network Infrastructures,” in Blockchain Detection of Cybersecurity Attacks and Risk Management, pp. 87–116, IGI Global Scientific Publishing, 2026. https://doi.org/10.4018/979-8-3373-1717-5.ch004.

[10] L. Beurer-Kellner, M. Fischer, and M. Vechev, “Prompting is programming: A query language for large language models,” Proceedings of the ACM on Programming Languages, vol. 7, pp. 1946–1969, 2023. https://doi.org/10.1145/3591300.

[11] S. Gulyamov, S. Gulyamov, A. Rodionov, R. Khursanov, K. Mekhmonov, D. Babaev, and A. Rakhimjonov, “Prompt Injection Attacks in Large Language Models and AI Agent Systems: A Comprehensive Review of Vulnerabilities, Attack Vectors, and Defense Mechanisms,” Information, vol. 17, no. 1, p. 54, 2026. https://doi.org/10.3390/info17010054.

[12] A. Ali and M. C. Ghanem, “Beyond detection: large language models and next-generation cybersecurity,” SHIFRA, pp. 81–97, 2025. https://doi.org/10.70470/SHIFRA/2025/005.

[13] T. Geng, Z. Xu, Y. Qu, and W. E. Wong, “Prompt injection attacks on large language models: A survey of attack methods, root causes, and defense strategies,” Computers, Materials, & Continua, vol. 87, no. 1, 2026. https://doi.org/10.32604/cmc.2025.074081.

[14] R. Mundlamuri, G. R. Gunnam, N. K. Mysari, and J. Pujuri, “The Evolution of AI: From Classical Machine Learning to Modern Large Language Models,” IEEE Access, vol. 13, pp. 178302-178341, 2025. https://doi.org/10.1109/ACCESS.2025.3621344.

[15] L. Marconi, L. Longo, and F. Cabitza, “Assessing Interaction Quality in Human–AI Dialogue: An Integrative Review and Multi-Layer Framework for Conversational Agents,” Machine Learning and Knowledge Extraction, vol. 8, no. 2, p. 28, 2026. https://doi.org/10.3390/make8020028.

[16] U. O. Matthew, D. O. Oyekunle, E. E. Akpan, M. A. Oladipupo, E. S. Chukwuebuka, T. S. Adekunle, and V. C. Onumaku, “Generative artificial intelligence (AI) on sustainable development goal 4 for tertiary education: conversational AI with user-centric ChatGPT-4,” in Impacts of Generative AI on Creativity in Higher Education, IGI Global Scientific Publishing, pp. 263–292, 2024. https://doi.org/10.4018/979-8-3693-2418-9.ch010.

[17] D. Emakporuena, V. O. Oluwasegun, O. M. Esegbona-Isikeh, W. O. Ugbomeh, M. Nwaiku, E. E. Bunmi, and U. O. Matthew, “Harnessing Higher Generative Artificial Intelligence for Educational Pedagogy: Human-AI Collaboration in ChatGPT Experiences,” in Integrating ChatGPT Into System Applications and Services, IGI Global Scientific Publishing, pp. 23–58, 2026. https://doi.org/10.4018/979-8-3693-9841-8.ch002.

[18] V. Alto, Building LLM Powered Applications: Create Intelligent Apps and Agents with Large Language Models, Packt Publishing Ltd., 2024. https://books.google.co.id/books?id=P1oIEQAAQBAJ.

[19] A. Livieratos et al., “MetaMind: A multi-agent transformer-driven framework for automated network meta-analyses,” PLOS ONE, vol. 21, no. 2, e0342895, 2026. https://doi.org/10.1371/journal.pone.0342895.

[20] M. A. K. Raiaan, M. S. H. Mukta, K. Fatema, N. M. Fahad, S. Sakib, and M. M. J. Mim, “A review on large language models: Architectures, applications, taxonomies, open issues and challenges,” IEEE Access, vol. 12, pp. 26839–26874, 2024. https://doi.org/10.1109/ACCESS.2024.3365742.

