Artificial Intelligence for Cybersecurity: A Scoping Survey of Paradigms, Applications, and Emerging Trends
Abstract
1. Introduction


- We propose a structured taxonomy of AI-driven cybersecurity organized across five core dimensions: technical paradigms, defensive capabilities, application domains, operational challenges, and emerging trends as shown in Figure 2.
- We operationalize the “when, where, and why” promise by providing a concrete decision matrix and deployment criteria for selecting AI models based on the threat model, data locality, and resource constraints as shown in Table 2.
- We provide a comprehensive synthesis of contemporary AI paradigms—including ML, DL, reinforcement learning (RL), FL, LLMs, and emerging quantum machine learning (QML). Further, critically analyze their capabilities, strengths, limitations, and suitability for cybersecurity tasks.
- Finally, we examine the adoption of AI across diverse cybersecurity domains, including enterprise networks, cloud computing, IoT, CPS, healthcare, and defense, highlighting common security objectives, domain-specific challenges, and representative real-world use cases.
2. AI Techniques and Paradigms for Cybersecurity
2.1. Machine Learning (ML) Models
2.1.1. Learning Approaches
2.1.2. Performance Characteristics
2.1.3. Comparative Advantages
2.2. Deep Learning (DL) Models
2.2.1. Prominent Architectures
2.2.2. Performance and Scalability
2.2.3. Emerging Architectures
2.3. Reinforcement Learning (RL)
2.4. Federated Learning (FL)
2.5. Explainable AI (XAI)
2.6. Generative AI (GenAI) and Large Language Models (LLMs)
2.6.1. Defensive Applications
2.6.2. Generative Adversarial Networks (GANs)
2.6.3. Security Challenges of LLMs
2.6.4. Trustworthiness and Governance
2.7. Quantum Machine Learning
2.7.1. Quantum Neural Networks
2.7.2. Quantum-Enhanced Intrusion Detection
2.7.3. Quantum Malware Detection
2.7.4. Current Limitations and Future Potential
3. Security Capabilities and Applications
3.1. Security Capability: Threat Prediction and Anomaly Detection
3.1.1. Application Domain: Network and Critical Infrastructure Security
3.1.2. Application Domain: Cyber-Physical Systems (CPS)
3.1.3. Application Domain: IoT and Other Autonomous Systems
3.1.4. Application Domain: Healthcare Systems
3.2. Security Capability: Incident Response Automation
3.3. Security Capability: Threat Intelligence and Security Analytics
3.4. Security Capability: Security Automation in Cyber Warfare and Military Networks
3.5. Security Capability: Digital Forensics
4. Challenges, Emerging Trends, and Open Research Directions
4.1. Deployment and Operational Challenges
4.1.1. Datasets
4.1.2. Adversarial AI and Evasion
4.1.3. Privacy, Ethics, and Governance
4.1.4. Explainability and Interpretability
4.1.5. Skilled Workforce
4.1.6. Cost and Resource Constraints
4.2. Emerging Trends
4.2.1. AI-Augmented Security Operation Centers (SOC)
4.2.2. Autonomous Cyber Defense Systems
4.2.3. Human-AI Collaboration
4.2.4. Zero-Trust Architecture
4.2.5. Agentic AI for Cybersecurity and Automation
4.3. Open Research Problems and Future Directions
5. Conclusions
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- ISACA. AI-Driven Cyber Threats Are the Biggest Concern for Cybersecurity Professionals Going into 2026, Finds New ISACA Research. Available online: https://www.businesswire.com/news/home/20251020612551/en/AI-Driven-Cyber-Threats-Are-the-Biggest-Concern-for-Cybersecurity-Professionals-Going-Into-2026-Finds-New-ISACA-Research (accessed on 20 October 2025).
- Ofusori, L.; Bokaba, T.; Mhlongo, S. Artificial intelligence in cybersecurity: A comprehensive review and future direction. Appl. Artif. Intell. 2024, 38, 2439609. [Google Scholar] [CrossRef]
- Ali, R.; Ali, A.; Iqbal, F.; Khattak, A.M.; Aleem, S. A systematic review of artificial intelligence and machine learning techniques for cyber security. In Proceedings of the International Conference on Big Data and Security; Springer: Berlin/Heidelberg, Germany, 2019; pp. 584–593. [Google Scholar]
- Mohamed, N. Current trends in AI and ML for cybersecurity: A state-of-the-art survey. Cogent Eng. 2023, 10, 2272358. [Google Scholar] [CrossRef]
- Randieri, C.; Fiani, F.; Lubrano, K.; Napoli, C. Innovations and Future Perspectives in the Use of Artificial Intelligence for Cybersecurity: A Scoping Review. Technologies 2025, 13, 584. [Google Scholar] [CrossRef]
- Ferrag, M.A.; Friha, O.; Maglaras, L.; Janicke, H.; Shu, L. Federated deep learning for cyber security in the internet of things: Concepts, applications, and experimental analysis. IEEE Access 2021, 9, 138509–138542. [Google Scholar] [CrossRef]
- Kilincer, I.F.; Ertam, F.; Sengur, A. Machine learning methods for cyber security intrusion detection: Datasets and comparative study. Comput. Netw. 2021, 188, 107840. [Google Scholar] [CrossRef]
- Lansky, J.; Ali, S.; Mohammadi, M.; Majeed, M.K.; Karim, S.H.T.; Rashidi, S.; Hosseinzadeh, M.; Rahmani, A.M. Deep learning-based intrusion detection systems: A systematic review. IEEE Access 2021, 9, 101574–101599. [Google Scholar] [CrossRef]
- Sarker, I.H. CyberLearning: Effectiveness analysis of machine learning security modeling to detect cyber-anomalies and multi-attacks. Internet Things 2021, 14, 100393. [Google Scholar] [CrossRef]
- ISCX-2012. Available online: https://www.unb.ca/cic/datasets/ids.html (accessed on 22 July 2026).
