Next Article in Journal
Probabilistic Assessment of Groundwater Potential Using Spatially Aware Machine Learning and Multimodal Geospatial Data
Previous Article in Journal
PMCI: A Prototype-Based Diagnostic Index for Cross-Modal Affective Agreement
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Systematic Review

Technological Evolution of Strategic Security Infrastructure: Transitioning from Reactive Models to Predictive Intelligence

1
Ingeniería Industrial, Facultad de Ingeniería y Ciencias Aplicadas, Universidad de las Américas, Quito 170125, Ecuador
2
International College of Defense Studies, National Defense University, Beijing 100036, China
3
Departamento de Evaluación e Investigación Académica, Academia de Guerra del Ejército, Sangolquí 171103, Ecuador
4
Departamento de Enlaces y Sistemas, Comunicaciones y Guerra Electrónica, Comando Conjunto de las Fuerzas Armadas, Quito 170902, Ecuador
5
Grupo de Ciberdefensa y Guerra Electrónica Nro. 97, Fuerzas Armadas, Quito 170902, Ecuador
6
Dirección de Policía Científica, Subdirección de Investigación Técnico-Científica, Policía Nacional del Ecuador, Quito 170147, Ecuador
7
Programa de Doctorado en Ciencias Forenses, Universidad de Alcalá, 28871 Madrid, Spain
8
Departamento de Ciencias Exactas, Universidad de las Fuerzas Armadas, Sangolquí 171103, Ecuador
9
Facultad de Sistemas y Telecomunicaciones, Universidad Estatal Península de Santa Elena, La libertad 240204, Ecuador
*
Author to whom correspondence should be addressed.
Technologies 2026, 14(7), 446; https://doi.org/10.3390/technologies14070446
Submission received: 19 May 2026 / Revised: 8 July 2026 / Accepted: 13 July 2026 / Published: 20 July 2026

Abstract

Security infrastructure has evolved from the use of reactive models toward the adoption of predictive technologies, transforming and enhancing threat anticipation, improving monitoring capabilities, and strengthening strategic decision-making driven by the integration of emerging technologies and artificial intelligence. This review study synthesizes the changes occurring across spatial, maritime, aerial, border, and cybersecurity infrastructure, evidencing the impact of the transition toward predictive technologies; it addresses the challenges and limitations these technologies introduce as a consequence of their operational deployment, and concludes by examining future lines of development in this domain. The review was conducted following the PRISMA® methodology, analyzing the scientific literature retrieved from seven indexed databases—SCOPUS, ScienceDirect, Web of Science, IEEE Xplore, Taylor & Francis, ProQuest, and PubMed—consistent with the full search scope. Articles were independently assessed by two reviewers, yielding an initial Cohen’s Kappa coefficient of 0.458; following structured discussion and consensus resolution, the final inter-rater reliability reached κ = 0.71, meeting the accepted threshold for scoping review methodology. The findings demonstrate a global transition toward intelligent security infrastructures, with measurable improvements in performance, accuracy, and response times in the generation of actionable intelligence to support strategic decision-making.

1. Introduction

Over the past two decades, national security architectures have shifted fundamentally. Traditional systems—fixed radar, manual border screening, rule-based network monitoring, and acoustic submarine detection—were based on the assumption that threats could be identified and contained once visible. However, this reactive model is increasingly inadequate in contexts where cyberattacks occur in milliseconds, smuggling routes change dynamically, and aerial incursions exploit sensor gaps. These limitations are now measurable, documented, and costly.
The emergence of machine learning architectures—including supervised deep convolutional networks, gradient-boosted ensemble classifiers, and recurrent sequence models—combined with large-scale sensor fusion, satellite-based surveillance, and autonomous platforms operating across SAE J3016 autonomy levels L3–L5, has introduced a qualitatively different operational logic [1,2,3]. Predictive security systems no longer wait for threats to appear; they analyze behavioral patterns, historical data, and real-time signals to estimate where and when risks may emerge. This shift from detection to anticipation is not only a technical upgrade but also a redefinition of institutional capabilities and performance standards.
Operational evidence increasingly supports this shift. AI-assisted Security Operations Centers have reduced uninvestigated alerts from about 67% of daily volume to nearly zero [4]. Predictive maritime surveillance has expanded detection scope eighteenfold compared with conventional sensors [5], while biometric border platforms process millions of travelers annually with identity-matching accuracy above 99% [6]. Although each result reflects advances in specific domains, together they reveal a systemic transition in the design, deployment, and evaluation of national security infrastructure. Figure 1 further shows that “information” is the dominant concept in the literature, confirming the central role of information technologies. Meanwhile, “social” and “territorial” appear with moderate frequency, whereas “military,” “population,” and “communication” remain underexplored, indicating relevant research gaps.
Despite this progress, the literature remains fragmented. Research has advanced on AI in cybersecurity [3], autonomous maritime surveillance [7], and biometric border identification [8], but these areas have largely developed in parallel, without a unified comparative framework. This limits the ability of defense planners, technology implementers, and policymakers to identify where predictive approaches offer the strongest operational benefits and where major challenges persist. As a result, investment decisions often rely on isolated case studies or vendor claims rather than systematically evaluated evidence [9,10,11,12].
This study addresses this gap through a PRISMA®-based systematic scoping review of 173 sources, including 143 peer-reviewed studies and 30 institutional reports retrieved from SCOPUS, ScienceDirect, Web of Science, IEEE Xplore, Taylor & Francis, ProQuest, and PubMed. Of these, 42 studies form the core empirical subset documenting quantified reactive-to-predictive performance transitions, while all 173 sources inform the broader synthesis. The analysis is structured around four research questions covering technological milestones, operational principles, implementation challenges, and future development trajectories. The study’s main contribution is a multidimensional evaluation framework that integrates technical performance, operational throughput, and organizational resilience metrics to support cross-domain comparison and evidence-based institutional planning.
The paper is organized as follows. Section 2 presents the methodology. Section 3 examines predictive technologies by security domain, along with cross-cutting challenges and future research directions. Section 4 analyzes convergent patterns across the five domains, Section 5 discusses implications for governance, institutional design, and research, and Section 6 presents the conclusions. The review argues that the reactive-to-predictive transition is not merely a domain-specific engineering advance, but a systemic institutional shift driven by three converging forces: mature machine learning architectures, unified data infrastructure, and operational evidence strong enough to justify governance and organizational change. Understanding these forces as an integrated triad constitutes the main conceptual contribution of this synthesis.

1.1. Theoretical and Conceptual Background

The technological evolution of strategic security infrastructure reflects a progressive transition from systems primarily designed to respond to observable incidents toward integrated architectures capable of detecting patterns, estimating risks, and supporting anticipatory decision-making. This transition does not imply the complete replacement of reactive mechanisms. Instead, it represents the development of layered security architectures in which detection, prediction, prevention, response, recovery, and institutional learning operate as interconnected functions.
For the purposes of this systematic review, five concepts provide the analytical basis for examining this transformation: reactive systems, predictive intelligence systems, anticipatory governance, strategic security infrastructures, and institutional resilience. These definitions are applied consistently throughout the review to classify the technologies, operational capabilities, and institutional mechanisms reported in the selected studies.

1.1.1. Reactive Security Systems

Reactive security systems are technological and organizational mechanisms designed to detect, report, contain, and respond to threats after they become observable within a monitored environment. Their operation follows a stimulus–response logic in which institutional action begins only after an incident, anomaly, or security breach has been detected. Examples include alarm systems, conventional video surveillance platforms, intrusion detection systems, and emergency response protocols. These technologies remain essential for incident containment, damage mitigation, evidence collection, and operational recovery. However, their effectiveness may be limited by detection delays, fragmented information flows, restricted situational awareness, and their dependence on post-event analysis. Within this review, reactive systems are considered the foundational layer of strategic security infrastructures upon which more advanced analytical and predictive capabilities are progressively developed.

1.1.2. Predictive Intelligence Systems

Predictive intelligence systems are technological architectures that integrate historical and real-time data to estimate the probability, location, timing, or potential impact of future security events. Their purpose is to identify emerging threats before they fully materialize and to provide decision-makers with actionable risk assessments.
These systems commonly combine artificial intelligence, supervised and unsupervised machine learning, sensor fusion, anomaly detection, behavioral analytics, pattern recognition, and spatiotemporal modelling. They process continuous data streams obtained from sources such as surveillance sensors, satellite imagery, radar platforms, cybersecurity logs, border control systems, unmanned vehicles, communication networks, and open-source intelligence. Their outputs may include probability-based alerts, risk maps, threat classifications, anomaly indicators, and operational forecasts. These outputs support the prioritization of threats, anticipatory resource allocation, and strategic planning. Nevertheless, they represent probabilistic estimations rather than deterministic predictions.

1.1.3. Anticipatory Governance

Anticipatory governance refers to the institutional frameworks and decision-making processes through which emerging risks are identified, interpreted, and managed before they escalate into critical security events. It incorporates future-oriented mechanisms such as horizon scanning, scenario planning, early-warning indicators, strategic forecasting, simulation, and risk modelling into policy and operational planning.
In the context of strategic security infrastructures, anticipatory governance connects technological forecasting with institutional action. It enables predictive information to be translated into preventive measures, contingency planning, interagency coordination, and anticipatory resource deployment.

1.1.4. Strategic Security Infrastructures

Strategic security infrastructures comprise the physical, digital, informational, and organizational systems whose disruption or degradation could significantly affect national security, territorial integrity, public safety, or the continuity of essential services.
These infrastructures include space-surveillance networks, satellite communication systems, maritime domain awareness platforms, border management architectures, cybersecurity operations centers, air traffic management systems, military communication networks, emergency-response platforms, and integrated command-and-control environments. Their strategic relevance is determined not only by their physical assets but also by their dependence on interconnected data platforms, communication protocols, artificial intelligence models, cloud services, skilled personnel, and interinstitutional coordination. Consequently, their disruption may result from physical attacks, cyber intrusions, data manipulation, system failures, supply chain interruptions, technological obsolescence, or institutional fragmentation.

1.1.5. Institutional Resilience

Institutional resilience is the capacity of security institutions to anticipate, absorb, withstand, adapt to, and recover from operational disruptions without experiencing systemic failure. It combines technical robustness with organizational adaptability.
Technical resilience includes system redundancy, secure data management, alternative communication channels, distributed computing, cybersecurity protection, maintainability, and continuity procedures. Organizational resilience includes trained personnel, adaptive leadership, flexible authority structures, interagency coordination, decentralized decision-making, and institutional learning. In predictive security environments, resilience also requires institutions to maintain operational capacity when automated systems fail, produce inconsistent results, or operate with incomplete information. Human expertise, procedural redundancy, clear responsibility structures, and continuous evaluation are therefore essential.

