Skip to content
Review Open access

Intelligent Cybersecurity for the Internet of Things: An AI-Based Adaptive Model and Landscape Analysis — A Systematic Literature Review

Aug 2026 · Journal of Intelligent Decision Making and Information Science · Vol 3, pp. 2155-2184 · 0 citations · 17 references

TL;DR

A conceptual model of an AI-based adaptive cybersecurity system for IoTs, designed to utilise edge intelligence, federated learning, and continuous feedback mechanisms to detect and respond dynamically to potential threats is proposed.

Abstract

Rapidly increasing numbers of devices connected to the Internet of Things have greatly changed how modern digital ecosystems operate by facilitating interoperability among industries such as healthcare, intelligent transportation systems, smart city technology and industrial automation. The increasing number of Internet connected devices has created new vulnerabilities for cyber-attacks on these devices, such as DDoS, Botnets, unauthorized access to devices and data breaches. Traditional IoT protection approaches generally fail to address these types of threats due to their limited resources, heterogeneity, and constant changes. In this regard, artificial intelligence has been proposed as a viable method to enhance cybersecurity for IoTs via AI-based systems capable of intelligent threat detection, adaptive learning, and real-time responses. To provide a clear understanding of AI-based cybersecurity methods for IoTs, this paper presents a systematic literature review (SLR) using a structured review process that follows the PRISMA guidelines. A total of 3072 original research papers on AI-based cybersecurity methods for IoTs published in top indexing databases were obtained. Each selected paper was analysed using a systematic screening process. The studies were grouped into six distinct theme areas, including machine learning-based intrusion detection, deep learning-based anomaly detection, hybrid/ensemble security models, federated learning frameworks, explainable AI, and blockchain-enabled IoT security mechanisms. Machine learning algorithms demonstrated high computational efficiency in detecting intrusions but lacked the flexibility to adapt to new threats. On the other hand, deep learning algorithms demonstrated a high intrusion detection capability but at a high computational cost. Hybrid/federated learning algorithms represent an emerging class that can deliver both the required accuracy and scalability while preserving user privacy. While several important advancements exist in AI-based cybersecurity methods for IoTs, many additional areas will require significant work before widespread adoption. Some examples include continued reliance on outdated benchmarks to evaluate algorithmic performance; the absence of validation testing for algorithms running in real-time environments; difficulty interpreting results generated by black-box AI-based algorithms; and a lack of collaboration among researchers studying different layers of the edge-cloud architecture. As a result of synthesising the current state of the art in AI-based cybersecurity methods for IoTs, this paper proposes a conceptual model of an AI-based adaptive cybersecurity system for IoTs, designed to utilise edge intelligence, federated learning, and continuous feedback mechanisms to detect and respond dynamically to potential threats. This paper makes contributions to the current body of knowledge regarding the rapidly changing landscape of IoT cybersecurity by providing an organised, analytical summary of the current state of the art in AI-based cybersecurity methods for IoTs; defining specific research gaps; and providing recommendations for future research to develop scalable, understandable, and adaptable security systems for IoT environments.

Read PDF

Similar papers

#federated learning Review Open access Sep 2026

AI-driven cybersecurity for industrial internet of things: architectures, challenges, datasets, and future research directions

This review critically analyzes the cybersecurity research published over the past few years on cyber threats across the various layers of the IIoT architecture, publicly available cybersecurity datasets, evaluation practices, and AI-based intrusion detection methods to provide a pathway toward resilient, adaptive, and operationally deployable cybersecurity solutions for next-generation IIoT.

Siddhartha Singhal, Kakelli Anil Kumar · 0 citations
Conference Aug 2026

Novel Cybersecurity and the Internet of Things (IoT) for Safeguarding Smart Grids: A Robust Architecture to Prevent Attacks on Specific Infrastructure

Energy networks are evolving into smart grids due to the expansion of the Internet of Things. Control is automated, monitored, and adjusted by intelligent network systems. While this method does enhance sustainability, efficiency, and reliability, it does so at the expense of cybersecurity. Critical infrastructure concerns have grown as a result of smart grids’ reliance on the Internet of Things. Smart meters, sensors, communication gateways, and controllers all fall under this category. Supply of electricity, confidentiality of data, and safety of the nation are all under risk from assaults on grid parts. To protect smart grid infrastructure from targeted attacks, this project employs an Internet of Things architecture driven by cybersecurity. Regions of the grid will be protected by multilayer security, advanced threat detection, and communication protocols. The most important things are ensuring the data is secure, authenticating devices, responding adaptively, and detecting anomalies in real-time. The smart grid’s visibility, resilience, and risk reduction are enhanced by a combination of centralized intelligence and decentralized security measures. Cybersecurity for smart grids is challenging because to the large amount of data, the number of devices involved, and the requirements for real-time operations. These concerns of cybersecurity based on the Internet of Things are addressed in this article. Scalability is ensured while infrastructure is protected. Sustainable, dependable, and environmentally friendly power systems are a result of secure IoT design.