- CICDDoS-17. Available online: https://www.unb.ca/cic/datasets/ids-2017.html (accessed on 22 July 2026).
- CICIDS-18. Available online: https://www.unb.ca/cic/datasets/ids-2018.html (accessed on 22 July 2026).
- UNSW-NB15. Available online: https://research.unsw.edu.au/projects/unsw-nb15-dataset (accessed on 22 July 2026).
- Markevych, M.; Dawson, M. A review of enhancing intrusion detection systems for cybersecurity using artificial intelligence (ai). In Proceedings of the International Conference Knowledge-Based Organization; Nicolae Balcescu Land Forces Academy: Sibiu, Romania, 2023; Volume 29, pp. 30–37. [Google Scholar]
- Goodfellow, I.; Bengio, Y.; Courville, A.; Bengio, Y. Deep Learning; MIT Press: Cambridge, MA, USA, 2016; Volume 1. [Google Scholar]
- Nguyen, T.T.; Reddi, V.J. Deep reinforcement learning for cyber security. IEEE Trans. Neural Netw. Learn. Syst. 2021, 34, 3779–3795. [Google Scholar]
- Halbouni, A.; Gunawan, T.S.; Habaebi, M.H.; Halbouni, M.; Kartiwi, M.; Ahmad, R. CNN-LSTM: Hybrid deep neural network for network intrusion detection system. IEEE Access 2022, 10, 99837–99849. [Google Scholar] [CrossRef]
- Zainel, H.; Koçak, C. LAN intrusion detection using convolutional neural networks. Appl. Sci. 2022, 12, 6645. [Google Scholar] [CrossRef]
- Alzahrani, A.I.; Ayadi, M.; Asiri, M.M.; Al-Rasheed, A.; Ksibi, A. Detecting the presence of malware and identifying the type of cyber attack using deep learning and VGG-16 techniques. Electronics 2022, 11, 3665. [Google Scholar] [CrossRef]
- Nataraj, L.; Karthikeyan, S.; Jacob, G.; Manjunath, B.S. Malware images: Visualization and automatic classification. In Proceedings of the 8th International Symposium on Visualization for Cyber Security, Pittsburgh, PA, USA, 20 July 2011; pp. 1–7. [Google Scholar]
- Wang, W.; Zhu, M.; Wang, J.; Zeng, X.; Yang, Z. End-to-end encrypted traffic classification with one-dimensional convolution neural networks. In Proceedings of the 2017 IEEE International Conference on Intelligence and Security Informatics (ISI), Beijing, China, 22–24 July 2017; pp. 43–48. [Google Scholar]
- Kim, J.; Kim, J.; Thu, H.L.T.; Kim, H. Long short term memory recurrent neural network classifier for intrusion detection. In Proceedings of the 2016 International Conference on Platform Technology and Service (PlatCon), Jeju, Republic of Korea, 15–17 February 2016; pp. 1–5. [Google Scholar]
- Yin, C.; Zhu, Y.; Fei, J.; He, X. A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access 2017, 5, 21954–21961. [Google Scholar] [CrossRef]
- Vedula, V.; Lama, P.; Boppana, R.V.; Trejo, L.A. On the detection of low-rate denial of service attacks at transport and application layers. Electronics 2021, 10, 2105. [Google Scholar] [CrossRef]
- Kingma, D.P.; Welling, M. Auto-encoding variational bayes. arXiv 2013, arXiv:1312.6114. [Google Scholar]
- Mirsky, Y.; Doitshman, T.; Elovici, Y.; Shabtai, A. Kitsune: An ensemble of autoencoders for online network intrusion detection. arXiv 2018, arXiv:1802.09089. [Google Scholar]
- Jain, S. Advancing cybersecurity with artificial intelligence and machine learning: Architectures, algorithms, and future directions in threat detection and mitigation. World J. Adv. Eng. Technol. Sci. 2025, 14, 273–290. [Google Scholar] [CrossRef]
- Ribeiro, M.T.; Singh, S.; Guestrin, C. “Why should i trust you?” Explaining the predictions of any classifier. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA, 13–17 August 2016; pp. 1135–1144. [Google Scholar]
- Sai, S.; Yashvardhan, U.; Chamola, V.; Sikdar, B. Generative AI for cyber security: Analyzing the potential of ChatGPT, DALL-E, and other models for enhancing the security space. IEEE Access 2024, 12, 53497–53516. [Google Scholar] [CrossRef]
- Xu, H.; Wang, S.; Li, N.; Wang, K.; Zhao, Y.; Chen, K.; Yu, T.; Liu, Y.; Wang, H. Large language models for cyber security: A systematic literature review. In ACM Transactions on Software Engineering and Methodology; ACM: New York, NY, USA, 2024. [Google Scholar]