2. Methodology

This review follows the PRISMA® extension for scoping studies, as its objective is to map the evolution of predictive security technologies across five heterogeneous operational domains rather than conduct a narrow causal or quantitative synthesis. The complete protocol, including the pre-registered search strategy and data extraction template, is documented in [13]. The Supplementary Material is the PRISMA 2020 checklist. A scoping design was therefore preferred over a systematic review or meta-analysis because the evidence base is diverse and requires conceptual synthesis rather than statistical aggregation.
The corpus includes peer-reviewed experimental studies, institutional reports, and documented case studies. Because performance indicators are domain-specific and not directly comparable across sectors, cross-domain findings are interpreted as synthetic comparisons rather than statistical equivalences. Claims are also classified by epistemic strength, distinguishing findings supported by multiple independent studies or verified large-scale deployments from those based on single-case studies, pilot projects, or non-independently validated vendor data.
The literature search covered seven indexed databases: SCOPUS, ScienceDirect, Web of Science, Taylor & Francis, ProQuest, PubMed, and IEEE Xplore. These sources were selected to capture both technical fields, such as engineering and applied computing, and institutional perspectives from defense studies, technology policy, and the social sciences. Publications from the last ten years were considered, with no language restrictions during the initial identification stage.
The review followed three phases. First, the research questions and conceptual boundaries were defined, distinguishing reactive technologies—those that detect and respond to visible threats—from predictive systems that anticipate risks through behavioral analysis, machine learning, and real-time sensor fusion. Second, these boundaries were translated into search strings and eligibility criteria. Third, screening, full-text assessment, data extraction, and quality appraisal were conducted.
The review was guided by one overarching question: how has the shift from reactive to predictive technologies transformed national security infrastructures across spatial, maritime, border, cybersecurity, and airspace domains? Four complementary sub-questions further structured the analysis.
RQ1. Which technological milestones have most significantly shifted security infrastructure from reactive to predictive operational models over the past two decades, and what measurable performance gains have accompanied those shifts?
RQ2. What are the technical principles underlying predictive security systems, and how do they differ architecturally from the reactive systems they are displacing?
RQ3. What implementation challenges—technical, organizational, ethical, and regulatory—arise when deploying predictive technologies within national security contexts?
RQ4. What development trajectories are emerging at the frontier of predictive security, and what conditions would need to be met for their broader operational adoption?
These questions were not applied uniformly; each source contributed to the sub-questions relevant to its scope. Study quality was assessed using four criteria: alignment with the reactive-to-predictive transition, technical depth, discussion of implementation limitations, and SJR journal ranking, with Q1 publications weighted most heavily. Two reviewers independently assessed each study, resolving disagreements through discussion and consulting a third reviewer when needed. Inter-rater reliability, measured with Cohen’s Kappa, was 0.458 at initial screening and increased to 0.71 after consensus, indicating acceptable agreement for a scoping review. Table 1 presents the questions for the quality assessment of the articles and the criteria that were met and therefore they were included.

2.1. Search Strategy

The bibliographic search was organized into three conceptual clusters: the technologies analyzed, the security domains in which they operate, and the transition from reactive to predictive models. Search terms were identified through preliminary scoping and refined according to each database’s controlled vocabulary. Table 2 presents the final search strings used across the seven sources.
Core terms included “technological evolution,” “predictive security systems,” “artificial intelligence,” “machine learning,” “cybersecurity frameworks,” “surveillance systems,” “autonomous platforms,” and “emerging defense innovations.” These were combined with domain descriptors such as “maritime domain awareness,” “airspace surveillance,” “border management,” and “space situational awareness” using Boolean operators. Search structures were adapted to each database, applying phrase-level operators in SCOPUS and Web of Science, and title-field restrictions in IEEE Xplore and Taylor & Francis to control retrieval volume. No language restrictions were applied. Publications from 2010 to 2025 were included, reflecting the period in which machine learning became operationally relevant in security research. Indexed conference proceedings were also considered when they met the quality criteria described in Section 2.

2.2. Screening and Selection

According to the PRISMA® flow diagram in Figure 2, the database search retrieved 431 records from SCOPUS (n = 202), ProQuest (n = 83), IEEE Xplore (n = 48), Web of Science (n = 43), ScienceDirect (n = 43), and Taylor & Francis (n = 12). An additional 32 records were identified through reports, books, and institutional websites. After removing 45 duplicates, 386 records underwent title screening, of which 126 were excluded for lacking relevance to strategic security or defense infrastructures.
The remaining 260 records were screened by abstract, leading to 115 exclusions due to limited technical specificity or thematic misalignment with the reactive-to-predictive transition. This left 145 records for full-text assessment; 2 were inaccessible, resulting in 143 eligible database studies. In parallel, 30 complementary records were assessed, with 28 retained. The final review corpus therefore included 173 sources: 143 peer-reviewed studies and 30 complementary reports.

2.3. Inclusion Criteria

Articles were considered eligible when their primary subject was the analysis of technologies applied within the defense and national security sector. Beyond this threshold condition, selected publications were required to address at least one of three substantive dimensions: the key technological developments underpinning security applications, the operational impact and measurable outcomes associated with their implementation, or the challenges and future prospects that condition their adoption and evolution. Studies that mentioned security technologies tangentially—as illustrative examples or secondary context—without examining their functioning, performance, or institutional implications did not meet this criterion.
Data extracted from eligible sources were organized in a structured spreadsheet in which each reference was assigned a systematic code to ensure full traceability between the evidence base and the findings reported in subsequent sections. Table 2 presents the search strings applied across each database during the identification stage.

2.4. Exclusion Criteria

Full-text articles were excluded when their main focus fell outside the review’s objectives, even if they mentioned security technologies. Three types of studies were ruled out: those addressing only indirect consequences of technology use, such as social, institutional, or policy effects; those focused on detailed design or engineering aspects rather than security deployment and performance; and those centered mainly on ethical, legal, social, or economic issues, where technology served only as a basis for normative analysis. Security-related terminology alone was not sufficient for inclusion, and studies meeting any exclusion criterion were removed.

2.5. Analytical Framework and Scope of Evidence Synthesis

This review performs a systematic bibliographic synthesis function: it maps, categorizes, and comparatively analyzes published evidence on deployed predictive security systems. It does not perform original modelling, simulation, or empirical validation of predictive algorithms. This distinction is inherent to the scoping review format and should be interpreted as a design feature rather than a limitation: the contribution lies in the integrative synthesis across five domains that no single primary study encompasses.
The modelling architectures documented across the five domains include: supervised deep learning (convolutional networks for spatial feature extraction, recurrent networks for temporal sequence modelling); unsupervised anomaly detection (autoencoders, isolation forests); ensemble methods (gradient-boosted trees, random forests); federated learning with differential privacy; and post-quantum lattice-based cryptographic algorithms. Each is described in terms of its training paradigm, architectural parameters where reported in primary sources, and validated performance outcomes—rather than reconstructed from first principles, which would exceed the scope of a scoping review and risk introducing artefacts absent from the documented evidence.
Limitations of the library-based methodology: (1) Performance metrics reported across domains are not directly comparable due to differences in measurement conditions, validation datasets, and reporting conventions. (2) Vendor-reported operational benchmarks have not been independently verified and are labeled throughout. (3) The absence of original modelling means that interaction effects between technologies, cross-domain transfer of predictive architectures, and system-of-systems emergent properties cannot be assessed from this evidence base alone. These constitute priority directions for future primary research using simulation, digital twin environments, or controlled operational trials.

3. Results

3.1. Space Security

3.1.1. Emerging Predictive Technologies in Space Security

Spatial security has evolved from systems designed to observe and report, to those that monitor and respond faster, and finally to predictive architectures capable of anticipating threats before they become incidents. This progression is essential for understanding current capabilities, as predictive systems gain meaning only when compared with the reactive infrastructures they have replaced (Figure 3a) [14,15,16].
The first generation of space surveillance relied on infrared detection and optical tracking to catalogue existing orbital objects rather than predict their behavior. The Midcourse Space Experiment satellite, launched in 1996, introduced infrared sensing for detecting objects and thermal signatures, while the Space-Based Surveillance System, deployed in 2003, expanded optical tracking. These platforms generated data but not assessments. A transition began with the Geosynchronous Space Situational Awareness Program in 2010 and the consolidation of Space Situational Awareness frameworks around 2015, which integrated multiple sensor sources and increased orbital data availability [5,17,18]. However, the logic remained reactive: systems tracked objects and flagged conjunctions only after proximity thresholds had been crossed [19,20,21,22,23,24].
Genuine predictive capacity emerged in 2018 with the integration of supervised convolutional neural networks and random forest classifiers for space object classification. These tools enabled automated distinction between debris, active satellites, and rocket bodies using radar cross-section signatures, shifting the focus from cataloguing objects to assessing collision risk: which configurations were likely to become dangerous and when [18,25,26,27,28].
This transition accelerated with event-based cameras for rapid orbital anomaly detection in 2022, DebriSen technology for monitoring sub-catalogued debris in 2023, and federated AI architectures for distributed sensor management without centralizing raw data in 2024 [5,17,29]. By 2025, global governance frameworks for space cybersecurity extended anticipatory protection beyond physical tracking to the digital integrity of orbital infrastructures [30,31,32,33,34].
At the territorial level, geospatial platforms have followed a similar trajectory. Geographic Information Systems were first used for reactive mapping, including event documentation, boundary delineation, and post-incident assessment [35,36,37]. The integration of real-time sensors, big data pipelines, and machine learning has transformed them into early warning tools capable of detecting anomalous spatial patterns before they escalate. Digital twins of critical infrastructure, combined with predictive analytics, now allow planners to simulate threats and assess response options before events occur—capabilities unavailable in earlier reactive systems [38,39].

