Back to #generative ai

Artificial Intelligence for Real-Time Cyber Threat Classification and Emerging Threat Detection: A Structured Review of Methods, Datasets, Challenges, and Research Directions

Aug 2026 · International Journal for Research in Applied Science and Engineering Technology · 0 citations

TL;DR

The reviewed literature indicates that AI-based methodologies often demonstrate superior detection capabilities for intricate and previously unseen attack patterns compared to traditional methods; however, direct performance comparisons are complicated due to discrepancies in datasets, experimental designs, and evaluation protocols.

Abstract

The swift adoption of cloud computing, the Internet of Things (IoT), fifth-generation (5G) communication, and edge computing has extensively broadened the cyber-attack surface, facilitating the emergence of threats with increased scale, speed, and complexity. Traditional detection techniques, which rely on signatures, rules, and statistical analysis, continue to be effective for identifying known attacks; however, their capacity to detect zero-day exploits, polymorphic malware, and advanced persistent threats is limited. Consequently, there has been a rise in the implementation of artificial intelligence (AI) for adaptive and realtime cyber threat analysis. This review evaluates the evolution of AI-driven methodologies for real-time cyber threat classification and the identification of new threats, drawing from over fifty peer-reviewed studies identified through a structured search of leading scholarly databases. Instead of treating the studies in isolation, the literature is synthesized based on detection objectives, computational techniques, datasets, evaluation metrics, deployment environments, and acknowledged limitations. The review juxtaposes conventional detection methods with machine learning, deep learning, explainable AI (XAI), reinforcement learning, federated learning, graph neural networks (GNNs), large language models (LLMs), and generative AI. It places particular emphasis on frequently utilized cybersecurity datasets and evaluation practices, as well as ongoing challenges related to class imbalance, adversarial manipulation, computational overhead, model interpretability, privacy concerns, and inadequate validation in real-world scenarios. The reviewed literature indicates that AI-based methodologies often demonstrate superior detection capabilities for intricate and previously unseen attack patterns compared to traditional methods; however, direct performance comparisons are complicated due to discrepancies in datasets, experimental designs, and evaluation protocols. Moreover, a limited number of proposed models have been evaluated under authentic operational circumstances. In light of these observations, the review identifies significant research gaps and outlines prospective paths for developing explainable, privacy-conscious, computationally efficient, and readily deployable AI-enabled cyber-defence systems.

Read PDF

Similar papers

Review Open access Jul 2026

AI-Driven Cybersecurity Frameworks for Real-Time Intrusion Detection and Threat Intelligence

The rapid expansion of digital infrastructures, cloud ecosystems, Internet of Things (IoT) environments, and intelligent enterprise platforms has significantly increased the complexity and frequency of cybersecurity threats. Traditional security mechanisms based on static rules and signature-based detection approaches are increasingly insufficient against sophisticated attacks involving zero-day exploits, advanced persistent threats, automated malware, and coordinated intrusion campaigns. This research paper presents a comprehensive analysis of AI-driven cybersecurity frameworks designed for real-time intrusion detection and threat intelligence generation. The study explores the integration of artificial intelligence (AI), machine learning (ML), deep learning, behavioral analytics, automation, and intelligent decision-making mechanisms for developing adaptive cybersecurity architectures. A research-oriented review methodology is adopted by synthesizing existing contributions from the provided literature, focusing on AI-enabled fraud detection, secure DevOps, zero-trust security, digital twin environments, distributed computing, privacy-preserving models, and intelligent risk assessment frameworks. The proposed analytical framework examines key components including real-time data acquisition, AI-based anomaly detection, threat intelligence processing, automated response orchestration, and continuous security optimization. Findings indicate that AI-driven cybersecurity architectures enhance detection accuracy, reduce response latency, and improve resilience against evolving cyber threats. However, challenges related to explainability, adversarial AI attacks, data privacy, computational requirements, and regulatory compliance remain significant barriers to large-scale adoption. The study contributes a structured understanding of how AI technologies can transform cybersecurity operations from reactive defense mechanisms into proactive, predictive, and autonomous security ecosystems.