- Andreoni, M.; Lunardi, W.T.; Lawton, G.; Thakkar, S. Enhancing autonomous system security and resilience with generative AI: A comprehensive survey. IEEE Access 2024, 12, 109470–109493. [Google Scholar] [CrossRef]
- Wei, Y.; Shangguan, M. A review of deep learning-based intrusion detection systems. Highlights Sci. Eng. Technol. 2023, 56, 188–199. [Google Scholar] [CrossRef]
- Rathod, V.; Nabavirazavi, S.; Zad, S.; Iyengar, S.S. Privacy and security challenges in large language models. In Proceedings of the 2025 IEEE 15th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, USA, 5–8 January 2025; pp. 00746–00752. [Google Scholar]
- Shayegani, E.; Mamun, M.A.A.; Fu, Y.; Zaree, P.; Dong, Y.; Abu-Ghazaleh, N. Survey of vulnerabilities in large language models revealed by adversarial attacks. arXiv 2023, arXiv:2310.10844. [Google Scholar]
- Sha, Z.; Zhang, Y. Prompt stealing attacks against large language models. arXiv 2024, arXiv:2402.12959. [Google Scholar]
- Penmetsa, M.; Bhumireddy, J.R.; Chalasani, R.; Tyagadurgam, M.S.V.; Gangineni, V.N.; Pabbineedi, S. Next-Generation Cybersecurity: The Role of AI and Quantum Computing in Threat Detection. Int. J. Emerg. Trends Comput. Sci. Inf. Technol. 2021, 2, 54–61. [Google Scholar] [CrossRef]
- Kalinin, M.; Krundyshev, V. Security intrusion detection using quantum machine learning techniques. J. Comput. Virol. Hacking Tech. 2023, 19, 125–136. [Google Scholar]
- Abreu, D.; Rothenberg, C.E.; Abelém, A. Qml-ids: Quantum machine learning intrusion detection system. In Proceedings of the 2024 IEEE Symposium on Computers and Communications (ISCC), Paris, France, 26–29 June 2024; pp. 1–6. [Google Scholar]
- Kukliansky, A.; Orescanin, M.; Bollmann, C.; Huffmire, T. Network anomaly detection using quantum neural networks on noisy quantum computers. IEEE Trans. Quantum Eng. 2024, 5, 3100611. [Google Scholar] [CrossRef]
- Mercaldo, F.; Ciaramella, G.; Iadarola, G.; Storto, M.; Martinelli, F.; Santone, A. Towards explainable quantum machine learning for mobile malware detection and classification. Appl. Sci. 2022, 12, 12025. [Google Scholar] [CrossRef]
- Hdaib, M.; Rajasegarar, S.; Pan, L. Quantum deep learning-based anomaly detection for enhanced network security. Quantum Mach. Intell. 2024, 6, 26. [Google Scholar] [CrossRef]
- Buczak, A.L.; Guven, E. A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Commun. Surv. Tutor. 2015, 18, 1153–1176. [Google Scholar]
- Ahmad, Z.; Shahid Khan, A.; Wai Shiang, C.; Abdullah, J.; Ahmad, F. Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Trans. Emerg. Telecommun. Technol. 2021, 32, e4150. [Google Scholar]
- CICDDoS-19. Available online: https://www.unb.ca/cic/datasets/ddos-2019.html (accessed on 22 July 2026).
- Sommer, R.; Paxson, V. Outside the closed world: On using machine learning for network intrusion detection. In Proceedings of the 2010 IEEE Symposium on Security and Privacy, Oakland, FL, USA, 16–19 May 2010; pp. 305–316. [Google Scholar]
- Kostyuk, N.; Gartzke, E. Why cyber dogs have yet to bark loudly in Russia’s invasion of Ukraine. Tex. Natl. Secur. Rev. 2022, 5, 113–126. [Google Scholar] [CrossRef] [PubMed]
- Sánchez-Zas, C.; Larriva-Novo, X.; Villagrá, V.A.; Rodrigo, M.S.; Moreno, J.I. Design and evaluation of unsupervised machine learning models for anomaly detection in streaming cybersecurity logs. Mathematics 2022, 10, 4043. [Google Scholar] [CrossRef]
- Apache Spark. Apache Spark Documentation. 2026. Available online: https://spark.apache.org/docs/latest/ml-guide.html (accessed on 5 May 2026).
- NSLKDD. Available online: https://www.kaggle.com/datasets/hassan06/nslkdd (accessed on 22 July 2026).
- NERC. 2026. Available online: https://www.nerc.com/standards/reliability-standards/cip (accessed on 11 July 2026).
- ISA/IEC. 2026. Available online: https://www.fortinet.com/resources/cyberglossary/iec-62443 (accessed on 11 July 2026).