3.1.2. Performance Outcomes: Space Security

The performance gap between reactive and predictive space surveillance architectures is among the most significant identified in this review. Reactive systems based on Two-Line Element sets and SGP4 orbital propagation processed about 500 Conjunction Data Messages (CDMs) per day, with 65% threat detection accuracy and a response latency of around 24 h. Predictive architectures integrating machine learning and deep learning now process 2 million CDMs daily—a 4000-fold throughput increase—while reaching 92% accuracy and reducing latency to 30 min [5,17,18]. False alarms have fallen by 77%, reflecting improved uncertainty quantification: unlike TLE-based systems, which lacked reliable positional error estimates, neural networks generate probabilistic error ellipsoids that help operators distinguish real conjunction risks from artefacts of imprecise orbit determination [5]. Detection scope has also expanded from roughly 27,000 catalogued objects to more than 500,000, an 18-fold increase made necessary by the growing density and maneuver frequency of commercial constellations in low Earth orbit [17,29].
Specific space safety functions show similar gains. Data management effectiveness rose from 30% to 95% after periodic TLE updates were replaced by continuous Data Lake architectures integrating radar, optical, and laser-ranging data with full provenance tracking [40]. Conjunction detection improved by 111%, supported by atmospheric modeling that reduced position prediction errors from kilometer-scale deviations to within 150 m. Covariance precision improved by 120%, enabling risk assessments based on quantified confidence intervals rather than deterministic point estimates [5]. Risk prediction capacity increased by 84% through Hidden Markov Models that represent conjunctions as evolving temporal sequences, while maneuver coordination efficiency improved by 64%, extending planning horizons from 2 to 3 days to one week and enabling fuel-optimal avoidance strategies beyond the capacity of reactive systems [5,18].
The throughput trajectory further illustrates the qualitative shift. Manual analysis supported about 50 conjunction assessments per analyst per day, limited by human cognitive capacity. TLE-based automation increased this to around 500 CDMs daily before reaching the computational limits of physics-equation models. Deep learning systems now process 2 million CDMs per day at 92% accuracy, achieving 40,000 times the throughput of manual processing while improving precision [17,40]. This simultaneous gain in scale and accuracy reflects the advantage of pattern-recognition architectures over rule-based propagation models. With orbital populations projected to approach 50,000 active satellites by 2030, predictive scalability is not an operational luxury but a structural requirement for maintaining situational awareness in an increasingly congested orbital environment [17,29].
Figure 3a reports normalized performance metrics for cross-system comparison. Threat detection rate measures the proportion of orbital risk events correctly identified by TLE/SGP4 pipelines versus ML/DL architectures trained on historical conjunction datasets. Response time captures latency between detection and operational alert, while false alarm rate measures misclassified events that increase ground-control workload. Detection scope and CDM processing capacity complete the main indicators. Figure 3b consolidates operational effectiveness variables—data management, maneuver coordination, object identification, risk prediction, covariance precision, and conjunction detection—from case studies, peer-reviewed literature, and technical reports from the European Space Agency and comparable institutions.

3.2. Maritime Security

3.2.1. Emerging Predictive Technologies in Maritime Security

Maritime surveillance has undergone one of the deepest technological transformations among security domains because its operational environment is vast, dynamic, and largely invisible from shore. Early acoustic systems could confirm that a submarine had crossed a monitored corridor, but not where it was heading or when it might return. This gap between detection and anticipation defined the reactive era and justified the shift toward predictive surveillance (Figure 4) [41,42,43,44,45].
The Sound Surveillance System, deployed in 1950, established the first-generation model: fixed hydrophone arrays that detected vessel movements through acoustic signatures and supported observation and post-detection response [46]. For decades, improvements in sensor sensitivity and coverage expanded this model without changing its reactive logic. A major shift occurred in 2010 with satellite reception of Automatic Identification System signals, which enabled near-global tracking of vessel position, speed, and heading, although still focused on reporting current behavior rather than predicting future actions [46]. Adaptive multisensor maritime situational awareness systems introduced in 2017 and acoustic buoys enhanced with advanced signal processing in 2018 added analytical depth but did not yet constitute genuine prediction [40,47,48,49,50].
The predictive threshold was crossed in the early 2020s. Autonomous vessel experiments under the e-Navigation initiative in 2020 showed that maritime platforms could operate remotely, creating a basis for later predictive architectures [7]. In 2022, BiLSTM and Transformer-based models applied to AIS data advanced from tracking to behavioral analysis, detecting probabilistic anomalies in speed, heading, and port call patterns associated with illicit activity before physical interception [51]. In 2023, self-supervised models targeted intentional AIS deactivation, a common deception tactic in smuggling and illegal fishing [52]. By 2024, deep recurrent neural networks were analyzing complex traffic flows across maritime zones [53], while convolutional neural networks applied to satellite imagery extended automated vessel detection beyond AIS coverage [54].
The predictive generation differs not only in speed or sensor resolution, but in analytical purpose. Reactive systems ask what is happening now; predictive systems estimate what is likely to happen next and where intervention would be most effective. Maritime Domain Awareness institutionalizes this shift by integrating satellite feeds, coastal radar, underwater acoustic data, and behavioral analytics into a unified operational picture for anticipatory decision-making [55]. Synthetic aperture radar microsatellite constellations with VDES/AIS payloads further extend high-resolution monitoring to remote areas without surface infrastructure, closing coverage gaps inherent to reactive systems [56]. Unmanned surface vessels and autonomous underwater platforms also expand surveillance reach into environments where persistent human presence is impractical [7,57,58,59,60,61].

3.2.2. Performance Outcomes: Maritime Security

The operational impact of the shift from reactive to predictive maritime surveillance is evident in three areas: incident prevention, navigation in congested environments, and traffic flow forecasting accuracy. Across these dimensions, predictive systems show gains that reflect a structural expansion of maritime security capabilities, rather than incremental engineering improvements [62].
At the incident prevention level, organizations using AI-driven risk management report 40–60% reductions in reportable accidents and safety incidents, with a central estimate of 50% [7,54]. These benefits also reduce operational costs: compliance-related administrative expenses have fallen by an average of 40% as automated monitoring, reporting, and documentation replace personnel-intensive workflows. Risk-adjusted insurance premiums have also declined, with insurers reducing costs by an average of 17.5% for operators with verified predictive risk management capabilities. Figure 5a–c illustrate this asymmetry: reactive systems absorb incident costs after they occur, while predictive systems reduce incident probability, influencing both operational budgets and insurance pricing.
The performance gap is especially clear in high-density navigation, where decision volume and speed exceed the capacity of human operators using conventional methods. The Yara Birkeland, operating autonomously in Norwegian coastal waters since March 2023, demonstrated collision avoidance in complex real-traffic conditions that would otherwise require continuous human intervention [7]. The autonomous voyage of Suzaku across Tokyo Bay—a 790 km round trip through one of the world’s most congested corridors—completed 107 collision avoidance maneuvers involving 400–500 vessels without human intervention. Samsung’s Self-Autonomous Navigation System, tested aboard a 15,000 TEU vessel over a 1500 km voyage, identified more than 9000 obstacles within a 50 km radius, issued 90 deviation recommendations during critical encounters, and achieved route accuracy above 90% compared with routes planned by experienced navigators [7]. These cases show that predictive architectures based on continuous sensor fusion and probabilistic modeling outperform reactive systems in conditions requiring sustained, high-frequency decisions under spatial and temporal constraints.
The most precisely quantified performance differential in this domain concerns traffic flow forecasting, where a direct comparison between conventional statistical methods and deep learning architectures has been conducted using real AIS data from the Port of Singapore. The traditional Support Vector Regression baseline produced a Normalized Mean Absolute Error of 50.1% and a Normalized Root Mean Square Error of 51.2%—error magnitudes that render the model operationally unreliable for port planning and resource allocation [53]. The hybrid BDLSTM-CNN architecture, combining bidirectional Long Short-Term Memory networks with Convolutional Neural Network layers, reduced those errors to 22.0% NMAE and 20.0% NRMSE, representing improvements of 56% and 61% respectively, and achieved prediction accuracy of 77.5–80% from as few as five historical data points [54]. The architectural advantage reflects a capability that conventional methods lack entirely: simultaneous modeling of spatial dependencies—vessel movement patterns across geographic zones—and temporal dependencies—sequential flow dynamics over time—within a single integrated framework. The practical consequences are direct: estimated time of arrival predictions become reliable enough to support just-in-time port operations, anomaly detection becomes early enough to permit intervention before incidents develop, and route optimization becomes precise enough to reduce fuel consumption and emissions at scale. These are not improvements in the efficiency of reactive monitoring—they are capabilities that reactive monitoring was unable to provide.
Figure 5 reports performance using two complementary error metrics. NMAE, or Normalized Mean Absolute Error, measures average prediction deviations relative to observed traffic volumes, treating all errors proportionally. NRMSE, or Normalized Root Mean Square Error, is stricter because it squares deviations before averaging, making it more sensitive to large errors. In both metrics, lower values indicate better performance. Together, NMAE captures typical prediction quality, while NRMSE reveals occasional large errors that could undermine operational planning.
The comparison is between SVR, the conventional statistical baseline for maritime traffic forecasting, and BDLSTM-CNN, the hybrid deep learning model reported above. Their main difference is representational capacity rather than speed. SVR maps inputs into a high-dimensional feature space and fits a regression surface, treating each prediction independently. BDLSTM-CNN learns both spatial traffic patterns across geographic zones and temporal flow sequences, using a bidirectional architecture to capture dependencies missed by unidirectional models. Accuracy represents the proportion of predictions within an operationally acceptable deviation threshold and indicates whether the model can support real-time port management rather than merely describe past traffic patterns.

3.3. Border Control

3.3.1. Emerging Predictive Technologies in Border Control

Border security infrastructure has evolved through three phases over the past three decades, each shaped by a different relationship between data, detection, and decision-making (Figure 6a). The first relied on physical presence and sensor coverage to extend human observation across large territories. The second introduced digital processing and faster response loops, while still assuming that threats had to become visible before action. The third, still consolidating, treats the border as a data environment to be modeled, where irregular movement, identity fraud, and contraband flows can be anticipated before reaching the checkpoint [63,64,65].
The reactive era is illustrated by SBInet, deployed in 1996 as a sensor and radar network designed to detect unauthorized movement and alert human operators [66]. Biometric eGates, introduced in 2003, automated part of identity verification and reduced checkpoint processing time, but still focused on confirming identity at crossing rather than assessing risk in advance [8]. During the 2010s, multi-sensor systems combining ground radar and thermal imaging improved detection in low-visibility conditions [67], while AI-assisted drones in 2015 and automated intrusion detection systems in 2018 expanded coverage and reduced response latency [68,69]. Despite these gains, the logic remained reactive: detect what had entered the monitored zone and respond.
The shift toward prediction became evident in the early 2020s. Computer vision systems deployed in 2020 automated classification at border points, identifying behavioral and documentary anomalies before crossings were completed [6]. Muon tomography, introduced in 2021, extended anticipation to cargo inspection by detecting density anomalies consistent with concealed contraband without physical intervention [67]. That same year, federated AI architectures integrated with IoT sensor networks allowed distributed border systems to share analytical outputs without centralizing raw data, preserving data sovereignty while enabling system-wide pattern recognition [70,71]. By 2022, predictive migration analytics supported resource allocation based on modeled flow probabilities rather than observed arrivals [72,73,74].
Together, these developments show a qualitative shift in border infrastructure. Reactive systems asked who is crossing now; predictive systems ask where risks are likely to emerge based on movement patterns, document characteristics, behavioral indicators, and historical flows. The convergence of biometric authentication, IoT sensors, federated learning, and real-time behavioral analytics has made this earlier intervention operationally viable and redefined modern border security performance.