Dilshan Jayawardena, Dr. Kavindi Perera · 0 citations
Review Open access Jun 2026

A Comprehensive Survey of Artificial Intelligence Applications in Cyber Security: Taxonomy, Challenges, and Future Directions

The increasing complexity and scale of cyber threats demand intelligent and adaptive defense mechanisms that extend beyond traditional approaches. Artificial Intelligence (AI) has emerged as a key enabler for enhancing cyber security through automated detection, analysis, and response. This paper presents a comprehensive survey of AI applications in cyber security across five major domains: malware detection, intrusion detection, phishing and spam detection, botnet detection, and cyber forensics. A systematic methodology based on data and methodological triangulation is employed to analyze 75 studies published between 2021 and 2025. The paper introduces a multi-layer taxonomy that maps cyber threats to application domains, analysis methods, AI approaches, and their associated capabilities and limitations. In addition, a cross-domain meta-analysis is conducted to identify recurring trends and assess the adoption of AI across different cyber security scenarios. The analysis reveals that deep learning and transformer-based models dominate data-intensive domains such as intrusion detection and malware analysis, whereas traditional machine learning techniques remain effective in structured and resource-constrained settings, particularly for phishing detection. Key challenges include dataset limitations, limited explainability, adversarial vulnerabilities, and computational constraints. Unlike existing surveys that focus on specific techniques or individual cyber security domains, this work provides a unified, application-oriented perspective on AI-driven cyber security. It further highlights emerging trends, open challenges, and future research directions toward more robust, scalable, and trustworthy cyber security systems.

Shahid Alam, Ehab T Alnfrawy, Amina Jameel et al. · 0 citations
Open access Jul 2026

Role of Artificial Intelligence in Preventing and Predicting Cybersecurity Threats

Abstract The rapid digitalization of modern society has significantly increased dependence on interconnected systems, cloud computing, Internet of Things (IoT) devices, and online communication platforms. While technological advancement has transformed industries and improved efficiency, it has also created an increasingly complex cybersecurity landscape characterized by sophisticated cyberattacks, data breaches, ransomware campaigns, phishing schemes, and advanced persistent threats (APTs). Traditional cybersecurity approaches, which primarily rely on rule-based systems and human intervention, often struggle to detect and respond to rapidly evolving threats. Artificial Intelligence (AI) has emerged as a transformative technology capable of enhancing cybersecurity through predictive analytics, anomaly detection, automated threat response, and intelligent risk assessment. This paper explores the role of Artificial Intelligence in preventing and predicting cybersecurity threats. It examines the evolution of AI-driven cybersecurity systems, underlying technologies such as machine learning, deep learning, and neural networks, and their applications in threat detection, malware analysis, intrusion prevention, and cyber threat intelligence. The study also analyzes challenges associated with AI implementation, including adversarial attacks, privacy concerns, algorithmic bias, and ethical considerations. Furthermore, it discusses future directions involving autonomous security systems, explainable AI, and collaborative human-AI defense frameworks. The paper concludes that AI has become an indispensable component of modern cybersecurity strategies and will play a critical role in safeguarding digital infrastructure against emerging cyber threats.

Shaurya Gupta · 0 citations
Review Open access Jul 2026

Machine Learning Techniques for Real-Time Cyber Threat Detection and Prevention

Background: India faced a surge of cyber threats, from their frequency to sophistication, as the growth of Digital Technologies, Cloud Computing, Internet of Things (IoT), Artificial Intelligence (AI), and the rise of online financial services. In this regard, machine learning (ML) is a potential solution that offers intelligence, adaptability, and real-time detection and prevention of cyber threats. While the studies on ML applications in the field of cybersecurity have been conducted, a thorough synthesis study on the available evidence on cybersecurity in the Indian context has yet to be carried out.Objective: This systematic review will focus on evaluating the literature related to machine learning techniques for real-time cyber threat detection and prevention in India.Methods: This study used a systematic review design and the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA 2020) guidelines were followed. A thorough literature search was performed in all major electronic databases such as IEEE Xplore, Scopus, Web of Science, ScienceDirect, SpringerLink, ACM Digital Library and Google Scholar. The articles were included if they were published in English and reviewed by peers from 2020-2026.Conclusion: Machine learning has proven to be a transformative technology for enhancing cybersecurity, with its ability to detect threats intelligently, adaptively, and automatically. Despite the progress made, there is still a need for more research and development to build easily explainable, scalable, and context-specific machine learning models that can adapt to India's growing cybersecurity challenges. The insights from this review offer tangible support for researchers, practitioners, and policymakers in their quest for enhanced AI-driven cybersecurity solutions and a more secure digital landscape.

