Skip to content

AI Approaches for Industrial Control System Cybersecurity: A Comprehensive Review of Methodological Contexts

Sep 2026 · Journal of Information and Communications Technology Algorithms Systems and Applications · 0 citations · 23 references
Smart Grid Security and Resilience

TL;DR

A re-view is systematic, analyzing the use of artificial intelligence (AI) methodologies in ICS cybersecurity from the year 2018 to 2024, suggesting that graph-based and hybrid methods yield the best detection accuracy, whereas classical methods still seem to be the most suitable for resource-constrained applications.

Abstract

The cyber infrastructure of Industrial Control Systems (ICSs) that monitor power grids, water treatment facilities, pipelines, and manufacturing lines has become a very com-plex cyber-physical systems, which now face a growing range of cyber threats, such as Stuxnet, Industroyer, TRITON, and Colonial Pipeline incident. In the era of new and sophisticated attacks, such as zero-day exploits, multi-stage intrusions and adversaries taking advantage of the unique ‘availability first' constraints of operational technology (OT), traditional signatures and rule-based defenses are proving less effective. This re-view is systematic, analyzing the use of artificial intelligence (AI) methodologies in ICS cybersecurity from the year 2018 to 2024. According to the guidelines of the PRISMA 2020, from the five scholarly databases, 1578 records were retrieved and 147 studies were included in the qualitative synthesis, and 102 studies were included in the quantitative comparison. The provided literature is categorized in a methodological taxonomy from classical machine learning to deep learning; from graph neural networks (GNNs) to reinforcement learning (RL); from autonomous response to intrusion detection, at-tack-graph analysis, malware analysis and vulnerability prioritization. Overall, the synthesis suggests that graph-based and hybrid methods yield the best detection accuracy (reported from 92% to 99.5% with less than 3% false-positive rates), whereas classical methods still seem to be the most suitable for resource-constrained applications. There are ongoing deficiencies in standardized benchmarking, adversarial robustness, safety–security co-engineering, and real-world validation. A research roadmap is advocated for guiding future research, which focuses on safe RL, federated learning, explainable GNNs, and digital-twin-based security assessment.

Read PDF

Similar papers

#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54
#machine learning Review Open access Jun 2014

Why Early-Stage Software Startups Fail: A Behavioral Framework

This state-of-practice investigation was performed using a literature review followed by a multiple-case study approach and presents how inconsistency between managerial strategies and execution can lead to failure by means of a behavioral framework.

Carmine Giardino, Xiaofeng Wang, P. Abrahamsson · 175 citations · ⚡19
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#machine learning Review Open access May 2016

Key Challenges in Software Startups Across Life Cycle Stages

It is found that what perceived as biggest challenges by software startups do vary across different life cycle stages, even though its significance decreases when the learning focuses of the startups move from problem to solution and their products mature.

Xiaofeng Wang, Henry Edison, Sohaib Shahid Bajwa et al. · 62 citations · ⚡6
#computer vision Conference Aug 2008

Scrum in a Multiproject Environment: An Ethnographically-Inspired Case Study on the Adoption Challenges

Agile methods continue to gain popularity. In particular, the Scrum method appears to be on the verge of becoming a de-facto standard in the industry, leading the so called Agile movement. While there are success stories and recommendations, there is little scientifically valid evidence of the challenges in the adoptio...

A. Marchenko, P. Abrahamsson · 59 citations · ⚡11

Related blog posts

Microsoft Research Blog Jul 13, 2026

Verifying Rust cryptography in SymCrypt, from standards to code

Cryptographic code supports vital protections in modern computing systems. Learn how a new method helps verify code as developers write it while preserving speed and adaptability as it gets implemented and evolves. The post Verifying Rust cryptography in SymCrypt, from standards to code appeared first on Microsoft Research.

MIT News · Artificial Intelligence Oct 7, 2026

Discovering the value of humanistic inquiry

Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.