[21] L. Lin and Y. Liu, Multimodal Large Models: A New Paradigm of Artificial Intelligence. Cham: Springer, 2026. https://doi.org/10.1007/978-981-95-4929-0.

[22] N. Esmi, M. Nezhad-Moghaddam, F. Borhani, A. Shahbahrami, A. Daemdoost, G. Gaydadjiev, “GPT-5 vs Other LLMs in Long Short-Context Performance,” in 2025 3rd International Conference on Foundation and Large Language Models (FLLM), pp. 129-133, 2025. https://doi.org/10.1109/FLLM67465.2025.11391194.

[23] A. Briouya, H. Briouya, A. Choukri, “Overview of the progression of state-of-the-art language models,”. TELKOMNIKA (Telecommunication, Computing, Electronics, and Control), vol. 22, no. 4, pp. 897-909, 2024. http://doi.org/10.12928/telkomnika.v22i4.25936.

[24] L. H. Yau, E. T. Y. Xian, Y. P. Yu, and T. M. Lim, “Retrieval Augmented Generation-based Large Language Model Chatbot,” in Proc. 2025 IEEE Int. Conf. on Computation, Big-Data and Engineering (ICCBE), pp. 856–861, Jun. 2025. https://doi.org/10.1109/ICCBE65177.2025.11255894.

[25] A. A. Gumel, A. B. Abdullahi, and U. M. O, “The Need for a Multimodal Means of Effective Digital Learning through Data Mining and Institutional Knowledge Repository: A Proposed System for Polytechnics in Northern Nigeria,” In Proceedings of the 2019 5th International Conference on Computer and Technology Applications, pp. 81–85, April 2019. https://doi.org/10.1145/3323933.3324068.

[26] B. Min, H. Ross, E. Sulem, A. P. B. Veyseh, T. H. Nguyen, O. Sainz, and D. Roth, “Recent advances in natural language processing via large pre-trained language models: A survey,” ACM Computing Surveys, vol. 56, no. 2, pp. 1–40, 2023. https://doi.org/10.1145/3605943.

[27] M. S. G. Sourav, A. Javaid, and L. Cheng, “A review of AI in human-machine cooperation: Machine perspective,” ACM Transactions on Autonomous and Adaptive Systems, vol. 21, no. 2, Art. No. 19, pp. 1–43, 2025. https://doi.org/10.1145/3774318.

[28] V. N. Oriakhi, O. M. Esegbona-Isikeh, B. Esseme, A. Claude, D. Emakporuena, A. C. Nwanakwaugwu, and U. O. Matthew, “Generative artificial intelligence in education: ChatGPT-4 experiences to anticipated ChatGPT-5,” HAFED POLY Journal of Science, Management and Technology, vol. 6, no. 1, pp. 149–169, 2024. https://doi.org/10.4314/hpjsmt.v6i1.1.

[29] L. Wang, W. Xu, Y. Lan, Z. Hu, Y. Lan, R. K. W. Lee, and E. P. Lim, “Plan-and-solve prompting: Improving zero-shot chain-of-thought reasoning by large language models,” in Proc. 61st Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), pp. 2609–2634, Jul. 2023. https://doi.org/10.18653/v1/2023.acl-long.147.

[30] J. Zheng et al., “Lifelong learning of large language model based agents: A roadmap,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 48, no. 5, pp. 5552 –5571, 2026. https://doi.org/10.1109/TPAMI.2025.3650546.

[31] Y. Qian, “Prompt engineering in education: A systematic review of approaches and educational applications,” Journal of Educational Computing Research, vol. 63, no. 7–8, pp. 1782–1818, 2025. https://doi.org/10.1177/07356331251365189.

[32] A. Mussa, Z. Tuimebayev, and M. Mansurova, “Make Large Language Models Efficient: A Review,” IEEE Access, vol. 13, pp. 154466–154490, 2025. https://doi.org/10.1109/ACCESS.2025.3605110.

