Skip to content

AI-Based Cybersecurity Threat Detection Using Machine Learning

Aug 2026 · International Scientific Journal of Engineering and Management · 0 citations

TL;DR

A multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time is introduced.

Abstract

Abstract - Rising volumes of sophisticated cyber attacks have rendered conventional signature-driven security tools insufficient for protecting modern digital assets. This study introduces a multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time. The pipeline begins with rigorous data cleansing and feature refinement that combines mutual-information ranking with principal-component analysis. Classification is performed by a soft-voting ensemble of Random Forest, gradient-boosted trees (XGBoost), and a compact deep neural network. Parallel anomaly scoring is obtained from Isolation Forest and a reconstruction-error autoencoder trained solely on benign flows. Evaluation on the NSL-KDD, CIC-IDS2017 and UNSW-NB15 collections yields detection accuracy reaching 98.7 %, precision of 97.9 %, recall of 98.4 % and an F1-score of 98.1 %, accompanied by a low rate of false alarms. SHAP-based explanations are attached to every prediction, giving security analysts transparent insight into model behaviour. Comparative benchmarks against recent published methods confirm that the proposed architecture delivers both higher accuracy and practical deployability inside enterprise security operations centres. Key Words: network intrusion detection, ensemble machine learning, anomaly scoring, deep autoencoder, explainable artificial intelligence, cyber-attack classification, security operations.

View source

Similar papers

Review Open access Aug 2026

AI-DRIVEN THREAT DETECTION AND AUTOMATED RESPONSE IN MODERN CYBERSECURITY SYSTEMS: A SYSTEMATIC REVIEW AND FRAMEWORK

A conceptual framework is proposed that combines detection, explanation, and orchestrated response in a continuous feedback loop that is suitable for zero trust and IoT-enabled critical-infrastructure environments that will allow for continuous retraining of the model.

Jayesh Dalmet · 0 citations
Open access 2026

AI-DRIVEN THREAT DETECTION USING DATA SCIENCE: A COMPARATIVE STUDY OF MACHINE LEARNING MODELS ON CYBERSECURITY DATASETS

They originate from the rapid rise of cyber threats such as malware, phishing, ransomware, denial of service, and unauthorised network intrusion, which have proven to be so difficult to tackle that traditional security measures can hardly deal with the issue. Signature-based intrusion detection system techniques in particular, which are commonly adopted by traditional methods, usually lack the ability to detect novel and evolving attack vectors in addition to high false positive rate and response time. In this regard, this paper proposes an AI threat detection framework, employing data science methods to boost cybersecurity performances. The researchers of this paper have tested the effectiveness of several models using a benchmark dataset for cyber security, including CICIDS2017 or NSL-KDD and machine learning techniques such as Random Forest, Support Vector Machine, Logistic Regression and XGBoost for evaluating performance. Using measures of accuracy, precision, recall and F1- score, the experiments show that the performance of ensemble learning models is higher than shallow learning models in this research; XGBoost and Random Forest.

Praveen Kumar Reddy Gouni · 0 citations
Open access Jul 2026

Beyond the Signature: Machine Learning for Adaptive Cyber Threat Intelligence

Modern cyberattacks are increasingly dynamic, multi-stage, and difficult to recognize with static signatures alone. Machine learning (ML) provides a complementary approach by learning patterns from large volumes of security telemetry and identifying behavior that may indicate compromise. This paper presents an integrated framework for applying ML across the cyber threat intelligence lifecycle, from data ingestion and preprocessing to model training, deployment, continuous monitoring, and response. It discusses supervised classification and anomaly detection, together with specialized security functions such as web filtering, dynamic sandboxing, behavioral analysis, deceptive-domain detection, and email protection. The paper also emphasizes a human-in-the-loop model in which automated systems prioritize evidence while analysts validate important decisions. Finally, it considers data drift, concept drift, adversarial manipulation, privacy, and retraining. The proposed approach treats ML as one layer of a broader defense system, combining automated pattern recognition with threat context and human expertise to improve detection speed, reduce alert fatigue, and support adaptive cyber defense.

Mitra Bhargeshbhai Patel, Bindi Bhatt, Dharvi Soni et al. · 0 citations
Open access Jul 2026

Artificial Intelligence-Driven Cybersecurity Framework for Enterprise Threat Detection: A Machine Learning Approach

The increasing complexity of cyber threats has exposed the limitations of traditional signature-based intrusion detection systems, creating a need for intelligent and adaptive cybersecurity solutions. This study proposes an artificial intelligence-driven cybersecurity framework for enterprise threat detection using the CICIDS2017 benchmark dataset. The framework incorporates data preprocessing, feature engineering, and supervised machine learning to classify network traffic as benign or malicious. Seven machine learning algorithms, including Logistic Regression, Decision Tree, Support Vector Machine, Random Forest, Extra Trees, LightGBM, and XGBoost, were evaluated using accuracy, precision, recall, F1-score, and AUC-ROC. The results indicate that ensemble learning models outperform conventional classifiers, with XGBoost achieving the highest performance, recording 99.42% accuracy, 99.39% precision, 99.31% recall, 99.35% F1-score, and an AUC-ROC of 0.999. LightGBM also demonstrated excellent performance with lower computational time. The findings suggest that the proposed XGBoost-based framework provides an accurate, scalable, and efficient solution for real-time enterprise threat detection and can be effectivel

Sanjida Akter Tisha · 0 citations
Open access Aug 2026

Cybersecurity Threat Intelligence Using Machine Learning Classification Techniques

New attacks are getting smarter and more sophisticated, so the old signature-based intrusion detection and prevention systems can't find them. This work proposes a machine learning approach to build a cybersecurity threat intelligence framework for effective multiclass intrusion detection, in which the Decision Tree classifier is used. The CICIDS2017 benchmark dataset, which contains both benign network traffic and several types of cyberattacks, is used to build and test the suggested model. The goal of the preparation process is to enhance classification performance by cleaning and separating data, utilizing Standard Scaler to scale features, and SMOTE to balance classes. Metrics like as recall, accuracy, precision, F1-score, confusion matrix, and ROC curve are used to test the Decision Tree model. An impressive 99.91% accuracy (ACC) rate, 97.79% precision (PRE), 97.08% recall (REC), 97.41% F1-score (F1), and 0.99 AUC were revealed by the experiment's outcomes. The suggested method beats state-of-the-art deep learning and ML approaches in terms of performance, execution time, and computational complexity. The results show that the suggested design is a reliable, efficient, and lightweight way to find cyber security threats and IDR apps with intelligence.

Madhav Sharma · 0 citations
Review Open access Jul 2026

A Review on Supervised Machine Learning Techniques for Enhancing Cyber Threat Prediction Accuracy

Experimental results demonstrate that an ensemble-optimized model achieves improved predictive accuracy, reduced false positives, and enhanced generalization to unseen attack patterns, providing a scalable and adaptive defense against evolving cyber threats in online banking.

Bandana Gupta, C. S. Gautam · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.