2026· International journal of research and scientific innovation· 0 citations
Abstract
To improve cybersecurity across industries, Cyber Threat Intelligence (CTI) is becoming increasingly crucial. This systematic review explores how CTI practices are evolving in response to advancements in Artificial Intelligence (AI), particularly in the context of Large Language Models (LLMs). We examined 61 peer-reviewed studies using the PRISMA methodology, which demonstrates a strict selection procedure founded on specified inclusion, exclusion, and quality standards. This approach aligns with the scope of similar systematic reviews in the field of cyber threat intelligence. The review provides a comparative synthesis of CTI research capabilities across threat detection and prediction, attribution, forecasting, and automated reporting. We classify these approaches into three categories: conventional methods, those enhanced by AI and Machine Learning, and those based on LLMs. Our findings indicate that LLMs offer significant advantages in contextual reasoning, processing unstructured threat intelligence, and generating actionable mitigation plans. However, challenges such as model explainability, data privacy, system interoperability, and standardization impede their integration into operational environments. In addition to highlighting the potential and practical limitations of LLMs in CTI, this study identifies research gaps and proposes methods to create scalable, secure, and flexible CTI systems that support real-time cyber defense.
The rapid evolution of cyberattacks, coupled with the increasing capacity of computing environments and the emergence of artificial intelligence (AI), has significantly complicated the security landscape. While existing studies largely emphasize improving AI model performance for individual cybersecurity tasks, this survey shifts the focus toward operationalizing the deployment rationale and understanding when, where, and why different AI paradigms should be deployed, the capabilities they offer; and the challenges that must be addressed to enable trustworthy and effective real-world cyber defense. This paper aims to provide researchers and practitioners with a comprehensive reference for understanding the evolving role of AI in cybersecurity and the challenges that must be addressed to develop trustworthy and resilient AI-driven cyber defense systems. In this paper, we propose a structured taxonomy to organize various dimensions of AI-driven cybersecurity; review them critically; and finally, discuss key challenges, open problems, and emerging trends.
Cyber threat intelligence (CTI) is considered an essential element of a robust cyber security programme. Given the relative nascency of the discipline, however, there is a degree of ambiguity among the community around what it takes to establish a credible CTI capability in support of the cyber security mission. At the same time, there is now a thriving industry offering commercial CTI products and services in support of the customer’s capability development efforts, with many instances of opportunistic vendors poised to exploit this fledgling market. This has spurred the growth of research and advisory companies that attempt to present an objective review and offer guidance around CTI vendor selection. Their perspective, however, is often heavily influenced by a small group of select vendors and the evaluation criteria is often incomplete and skewed towards the participating vendors. This paper makes the case for a first-principles approach that CTI teams can adopt as an unbiased anchor to guide their decisions around establishing an adequate CTI capability, and offers pragmatic recommendations to assist CTI teams with qualifying their prospective vendors to ensure good fit. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Aaron Aubrey Ng· International Conference on...· 0 citations
The United Arab Emirates (UAE) has emerged as a regional leader in digital transformation, positioning itself at the forefront of smart city initiatives and critical infrastructure modernisation. However, this rapid digitalisation has exposed the nation to increasingly sophisticated cyber threats that challenge traditional security paradigms. This scoping literature review examines the role of artificial intelligence (AI) in strengthening UAE cyber resilience through a mixed-methods approach, synthesising evidence from 243 scholarly sources identified through systematic database searches. Following PRISMA-ScR guidelines, 60 studies were included in qualitative synthesis and 42 contributing to quantitative descriptive synthesis. The review reveals that AI-driven threat detection systems demonstrate substantial performance improvements, with machine learning classifiers achieving up to 98.2% accuracy and reducing response times by 75%. Empirical evidence from UAE-specific studies shows strong positive correlations between AI adoption and enhanced decision-making (r = 0.78, p < 0.001), whilst AI-enabled cyber threat intelligence systems demonstrate significant effectiveness (R² = 0.76, p < 0.001) when supported by appropriate organisational maturity. The review identifies critical success factors including multi-layered defence architectures, human-in-the-loop governance frameworks, and alignment with UAE National Cybersecurity Strategy objectives. Key challenges encompass adversarial manipulation risks, explainability concerns, data sovereignty constraints, and workforce capability gaps. The findings suggest that responsible AI deployment, underpinned by robust governance, continuous workforce development, and federated learning approaches, offers a viable pathway for the UAE to achieve its vision of becoming one of the world's most cyber-resilient nations. This review contributes to both academic discourse and policy formulation by providing evidence-based recommendations for AI integration in national cybersecurity frameworks.