- Humayed, A.; Lin, J.; Li, F.; Luo, B. Cyber-physical systems security—A survey. IEEE Internet Things J. 2017, 4, 1802–1831. [Google Scholar] [CrossRef]
- Cárdenas, A.A.; Amin, S.; Lin, Z.S.; Huang, Y.L.; Huang, C.Y.; Sastry, S. Attacks against process control systems: Risk assessment, detection, and response. In Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, Hong Kong, China, 22–24 March 2011; pp. 355–366. [Google Scholar]
- Cardenas, A.A.; Amin, S.; Sastry, S. Secure control: Towards survivable cyber-physical systems. In Proceedings of the 2008 the 28th International Conference on Distributed Computing Systems Workshops, Beijing, China, 17–20 June 2008; pp. 495–500. [Google Scholar]
- Langner, R. Stuxnet: Dissecting a cyberwarfare weapon. IEEE Secur. Priv. 2011, 9, 49–51. [Google Scholar] [CrossRef]
- SWaT. Available online: https://www.kaggle.com/datasets/vishala28/swat-dataset-secure-water-treatment-system (accessed on 22 July 2026).
- BATADAL. Available online: https://www.batadal.net/data.html (accessed on 22 July 2026).
- Liu, Y.; Wang, J.; Li, J.; Niu, S.; Song, H. Machine learning for the detection and identification of Internet of Things devices: A survey. IEEE Internet Things J. 2021, 9, 298–320. [Google Scholar]
- Sánchez, P.M.S.; Celdrán, A.H.; Bovet, G.; Pérez, G.M. Adversarial attacks and defenses on ML-and hardware-based IoT device fingerprinting and identification. Future Gener. Comput. Syst. 2024, 152, 30–42. [Google Scholar] [CrossRef]
- Chen, D.D.; Woo, M.; Brumley, D.; Egele, M. Towards automated dynamic analysis for linux-based embedded firmware. In Proceedings of the NDSS, San Diego, CA, USA, 21–24 February 2016; Volume 1, pp. 1–16. [Google Scholar]
- Warden, P.; Situnayake, D. Tinyml: Machine Learning with Tensorflow Lite on Arduino and Ultra-Low-Power Microcontrollers; O’Reilly Media: Sebastopol, CA, USA, 2019. [Google Scholar]
- Lane, N.D.; Bhattacharya, S.; Georgiev, P.; Forlivesi, C.; Jiao, L.; Qendro, L.; Kawsar, F. Deepx: A software accelerator for low-power deep learning inference on mobile devices. In Proceedings of the 2016 15th ACM/IEEE International Conference on Information Processing in Sensor Networks (IPSN), Vienna, Austria, 11–14 April 2016; pp. 1–12. [Google Scholar]
- Palaniappan, K.; Duraipandi, B.; Balasubramanian, U.M. Dynamic behavioral profiling for anomaly detection in software-defined IoT networks: A machine learning approach. Peer-to-Peer Netw. Appl. 2024, 17, 2450–2469. [Google Scholar] [CrossRef]
- Wu, H.; Han, H.; Wang, X.; Sun, S. Research on artificial intelligence enhancing internet of things security: A survey. IEEE Access 2020, 8, 153826–153848. [Google Scholar] [CrossRef]
- Akter, S.S.; Ahmed, R.; Khan, F.H.; Rahman, M.S. Cyber-Physical Energy Systems Security: Attacks, Vulnerabilities and Risk Management. In Cyber Security Using Modern Technologies; CRC Press: Boca Raton, FL, USA, 2023; pp. 155–182. [Google Scholar]
- BoTIoT. Available online: https://research.unsw.edu.au/projects/bot-iot-dataset (accessed on 22 July 2026).
- TonIoT. Available online: https://research.unsw.edu.au/projects/toniot-datasets (accessed on 22 July 2026).
- N-BaIoT. Available online: https://www.kaggle.com/datasets/mkashifn/nbaiot-dataset (accessed on 22 July 2026).
- CICIoT-23. Available online: https://www.unb.ca/cic/datasets/iotdataset-2023.html (accessed on 22 July 2026).
- Alabdulatif, A.; Khalil, I.; Saidur Rahman, M. Security of blockchain and AI-empowered smart healthcare: Application-based analysis. Appl. Sci. 2022, 12, 11039. [Google Scholar] [CrossRef]
- Subramanian, G.; Thampy, A.S. Implementation of blockchain consortium to prioritize diabetes patients’ healthcare in pandemic situations. IEEE Access 2021, 9, 162459–162475. [Google Scholar] [CrossRef]
- Abdellatif, A.A.; Samara, L.; Mohamed, A.; Erbad, A.; Chiasserini, C.F.; Guizani, M.; O’Connor, M.D.; Laughton, J. Medge-chain: Leveraging edge computing and blockchain for efficient medical data exchange. IEEE Internet Things J. 2021, 8, 15762–15775. [Google Scholar] [CrossRef]
- Farhan, M. Empowering healthcare: Symbiotic innovations of AI and blockchain technology. In Blockchain and AI; CRC Press: Boca Raton, FL, USA, 2024; pp. 23–57. [Google Scholar]
- McGhin, T.; Choo, K.K.R.; Liu, C.Z.; He, D. Blockchain in healthcare applications: Research challenges and opportunities. J. Netw. Comput. Appl. 2019, 135, 62–75. [Google Scholar] [CrossRef]
- Shaked, A.; Cherdantseva, Y.; Burnap, P.; Maynard, P. Operations-informed incident response playbooks. Comput. Secur. 2023, 134, 103454. [Google Scholar] [CrossRef]
- Tariq, S.; Baruwal Chhetri, M.; Nepal, S.; Paris, C. Alert fatigue in security operations centres: Research challenges and opportunities. ACM Comput. Surv. 2025, 57, 1–38. [Google Scholar] [CrossRef]
- Aramide, O.O. AI-driven automated incident response and remediation in networks. Int. J. Technol. Manag. Humanit. 2025, 11, 1–9. [Google Scholar] [CrossRef]
- Waelchli, S.; Walter, Y. Reducing the risk of social engineering attacks using SOAR measures in a real world environment: A case study. Comput. Secur. 2025, 148, 104137. [Google Scholar] [CrossRef]
- Kinyua, J.; Awuah, L. AI/ML in Security Orchestration, Automation and Response: Future Research Directions. Intell. Autom. Soft Comput. 2021, 28, 527–545. [Google Scholar] [CrossRef]
- IBM. Explainable AI. 2026. Available online: https://www.ibm.com/think/topics/explainable-ai (accessed on 27 April 2026).