[33] M. Chen, Z. Liu, C. Chen, J. Wang, Y. Xue, B. Wu, and Q. Wang, “Beyond Static GUI Agent: Evolving LLM-based GUI Testing via Dynamic Memory,” in Proc. 2025 40th IEEE/ACM Int. Conf. on Automated Software Engineering (ASE), pp. 1603–1615, Nov. 2025. https://doi.org/10.1109/ASE63991.2025.00135.

[34] J. Zhang et al., “When LLMs meet cybersecurity: A systematic literature review,” Cybersecurity, vol. 8, art. No. 55, 2025. https://doi.org/10.1186/s42400-025-00361-w.

[35] J. Malik, R. Muthalagu, and P. M. Pawar, “A systematic review of adversarial machine learning attacks, defensive controls, and technologies,” IEEE Access, vol. 12, pp. 99382–99421, 2024. https://doi.org/10.1109/ACCESS.2024.3423323.

[36] M. F. Kharma, S. Choi, M. Alkhanafseh, and D. Mohaisen, “Security and quality in LLM-generated code: A multi-language, multi-model analysis,” IEEE Transactions on Dependable and Secure Computing, vol. 23, no. 3, 2026. https://doi.org/10.1109/TDSC.2026.3672745.

[37] L. Wang, C. Chen, J. Zhu, R. Zhan, and W. Han, “CQLLM: A Framework for Generating CodeQL Security Vulnerability Detection Code Based on Large Language Model,” Applied Sciences, vol. 16, no. 1, p. 517, 2026. https://doi.org/10.3390/app16010517.

[38] H. Su, J. Luo, C. Liu, X. Yang, Y. Zhang, Y. Dong, and J. Zhu, “A survey on autonomy-induced security risks in large model-based agents,” arXiv preprint arXiv:2506.23844, 2026. https://doi.org/10.48550/arXiv.2506.23844.

[39] M. N. Musa and M. E. Irhebhude, “An Empirical Analysis of Injection Attack Vectors and Mitigation Strategies in Redis NoSQL Database,” Journal of Computing Theories and Applications, vol. 2, no. 4, pp. 553–571, 2025. https://doi.org/10.62411/jcta.12640.

[40] I. Hasanov, S. Virtanen, A. Hakkala, and J. Isoaho, “Application of large language models in cybersecurity: A systematic literature review,” IEEE Access, vol. 12, pp. 176751–176778, 2024. https://doi.org/10.1109/ACCESS.2024.3505983.

[41] Y. Wang et al., “Large model-based agents: State-of-the-art, cooperation paradigms, security and privacy, and future trends,” IEEE Communications Surveys & Tutorials, vol. 28, pp. 1906–1949, 2025. https://doi.org/10.1109/COMST.2025.3576176.

[42] S. Izadi and M. Forouzanfar, “Error correction and adaptation in conversational AI: a review of techniques and applications in chatbots,” AI, vol. 5, no. 2, pp. 803–841, 2024. https://doi.org/10.3390/ai5020041.

[43] B. Peng, K. Chen, M. Li, P. Feng, Z. Bi, J. Liu, and Q. Niu, “Securing large language models: Addressing bias, misinformation, and prompt attacks,” arXiv preprint arXiv:2409.08087, 2024. https://doi.org/10.48550/arXiv.2409.08087.

[44] C.-H. H. Yang, A. Stolcke, and L. P. Heck, “Spoken Conversational Agents with Large Language Models,” arXiv preprint arXiv:2512.02593, 2025. https://doi.org/10.48550/arXiv.2512.02593.

[45] G. P. Oise, B. S. Olanrewaju, O. A. Orukpe, K. C. Pius, and A. O. Airhiavbere, “A Convolutional Neural Network Framework for Intelligent Intrusion Detection,” Scientific Journal of Computer Science, vol. 2, no. 1, pp. 50–59, 2026. https://doi.org/10.64539/sjcs.v2i1.2026.404.

[46] A. Banerjee and D. Banik, “A Comprehensive Survey on Transformer-Based Machine Translation: Identifying Research Gaps and Solutions for Large Language Models,” ACM Computing Surveys, vol. 58, no. 5, pp. 1–33, 2025. https://doi.org/10.1145/3773076.