3.3.2. Performance Outcomes: Border Control

The performance gap between reactive inspection and predictive risk-based border systems is highly quantifiable because both manage the same throughput—travelers and cargo—and can be assessed through detection rate, processing speed, and operational efficiency (Figure 6).
Reactive border inspection has historically used two modes, each with clear limits. Random sampling, common in high-volume settings where full inspection is impractical, achieves about 15% detection and 30% operational efficiency, allowing many non-compliant shipments and fraudulent entries to pass undetected as a structural limitation of the method. Complete manual inspection increases detection to about 60%, but reduces efficiency to 20% and process speed to 5% of capacity, creating bottlenecks that affect both security and legitimate trade [75]. In both cases, inspection resources are allocated without prior risk information, treating every traveler and container as an equivalent unknown until physical evidence appears.
Predictive systems change this logic. Taiwan’s Border Prediction Intelligent system uses shipment risk scoring to raise detection of non-compliant products from 3.0% to 4.7%, while reducing post-market detection from 2.1% to 1.9%, indicating earlier interception in the supply chain [76]. Its operational efficiency reaches 85% and process speed 70%, compared with 20% and 5% under complete manual inspection. China’s Intelligent Customs Inspection system combines AI, computer vision, and X-ray analysis to process more than 10 million containers annually, with contraband detection accuracy above 95%, processing times about 50% shorter than manual procedures, 95% efficiency, and 90% process speed [75]. For travelers, the CBP Traveler Verification Service has processed over 193 million people with 99.4% biometric matching accuracy, reducing verification time to about 3.5 s per traveler, a 94% reduction compared with conventional document checks [6].
The European Union’s Entry/Exit System, operational from October 2025, offers the largest-scale validation of predictive border management reviewed here. In its first months, it registered 17 million travelers and 30 million border crossings, identifying 16,000 entry denials linked to identity fraud, document falsification, and related grounds, as well as 4000 authorized-stay violations—infractions that manual processing at this scale could not consistently detect [76]. Deployment in ports such as Barcelona, with 33 automated border gates and 134 verification kiosks across terminals handling 5.4 million passengers annually, shows that predictive architectures can operate at continental scale while maintaining detection standards beyond reactive capacity. However, stabilization challenges in three member states during rollout show that predictive border infrastructure also entails institutional and integration costs, as discussed in Section 3.6.
Major International Predictive Security Programs
  • EU—Entry/Exit System (EES)
The European Union’s EES, administered by eu-LISA and operational from October 2025, constitutes the largest biometric border management deployment globally. Its architecture integrates facial recognition (ISO/IEC 19794-5 compliant) [77], fingerprint verification (4-4-2 slap capture), and automated overstay detection across 1800+ border crossing points. Within initial months: 17 million travelers registered, 30 million crossings processed, 16,000 entry denials issued, 4000 overstay violations detected.
  • EU—U-space Framework
The SESAR JU U-space ConOps (4th ed., 2023) establishes a digital traffic management ecosystem for unmanned aircraft in very low-level airspace (VLL, 0–150 m AGL). Its predictive conflict resolution engine applies dynamic programming over 4D trajectory envelopes, issuing pre-tactical deconfliction advisories up to 30 min before projected conflicts materialize, integrated with ASTERIX Cat 129 surveillance feeds across 27 EU member states.
  • US—NextGen Air Traffic Modernization
The FAA NextGen program transitions US national airspace to Performance-Based Navigation (PBN) supported by satellite-based ADS-B, Data Communications (Data Comm), and System Wide Information Management (SWIM). Its predictive Traffic Flow Management module applies ensemble weather-impact models and ML-based demand forecasting to generate Ground Delay Program advisories 6–8 h in advance. Documented outcomes: 35% reduction in weather-related delays and $2.7B in annual fuel savings.
  • US—NIST Post-Quantum Cryptography (FIPS 203/204)
Finalized August 2024, FIPS 203 (ML-KEM lattice-based key encapsulation) and FIPS 204 (ML-DSA lattice-based digital signatures) are the first operational post-quantum cryptographic standards for federal systems, hardening infrastructure against Shor’s algorithm attacks before quantum processors reach cryptographically relevant scale (estimated 2030–2035 per NSA CNSA 2.0 roadmap).
  • Asia—Indo-Pacific Maritime Domain Awareness (IPMDA)
The Quad IPMDA initiative (2022) fuses dark vessel detection from SAR microsatellite constellations, AIS behavioral analytics, and RF emission monitoring across 3 million square nautical miles of Indo-Pacific waters, targeting IUU fishing and sanctions evasion. The architecture demonstrates federated multi-national predictive MDA without centralized raw data pools.
  • China—Intelligent Customs Inspection (ICI)
The General Administration of Customs deploys dual-energy X-ray tomography with YOLOv5-based object detection and risk-scoring ML trained on 10+ years of violations data. Processes 10M+ containers annually: 95%+ contraband detection accuracy, 50% processing time reduction, 95% operational efficiency.
Taken across these cases, the comparative data establish a consistent pattern: predictive border systems do not simply process the same inspections faster—they change which inspections are conducted, concentrating resources where prior risk assessment indicates they are most likely to be productive. That reallocation is what drives the simultaneous improvement in detection rates and processing efficiency that reactive methods, by design, cannot achieve.
Figure 6 compares four border management systems and two reactive baselines using terminology from border control and customs literature. The systems include CBP TVS, the U.S. biometric facial recognition platform for matching travelers against secure identity databases; ICI, an AI-assisted cargo screening system combining X-ray imaging, computer vision, and machine learning to detect container anomalies; BPI, a predictive risk-based framework for selecting shipments or travelers for targeted inspection; and EES, the European Union’s centralized biometric platform for recording entries, exits, and refusals of third-country nationals at Schengen external borders, administered by eu-LISA.
Performance is reported through three normalized percentage metrics. Operational efficiency reflects security outcomes relative to personnel and processing resources. Detection rate measures the proportion of true non-compliant cases correctly identified. Process speed captures inspection cycle rapidity compared with conventional procedures. Together, these metrics show the main difference between reactive and predictive architectures: random sampling and manual inspection tend to improve one dimension at the expense of others, while AI-driven risk scoring enables simultaneous gains in efficiency, detection, and speed. Volume figures are expressed in millions (M) and thousands (K), following eu-LISA and national customs reporting conventions.

3.4. Cybersecurity

3.4.1. Emerging Predictive Technologies in Cybersecurity

Cybersecurity is the domain where the gap between reactive and predictive approaches carries the most immediate operational cost. An intrusion detection system that alerts after a breach has occurred has already failed its primary purpose, since the attacker is already inside. This limitation drove decades of investment in faster detection and response, until it became clear that speed alone could not solve an architectural problem. The shift toward prediction—identifying threat indicators before an attack is completed—required not only better algorithms but a new understanding of cybersecurity infrastructure (Figure 7b) [78,79,80,81,82].
The reactive era of national cybersecurity was based on monitoring traffic that had already entered a network. Bro/Zeek, developed in 1999, established the model as a high-performance Network Intrusion Detection System that analyzed live traffic and flagged anomalies linked to known attack signatures [83]. Although effective, it operated on events already underway. Later advances improved analytical capacity without changing this orientation: a 2006 framework for evaluating detection efficiency supported national cybersecurity metrics [84]; Internet Background Radiation telescopes introduced in 2010 expanded visibility into large-scale malicious traffic [85]; and Software-Defined Networking in 2013 enabled centralized control and faster incident response [86]. Institutional capacity also grew through cyber range environments such as CyRIS in 2016 and the NICE Framework in 2017 for workforce competency standards [87,88]. These systems made reactive cybersecurity more efficient, but did not yet enable anticipation [89,90,91].
The transition toward predictive operation began in earnest toward the end of the 2010s. Supervised deep learning models—specifically multi-layer perceptrons with 8-layer architectures and bidirectional LSTM networks trained on labelled network traffic datasets—deployed in 2019 moved beyond signature matching to behavioral analysis, identifying complex attack patterns in network traffic that had no prior signature in known threat databases through learned feature representations rather than static rule matching [75]. This represented a qualitative shift: rather than asking whether observed traffic matched a catalogued threat, these systems assessed whether the pattern of activity was consistent with attack behavior—a distinction that allowed detection of novel threats that reactive systems were structurally unable to recognize. The standardization of Zero Trust architecture under NIST SP 800–207 in 2020 reinforced this shift at the infrastructure level, replacing perimeter-based access control with continuous verification that treated every connection as potentially adversarial regardless of its origin [92,93,94,95,96,97,98].
More recent developments have extended predictive capacity across organizational boundaries and into the post-quantum threat environment. The adoption of STIX/TAXII protocols with OAuth2 in 2021 enabled automated threat intelligence sharing among institutions, allowing predictive models trained on one organization’s traffic to inform detection at others before the same attack vector reached them [99]. The CycloneDX 1.5 Software Bill of Materialsframework introduced in 2023 extended anticipatory risk management to software supply chains, enabling organizations to identify vulnerable components before exploitation rather than after [100]. Post-quantum cryptography standards under FIPS 203/204 [101], established in 2024, addressed a threat that does not yet exist at operational scale—an explicit act of anticipatory governance rather than reactive adaptation [102]. Federated learning applied to collaborative intrusion detection systems, emerging in 2025, has added a further dimension: organizations can now train shared threat detection models without exposing the raw network data that would be required under centralized architectures [103,104,105,106,107].
What the cybersecurity trajectory illustrates, more clearly than any other domain in this review, is that the reactive-to-predictive transition is not a single event but a compounding process. Each generation of predictive capability revealed the limits of the previous one and created the conditions—in data availability, computational infrastructure, and institutional readiness—for the next.

