Aug 2026· International Scientific Journal of Engineering and Management· 0 citations
TL;DR
A conceptual layered framework for machine-learning-based security operations that integrates detection, adversarial-robustness testing, and human-analyst oversight is proposed by outlining directions for future research.
Abstract
Abstract
The escalating scale and sophistication of cyber threats - including advanced persistent threats, ransomware, and zero-day exploits - has driven a decade-long shift in cybersecurity research away from static, signature-based defences and toward machine learning (ML) systems capable of learning attack patterns from data and generalising to previously unseen threats. This paper presents a systematic literature review of machine learning in cyber security, organising the field into classical supervised intrusion detection, deep learning and hybrid detection architectures, graph-based and provenance-aware detection, machine-learning-based malware and phishing detection, and the adversarial machine learning literature that studies how the very ML systems built to defend networks can themselves be attacked and manipulated. The review examines the benchmark datasets - including NSL-KDD, UNSW-NB15, and CICIDS2017 - and evaluation practices that recur across this literature, situates the technical literature against industry data on the real-world cost and frequency of breaches, and discusses cross-cutting challenges including class imbalance, concept drift, adversarial vulnerability, explainability, and the operational gap between benchmark accuracy and production deployment. The paper concludes by proposing a conceptual layered framework for machine-learning-based security operations that integrates detection, adversarial-robustness testing, and human-analyst oversight, and by outlining directions for future research.
Keywords: machine learning, cyber security, intrusion detection, malware detection, adversarial machine learning, phishing detection, network security
A Kitchenham-informed systematic literature review methodology, this review synthesizes 186 studies published between 2018 and 2026 and develops a perturbation-realism taxonomy, ranging from feature-level manipulation to executable packet-level attacks, that clarifies when reported success corresponds to deployable risk.
The review explores the key adversarial attack classes: poisoning, evasion, model extraction, model extraction, model inversion, and membership inference and also white-box, black-box, and grey-box threat models.
Ujjwal Deshmukh· International Journal of Inn...· 0 citations
No single defense mechanism can provide complete protection against adversarial machine learning attacks, therefore, resilient AI-based cybersecurity requires a layered approach that protects data, features, models, inference processes, and the entire machine learning lifecycle.
Nwamini Bartholomew Tochukwu, C. Ezeaku-Ezeme· International journal of res...· 0 citations
A multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time is introduced.
Ameen Pasha.A· International Scientific Jou...· 0 citations
They originate from the rapid rise of cyber threats such as malware, phishing, ransomware,
denial of service, and unauthorised network intrusion, which have proven to be so difficult to
tackle that traditional security measures can hardly deal with the issue. Signature-based
intrusion detection system techniques in particular, which are commonly adopted by traditional
methods, usually lack the ability to detect novel and evolving attack vectors in addition to high
false positive rate and response time. In this regard, this paper proposes an AI threat detection
framework, employing data science methods to boost cybersecurity performances. The
researchers of this paper have tested the effectiveness of several models using a benchmark
dataset for cyber security, including CICIDS2017 or NSL-KDD and machine learning
techniques such as Random Forest, Support Vector Machine, Logistic Regression and
XGBoost for evaluating performance. Using measures of accuracy, precision, recall and F1-
score, the experiments show that the performance of ensemble learning models is higher than
shallow learning models in this research; XGBoost and Random Forest.
Praveen Kumar Reddy Gouni· International Journal of Soc...· 0 citations
Modern cyberattacks are increasingly dynamic, multi-stage, and difficult to recognize with static signatures alone. Machine learning (ML) provides a complementary approach by learning patterns from large volumes of security telemetry and identifying behavior that may indicate compromise. This paper presents an integrated framework for applying ML across the cyber threat intelligence lifecycle, from data ingestion and preprocessing to model training, deployment, continuous monitoring, and response. It discusses supervised classification and anomaly detection, together with specialized security functions such as web filtering, dynamic sandboxing, behavioral analysis, deceptive-domain detection, and email protection. The paper also emphasizes a human-in-the-loop model in which automated systems prioritize evidence while analysts validate important decisions. Finally, it considers data drift, concept drift, adversarial manipulation, privacy, and retraining. The proposed approach treats ML as one layer of a broader defense system, combining automated pattern recognition with threat context and human expertise to improve detection speed, reduce alert fatigue, and support adaptive cyber defense.
Mitra Bhargeshbhai Patel, Bindi Bhatt, Dharvi Soni et al.· International Journal of Sci...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.