Skip to content
Review Open access

Machine Learning Framework for Predicting Emerging Cyber Threats

Jul 2026 · International Journal for Research in Applied Science and Engineering Technology · Vol 14, pp. 62-67 · 0 citations

TL;DR

The results show that combining anomaly, temporal, and graph sig-nals improves proactive threat identification while explainability, auditability, and analyst governance improve operational trust.

Abstract

Modern cyber attacks increasingly involve adaptive adversaries, zero-day exploitation, polymorphic behavior, multistage campaigns, and weak signals distributed across heterogeneous security telemetry. Traditional signature-based intrusion detection systems are effective for known threats but provide limited capability for predicting emerging attacks before they fully materialize. This paper presents THREATPREDICT-AI, a machine learning framework for predicting emerging cyber threats through weak-signal anomaly detection, time-series threat forecasting, graph-based threat correlation, ensemble risk scor-ing, explainable prediction artifacts, audit logging, and Human-in-the-Loop analyst validation. The proposed framework ingests safe cyber telemetry such as SIEM logs, IDS alerts, endpoint events, firewall records, authentication logs, and cyber threat intelligence indicators. It converts raw events into event-level, window-level, temporal, and graph-level features. Anomaly risk, forecast risk, and graph risk are fused into a calibrated threat score and mapped to low, medium, or high risk levels. A Flask-based prototype was implemented with a SOC dashboard, role-based access control, synthetic event generation, prediction management, HITL review, configurable model settings, and audit logs. Experimental demonstration using 220 synthetic cyber events generated 59 prediction windows and detected a high-risk emerging threat window with a final score of 0.83. The results show that combining anomaly, temporal, and graph sig-nals improves proactive threat identification while explainability, auditability, and analyst governance improve operational trust.

Read PDF

Similar papers

Open access Jul 2026

Beyond the Signature: Machine Learning for Adaptive Cyber Threat Intelligence

Modern cyberattacks are increasingly dynamic, multi-stage, and difficult to recognize with static signatures alone. Machine learning (ML) provides a complementary approach by learning patterns from large volumes of security telemetry and identifying behavior that may indicate compromise. This paper presents an integrated framework for applying ML across the cyber threat intelligence lifecycle, from data ingestion and preprocessing to model training, deployment, continuous monitoring, and response. It discusses supervised classification and anomaly detection, together with specialized security functions such as web filtering, dynamic sandboxing, behavioral analysis, deceptive-domain detection, and email protection. The paper also emphasizes a human-in-the-loop model in which automated systems prioritize evidence while analysts validate important decisions. Finally, it considers data drift, concept drift, adversarial manipulation, privacy, and retraining. The proposed approach treats ML as one layer of a broader defense system, combining automated pattern recognition with threat context and human expertise to improve detection speed, reduce alert fatigue, and support adaptive cyber defense.

Mitra Bhargeshbhai Patel, Bindi Bhatt, Dharvi Soni et al. · 0 citations
Open access Aug 2026

Adaptive Threat Intelligence Framework for Real-Time Cyberattack Detection Using Behavior-Based Analytics