- Ferrara, E. Fairness and bias in artificial intelligence: A brief survey of sources, impacts, and mitigation strategies. Sci 2024, 6, 3. [Google Scholar] [CrossRef]
- Alliouche, R.; Chenni, H. Toward Intelligent Cyber Defense: A Comprehensive Study of SOAR Technologies for AI-Based DDoS Detection. Available online: https://www.researchgate.net/publication/394967622_Toward_Intelligent_Cyber_Defense_A_Comprehensive_Study_of_SOAR_Technologies_for_AI-Based_DDoS_Detection (accessed on 30 December 2025).
- Matthias, A. The responsibility gap: Ascribing responsibility for the actions of learning automata. Ethics Inf. Technol. 2004, 6, 175–183. [Google Scholar] [CrossRef]
- ISA/IEC. 2026. Available online: https://www.nis-2-directive.com (accessed on 11 July 2026).
- Sun, N.; Ding, M.; Jiang, J.; Xu, W.; Mo, X.; Tai, Y.; Zhang, J. Cyber threat intelligence mining for proactive cybersecurity defense: A survey and new perspectives. IEEE Commun. Surv. Tutor. 2023, 25, 1748–1774. [Google Scholar] [CrossRef]
- Santos, P.; Abreu, R.; Reis, M.J.; Serôdio, C.; Branco, F. A systematic review of cyber threat intelligence: The effectiveness of technologies, strategies, and collaborations in combating modern threats. Sensors 2025, 25, 4272. [Google Scholar] [CrossRef] [PubMed]
- Balasubramanian, P.; Liyana, S.; Sankaran, H.; Sivaramakrishnan, S.; Pusuluri, S.; Pirttikangas, S.; Peltonen, E. Generative AI for cyber threat intelligence: Applications, challenges, and analysis of real-world case studies. Artif. Intell. Rev. 2025, 58, 336. [Google Scholar] [CrossRef]
- Roy, K. A Global History of Warfare and Technology: From Slings to Robots; Springer: Berlin/Heidelberg, Germany, 2022; pp. 163–173. [Google Scholar]
- Zweibelson, B. Understanding the Military Design Movement: War, Change and Innovation; Routledge: Abingdon, UK, 2023; pp. 63–72. [Google Scholar]
- Najžer, B. The Hybrid Age. 2020. Available online: https://api.pageplace.de/preview/DT0400.9780755602537_A39699286/preview-9780755602537_A39699286.pdf (accessed on 28 December 2025).
- Chen, J.Q.; Dinerman, A. Cyber capabilities in modern warfare. In Cyber Security: Power and Technology; Springer: Berlin/Heidelberg, Germany, 2018; pp. 21–30. [Google Scholar]
- Demchak, C.C. Cybered conflict, hybrid war, and informatization wars. In Routledge Handbook of International Cybersecurity; Routledge: Abingdon, UK, 2020; pp. 36–51. [Google Scholar]
- Singh, A.; Gupta, S.; Jain, M. Adaptation of modern technologies and challenges in the defense sectors. Res Mil. 2022, 12, 1547–1556. [Google Scholar]
- Werkhoven, P.; Kester, L.; Neerincx, M. Telling autonomous systems what to do. In Proceedings of the 36th European Conference on Cognitive Ergonomics, Utrecht, The Netherlands, 5–7 September 2018; pp. 1–8. [Google Scholar]
- Zurek, T.; Kwik, J.; Van Engers, T. Model of a military autonomous device following International Humanitarian Law. Ethics Inf. Technol. 2023, 25, 15. [Google Scholar] [CrossRef]
- Abaimov, S.; Martellini, M. Artificial intelligence in autonomous weapon systems. In 21st Century Prometheus: Managing CBRN Safety and Security Affected by Cutting-Edge Technologies; Springer: Berlin/Heidelberg, Germany, 2020; pp. 141–177. [Google Scholar]
- Konert, A.; Balcerzak, T. Military autonomous drones (UAVs)-from fantasy to reality. Legal and Ethical implications. Transp. Res. Procedia 2021, 59, 292–299. [Google Scholar] [CrossRef]
- Munir, M. Autonomous Weapons Systems: Taking the Human Out of the Loop. 2022. Available online: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4074072# (accessed on 28 December 2025).
