Skip to content
Review Open access

AI-DRIVEN THREAT DETECTION AND AUTOMATED RESPONSE IN MODERN CYBERSECURITY SYSTEMS: A SYSTEMATIC REVIEW AND FRAMEWORK

Aug 2026 · Journal of Digital Security and Forensics · Vol 3, pp. 31-37 · 0 citations · 6 references

TL;DR

A conceptual framework is proposed that combines detection, explanation, and orchestrated response in a continuous feedback loop that is suitable for zero trust and IoT-enabled critical-infrastructure environments that will allow for continuous retraining of the model.

Abstract

As the number and sophistication of cyberattacks increase, including those like ransomware, advanced persistent threats (APTs), and zero-day exploits, the structural weaknesses of signature-based and static intrusion detection systems (IDS) become evident as they fail to generalize to novel or adversarially crafted attack patterns Agbroko (2024), Hakke et al. (2025). The paper provides a systematic review of the application of modern security operations in threat detection and automated incident response using classical machine learning (ML), deep learning (DL), reinforcement learning (RL), and metaheuristic optimization. A review of some of the benchmark sets shows that the ensemble and hybrid AI models consistently yield detection accuracy rates of 97–99% on curated datasets like NSL-KDD, CICIDS2017, and UNSW-NB15, which is significantly higher than the detection accuracy rates of legacy rule-based tools Waghmode and Kanumuri (2025), Sah et al. (2023), Jairu (2021). The paper also reviews Security Orchestration, Automation and Response (SOAR) integration, reinforcement-learning-driven adaptive defense policies, and threat-intelligence feedback loops that will allow for continuous retraining of the model. Some persistent challenges include adversarial evasion and data-poisoning attacks, false positives causing alert fatigue, interpretability problems in deep models, and autopilot restrictions on autonomous response actions Jha (2025), Dong et al. (2018). The most significant frontiers for making this leap from high laboratory accuracy to robust, audit- and legally sound operational deployments are explainable AI (XAI), federated and privacy-preserving learning, and standardized benchmarking Hermosilla et al. (2025), Bi et al. (2024). A conceptual framework is proposed that combines detection, explanation, and orchestrated response in a continuous feedback loop that is suitable for zero trust and IoT-enabled critical-infrastructure environments Silva (2026).

Read PDF

Similar papers

Aug 2026

AI-Based Cybersecurity Threat Detection Using Machine Learning

A multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time is introduced.

Ameen Pasha.A · 0 citations
Open access 2026

AI-DRIVEN THREAT DETECTION USING DATA SCIENCE: A COMPARATIVE STUDY OF MACHINE LEARNING MODELS ON CYBERSECURITY DATASETS

They originate from the rapid rise of cyber threats such as malware, phishing, ransomware, denial of service, and unauthorised network intrusion, which have proven to be so difficult to tackle that traditional security measures can hardly deal with the issue. Signature-based intrusion detection system techniques in particular, which are commonly adopted by traditional methods, usually lack the ability to detect novel and evolving attack vectors in addition to high false positive rate and response time. In this regard, this paper proposes an AI threat detection framework, employing data science methods to boost cybersecurity performances. The researchers of this paper have tested the effectiveness of several models using a benchmark dataset for cyber security, including CICIDS2017 or NSL-KDD and machine learning techniques such as Random Forest, Support Vector Machine, Logistic Regression and XGBoost for evaluating performance. Using measures of accuracy, precision, recall and F1- score, the experiments show that the performance of ensemble learning models is higher than shallow learning models in this research; XGBoost and Random Forest.

Praveen Kumar Reddy Gouni · 0 citations
Open access Aug 2026

Towards a comprehensive landscape of AI and generative AI in cybersecurity

An in-depth comprehensive Systematic Mapping Study (SMS) of 110 relevant articles published between 2015 and 2025 related to AI/GenAI-based IDS, offering a novel and integrated, comprehensive mapping of both defensive and offensive dimensions of AI/GenAI-enabled cybersecurity.

Abdelilah Hssaini, Imane Chlioui, Maryam Radgui · 0 citations
Open access Jul 2026

Explainable AI for Intrusion Detection Systems: Enhancing Trust in Automated Cyber Defense

The results showed that embedding explainability in an IDS enhances the human-AI partnership, allowing security analysts to confirm the results of their IDS, mitigate false-positive ambiguity, optimize incident response, and meet regulatory and ethical obligations.

Christian Manna Guimma · 0 citations
Open access 2026

Autonomous Cyber Defense Learning Using Reinforcement and Threat Intelligence

The increasing sophistication, frequency, and scale of cyberattacks have created significant challenges for conventional cybersecurity systems. Traditional security solutions such as firewalls, signature-based intrusion detection systems, and antivirus software are largely reactive and depend on predefined rules and known attack patterns. Consequently, these systems often struggle to detect and respond effectively to emerging threats such as Advanced Persistent Threats (APTs), zero-day attacks, ransomware, botnets, and insider attacks. Recent advancements in Artificial Intelligence (AI), particularly Reinforcement Learning (RL), have demonstrated the potential to create autonomous systems capable of learning and adapting to dynamic environments. Simultaneously, Cyber Threat Intelligence (CTI) provides valuable contextual information regarding threat actors, attack techniques, vulnerabilities, and indicators of compromise. This study proposes an Autonomous Cyber Defense Framework that integrates Reinforcement Learning and Threat Intelligence to enhance threat detection, decision-making, and automated response capabilities. The framework employs a Deep Q-Network (DQN) agent that continuously learns optimal defense actions through interaction with network environments while utilizing threat intelligence feeds to improve situational awareness. Experimental evaluation was conducted using benchmark cybersecurity datasets, including CICIDS2017 for Intrusion Detection, UNSW-NB15 for attack classification, CTU-13 for botnet detection and Custom Threat Feeds for threat intelligence. The results indicate that the proposed framework achieved a precision rate of 98.4%, a recall rate of 98.2%, an F1-score of 98.3%, and a threat mitigation rate of 96.8%. False positive rate of 1.9, False negative rate of 1.5 and Response rate of 41%, significantly outperforming traditional machine learning and signature-based security approaches. The findings demonstrate that integrating reinforcement learning with threat intelligence can provide a highly adaptive and proactive cyber defense mechanism suitable for modern network environments.

Abimbola B. Owolabi, F. Osang · 0 citations
Conference Aug 2026

Improving Cybersecurity with Artificial Intelligence: Identification, Examination, and Mitigation of Cyber Threats

Cyberattacks are becoming more frequent and sophisticated in today’s digital world, rendering conventional security measures inadequate. In order to increase the accuracy of cyber threat detection, this study investigates the application of deeplearning methods to increase the accuracy of cyber threat detection. A cybersecurity dataset was used to test four classification models: Artificial Neural Networks (ANN), Random Forest, XGBoost, and Logistic Regression. The models were evaluated using the key 95.32. The performance of Artificial Neural Networks, Random Forest, XGBoost, and Logistic Regression was examined. These findings imply that learning-based and ensemble models are better at spotting intricate and changing attack patterns. In general, the study highlights the significance of clever, data-driven methods for creating cybersecurity defence systems that are quicker, more dependable, and more resilient.

D. Sharma, Inderdeep Kaur, Krishika Gupta et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.