3.4.2. Performance Outcomes: Cybersecurity

The crisis in Security Operations Centers (SOCs) has reached levels that threaten national cyber defense, while predictive technologies show major improvements (Figure 8). Reactive SOCs without AI face an average of 4484 daily alerts, with peaks above 3000 in large enterprises, and 67% remain uninvestigated, leaving critical gaps undetected [108]. This overload has created a personnel crisis: 71% of analysts report burnout, 64% consider changing jobs, and the global cybersecurity workforce gap has reached 4.8 million positions [109,110]. The situation is further reflected in reports that 40% of alerts go uninvestigated and 60% of teams have suffered breaches linked to ignored alerts [111]. Predictive SOCs with AI reverse these conditions: processing capacity rises from 10% to 100%, all alerts are reviewed, burnout falls from 71% to 20%, and uninvestigated alerts drop to 0%. Some organizations reduce daily volumes from more than 1000 alerts to a few actionable incidents, achieving tenfold processing gains and full investigation coverage [112]. These results show that predictive automation is essential for sustaining national security operations [113,114].
Machine learning and deep learning models also outperform traditional signature-based detection. XGBoost reaches 97.2% threat classification accuracy, with precision, recall, and F1-scores above 94%, including 98.2% precision for password attacks and 93.0% for phishing detection [75]. CyberDetect-MLP, designed for IoT big data environments, achieves 98.87% accuracy and 99.10% ROC-AUC, surpassing Random Forest (94.21%), standard XGBoost (96.35%), and vanilla MLP (97.12%) by combining Kafka/Flume-HDFS-Spark pipelines, optimized 8-layer MLP architectures, and explainable AI tools such as Grad-CAM and SHAP [103]. In IoT network detection, CNNs achieve 96.37% accuracy, 96.15% precision, and 96.37% recall, while RNNs reach 96.56% accuracy, showing that deep learning detects complex attack patterns missed by traditional methods [115]. Ensemble deep learning with MPOA optimization reaches 97% accuracy, 95% specific precision, and strong recall and specificity, confirming the advantage of combined neural architectures [102]. These 96–99% precision rates mark a qualitative improvement over reactive systems based on manual signature updates and static rules [116,117].
The operational return on AI automation in SOCs is also measurable. Investigation time falls by 50% in many organizations, with reported reductions of 25–50% in the 2025 Pulse of the AI SOC Report [118], turning hour-long investigations into minute-scale processes. Routine task automation reaches 70%, allowing analysts to focus on the 30% of complex threats requiring expert judgment, while AI manages high-volume, low-complexity alerts [112]. Analyst overtime drops by 50% within six months, directly addressing burnout in the cybersecurity workforce [111]. Investigation coverage reaches 100%, eliminating the 40% of previously ignored alerts associated with breaches. Financial ROI can be expressed as: time saved × analyst hourly cost + prevented incidents × average incident cost − automation investment. With the average data breach costing $4.88 million, preventing even one incident can justify AI adoption [112]. Organizations relying only on manual processes risk being overwhelmed by alert volume, personnel shortages, and sophisticated attacks, making AI integration a strategic necessity for national cybersecurity [119,120].

3.5. Airspace Management

3.5.1. Emerging Predictive Technologies in Airspace Management

Airspace security poses a distinctive challenge in the reactive-to-predictive transition (Figure 9): monitored objects move rapidly, share infrastructure with civilian aviation, and now include thousands of low-altitude drones, often without flight plans or cooperative identification. Radar networks designed for commercial and military aircraft were not built for this level of unmanned system complexity. This gap between inherited reactive surveillance and modern airspace realities has driven the predictive transformation described here [121,122].
Mode S radar, introduced in 1969, established the reactive baseline by interrogating aircraft and receiving transponder responses, improving identification accuracy and reducing interference [123]. Its logic was to observe and identify aircraft already within monitored airspace, with no capacity for trajectory prediction or behavioral assessment. System Wide Information Management, integrated in 2005, unified aviation and meteorological data across air traffic management systems, improving coordination while preserving the reactive orientation [124]. GPS-based ADS-B, adopted in 2009, marked a stronger advance by allowing aircraft to broadcast position, speed, and trajectory data, expanding coverage and reducing reliance on ground radar [125]. However, it still reported current aircraft behavior rather than predicting future actions.
The 2010s created the data foundations for predictive airspace management. The OpenSky Network, launched in 2013, provided a large-scale ADS-B repository for studying flight patterns and detecting anomalies [126]. Passive radar technologies explored from 2014 onward showed that civil communication signals could support aircraft detection without dedicated transmitters, extending coverage at lower cost [127]. Satellite-based ADS-B, deployed in 2018, closed oceanic and remote-region blind spots, enabling near-global monitoring of equipped aircraft [128]. These advances did not yet constitute prediction, but they built the required data infrastructure [129].
The predictive phase accelerated in the early 2020s, largely due to unmanned aircraft integration. Multisensor fusion introduced in 2020 combined radar, optical, and radio frequency signals to improve drone detection and classification, addressing airspace users that ADS-B and Mode S were not designed to track [69]. U-space, developed in 2022, created a digital traffic management ecosystem for real-time drone coordination, predictive conflict resolution, and dynamic airspace allocation [130]. Remote ID, mandated in 2023, established continuous digital identification of drones and operators, shifting from post-incident identification to persistent anticipatory accountability [131].
Recent developments have expanded prediction to trajectory modeling and infrastructure protection. AI systems operational by 2024 can predict flight trajectories and detect anomalous deviations in ADS-B streams, enabling intervention before conflicts or incursions reach critical thresholds [132]. In 2025, cyber resilience protocols were incorporated into national airspace infrastructures, recognizing that the data and communication networks supporting predictive management are themselves attack surfaces [131]. Together, these developments define an airspace security architecture centered not on detection and response, but on continuous assessment and anticipatory management [133].

3.5.2. Performance Outcomes: Airspace Management

Predictive technologies affect airspace security across three operational areas: aircraft maintenance, runway and infrastructure monitoring, and air traffic management. Each shows a distinct shift from reactive to anticipatory systems, with measurable performance gains beyond the capacity of traditional architectures (Figure 10).
In aircraft maintenance, Delta Air Lines’ Advanced Predictive Engine system, operational since 2010, reduced maintenance-related flight cancellations from 5600 per year to 55 over eight years, a reduction of about 99% [134]. This was achieved through real-time monitoring of engine parameters and AI-based degradation modeling that identifies component failure risks before operational disruption occurs. The system processes more than 10,000 sensor parameters per engine per flight, allowing maintenance teams to receive specific, time-bounded recommendations instead of reacting to failures. Industry data confirm similar gains: predictive maintenance can reduce unplanned downtime by up to 70%, lower maintenance costs by 25–30%, and extend component lifespan by 20–40% through optimized intervention timing [134]. Parts forecasting accuracy has also increased from about 60% to over 90%, reducing inventory costs while ensuring availability. This shift from schedule-based replacement to condition-based intervention represents a structural reallocation of maintenance resources that reactive protocols cannot replicate.
Runway and airfield monitoring provides a second example. Foreign Object Debris causes an estimated $4.5 billion annually in engine damage, tire failures, and operational disruptions, largely due to the delay between debris deposition and human detection under visual inspection methods [71]. AI-powered computer vision achieves 96% defect-detection accuracy at 3 mm spatial resolution and operates eight times faster than manual inspection. At Calgary International Airport, autonomous UAS platforms using ResNet-50 and YOLO-v8 inspected three million square meters of pavement in 40 h, performing real-time feature extraction at 3 mm resolution—a task that would require several days using vehicle-based manual methods [71]. Integrated thermal imaging also detects subsurface degradation before visible cracking, enabling earlier and less costly intervention.
Air traffic management shows the broadest comparison. Reactive ATM systems based on fixed schedules, historical averages, and manual controller coordination achieve only 10–25% effectiveness in delay reduction, fuel efficiency, safety improvement, and throughput. Predictive ATM systems using real-time data fusion, machine learning trajectory prediction, and dynamic route optimization reach 85–96% effectiveness across the same dimensions [132]. The MIT Air-Guardian system illustrates this at the flight level by combining eye-tracking analytics with real-time flight data to detect risk conditions and provide decision support before pilot attention shifts to relevant instruments. At the airport level, predictive crew scheduling and fatigue management reduced ground delays by 6% and turnaround times by 4% at Rome Fiumicino Airport through resource allocation before demand peaks [132]. Across these applications, predictive systems do not simply accelerate reactive processes; they enable functions such as detecting subsurface runway degradation and anticipating pilot attentional gaps, which reactive architectures cannot provide.
Table 3 synthesizes the transition from reactive models to predictive intelligence systems across five strategic security domains. It identifies the main predictive technologies, performance gains, evidence validation levels, and technical, operational, and institutional challenges that may limit large-scale implementation.
Figure 10 uses terminology from aviation maintenance, airfield operations, and air traffic management that requires clarification for non-specialist readers.
In maintenance, predictive maintenance refers to condition-based intervention, where AI and machine learning models trained on sensor telemetry and historical failure data estimate component degradation before failure. This contrasts with reactive maintenance, which acts only after failure occurs. Three metrics describe its operational effects: unplanned downtime, or interruptions caused by unexpected failures; component lifespan extension, or increased service life through optimized maintenance timing; and parts forecasting accuracy, which measures how precisely replacement demand can be anticipated to reduce inventory costs without affecting availability.
In airfield operations, FOD (Foreign Object Debris) refers to any material on runways or taxiways that may damage aircraft structures or engines. FOD detection accuracy and inspection speed measure automated computer vision systems that analyze high-resolution aerial imagery using convolutional neural networks, compared with conventional vehicle-based manual inspection. Controller training time reduction reflects gains from AI-assisted simulation platforms, such as those at the FAA Academy, where algorithmic aircraft behavior models replace human pseudo-pilots and dynamically adjust scenario difficulty to trainee performance.
In air traffic management, ATC (Air Traffic Control) refers to real-time aircraft sequencing and separation, while ATM (Air Traffic Management) covers broader planning, coordination, and optimization of traffic flows across national airspace. Figure 10 distinguishes reactive ATM, based on controller intervention after detected conflicts, from predictive ATM, supported by systems such as NextGen, the U.S. FAA modernization program that integrates satellite navigation, data-driven flow management, and AI decision-support tools for anticipatory traffic coordination.

