AI-driven cybersecurity for industrial internet of things: architectures, challenges, datasets, and future research directions
TL;DR
This review critically analyzes the cybersecurity research published over the past few years on cyber threats across the various layers of the IIoT architecture, publicly available cybersecurity datasets, evaluation practices, and AI-based intrusion detection methods to provide a pathway toward resilient, adaptive, and operationally deployable cybersecurity solutions for next-generation IIoT.
Abstract
While the Industrial Internet of Things (IIoT) has a wide range of applications in the modern era, including smart manufacturing, healthcare, transportation, energy, and critical infrastructure, the multitude of devices and distributed communication, alongside the convergence of cyber and physical systems, makes these environments vulnerable to more advanced cyber-attacks. Traditional signature or pattern-based security solutions continue to be ineffective against new, sneaky, and zero-day attack strategies, fueling the interest in AI-powered cybersecurity. This review aims to analyze the latest developments systematically in intelligent threat detection and defense in IIoT environments. The review critically analyzes the cybersecurity research published over the past few years (2020–2026) on cyber threats across the various layers of the IIoT architecture, publicly available cybersecurity datasets, evaluation practices, and AI-based intrusion detection methods, such as machine learning, deep learning, hybrid architectures, transformers, graph neural networks, federated learning, reinforcement learning, and explainable AI. High benchmark performance alone is not sufficient to claim cybersecurity effectiveness, as the synthesis shows persistent limitations in cross-domain generalization, computational overhead, explainability, adversarial robustness, edge deployment, and operational validation. Emerging research priorities included in this review are lightweight edge intelligence, continual and adaptive learning, explainable federated intelligence, digital-twin-enabled security, foundation-model-driven cyber intelligence, autonomous cyber defense, and trustworthy AI. This review provides a pathway toward resilient, adaptive, and operationally deployable cybersecurity solutions for next-generation IIoT and highlights the PRISMA-based identification process.