Dr. Shankar Subramanian Iyer, Dr Brinitha Raji· International journal of res...· 0 citations
Proactive cyber defenses, AI-powered threat detection systems, and automated reactions are changing the face of cybersecurity in the modern era. In security-critical applications, however, Explainable Artificial Intelligence (XAI) is in high demand due to the need to improve trust, transparency, and decision-making in light of the fact that traditional AI models are not transparent. Intelligent threat detection and response mechanisms, key cybersecurity applications, the most recent advances in the area of XAI-based security solutions, and the fundamentals of explainable AI are all covered in detail in this survey. Highlighting the most prominent explainability methods including SHAP, LIME, Grad-CAM, and counterfactual explanations, this article delves into their applications in several security domains, including cloud security, IoT security, fraud detection, intrusion detection, phishing, spam, cloud security, and identity and access management. The comparative analysis of recent studies is used to emphasize current accomplishments, problems, and new research areas. The results show that XAI can improve the transparency, trustworthiness and effectiveness of AI-based cybersecurity systems, in addition to highlighting a range of privacy, adversarial robustness, scalability and evaluation challenges that warrant further research to ensure reliable deployment in the real world.
Mr. Raman Kumar· International Journal of Adv...· 0 citations
The growing complexity and frequency of cyberattacks make cybersecurity risk assessment an increasingly demanding task for organisations, requiring substantial expertise, resources, and adherence to established standards. This work explores the applicability of Large Language Model (LLM) to cybersecurity risk assessment, with a focus on threat identification and risk scoring. The paper presents a standalone consistency analysis across five models, measuring accuracy and stability under lexical, structural, and noisy prompt perturbations using an OWASP-oriented rubric. Building on the analysis results, we present a modular LLM-based system that combines Retrieval-Augmented Generation, MITRE ATT&CK-Aligned threat evaluation, rubric-constrained risk scoring, and a Judge Reviewer, orchestrated through a Beliefs–Desires–Intentions control loop. The validation against incidents from the VERIS and EuRepoC datasets highlights limitations and weaknesses, and allows identifying the architectural and structural mitigations that can reduce prompt sensitivity in LLM-based risk assessment.
Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat intelligence platforms, and automated incident response tools, enabling organizations to identify and neutralize threats with greater speed and precision. However, the same interconnectedness that drives digital transformation—spanning IoT ecosystems, cloud infrastructures, and 5G networks—has also expanded the attack surface available to malicious actors, giving rise to increasingly sophisticated, adaptive, and often AI-enabled threats such as adversarial machine learning attacks, deepfake-driven social engineering, and automated supply chain exploits. This paper examines the dual role of AI as both a defensive asset and a potential vector of risk within modern cybersecurity ecosystems. Drawing on a review of existing AI-driven security solutions, comparative analysis of AI-based versus traditional defense mechanisms, and case study evaluation, the study assesses the effectiveness, limitations, and ethical implications of AI integration in cyber defense. Findings indicate that while AI substantially improves threat detection accuracy and response times, challenges related to explainability, adversarial vulnerability, and regulatory oversight remain significant barriers to widespread adoption. The paper concludes with practical recommendations for organizations and policymakers seeking to harness AI's defensive potential while mitigating its associated risks, emphasizing the need for explainable AI frameworks, human-AI collaboration, and adaptive governance structures in an increasingly interconnected digital age.
Nicolas Guzman Camacho· Journal of Artificial Intell...· 0 citations