- Fisher, B.A. How International Humanitarian Law Will Constrain the Use of Autonomous Weapon Systems in the Conduct of Hostilities. Ph.D. Thesis, Murdoch University, Perth, Australia, 2022. [Google Scholar]
- Watts, T.F.; Bode, I. Automation and Autonomy in Loitering Munitions Catalogue (v. 1); Zenodo: Geneva, Switzerland, 2023. [Google Scholar] [CrossRef]
- Bianconi, G.; Arenas, A.; Biamonte, J.; Carr, L.D.; Kahng, B.; Kertesz, J.; Kurths, J.; Lü, L.; Masoller, C.; Motter, A.E.; et al. Complex systems in the spotlight: Next steps after the 2021 Nobel Prize in Physics. J. Phys. Complex. 2023, 4, 010201. [Google Scholar] [CrossRef]
- Dresp-Langley, B. The weaponization of artificial intelligence: What the public needs to be aware of. Front. Artif. Intell. 2023, 6, 1154184. [Google Scholar] [CrossRef] [PubMed]
- Klare, M.T. Assessing the Dangers: Emerging Military Technologies and Nuclear (In) Stability; Arms Control Association: Washington, DC, USA, 2023. [Google Scholar]
- Armitage, R. We must oppose lethal autonomous weapons systems. Br. J. Gen. Pract. 2019, 69, 510. [Google Scholar] [CrossRef] [PubMed]
- Lohn, A.; Knack, A.; Burke, A.; Jackson, K. Autonomous Cyber Defence: A Roadmap from Lab to Ops; Center for Emerging Technology and Security: Washington, DC, USA, 2023. [Google Scholar]
- Mareedu, A. Autonomous Security Operations Centers (SOC): AI Agents for Threat Triage, Response, and Orchestration. Int. J. Emerg. Res. Eng. Technol. 2025, 6, 63–70. [Google Scholar] [CrossRef]
- Santoni de Sio, F.; Van den Hoven, J. Meaningful human control over autonomous systems: A philosophical account. Front. Robot. AI 2018, 5, 323836. [Google Scholar] [CrossRef] [PubMed]
- EMBER. Available online: https://www.kaggle.com/datasets/trinhvanquynh/ember-for-static-malware-analysis (accessed on 22 July 2026).
- SOREL-20M. Available online: https://github.com/sophos/SOREL-20M (accessed on 22 July 2026).
- MSMalChallenge. Available online: https://www.kaggle.com/competitions/malware-classification/data (accessed on 22 July 2026).
- Malimg. Available online: https://www.kaggle.com/datasets/manmandes/malimg (accessed on 22 July 2026).
- Malnet. Available online: http://malnet.cc.gatech.edu/image-data/ (accessed on 22 July 2026).
- VirusShare. Available online: https://virusshare.com (accessed on 22 July 2026).
- CICMalMem22. Available online: https://www.unb.ca/cic/datasets/malmem-2022.html (accessed on 22 July 2026).
- APICallSeq. Available online: https://www.kaggle.com/datasets/ang3loliveira/malware-analysis-datasets-api-call-sequences (accessed on 22 July 2026).
- KDDCUP. Available online: https://kdd.ics.uci.edu/databases/kddcup99/kddcup99.html (accessed on 22 July 2026).
- Kyoto2006+. Available online: https://www.kaggle.com/datasets/harshwardhanbhangale/kyoto-2006 (accessed on 22 July 2026).
- Hikari2021. Available online: https://zenodo.org/records/5199540 (accessed on 22 July 2026).
- IoT-23. Available online: https://www.stratosphereips.org/datasets-iot23 (accessed on 22 July 2026).
- mqtt-2020. Available online: https://ieee-dataport.org/open-access/mqtt-iot-ids2020-mqtt-internet-things-intrusion-detection-dataset (accessed on 22 July 2026).
- EdgeIoT. Available online: https://www.kaggle.com/datasets/mohamedamineferrag/edgeiiotset-cyber-security-dataset-of-iot-iiot?select=Edge-IIoTset+dataset (accessed on 22 July 2026).