3.6. Challenges and Limitations

The performance gains described above do not occur without cost. The shift from reactive to predictive security infrastructure introduces structural challenges tied to both the technologies and the institutions that deploy them. Some are technical, linked to data quality, adversarial behavior, and the complexity of national security environments. Others are organizational, reflecting tensions between algorithmic decision-making and existing professional cultures, authority structures, and workforce skills. Ethical and regulatory challenges also arise from automated decisions that affect individual rights and from governance frameworks that lag behind operational realities. Addressing these challenges is essential for translating predictive capabilities into effective and sustainable implementation policy [135,136,137].

3.6.1. Data Availability and Quality

Machine learning models require large, representative, and accurately labeled datasets, yet national security domains make these conditions difficult to achieve. Threat data are scarce, classified, and often imbalanced, with routine activity overrepresented and rare threat patterns underrepresented [138,139,140].
In cybersecurity, adversarial dynamics intensify this problem. Some uninvestigated alerts—reported at 40% in certain environments—remain unreviewed not only because of analyst overload, but also because they involve novel attack patterns absent from historical training data [103]. Adversaries exploit this by adapting tactics beyond the distributional boundaries of deployed models. CyberDetect-MLP partly addresses the issue through data augmentation and semi-supervised learning, but still retains a 1–2% false negative rate, which may be acceptable commercially but remains significant in critical infrastructure contexts [103].
In biometric systems, the main challenge is consistency rather than scarcity. During initial EES deployment, three Member States failed to meet the 35% biometric registration target due to differences in capture hardware and enrollment procedures, not recognition algorithm performance. This shows that data infrastructure, governance pipelines, and capture standardization must precede algorithmic investment. Sophisticated models cannot solve weak data foundations; they only hide the problem until operational failures expose it.

3.6.2. Resistance to Technology

Predictive systems do not fail only for technical reasons. Their adoption requires changes in professional roles, decision authority, and organizational culture, often generating resistance based on legitimate operational concerns. In aviation, experienced air traffic controllers have resisted RNN-LSTM trajectory recommendations not because of poor performance, but because algorithmic outputs may conflict with expert judgment based on situational context not captured by data [132]. This raises unresolved accountability questions: who is responsible when a human overrides a correct machine recommendation or accepts an incorrect one [141]?
The digital skills gap intensifies these challenges. SOC analyst burnout, reported at 71%, reflects not only alert volume but also frustration with systems whose internal logic is difficult to interpret or predict [103]. In maritime security, turnover intention among predictive system operators reaches 64%, associated with perceived loss of control over automated decisions with operational consequences [55]. These figures show that poorly managed technology transitions create human costs that may worsen the coverage gaps predictive systems are intended to close.
Mitigation requires three parallel actions: participatory design involving end users from the earliest stages; training focused on data literacy and system understanding, not only tool operation; and human-in-the-loop architectures that preserve clear human authority over irreversible operational decisions. This is not a concession to resistance, but a governance requirement that allows operators to use predictive systems as tools for augmented judgment rather than replacements for expertise [142,143,144,145].

3.6.3. Algorithmic Fairness and Demographic Bias

Predictive systems in national security do not distribute errors randomly; they often distribute them demographically, with consequences for fundamental rights. Facial recognition systems used in border control and aviation security show false positive rates up to 10–100 times higher for women with darker skin tones than for men with lighter skin, as documented by NIST and FBI operational data [146]. During EES deployment, these disparities required independent audits and threshold adjustments before operational acceptance, adding cost and delay to an already complex rollout. The problem is structural: facial recognition datasets have historically overrepresented certain demographic groups, producing skewed error patterns. Although vendors report improvements through dataset diversification, independent peer-reviewed validation remains limited, making vendor claims insufficient for high-stakes deployments where misidentification may affect individual liberty [147].
Bias also affects other domains. Cybersecurity machine learning models may develop geographic and sectoral biases, underrepresenting attack patterns from actors or industries less visible in historical training data [103]. A model trained mainly on North American and European enterprise threats may perform differently against attacks from other geopolitical contexts or critical infrastructure sectors. This is not only a fairness issue but also a security vulnerability, as predictable blind spots can be exploited by sophisticated adversaries [148].
Regulation is emerging but uneven. The EU AI Act classifies biometric identification as high-risk and requires conformity assessments, although its application to national security border systems remains under negotiation. In the United States, OMB Directive M-24-10 requires algorithmic impact assessments for federal AI deployments but leaves fairness thresholds to agency discretion. Current frameworks still lack mandatory pre-deployment fairness audits, public reporting of disparity metrics, standardized demographic performance data, and accessible appeal mechanisms for individuals affected by algorithmic security decisions [149,150].

3.6.4. Technical Interoperability and Vendor Dependency

Predictive security systems do not operate in isolation. They must exchange data with legacy infrastructure, share threat intelligence across agencies, and process sensitive information within jurisdictional constraints that commercial cloud architectures were not designed to support. When interoperability is not addressed before deployment, even technically capable systems may fail to access required data, communicate with complementary platforms, or avoid creating new fragmentation problems [151,152,153].
This pattern appears across domains. In maritime security, Data Lake architectures integrating multi-source surveillance data faced barriers when connecting with legacy AISs, requiring middleware that increased cost and delay without fully resolving differences in data formats and update frequencies [55]. In cybersecurity, many SOC teams report integration problems between ML-based detection tools and existing SIEM platforms, creating fragmented data and duplicated workflows that reduce efficiency gains [103]. Aviation offers a contrasting model: standardized protocols such as ASTERIX for surveillance data and ADS-B for cooperative tracking allow systems from different vendors and national authorities to share data without custom integration. Cybersecurity and border control lack comparable standards, leaving inter-agency intelligence exchange dependent on bilateral agreements and proprietary formats that limit speed and scope.
Cloud dependency adds another challenge. GPU-intensive tasks such as model training, real-time inference, and large-scale behavioral analytics are often shifted to commercial cloud providers governed by commercial rather than security-classification frameworks. For systems handling sensitive or classified data, this creates data sovereignty risks. Edge computing offers partial mitigation by processing data locally under institutional control, but reduces the computational scale that makes cloud use attractive. Long-term solutions require sector-specific interoperability standards, procurement requirements for open architectures, and investment in classified computing infrastructure that preserves both analytical capability and data sovereignty.

3.6.5. Validation and Explainability Under Adversarial Conditions

Predictive security systems face a validation problem unlike most other domains: the entities they detect actively study and adapt to them. As a result, conventional metrics—accuracy on test sets or historical benchmarks—do not reliably predict performance against intelligent adversaries that deliberately craft inputs outside training distributions [154].
In cybersecurity, adversarial machine learning exploits this weakness directly. Small perturbations in network traffic or malware payloads can cause misclassification in models that reach 96–99% accuracy under standard conditions, with reported accuracy drops of 15–30% under evasion attacks [103]. Thus, models validated in laboratory settings may degrade substantially in real operations, especially against adversaries familiar with their behavior. Standard testing often misses this because test datasets rarely include adversarially crafted inputs. In border control, similar evasion occurs through synthetic identity documents and biometric manipulation designed to bypass facial recognition thresholds [155].
Explainability creates a second challenge. National security decisions—entry denials, inspection targeting, and threat prioritization—require justifiable explanations, not only accurate outputs. Current XAI methods usually provide post hoc approximations. For example, SHAP in Taiwan’s BPI system attributes risk scores to product features, but these explanations may not fully reproduce the model’s actual reasoning process [76]. For audits and appeals, such approximations may be legally and operationally insufficient. The core problem is architectural: the deep learning models with the strongest detection performance are often the least interpretable, creating a trade-off between accuracy and accountability [156,157].
Inherently interpretable architectures, including liquid neural networks, neuro-symbolic models, and constrained attention mechanisms, offer a promising solution by embedding interpretability into system design rather than adding it afterward. These approaches aim to preserve competitive performance while producing inspectable decision processes. Although still immature for large-scale national security applications, their development suggests they may become viable within current procurement timelines.

3.6.6. Regulatory Governance and Accountability

The deployment of predictive systems in national security has advanced faster than the governance frameworks meant to regulate them. Standards such as ISO 27001 [158] for information security and ICAO SARPs for aviation were designed for systems with transparent decision logic and predictable failure modes. Machine learning systems used in predictive security often lack both, creating a structural governance gap [159,160,161].
Accountability is central to this problem. When a predictive border system wrongly denies entry or an AI-assisted SOC misclassifies a critical intrusion, responsibility may be shared among the operator, developer, and deploying institution. However, no jurisdiction has fully defined how this responsibility should be allocated. This ambiguity limits institutional redress, increases legal uncertainty, and may delay adoption of technologies with proven security benefits.
Current initiatives address the issue only partially. The EU AI Act requires conformity assessments for high-risk AI systems but excludes many national security deployments from its core provisions. OMB Directive M-24-10 mandates algorithmic impact assessments for U.S. federal systems but leaves validation criteria to individual agencies, creating inconsistent implementation. Evidence across the five domains suggests that sector-specific governance frameworks, developed with operational institutions, standard-setting bodies, and civil society, are more practical than broad AI regulation applied uniformly across contexts with different threat models and accountability structures [161,162,163,164].

3.7. Future Lines of Research

The challenges discussed above define the current limits of predictive security systems, where data scarcity, organizational resistance, algorithmic bias, interoperability gaps, and regulatory uncertainty restrict operational reliability. The trajectories examined here aim to overcome these limits not through incremental refinement, but through qualitative shifts in computation, collaboration, and governance [165,166,167,168].
Five future lines are identified: generative AI and large language models for security operations, post-quantum cryptography and quantum-assisted optimization, federated learning across institutional and jurisdictional boundaries, autonomous cyber-physical systems acting on predictive intelligence in contested environments, and explainability embedded as a design requirement. Each responds to limitations exposed by current predictive systems and presents unresolved challenges that will shape research and policy over the next decade.

