The increasing complexity and scale of cyber threats demand intelligent and adaptive defense mechanisms that extend beyond traditional approaches. Artificial Intelligence (AI) has emerged as a key enabler for enhancing cyber security through automated detection, analysis, and response. This paper presents a comprehensive survey of AI applications in cyber security across five major domains: malware detection, intrusion detection, phishing and spam detection, botnet detection, and cyber forensics. A systematic methodology based on data and methodological triangulation is employed to analyze 75 studies published between 2021 and 2025. The paper introduces a multi-layer taxonomy that maps cyber threats to application domains, analysis methods, AI approaches, and their associated capabilities and limitations. In addition, a cross-domain meta-analysis is conducted to identify recurring trends and assess the adoption of AI across different cyber security scenarios. The analysis reveals that deep learning and transformer-based models dominate data-intensive domains such as intrusion detection and malware analysis, whereas traditional machine learning techniques remain effective in structured and resource-constrained settings, particularly for phishing detection. Key challenges include dataset limitations, limited explainability, adversarial vulnerabilities, and computational constraints. Unlike existing surveys that focus on specific techniques or individual cyber security domains, this work provides a unified, application-oriented perspective on AI-driven cyber security. It further highlights emerging trends, open challenges, and future research directions toward more robust, scalable, and trustworthy cyber security systems.
The reviewed literature indicates that AI-based methodologies often demonstrate superior detection capabilities for intricate and previously unseen attack patterns compared to traditional methods; however, direct performance comparisons are complicated due to discrepancies in datasets, experimental designs, and evaluation protocols.
Jaswanth Garugu· International Journal for Re...· 0 citations
The rapid expansion of cloud computing infrastructures has fundamentally transformed how organizations manage
and deploy digital services, simultaneously introducing a complex and evolving attack surface that traditional security
mechanisms fail to adequately address. This survey examines the convergence of artificial intelligence (AI) and autonomous
cybersecurity with a focus on cloud environments. We systematically review thirteen recent papers spanning five core research
themes: AI-driven threat detection and classification, explainable AI (XAI) for cybersecurity transparency, autonomous response
and mitigation strategies, real-time cyber threat attribution, and AI-enhanced education for cybersecurity workforce
development. Our analysis highlights the state-of-the-art techniques including Graph Neural Networks (GNNs), transformerbased attention mechanisms, Federated Deep Learning (FDL), reinforcement learning, and multi-modal data fusion, all applied
to the challenge of building self-healing, autonomous cloud defense systems. We further discuss persistent challenges such as
dataset quality, model interpretability, adversarial robustness, and the gap between academic research and real-world
deployment. This survey provides a structured synthesis of the current state of the art, identifying key research directions for the
next generation of intelligent, autonomous cloud security systems
Mohammed Adeen Khurshid, Mulla, Mohammed Zuber Mulla, Mohammed Aziz A Khazi et al.· International Journal for Re...· 0 citations
Conventional Intrusion Detection Systems (IDS) mechanisms based on signatures and anomalies struggle and have shown their limitations with novel and dynamic attack patterns, and it has become essential to discover the emerging potential offered by AI and GenAI. These models open new perspectives but also present significant risks that must be properly managed. This paper presents an in-depth comprehensive Systematic Mapping Study (SMS) of 110 relevant articles published between 2015 and 2025 related to AI/GenAI-based IDS. The proposed work offers a novel and integrated, comprehensive mapping of both defensive and offensive dimensions of AI/GenAI-enabled cybersecurity, a classification of AI models and Large Language Models (LLMs), a deep dive analysis of traditional and next generation cyber-attacks, synthesis datasets and methodologies utilized for evaluating AI-based Intrusion Detection System approaches. The findings highlight a substantial intensification in research efforts beginning in 2022. Regarding traditional Cyber Attacks (CA), malicious actors are taking advantage of AI/GenAI techniques to enhance existing conventional CA. In the meantime, academic research continues to focus on traditional attack types while leveraging the new capabilities offered by AI and GenAI. About studies on AI models that deal with IDS, we have noted that most articles are based on a hybrid approach combining different models. They are based on ensemble learning and AI boosting techniques, coupled with metaheuristic optimization algorithms for the implementation of the IDS pipelines. While supervised learning is still the dominant approach, semi-supervised, unsupervised, graph-based, and reinforcement learning also hold promise in detecting unknown and zero-day threats. In addition, we presented the evolution of LLMs timeline through several waves, from Transformer Architectures Based LLMs era to Hybrid multimodal models. We presented also the classification of the most used LLMs in cybersecurity field. Regarding the datasets for training and evaluating AI models related to IDS: NSL-KDD and UNSW-NB15 datasets have emerged as the primary benchmarks favoured by the scientific community.