- Mittelstadt, B.D.; Allo, P.; Taddeo, M.; Wachter, S.; Floridi, L. The ethics of algorithms: Mapping the debate. Big Data Soc. 2016, 3, 2053951716679679. [Google Scholar] [CrossRef]
- Floridi, L.; Cowls, J.; Beltrametti, M.; Chatila, R.; Chazerand, P.; Dignum, V.; Luetge, C.; Madelin, R.; Pagallo, U.; Rossi, F.; et al. AI4People—An ethical framework for a good AI society: Opportunities, risks, principles, and recommendations. Minds Mach. 2018, 28, 689–707. [Google Scholar] [CrossRef] [PubMed]
- Radanliev, P. AI ethics: Integrating transparency, fairness, and privacy in AI development. Appl. Artif. Intell. 2025, 39, 2463722. [Google Scholar] [CrossRef]
- Cadet, E.; Etim, E.; Essien, I.; Ajayi, J.; Erigha, E. Ethical challenges in AI-driven cybersecurity decision-making. Int. J. Sci. Res. Comput. Sci. Eng. Inf. Technol. 2024, 10, 1031–1064. [Google Scholar] [CrossRef]
- Humphreys, D.; Koay, A.; Desmond, D.; Mealy, E. AI hype as a cyber security risk: The moral responsibility of implementing generative AI in business. AI Ethics 2024, 4, 791–804. [Google Scholar] [CrossRef]
- Saurabh, B.; Utkrisht, S.; Sandeep, S.; Kumar, D.; Rajkumar, U. Generative AI Enabled Actionable Decision Support in Cyber Security Operations for Enterprise Security. In Proceedings of the 2024 ITU Kaleidoscope: Innovation and Digital Transformation for a Sustainable World (ITU K), New Delhi, India, 21–23 October 2024; pp. 1–8. [Google Scholar]
- Rajgopal, P.R. SOC Talent Multiplication: AI Copilots as Force Multipliers in Short-Staffed Teams. Int. J. Comput. Appl. 2025, 187, 46–62. [Google Scholar] [CrossRef]
- Akre, V.; Kobbaey, T.; Lazarov, G.; Abdulsalam, K.; Al-Sit, W.; Diab, J. From Alert Fatigue to Augmented Defense: A Case for AI Copilots in Cybersecurity Operation Centers. In Proceedings of the 2025 10th International Conference on Information Technology Trends (ITT), Dubai, United Arab Emirates, 6–7 November 2025; pp. 282–287. [Google Scholar]
- Karunasingha, N.; Chhetri, M.B.; Nepal, S.; Paris, C.; Kanhere, S.S. SoK: AI Support for Analyst Situation Awareness in Security Operation Centres. In Proceedings of the 2025 European Symposium on Usable Security (EuroUSEC), Manchester, UK, 10–11 September 2025; pp. 151–163. [Google Scholar]
- Loevenich, J.F.; Adler, E.; Bécue, A.; Velazquez, A.; Wrona, K.; Boshnakov, V.; Falkcrona, J.; Nordbotten, N.; Worthington, O.L.; Röning, J.; et al. Training autonomous cyber defense agents: Challenges & opportunities in military networks. In Proceedings of the MILCOM 2024-2024 IEEE Military Communications Conference (MILCOM), Washington, DC, USA, 28 October–1 November 2024; pp. 158–163. [Google Scholar]
- Pokhrel, S.R.; Yang, L.; Rajasegarar, S.; Li, G. Robust zero trust architecture: Joint blockchain-based federated learning and anomaly detection-based framework. In Proceedings of the SIGCOMM Workshop on Zero Trust Architecture for Next Generation Communications, Sydney, Australia, 4–8 August 2024; pp. 7–12. [Google Scholar]
- Ramezanpour, K.; Jagannath, J. Intelligent zero trust architecture for 5G/6G networks: Principles, challenges, and the role of machine learning in the context of O-RAN. Comput. Netw. 2022, 217, 109358. [Google Scholar] [CrossRef]
- Hussain, M.; Pal, S.; Jadidi, Z.; Foo, E.; Kanhere, S. Federated zero trust architecture using artificial intelligence. IEEE Wirel. Commun. 2024, 31, 30–35. [Google Scholar] [CrossRef]
- Javeed, D.; Saeed, M.S.; Adil, M.; Kumar, P.; Jolfaei, A. A federated learning-based zero trust intrusion detection system for Internet of Things. Ad Hoc Netw. 2024, 162, 103540. [Google Scholar] [CrossRef]
- Ajish, D. The significance of artificial intelligence in zero trust technologies: A comprehensive review. J. Electr. Syst. Inf. Technol. 2024, 11, 30. [Google Scholar] [CrossRef]
- EU Artificial Intelligence ACT. 2024. Available online: https://artificialintelligenceact.eu/high-level-summary/ (accessed on 11 July 2026).
- NIST AI Risk Management Framework. 2023. Available online: https://www.nist.gov/itl/ai-risk-management-framework (accessed on 11 July 2026).
- ISO/IEC 42001; Information Technology-Artificial Intelligence-Management System. ISO: Geneva, Switzerland, 2023. Available online: https://www.iso.org/standard/42001 (accessed on 11 July 2026).