3.7.1. Generative AI and Large Language Models in Security Operations

The predictive systems reviewed here rely mainly on structured data, such as sensor readings, network logs, and biometric measurements. However, they still struggle to process the unstructured intelligence that analysts use daily, including incident reports, intercepted communications, policy documents, and threat assessments. Large language models offer the first computational architecture capable of operating across this heterogeneous information space at operational scale.
Multimodal LLMs—transformer-based models with 7B–70B parameters, trained through instruction fine-tuning and reinforcement learning from human feedback on security-relevant corpora—can support analytical augmentation. Their attention mechanisms enable cross-document reasoning, while retrieval-augmented generation reduces hallucination risk by grounding outputs in verified knowledge bases. These systems can synthesize dispersed intelligence, generate threat hypotheses for analyst review, and produce preliminary assessments for expert validation. In cybersecurity, prototypes analyze unseen malicious code, explain attack vectors in accessible language, and recommend countermeasures [169]. In border control, multilingual LLMs can detect narrative inconsistencies linked to document fraud and generate targeted verification questions for officer-led interviews.
The main limitation is hallucination: plausible but incorrect outputs. In national security, this is a safety risk, not merely a quality issue, because erroneous threat assessments may trigger irreversible decisions. Retrieval-augmented generation mitigates this risk by linking outputs to verifiable sources, making residual errors more manageable within human-in-the-loop oversight frameworks [170,171].

3.7.2. Post-Quantum Cryptography and Quantum-Assisted Optimization

The cryptographic infrastructure supporting predictive security systems was built on assumptions that quantum computing may eventually invalidate. Shor’s algorithm, running on a sufficiently advanced quantum processor, can break RSA and elliptic curve cryptography in polynomial time. Although this threshold has not yet been reached, it is close enough for the U.S. NSA CNSA 2.0 roadmap and the European Quantum Communication Infrastructure program to establish migration timelines toward post-quantum standards. NIST FIPS 203 and 204, issued in 2024, provide the first operational standards for adopting quantum-resistant algorithms before the threat becomes practical [102].
Quantum computing may also improve optimization tasks central to security operations, including border patrol routing, sensor allocation, and threat pattern search in large datasets. Grover’s algorithm offers quadratic speedup for unstructured search, potentially accelerating threat signature identification in high-volume environments. However, current limits such as quantum decoherence and qubit error rates restrict reliable computation below operational scale. Hybrid quantum-classical architectures, where quantum processors handle specific optimization subroutines within classical workflows, appear to be the most viable path for security applications in the 2028–2032 horizon [102].

3.7.3. Federated Learning and Privacy-Preserving Collaborative Intelligence

One structural constraint on predictive security performance is the organizational silo problem: models trained on data from a single agency or jurisdiction often underperform those trained on broader datasets, yet legal, classification, and sovereignty restrictions make centralized training impractical. Federated learning addresses this by separating model improvement from data sharing. Each institution trains locally, shares only model gradient updates, and receives a model improved by the collective experience of all participants without transferring raw data [172,173].
The implications span several domains. In cybersecurity, federated architectures allow banks, critical infrastructure operators, and government agencies to build threat detection models from attack patterns observed across the wider economy, including rare vectors that no single institution sees often enough to model reliably [70]. In maritime security, port authorities across jurisdictions can collaboratively train vessel behavior models while preserving national data sovereignty. In border control, immigration data from different member states could inform shared predictive models without requiring politically or legally difficult centralized data agreements.
Differential privacy strengthens this approach by adding calibrated noise to gradient updates, preventing the characteristics of any institution’s data from being inferred from the aggregated model. Together, federated learning and differential privacy reduce information leakage risks to quantifiable and auditable levels, creating the trust conditions needed for collaborative learning in national security [174].

3.7.4. Autonomous Robotics and Cyber-Physical Security Systems

The predictive systems reviewed here generate intelligence—anomaly scores, risk assessments, and trajectory predictions—but physical response still depends on human operators who interpret outputs and initiate action. The next generation of security infrastructure seeks to close this gap by linking predictive analytics to autonomous platforms capable of acting on generated intelligence, extending operations into environments where human presence is impractical or tactically inadvisable.
In maritime security, unmanned surface vessels equipped with multispectral sensors and onboard ML can maintain patrol coverage across coastal areas too large for crewed deployment. They flag vessels of interest only when predictive models indicate elevated illicit activity risk, reducing human operational costs by an estimated 60–70% while sustaining continuous monitoring [144]. In border control, UAVs with computer vision extend infrastructure inspection to remote terrain lacking fixed sensors. Integrated with digital twins—real-time virtual replicas of physical infrastructure—these platforms allow threat simulation and response validation before deployment, reducing operational risk and experimentation costs.
The main unresolved constraint is human authority over consequential decisions. International humanitarian law and national legal frameworks require human oversight in any use-of-force decision, reflecting constitutional and treaty obligations rather than technological conservatism. Therefore, system architectures must preserve meaningful human control over force-related actions while allowing autonomy in surveillance, detection, and alerting functions.

3.7.5. Explainable and Trustworthy AI by Design

The explainability limits discussed in Section 3.6 share a common architectural cause: deep learning models achieve high predictive performance through complex internal representations that are difficult to interpret. Current XAI methods address this after deployment through post hoc approximations that correlate with model behavior but do not fully reproduce its decision process. The emerging response is architectural: embedding interpretability from the design stage rather than trying to recover it from models optimized only for accuracy.
Liquid Neural Networks, developed at MIT CSAIL, show that competitive performance can be achieved with interpretable architectures whose temporal dynamics remain explicit during inference. Neuro-symbolic ensemble models go further by combining neural pattern recognition with logical reasoning, producing decisions supported by auditable rules. Both approaches treat transparency not as a trade-off with accuracy, but as a parallel design objective. This is especially relevant in national security contexts, where decisions affecting entry, detention, or surveillance often require legal and institutional justification.
Formal certification represents the frontier of this line of development. It mathematically verifies that a system satisfies defined safety specifications across all possible inputs, offering stronger assurance than test-set validation, which cannot cover the full input space adversaries may exploit. Although current certification methods are feasible only for smaller systems, their development matters for present procurement decisions, since systems acquired today may still operate when large-scale certification becomes practical [175,176].

4. Comparative Evidence Synthesis Across Strategic Security Domains

The cross-domain patterns analyzed in this section are based on the domain-specific evidence synthesized in Section 3 and reflect different levels of epistemic strength. Findings with stronger support are grounded in multiple independent peer-reviewed studies, large-scale operational deployments with third-party verified metrics, or published regulatory assessments. Other findings derive from single-organization case studies, pilot programs, or vendor-reported operational data without independent corroboration. Cross-domain performance comparisons are interpretive syntheses and should not be understood as direct statistical equivalences across heterogeneous measurement contexts.

4.1. Technological Convergence and Unified Data Architectures

The performance gains documented across domains share a common condition: the consolidation of heterogeneous data streams into unified architectures that provide the scale, speed, and provenance quality required by predictive models. Traditional security systems operated in organizational and technical silos, with scattered data, manual transfer, and incompatible formats creating bottlenecks before analysis began. Data Lake architectures, integrating continuous multi-sensor ingestion, source-preserving normalization, and GPU-accelerated processing, have produced measurable results where implemented. In maritime security, unified sensor fusion demonstrated operational viability [55]; in cybersecurity, similar architectures increased SOC investigation coverage from about 33% of daily alerts to 100%, while analyst burnout fell from 71% to 20%. These outcomes reflect not only better algorithms but also data infrastructures that removed ingestion and normalization constraints. CyberDetect-MLP illustrates this ceiling, achieving 98.87% accuracy and 99.10% ROC-AUC in IoT cyberattack detection, outperforming Random Forest baselines at 94.21% through pipeline integration as much as model design [103]. For national security organizations, the implication is clear: interoperable data architecture is a precondition for predictive performance, not a consequence. Point-to-point integration that preserves silos will limit performance regardless of model sophistication.

4.2. Predictive Accuracy and Operational Interpretability

Machine learning models in national security achieve detection accuracies of 96–99%, far beyond reactive systems, but accuracy alone is insufficient when operators cannot understand the basis for algorithmic recommendations. This tension between performance and interpretability is structural and varies by domain. In border control, Taiwan’s BPI system increased non-compliant product detection from 3.0% to 4.7% while reducing post-market incidence from 2.1% to 1.9% [76], yet agents cannot rely on risk scores they cannot explain to supervisors or justify in appeals. In aviation, air traffic controllers must understand RNN-LSTM trajectory recommendations well enough to retain meaningful operational authority rather than defer to opaque outputs [132]. In cybersecurity, SOC analysts need to know why an alert is prioritized to make reliable triage decisions under pressure.
Ensemble deep learning with MPOA optimization partially addresses this balance, achieving 97% accuracy and 95% precision while preserving operator-accessible performance metrics [103]. Grad-CAM and SHAP also provide post hoc attribution by linking model decisions to specific input features, helping operators construct justifiable explanations. Across the five domains, the finding is consistent: XAI is not optional but a deployment prerequisite. Its adequacy should be validated through usability testing with real operators, not only technical benchmarks. More broadly, a predictive system that cannot be explained cannot be audited, appealed, or held accountable. In national security contexts affecting liberty, territorial control, and critical infrastructure, interpretability is not merely a technical issue but a governance condition for meaningful democratic and legal oversight.

4.3. Workforce and Human Capital Implications

The workforce consequences of the reactive-to-predictive transition have proven more nuanced than displacement narratives suggest. Across the five domains examined, predictive automation has not eliminated security roles but restructured them—absorbing high-volume, low-complexity tasks and redirecting human capacity toward functions that require contextual judgment, institutional knowledge, and accountability that current ML systems cannot provide. In cybersecurity, automation of 70% of routine alert triage allows analysts to concentrate on the 30% of complex threats requiring expert judgment [103]. In border control, 85% of document verification is automated, enabling officers to focus on risk analysis cases that algorithmic scoring flags but cannot resolve. In aviation, a 27% reduction in ATC certification time frees experienced controllers for supervisory roles over AI-assisted systems. In maritime security, automation of 70% of documentation processing facilitates coordination across jurisdictions that manual workflows could not sustain [55].
The measurable workforce resilience improvements that follow—50% reduction in overtime hours within six months, 64% decrease in turnover intention among SOC analysts, 25% improvement in training efficiency—suggest that predictive automation addresses the personnel sustainability crisis that reactive systems were generating, not merely the detection performance gap. The persistent constraint is the digital skills gap: analysts who cannot interrogate or reliably predict system behavior cannot effectively supervise it, and supervision is precisely the role that automation creates. National security agencies must therefore implement workforce transition programs—focused on data literacy and system understanding rather than tool operation—in parallel with technological deployment, treating human capital investment as a prerequisite for realizing the performance gains that predictive infrastructure makes possible.

