Aug 2026· Progress in Artificial Intelligence· 0 citations· 142 references
TL;DR
This systematic literature review provides a rigorous, transparent, and reproducible foundation for knowledge by synthesizing all available evidence on IDSs over recent years by highlighting the differences, strengths, and shortcomings from each MI-IDS approach.
Abstract
In academia, the epistemology of Adversarial Malware Attacks (
AMAs
) in the context of an Intrusion Detection System (
IDS
) has not been fully grasped. Using Machine Intelligence (
MI
), many attempts have been made to reproduce modeling techniques and methods within IDSs that can properly track, trace, and prevent AMAs from reappearing. However, there seems to be a lack of comprehensive and cohesive literature reviews in this area on which existing scholars can rely to pursue future research and broaden the field of Information Security and Networks (
ISN
) research. Motivated by the absence of a universal IDSs framework,
termed a ’one-stop shop,’
this systematic review hopes to serve the research community by aligning thinking and firmly consolidating the historical knowledge and progress made in MI approaches, thereby providing a better understanding of AMAs, including their prevention and the implementation of viable and efficient IDSs. No other systematic review of this kind has yet been produced. Starting with nearly 1,000 papers and applying rigorous analysis, this study covers 132 research papers in multiple bibliographic databases since January 2020, highlighting studies on IDSs deployed for AMA detection and classification using MI learning techniques such as Machine Learning (
ML
) and Deep Learning (
DL
); methods involving feature extraction; studies discussing static, dynamic, memory, and hybrid feature analysis; and finally, studies providing experimental results and accuracy metrics from these IDSs. Throughout this comprehensive review, the emphasis is placed on highlighting the differences, strengths, and shortcomings from each MI-IDS approach, as well as providing discussions and suggestions for further exploration in future research. Following the PRISMA protocol, this systematic literature review (SLR) provides a rigorous, transparent, and reproducible foundation for knowledge by synthesizing all available evidence on IDSs over recent years.
The use of Artificial Intelligence (AI) and Machine Learning (ML) in cybersecurity, especially for creating Intrusion Detection Systems (IDSs), has become increasingly important. These systems are essential for detecting malicious behaviour, identifying network issues, and stopping cyberattacks in real time. Despite extensive research on various ML and Deep Learning (DL) models for IDS, the current literature remains incomplete. It has many different datasets, methods, and evaluation standards. As cyber threats become more advanced, it is crucial to conduct a thorough analysis of ML techniques for intrusion detection. The goal of this Systematic Literature Review (SLR) is to provide a full picture of the most recent academic articles on ML-based IDS. The study addresses important research questions about the most widely used algorithms, the types of attacks and network environments covered, the methodological problems that remain unsolved, and the new trends that should shape future research. Following the PRISMA framework, we conducted a systematic review of peer-reviewed articles published between January 2022 and May 2025. We searched IEEE Xplore, ACM Digital Library, and SpringerLink, yielding 22,558 initial records. After carefully applying strict inclusion criteria, 125 papers were selected for the final analysis. We created a standardised data extraction form (i.e., using MS Excel) to gather bibliographic details, research emphasis, methodological strategies, datasets, evaluation criteria, and recognised constraints. We employed thematic analysis to develop a clear taxonomy. We identified five main research themes in our analysis: (1) ensemble and hybrid learning pipelines focused on performance optimisation (30 papers), (2) context-specific IDS designs for Internet of Things (IoT), cloud, and Software-Defined Networking (SDN) environments (34 papers), (3) data-centric engineering that deals with class imbalance and feature selection (20 papers), (4) deep neural architectures for representation learning (31 papers), and (5) trustworthiness concerns like adversarial robustness, zero-day detection, and Explainable AI (XAI) (10 papers). Convolutional Neural Networks (CNNs), Long Short-Term Memory (LSTM), and Random Forests are the most commonly used algorithms, often combined. Nonetheless, significant deficiencies remain: about 2% of papers incorporate XAI, only 4% focus on adversarial robustness, and none validate their models in real-world production settings. Denial-of-Service (DoS) and Distributed DoS (DDoS) attacks are the most common types in the literature, whereas Web attacks, ransomware, and advanced persistent threats remain poorly studied. The number of publications grows at an average of 30.2% annually, but the field still relies on legacy benchmark datasets rather than operational validation.
Ali Ahmed, Ramy Mostafa, Mahmoud H. Qutqut et al.· Future Internet· 0 citations
The results showed that embedding explainability in an IDS enhances the human-AI partnership, allowing security analysts to confirm the results of their IDS, mitigate false-positive ambiguity, optimize incident response, and meet regulatory and ethical obligations.
Christian Manna Guimma· Scriptora International Jour...· 0 citations
The increasing sophistication and volume of malware pose a persistent and evolving threat to cybersecurity. The research paper systematically examines and compares various malware detection techniques, including traditional methods such as signature, heuristic, and anomaly detection, and more advanced methods such as behavior analysis, sandboxing, and machine learning, including deep learning. The study examined the mechanisms, advantages, and disadvantages of each technique using recent empirical data from academic literature. A comprehensive table provides a parallel comparison of these methods based on key performance indicators, efficacy against evasive malware, and resource consumption. In addition, it discusses the current challenges of malware detection, such as the increasing complexity of malware, evasion tactics, and threats to machine learning models. Finally, it explores emerging trends and future directions in this field, including integration of artificial intelligence, cloud analysis, proactive defense mechanisms, and the growing role of large language models. This review underscores the need to continuously innovate and adapt malware detection strategies to effectively counter the evolving landscape of cyber threats.
A. Cvetkovic, S. Adamovic, Marko Šarac· ZBORNIK RADOVA UNIVERZITETA...· 0 citations
The review outlines future research directions emphasizing lightweight and explainable AI models, graph neural networks, federated and continual learning, adaptive hybrid intelligence, and standardized real-world evaluation frameworks to support the development of accurate, scalable, robust, and deployable malware detection systems for next-generation Software-Defined Networks.
Sudhakar Yerme, Prabhakar L. Ramteke· International journal of adv...· 0 citations
A conceptual layered framework for machine-learning-based security operations that integrates detection, adversarial-robustness testing, and human-analyst oversight is proposed by outlining directions for future research.
Dr. C. Thilagavathy, Saeed Mudether Saeed Taha, Krithik M S et al.· International Scientific Jou...· 0 citations
A Kitchenham-informed systematic literature review methodology, this review synthesizes 186 studies published between 2018 and 2026 and develops a perturbation-realism taxonomy, ranging from feature-level manipulation to executable packet-level attacks, that clarifies when reported success corresponds to deployable risk.
Huda Ali Alatawi· IEEE Access· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.