| Survey Ref | Year | Primary Focus | Key Contribution | Deployment Framework |
|---|---|---|---|---|
| Ofusori et al. [2] | 2024 | General AI Review | Bibliometric analysis of 939 papers. | No |
| Ali et al. [3] | 2019 | General AI/ML Review | Systematic review of ML algorithms and model performance benchmarking. | No |
| Mohamed [4] | 2023 | Trends in AI/ML | State-of-the-art survey of IEEE/ACM/Springer articles. | No |
| Randieri et al. [5] | 2025 | Innovations Scoping | Future perspectives and scoping review. | No |
| Ferrag et al. [6] | 2024 | FL, DL, and Blockchain | Alignment and hardware design security. | No |
| Our Paper | 2026 | Cyber Defense | Formal taxonomy and `When, Where, Why’ matrix. | Yes |
| Paradigm | When to Deploy | Where to Place | Why (Rationale) |
|---|---|---|---|
| FL | High privacy, decentralized data. | Edge Gateways, Local LANs | Preserves data locality; prevents raw log leakage |
| DL | High-volume, complex traffic patterns. | Network Perimeter, Cloud | Excels at feature extraction from raw flows |
| LLMs | Semantic analysis, CTI synthesis. | SOC, Management Layer | Processes unstructured data; automates reports |
| Classical ML | Resource-constrained, simple anomalies. | IoT End-devices, Sensors | Low compute overhead; high interpretability |
| Attack Type | Target | Description | Impact |
|---|---|---|---|
| Evasion Attacks | Trained models or classifiers | Adversarial inputs manipulate model predictions during inference | Bypass detection and misclassification |
| Poisoning Attack | Training datasets | Handcrafted malicious samples injected during training | Corrupted models and compromised threat detection and prediction |
| Prompt Injection | LLM and Security copilots | Malicious prompts to manipulate model behavior | Incorrect and unsafe outputs and bypass safeguards |
| Model Inversion | Trained models or classifiers | Inferring sensitive training information from model outputs | Privacy leakage and exposing sensitive data |
| Jailbreaking | LLMs and transformer-based models | Handcrafted prompted to bypass restrictions | Model generates malicious and prohibited content |
| Datasets | Attacks | Features | Limitation |
|---|---|---|---|
| EMBER [108] | Windows malware families | Portable Executable (PE) header features, byte histograms | Suitable for static analysis |
| SOREL-20M [109] | Ransomware, Dropper, Worm, Trojan, etc | PE metadata behavioral labels | large computational requirements |
| Microsoft Malware Challenge [110] | Ramnit, Kelihos, Lollipop, Obfuscator | Assembly code, byte code | Old malware families |
| Malimg [111] | 25 malware families with various malware types | Grayscale malware images | Limited semantic behavior information |
| Malnet [112] | Various malware families | Large malware image corpus | Resource intensive training |
| CICMalMem 2020 [114] | Ransomware, file-less malware | Memory dump artifacts | Limited malware family diversity |
| VirusShare [113] | Diverse malware binaries | Raw malware samples | Inconsistencies in labeling |
| API Call Sequence Dataset [115] | Execution behavior data | API call sequences | High-dimensional sequential data |
| Datasets | Attacks | Features | Limitation |
|---|---|---|---|
| KDD Cup [116] | DoS, Probe, R2L, U2R | 41 TCP/IP handcrafted features | Outdated, redundant records, unrealistic traffic |
| NSL KDD [49] | DoS, Probe, R2L, U2R | Refined KDD99 feature set | Outdated, lacks modern attacks |
| UNSW-NB15 [13] | Fuzzers, DoS, Reconnaissance, Shellcode, Exploits, worms | 49 flow-based network features | Limited encrypted traffic realism |
| CICIDS2017 [11] | DDoS, Brute Force, Botnet, PortScan, Web attacks, Infiltration | Flow statistics, packet metrics | Lab-generated environment |
| CSE-CIC-IDS2018 [12] | DDoS, Brute Force, DoS, Botnet, Infiltration | Netflow statistical Features | High processing complexity and controlled environment |
| CIC-DDoS2019 [44] | WebDDoS, Botnet, UDP Flood, Amplification, SYN Flood attacks | Flow-based statistical features | Focuses only on DDoS attacks and controlled environment |
| Kyoto 2006+ [117] | Malware, Scanning, unknown attacks | Honeypot logs and traffic flows | Limited attack labeling |
| HIKARI-2021 [118] | Malware traffic VPN and non-VPN attacks | Statistical flow features | Limited attack diversity |
| Datasets | Attacks | Features | Limitation |
|---|---|---|---|
| ToN-IoT [67] | DDoS, Ransomware, Backdoor, Injection, Password attacks | Zeek logs and features | Complex, multi modal records and preprocessing |
| Bot-IoT [66] | DDoS, Dos, Scanning, Keylogging | Argus tool-based flow features | Synthetic traffic, lacks modern attacks |
| IoT-23 [119] | Mirai, Torii, Okiru, Botnets | Zeek logs and features | Labeling is based on zeek features |
| N-BaIoT [68] | Mirai, BASHLITE | Device traffic statistics | Limited attack families |
| MQTT-IoT-IDS2020 [120] | MQTT Flood, Malformed packets, brute force | MQTT protocol features | limited scope |
| EdgeIIoTset [121] | DDoS, MITM, Injection, Malware | Edge traffic telemetry logs | Relatively new benchmark |
| CICIoT2023 [69] | DoS, Spoofing, Botnet, Reconnaissance | HIoT Flow features | Realism and reproducibility concerns |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Mishra, A.; Vedula, V.; Mishra, A.; Sharma, S. Artificial Intelligence for Cybersecurity: A Scoping Survey of Paradigms, Applications, and Emerging Trends. Algorithms 2026, 19, 653. https://doi.org/10.3390/a19080653
Mishra A, Vedula V, Mishra A, Sharma S. Artificial Intelligence for Cybersecurity: A Scoping Survey of Paradigms, Applications, and Emerging Trends. Algorithms. 2026; 19(8):653. https://doi.org/10.3390/a19080653
Chicago/Turabian StyleMishra, Amitabh, Vasudha Vedula, Asmi Mishra, and Shrishti Sharma. 2026. "Artificial Intelligence for Cybersecurity: A Scoping Survey of Paradigms, Applications, and Emerging Trends" Algorithms 19, no. 8: 653. https://doi.org/10.3390/a19080653
APA StyleMishra, A., Vedula, V., Mishra, A., & Sharma, S. (2026). Artificial Intelligence for Cybersecurity: A Scoping Survey of Paradigms, Applications, and Emerging Trends. Algorithms, 19(8), 653. https://doi.org/10.3390/a19080653