Kartikeya Tiwari · 0 citations
Open access Aug 2026

Adaptive Threat Intelligence Framework for Real-Time Cyberattack Detection Using Behavior-Based Analytics

The rapid growth of interconnected digital infrastructures, cloud computing environments, Internet of Things devices, and enterprise networking systems has significantly increased the frequency, complexity, and sophistication of cyberattacks targeting organizational information assets. Traditional cybersecurity mechanisms based primarily on signature detection and static rule-based monitoring are becoming increasingly ineffective against modern attack strategies such as zero-day exploits, advanced persistent threats, insider attacks, ransomware campaigns, and polymorphic malware. In this context, adaptive threat intelligence frameworks integrated with behavior-based analytics have emerged as a promising approach for enhancing real-time cyberattack detection and proactive security response capabilities. This research investigates the design and implementation of an adaptive threat intelligence framework capable of identifying malicious activities through continuous behavioral analysis, anomaly detection, and dynamic threat assessment techniques. The study focuses on how behavioral analytics can improve cybersecurity resilience by monitoring user activities, network communication patterns, system interactions, application behavior, and endpoint activities to identify deviations from established normal operational baselines. Unlike traditional detection approaches that depend heavily on predefined signatures, behavior-based analytics enables the identification of previously unknown threats and evolving attack vectors through machine learning algorithms, predictive analytics, and intelligent pattern recognition models. The proposed framework integrates adaptive learning mechanisms that continuously update threat intelligence repositories based on real-time attack behaviors, thereby improving detection accuracy and minimizing response delays. The research further examines the role of artificial intelligence, big data analytics, and automated incident response systems in strengthening cyber defense infrastructures across enterprise environments. In addition to operational advantages, the study critically evaluates challenges associated with implementing adaptive threat intelligence systems, including false-positive generation, data privacy concerns, computational complexity, adversarial machine learning attacks, scalability limitations, and integration difficulties within heterogeneous network architectures. The research methodology incorporates quantitative analysis, simulated attack scenarios, case study evaluations, and expert assessments to measure the effectiveness of behavior-based threat detection techniques in identifying malicious activities across dynamic cybersecurity environments. Findings from the study indicate that adaptive threat intelligence frameworks significantly enhance threat visibility, accelerate incident response, reduce detection latency, and improve organizational preparedness against sophisticated cyber threats when compared to conventional security monitoring systems. The research also emphasizes the importance of continuous learning models, human oversight, ethical cybersecurity governance, and secure data management practices to ensure sustainable and reliable implementation of intelligent threat detection systems. The study concludes that behavior-based adaptive cybersecurity frameworks represent a critical advancement in modern cyber defense strategies by enabling organizations to detect, analyze, and respond to emerging cyber threats in real time while maintaining operational continuity, information security, and digital infrastructure resilience in increasingly hostile cyber environments.

Dr. S. Tamilselvi, Simhadri Madhuri, Wong Tze · 0 citations
Review Open access Aug 2026

Artificial Intelligence and Cyber Defense: Navigating Emerging Threats in an Interconnected World

Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat intelligence platforms, and automated incident response tools, enabling organizations to identify and neutralize threats with greater speed and precision. However, the same interconnectedness that drives digital transformation—spanning IoT ecosystems, cloud infrastructures, and 5G networks—has also expanded the attack surface available to malicious actors, giving rise to increasingly sophisticated, adaptive, and often AI-enabled threats such as adversarial machine learning attacks, deepfake-driven social engineering, and automated supply chain exploits. This paper examines the dual role of AI as both a defensive asset and a potential vector of risk within modern cybersecurity ecosystems. Drawing on a review of existing AI-driven security solutions, comparative analysis of AI-based versus traditional defense mechanisms, and case study evaluation, the study assesses the effectiveness, limitations, and ethical implications of AI integration in cyber defense. Findings indicate that while AI substantially improves threat detection accuracy and response times, challenges related to explainability, adversarial vulnerability, and regulatory oversight remain significant barriers to widespread adoption. The paper concludes with practical recommendations for organizations and policymakers seeking to harness AI's defensive potential while mitigating its associated risks, emphasizing the need for explainable AI frameworks, human-AI collaboration, and adaptive governance structures in an increasingly interconnected digital age.

Nicolas Guzman Camacho · 0 citations

Related blog posts

MIT News · Artificial Intelligence Jul 14, 2026

Helping AI models to meet the real world

Through research and entrepreneurship, Professor Devavrat Shah is helping to design methods that can handle constant decision-making using limited computational resources.

MIT News · Artificial Intelligence Jun 5, 2026

The crucial human component in computing and AI

The MIT Ethics of Computing Research Symposium brought together experts and researchers working at the heart of ethical and social impact in technology.