AI Approaches for Industrial Control System Cybersecurity: A Comprehensive Review of Methodological Contexts
TL;DR
A re-view is systematic, analyzing the use of artificial intelligence (AI) methodologies in ICS cybersecurity from the year 2018 to 2024, suggesting that graph-based and hybrid methods yield the best detection accuracy, whereas classical methods still seem to be the most suitable for resource-constrained applications.
Abstract
The cyber infrastructure of Industrial Control Systems (ICSs) that monitor power grids, water treatment facilities, pipelines, and manufacturing lines has become a very com-plex cyber-physical systems, which now face a growing range of cyber threats, such as Stuxnet, Industroyer, TRITON, and Colonial Pipeline incident. In the era of new and sophisticated attacks, such as zero-day exploits, multi-stage intrusions and adversaries taking advantage of the unique ‘availability first' constraints of operational technology (OT), traditional signatures and rule-based defenses are proving less effective. This re-view is systematic, analyzing the use of artificial intelligence (AI) methodologies in ICS cybersecurity from the year 2018 to 2024. According to the guidelines of the PRISMA 2020, from the five scholarly databases, 1578 records were retrieved and 147 studies were included in the qualitative synthesis, and 102 studies were included in the quantitative comparison. The provided literature is categorized in a methodological taxonomy from classical machine learning to deep learning; from graph neural networks (GNNs) to reinforcement learning (RL); from autonomous response to intrusion detection, at-tack-graph analysis, malware analysis and vulnerability prioritization. Overall, the synthesis suggests that graph-based and hybrid methods yield the best detection accuracy (reported from 92% to 99.5% with less than 3% false-positive rates), whereas classical methods still seem to be the most suitable for resource-constrained applications. There are ongoing deficiencies in standardized benchmarking, adversarial robustness, safety–security co-engineering, and real-world validation. A research roadmap is advocated for guiding future research, which focuses on safe RL, federated learning, explainable GNNs, and digital-twin-based security assessment.