The rapid growth of interconnected digital infrastructures, cloud computing environments, Internet of Things devices, and enterprise networking systems has significantly increased the frequency, complexity, and sophistication of cyberattacks targeting organizational information assets. Traditional cybersecurity mechanisms based primarily on signature detection and static rule-based monitoring are becoming increasingly ineffective against modern attack strategies such as zero-day exploits, advanced persistent threats, insider attacks, ransomware campaigns, and polymorphic malware. In this context, adaptive threat intelligence frameworks integrated with behavior-based analytics have emerged as a promising approach for enhancing real-time cyberattack detection and proactive security response capabilities. This research investigates the design and implementation of an adaptive threat intelligence framework capable of identifying malicious activities through continuous behavioral analysis, anomaly detection, and dynamic threat assessment techniques. The study focuses on how behavioral analytics can improve cybersecurity resilience by monitoring user activities, network communication patterns, system interactions, application behavior, and endpoint activities to identify deviations from established normal operational baselines. Unlike traditional detection approaches that depend heavily on predefined signatures, behavior-based analytics enables the identification of previously unknown threats and evolving attack vectors through machine learning algorithms, predictive analytics, and intelligent pattern recognition models. The proposed framework integrates adaptive learning mechanisms that continuously update threat intelligence repositories based on real-time attack behaviors, thereby improving detection accuracy and minimizing response delays. The research further examines the role of artificial intelligence, big data analytics, and automated incident response systems in strengthening cyber defense infrastructures across enterprise environments. In addition to operational advantages, the study critically evaluates challenges associated with implementing adaptive threat intelligence systems, including false-positive generation, data privacy concerns, computational complexity, adversarial machine learning attacks, scalability limitations, and integration difficulties within heterogeneous network architectures. The research methodology incorporates quantitative analysis, simulated attack scenarios, case study evaluations, and expert assessments to measure the effectiveness of behavior-based threat detection techniques in identifying malicious activities across dynamic cybersecurity environments. Findings from the study indicate that adaptive threat intelligence frameworks significantly enhance threat visibility, accelerate incident response, reduce detection latency, and improve organizational preparedness against sophisticated cyber threats when compared to conventional security monitoring systems. The research also emphasizes the importance of continuous learning models, human oversight, ethical cybersecurity governance, and secure data management practices to ensure sustainable and reliable implementation of intelligent threat detection systems. The study concludes that behavior-based adaptive cybersecurity frameworks represent a critical advancement in modern cyber defense strategies by enabling organizations to detect, analyze, and respond to emerging cyber threats in real time while maintaining operational continuity, information security, and digital infrastructure resilience in increasingly hostile cyber environments.

S. Tamilselvi · 0 citations
Aug 2026

AI-Based Cybersecurity Threat Detection Using Machine Learning

A multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time is introduced.

Ameen Pasha.A · 0 citations
Review Open access Jul 2026

A Review on Supervised Machine Learning Techniques for Enhancing Cyber Threat Prediction Accuracy

Experimental results demonstrate that an ensemble-optimized model achieves improved predictive accuracy, reduced false positives, and enhanced generalization to unseen attack patterns, providing a scalable and adaptive defense against evolving cyber threats in online banking.

Bandana Gupta, C. S. Gautam · 0 citations
Conference Jul 2026

Explainable AI and Machine Learning Framework for Cyber Threat Detection and Adaptive Defense Systems

Advanced persistent threats, zero-day exploits, encrypted command-and-control traffic, and botnet campaigns continue to reduce the reliability of conventional intrusion detection systems because static detectors provide limited transparency and weak adaptation under traffic drift. This paper presents an explainable and adaptive machine learning framework that integrates a LightGBM threat detector, SHAP-based decision explanations, density-aware concept drift detection, active incremental updating, and a contextual bandit defense policy. LightGBM is adopted because its leaf-wise gradient boosting structure provides high discrimination for heterogeneous flow features while maintaining low inference latency and native feature-importance support. The framework is evaluated on CIC-IDS2017, UNSW-NB15, and ToN_IoT using stratified train-validation-test splits, leakage prevention, five-run validation, and a 48-hour Kafka-based streaming simulation. The proposed model achieved 99.1% accuracy, 98.7% F1-score, 98.4% recall, and a 0.007 false alarm rate. During streaming evaluation, 14 adaptive model updates reduced mean detection latency from 27.4 s to 11.2 s, while SHAP explanations based on DNS entropy, JA3 rarity, packet interval, and flow-duration evidence reduced analyst triage time by 23%. Comparative results show that the proposed explainable adaptive pipeline improves detection reliability, reduces false alarms, and supports auditable mitigation decisions better than static and black-box IDS baselines.

P. A. Prakash, Salath Joseph A, A. M et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.