Muruganantham Angamuthu, R. Alazaidah, Arumai Shiney et al. · 0 citations
Open access Sep 2026

AI-Driven Vulnerability Management Framework for the Internet of Things

This rapid growth of IoT has changed the landscape of today’s digital world by allowing devices to communicate effectively, especially in different fields like healthcare, smart cities, industrial control, and defense. Despite its advantages, IoT introduces significant security challenges due to device heterogeneity, constrained computational resources, and weak security architectures, making it highly vulnerable to cyber threats. Traditional vulnerability management approaches, including rule-based intrusion detection systems and signature-based scanning, have proven inadequate in addressing the dynamic and large-scale nature of IoT environments, as they are largely reactive and incapable of detecting novel attack patterns. This study proposes an AI driven vulnerability management framework that integrates anomaly detection techniques using machine learning to enhance proactive threat identification and mitigation in IoT ecosystems. The framework leverages publicly available datasets such as Bot-IoT, CIC-IoT, and UNSW NB15 to train and evaluate models capable of distinguishing between normal and malicious network behaviors. Various machine learning algorithms, including supervised and unsupervised techniques, were implemented and assessed using performance metrics such as accuracy, precision, recall, F1-score and false positive rate. The results demonstrate that AI based models significantly outperform traditional methods in detecting previously unseen threats, achieving high detection accuracy and reduced false positives. The proposed framework integrates anomaly detection into a structured vulnerability management lifecycle encompassing identification, prioritization and remediation of vulnerabilities. Generally, the study provides a scalable and adaptive solution for improving IoT security, reducing system vulnerabilities, and enhancing resilience against evolving cyber threats, with potential for future real-world deployment across critical sectors.

Daniel Nafisatu Mshelbila · 0 citations
Review Open access Aug 2026

A Comprehensive Review of Cybersecurity Threats, Vulnerabilities, and Mitigation Techniques in the Internet of Things (IoT)

Internet of Things (IoT) has become a new paradigm that combines physical devices with computing and networking features to form intelligent systems that can accomplish their tasks with minimal human interaction. It is estimated that by 2030, there will be more than 30 billion interconnected IoT devices, which will transfer more than 40 zettabytes of data each year. Nevertheless, this exponential increase has brought surprising cybersecurity issues, and recent evaluations show that over 70% of IoT devices are susceptible to hacking. This review examines the complex security environment of IoT ecosystems, evaluates vulnerabilities at each layer of architecture, explores new threat vectors, and assesses new defense solutions. This paper introduces a systematic review of IoT security issues based on a five-layer architecture and specifically focuses on the vulnerabilities of the network and application layers. It examines the ways in which artificial intelligence, blockchain technology, edge computing, and Zero Trust Architecture will transform IoT security paradigms. This review helps reveal long-standing issues such as resource limitations, device heterogeneity, and scaling challenges through the analysis of actual attack cases and defenses in the field of smart healthcare, industrial IoT, smart cities, and other vital infrastructures. Recommendations on future research directions are then given at the end of the paper with an emphasis on quantum-resistant cryptography, 6G network security, and standardized security frameworks required to construct resilient IoT ecosystems.

Muhammad Sami Intizar, Maria Sikandar, Aqsa Siddique et al. · 0 citations
Review Open access Aug 2026

Cybersecurity in the IoT Era: Protecting the Expanding Internet of Things

The Internet of Things (IoT) is transforming industries and daily life by connecting billions of devices, enabling smart homes, cities and industrial systems. This rapid expansion, however, introduces significant cybersecurity vulnerabilities, leaving IoT systems increasingly exposed to both established and emerging attack techniques. This paper presents a structured critical review of IoT cybersecurity, distinguished from prior general surveys by three contributions: first, a cross-layer mapping of named, dated case studies to the specific Security-by-Design principles that would have mitigated them; second, a comparative, feasibility-based evaluation of lightweight cryptographic primitives and blockchain consensus protocols for resource-constrained devices, rather than a descriptive overview; and third, a critical appraisal of the operational limitations of AI-based and blockchain-based defences, including adversarial manipulation, data scarcity and energy cost, set against the claims commonly made for these technologies. We examine the current state of IoT security across the perception, network and application layers; the common vulnerabilities that affect these systems, from insecure device design and weak default credentials to unencrypted communications; and the real-world consequences of these flaws through recent, named case studies, including the Aisuru botnet which is active since 2024 and 2024 vulnerability disclosures affecting Mitsubishi Electric and OMRON industrial controllers. We argue that securing the IoT ecosystem requires sustained, coordinated effort from manufacturers, regulators and end-users, and we identify where current technological and regulatory responses fall short of that goal.

K. Curran, J. Kyle, Lovepreet Singh · 0 citations
#explainable ai Review Open access Sep 2026

Artificial Intelligence for Anomaly Detection in Cyber Defense: A Critical Review of Methodological Trends, Datasets, and Explainability

The increase in the number and complexity of interconnected systems requires new methods to identify potential threats in today’s hyperconnected world. This trend affects systems ranging from smart homes and Internet of Things (IoT) devices to critical infrastructure which must be equipped with the corresponding cyber defense methods. Given the new landscape, it is more difficult for classical cybersecurity systems to stay up to date with novel threats, as well as to keep track of all interconnected devices defined by various protocols and behaviors. Artificial intelligence (AI) represents a strong candidate to complement traditional cyber defense methods due to its adaptability to variation and capability to identify complex data patterns, which has led researchers to develop state-of-the-art anomaly detection systems. The current critical review aims to analyze the scientific literature on three dimensions including used algorithms and datasets, domain challenges hindering AI deployment in productive environments, and the capability of explainable artificial intelligence (XAI) to support cyber security experts with insights into the model’s inner workings and decision rationale. Compared to existing scientific reviews, this paper moves beyond algorithmic comparison by providing a methodological interpretation of AI anomaly detection landscape, demonstrating how data availability, learning paradigms, and explainability collectively influence the evolution of cyber defense research towards operational deployment. This approach revealed that AI development for cyber defense is highly heterogenous, and that the available datasets strongly influence the algorithm of choice, rather than the models being chosen methodologically based on proven performance. The analysis further indicates that operational deployment remains challenging, as the literature continues to report substantial limitations related to data quality, computational requirements, and model interpretability.

P. Vezeteu, Nicolae-Daniel Boboc, D. Năstac · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.