[47] T. Zhang, L. Patterson, B. Webb, Z. Jin, and M. Beiting-Parrish, “Evaluating generative AI chatbots for large-scale assessment data: comparing LLM-as-a-judge and human ratings,” Large-scale Assessments in Education, vol. 14, 2026. https://doi.org/10.1186/s40536-026-00287-w.

[48] R. Shadiev, A. Kaliyeva, A. Kairatova, Z. Yerbulatova, A. Ryskulbek, and Z. Beisembayeva, “Exploring the Role of Conversational AI in Developing Communicative Skills: A Systematic Review,” Digital Applied Linguistics, vol. 4, p. 103058, 2025. https://doi.org/10.29140/dal.v4.103058.

[49] H. Mirshekali, M. R. Shadi, F. G. Ladani, and H. R. Shaker, “A Review of Large Language Models for Energy Systems: Applications, Challenges, and Future Prospects,” IEEE Access, vol. 13, pp. 163162 – 163188, 2025. https://doi.org/10.1109/ACCESS.2025.3610994.

[50] L. Aldhafeeri, F. Aljumah, F. Thabyan, M. Alabbad, S. AlShahrani, F. Alanazi, and A. Al-Nafjan, “Generative AI Chatbots Across Domains: A Systematic Review,” Applied Sciences, vol. 15, no. 20, p. 11220, 2025. https://doi.org/10.3390/app152011220.

[51] M. Al-olaqi, A. Al-gailani, and M. H. Rahman, “Comprehensive study of SQL injection attacks mitigation methods and future directions,” Journal of Cyber Security and Risk Auditing, vol. 2025, no. 4, pp. 347–365, 2025. https://doi.org/10.63180/jcsra.thestap.2025.4.11.

[52] O. O. Abayomi, A. E. Kayode, O. Oluwasanya, A. E. Mesioye, “Comparative Analysis of Machine Learning Algorithms for Predictive Maintenance,” Methods in Science and Technology Studies, vol. 2, no. 2, pp. 131-144, 2026. https://doi.org/10.64539/msts.v2i2.2026.505.

[53] G. Saleem, N. Ahmed, M. I. Zaman, and A. Hassan, “A Layered Security Framework Against Prompt Injection in RAG-Based Chatbots,” arXiv preprint arXiv:2606.19660, 2026. https://doi.org/10.48550/arXiv.2606.19660.

[54] W. Xing, Z. Qi, Y. Qin, Y. Li, C. Chang, J. Yu, and M. Han, “Mcp-Guard: A Multi-Stage Defense-in-Depth Framework for Securing Model Context Protocol in Agentic AI,” Findings of the Association for Computational Linguistics: ACL 2026, pp. 4877–4889, July 2026. https://doi.org/10.18653/v1/2026.findings-acl.240.

[55] B. Ramakrishnan and A. Balaji, “Securing AI Agents Against Prompt Injection Attacks,” arXiv preprint arXiv:2511.15759, 2025. https://doi.org/10.48550/arXiv.2511.15759.

[56] H. Li, X. Liu, C. H. I. U. Chun, D. Li, N. Zhang, and C. Xiao, “Drift: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agents,” arXiv preprint arXiv:2506.12104, vol. 38, pp. 83262–83290, 2026. https://doi.org/10.48550/arXiv.2506.12104.

Downloads

Published

2026-08-02

How to Cite

Oluwasegun, V. O., Falebita, O. S., Adebola, N. T., Adekunle, V. A., Uzodinma, D. C., Lanre, T. M., … Matthew, U. O. (2026). D2ANN-RL: Defense-in-Depth ANN-Reinforcement Learning Framework for LLM Chatbot Code Injection Mitigation. Scientific Journal of Computer Science, 2(2), 312–329. https://doi.org/10.64539/sjcs.v2i2.2026.506

Similar Articles

<< < 1 2 3 4 > >> 

You may also start an advanced similarity search for this article.