With the widespread adoption of cloud computing, securing enterprise networks against cyber threats has become increasingly important. Cloud environments are highly dynamic and constantly changing, making them susceptible to sophisticated cyberattacks that traditional Intrusion Detection Systems (IDS) often fail to detect. This study focuses on Intelligent Intrusion Detection Systems (IIDS) and their critical role in strengthening cloud security. Unlike conventional signature-based IDS that rely on fixed attack patterns, IIDS employ advanced Machine Learning (ML) and Artificial Intelligence (AI) techniques including deep learning, decision trees, and ensemble models to identify both known and emerging threats with greater accuracy. The paper proposes an integrated framework that combines real-time anomaly detection with automated response capabilities for cloud networks. Key architectural elements of IIDS are examined, alongside major deployment challenges such as scalability, false-positive rates, and computational requirements. Additionally, practical case studies and performance evaluations illustrate how IIDS enhance threat detection by improving accuracy, adaptability, and efficiency. Finally, the paper outlines future research directions to further advance IIDS capabilities and address the evolving security needs of modern cloud infrastructures.
R. Velu· 2026 4th International Confe...· 0 citations
Software-Defined Networking has emerged as a fundamental networking paradigm for cloud computing, Internet of Things, fifth-generation (5G) communication, and data-center infrastructures because of its centralized control, programmability, and flexible network management. However, the logical centralization of the control plane also introduces significant security vulnerabilities, making SDN increasingly susceptible to malware, botnets, ransomware, Distributed Denial-of-Service, and other sophisticated cyberattacks. Artificial Intelligence (AI)-based malware detection techniques have gained considerable attention due to their capability to identify complex and previously unseen attack patterns. This paper presents a comprehensive Systematic Literature Review of intelligent malware detection approaches for SDN by following the PRISMA 2020 framework and Kitchenham guidelines. A total of 30 primary studies published between 2020 and 2026 were systematically selected, assessed, and synthesized. The reviewed literature was classified into three major categories: Machine Learning, Deep Learning, and Hybrid AI approaches, followed by comprehensive comparative analyses of datasets, learning algorithms, feature engineering strategies, evaluation metrics, detection performance, and reported limitations. The quantitative synthesis indicates a clear research transition from conventional ML techniques toward deep learning and hybrid intelligence frameworks, with hybrid models consistently shows the highest detection performance, frequently exceeding 99% detection accuracy. The analysis further reveals that Random Forest, Support Vector Machine, Convolutional Neural Networks, Long Short-Term Memory networks, Deep Neural Networks, and CNN–LSTM hybrid architectures are among the most widely adopted algorithms, whereas NSL-KDD, InSDN, UNSW-NB15, CICIDS2017, and IoT-23 remain the dominant evaluation datasets. The review identifies several persistent challenges, including dependence on benchmark datasets, limited real-world SDN validation, class imbalance, high computational complexity, insufficient explainability, limited cross-dataset generalization, and the absence of standardized benchmarking protocols. The review outlines future research directions emphasizing lightweight and explainable AI models, graph neural networks, federated and continual learning, adaptive hybrid intelligence, and standardized real-world evaluation frameworks to support the development of accurate, scalable, robust, and deployable malware detection systems for next-generation Software-Defined Networks.
Sudhakar Yerme, Prabhakar L. Ramteke· International journal of adv...· 0 citations
The rapid expansion of digital infrastructures, cloud ecosystems, Internet of Things (IoT) environments, and intelligent enterprise platforms has significantly increased the complexity and frequency of cybersecurity threats. Traditional security mechanisms based on static rules and signature-based detection approaches are increasingly insufficient against sophisticated attacks involving zero-day exploits, advanced persistent threats, automated malware, and coordinated intrusion campaigns. This research paper presents a comprehensive analysis of AI-driven cybersecurity frameworks designed for real-time intrusion detection and threat intelligence generation. The study explores the integration of artificial intelligence (AI), machine learning (ML), deep learning, behavioral analytics, automation, and intelligent decision-making mechanisms for developing adaptive cybersecurity architectures. A research-oriented review methodology is adopted by synthesizing existing contributions from the provided literature, focusing on AI-enabled fraud detection, secure DevOps, zero-trust security, digital twin environments, distributed computing, privacy-preserving models, and intelligent risk assessment frameworks. The proposed analytical framework examines key components including real-time data acquisition, AI-based anomaly detection, threat intelligence processing, automated response orchestration, and continuous security optimization. Findings indicate that AI-driven cybersecurity architectures enhance detection accuracy, reduce response latency, and improve resilience against evolving cyber threats. However, challenges related to explainability, adversarial AI attacks, data privacy, computational requirements, and regulatory compliance remain significant barriers to large-scale adoption. The study contributes a structured understanding of how AI technologies can transform cybersecurity operations from reactive defense mechanisms into proactive, predictive, and autonomous security ecosystems.
Dilshan Jayawardena, Dr. Kavindi Perera· International Journal of Com...· 0 citations