4.4. Operational Validation and Real-World Impact

Laboratory accuracy shows what predictive systems can achieve under controlled conditions, but not what they deliver in real operational environments. This gap appears across domains. Maritime surveillance accuracy falls from 89% to 85% when network throughput drops from 1 Gbps to 100 Mbps, a common field condition [70]. Air traffic prediction with RNN-LSTM models shows a Mean Absolute Error of 4.52 at Class B airports versus 0.87 at Class D airports, indicating weaker performance in high-density environments where prediction is most needed [130]. Biometric recognition reaches 99.4% accuracy under controlled enrollment but shows demographic false-positive disparities not captured by standard test sets [146]. Thus, validation datasets that ignore infrastructure variability, operational complexity, and demographic diversity will overestimate deployment performance.
The EU EES provides the most significant real-world validation in this review: 17 million travelers registered, 30 million crossings processed, 16,000 entry denials issued, and 4000 overstay violations detected within its initial months. These results confirm that predictive architectures can sustain continental-scale throughput while maintaining detection levels beyond manual systems. However, rollout stabilization challenges show that moving from validation to deployment requires an integration period often underestimated in procurement timelines. As a consolidating contribution, this study proposes a multidimensional evaluation framework combining technical metrics, such as accuracy and recall; operational metrics, such as MTTR and throughput; and organizational metrics, such as adoption and burnout reduction. This framework addresses the lack of a common evaluative language across domains, enabling defense planners, governance bodies, and institutions to compare investments, define standards, and learn from deployments. It is therefore not only a synthesis tool but an analytical contribution for future cross-domain research.

5. Discussion

Considered separately, the performance data in Section 3 may suggest a straightforward technology success story: metrics improve, throughput increases, and detection rates exceed reactive capabilities. However, the cross-domain evidence reveals a deeper pattern: the gap between reactive and predictive systems depends less on algorithmic sophistication than on data architecture, institutional readiness, and organizational design. Where these conditions exist, predictive systems deliver documented gains; where they are absent, the same algorithms underperform, face resistance, or generate harms that offset efficiency benefits. This reframes the policy question from “which technology should we adopt?” to “what organizational and governance infrastructure is required for adoption to deliver value?”
The preceding sections show what predictive security technologies can achieve under documented operational conditions, but not how those capabilities translate into institutional practice. Four cross-cutting patterns require discussion beyond domain-specific findings: the role of unified data architectures in enabling performance gains, the tension between predictive accuracy and interpretability, the workforce effects of automating functions historically based on human judgment, and the gap between laboratory validation and real-world deployment. These patterns show that the transition from reactive to predictive infrastructure is not merely a procurement decision, but an institutional transformation requiring simultaneous technical, organizational, and governance action.
The three-force framework proposed in this review—machine learning maturation, unified data infrastructure, and institutional readiness—helps explain why some deployments achieve expected gains while others fall short. Evidence shows that advanced algorithms alone explain only part of the performance difference. Institutions that invest in models without first building data governance, interoperability standards, and workforce development programs are unlikely to reproduce the outcomes seen in high-performing deployments.
The governance implications are significant. Accountability frameworks centered on human decision-makers do not automatically apply to systems where consequential outputs are algorithmically generated. The explainability limits described in Section 3.6.5, demographic bias in biometric systems, and performance degradation under adversarial conditions indicate that predictive deployment without adequate regulation creates accountability gaps. The EU AI Act and NIST frameworks offer partial responses, but their effectiveness will depend on deep organizational implementation rather than superficial compliance.
The multidimensional evaluation framework proposed in Section 4.4—combining technical performance, operational throughput, and organizational resilience metrics—offers a practical way to bridge laboratory validation and field performance. Its adoption by procurement bodies, regulators, and research institutions would support cross-domain comparison of predictive security investments on a common evidential basis. Future primary research applying this framework across the five domains examined here would strengthen evidence-based institutional planning.

6. Conclusions

The operational superiority of predictive systems over reactive architectures is empirically established across all five domains examined. Security Operations Centers integrating AI-assisted triage reduce investigation time by 50%, automate 70% of routine tasks, and achieve 100% alert coverage against a 40% uninvestigated alert baseline under reactive operation. Maritime predictive architectures process 4000 times more conjunction data daily with a 77% reduction in false alarms. The EU EES processed 17 million travelers and detected 4000 overstay violations within its first months of operation, while biometric verification maintains 99.4% matching accuracy. Delta Airlines reduced maintenance-related cancellations from 5600 to 55 annually through predictive maintenance, and FOD detection systems achieve 96% accuracy at eight times manual inspection speed. These are not isolated achievements—they reflect a systematic pattern in which machine learning architectures identify threat-relevant signals within data volumes and at temporal resolutions that reactive methods based on static rules and expert judgment cannot access.
Performance gains materialize only when technological deployment is accompanied by organizational transformation. The evidence is consistent: organizations that implement predictive systems without redesigning workflows, reconfiguring roles, and investing in data literacy obtain suboptimal results regardless of system technical quality. Analyst burnout persists when automation is layered onto unreformed processes. Controller resistance to algorithmic recommendations reflects legitimate concerns about operational authority that system design must address, not organizational inertia to be managed around. Successful transitions involve end-users from the design phase, restructure roles toward system supervision and strategic judgment, and treat human capital investment as a prerequisite for realizing documented performance gains—not as a secondary budget line after hardware and licensing.
Algorithmic bias, data sovereignty, and accountability gaps require proactive governance, not reactive remediation. Facial recognition systems exhibit false-positive rates up to 100 times higher for women with darker skin tones. Cybersecurity models trained on geographically concentrated threat data underdetect attack vectors from less represented actors. Border risk-prediction systems may encode historical discriminatory patterns into automated decisions with legal consequences for individuals. These are not edge cases—they are structural features of systems trained on historically skewed data, and they will persist without explicit governance intervention. Effective frameworks require mandatory pre-deployment fairness audits with publicly reported disparity metrics, appeal mechanisms for individuals adversely affected by algorithmic decisions, investment in local processing infrastructure for sensitive data, and open standards that prevent the vendor dependency that currently concentrates predictive capacity in ways incompatible with national security sovereignty requirements.
The next frontier will be defined by the convergence of emerging technologies into integrated security architectures, not by the isolated advancement of individual capabilities. Multimodal language models, quantum-assisted optimization, federated learning, autonomous cyber-physical platforms, and explainable-by-design architectures each address specific limitations of the current generation of predictive systems. Their transformative potential, however, depends on deliberate interoperability—system architectures designed from the outset for integration rather than accumulation. Nations that build the research infrastructure, operational testbeds, and interdisciplinary workforce required to accelerate that convergence will establish sustainable advantages. Those that procure technologies in isolation, without an architectural vision that connects individual capabilities into coherent systems, risk investments that improve individual metrics without achieving the systemic transformation that the security environment of the coming decade will require [177,178,179].

Supplementary Materials

The following supporting information can be downloaded at: https://www.mdpi.com/article/10.3390/technologies14070446/s1, Table S1: PRISMA 2020 checklist. The checklist was prepared in accordance with the guidelines of [180].

Author Contributions

Conceptualization, O.F.-U. and D.P.; methodology, O.F.-U.; software, O.F.-U.; validation, O.F.-U., D.P. and H.A.; formal analysis, O.F.-U.; investigation, O.F.-U., D.P., H.A., G.E., X.C., D.F., F.V. and C.T.; resources, O.F.-U., D.P., H.A., G.E., X.C., D.F., F.V. and C.T.; data curation, O.F.-U. and D.P.; writing—original draft preparation, O.F.-U., D.P., H.A., G.E., X.C., D.F., F.V. and C.T.; writing—review and editing, O.F.-U., D.P., H.A., G.E., X.C., D.F., F.V. and C.T.; visualization, O.F.-U.; supervision, O.F.-U.; project administration, O.F.-U.; funding acquisition, O.F.-U. All authors have read and agreed to the published version of the manuscript.

Funding

This research was funded by the Universidad de Las Américas-Ecuador; grant number 504.A.XIV.24.

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

No new data were created or analyzed in this study. Data sharing is not applicable to this article.

Acknowledgments

The authors gratefully acknowledge the financial support of Universidad de las Américas and the institutional contributions of Universidad de las Fuerzas Armadas, National Defense University (Beijing-China), Comando Conjunto de las Fuerzas Armadas (Ecuador), Dirección de Policía Científica (Ecuador) and Universidad Estatal Península de Santa Elena (Ecuador).

Conflicts of Interest

The authors declare no conflicts of interest.

Abbreviations

The following abbreviations are used in this manuscript:
ADS-BAutomatic Dependent Surveillance–Broadcast
AIArtificial Intelligence
AISAutomatic Identification System
AMSAAustralian Maritime Safety Authority
APEXAdvanced Predictive Engine (Delta Air Lines)
ASTERIXAll-Purpose Structured Eurocontrol Surveillance Information Exchange
ATCAir Traffic Control
ATMAir Traffic Management
BDLSTM-CNNBidirectional Deep Long Short-Term Memory combined with Convolutional Neural Network
BPIBorder Prediction Intelligent
CBPCustoms and Border Protection (United States)
CDMConjunction Data Message
CNNConvolutional Neural Network
CNSACommercial National Security Algorithm (NSA roadmap)
COLREGsInternational Regulations for Preventing Collisions at Sea
CyRISCyber Range Instantiation System
DLDeep Learning
EESEntry/Exit System (European Union)
ESAEuropean Space Agency
eu-LISAEuropean Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice
FAAFederal Aviation Administration
FBIFederal Bureau of Investigation
FIPSFederal Information Processing Standards
FODForeign Object Debris
GISGeographic Information System
GPSGlobal Positioning System
GPUGraphics Processing Unit
GSSAPGeosynchronous Space Situational Awareness Program
ICIIntelligent Customs Inspection
ICAOInternational Civil Aviation Organization
ICTInformation and Communication Technologies
IoDInternet of Drones
IoTInternet of Things
ISC2International Information System Security Certification Consortium
ISOInternational Organization for Standardization
LLMLarge Language Model
LSTMLong Short-Term Memory
MAEMean Absolute Error
MDAMaritime Domain Awareness
MLMachine Learning
ML-DSAModule-Lattice-Based Digital Signature Standard
MLPMultilayer Perceptron
MPOAModified Puzzle Optimization Algorithm
MSXMidcourse Space Experiment
MTTRMean Time To Respond
NICENational Initiative for Cybersecurity Education
NIDSNetwork Intrusion Detection System
NISTNational Institute of Standards and Technology
NMAENormalized Mean Absolute Error
NRMSENormalized Root Mean Square Error
NSANational Security Agency
OAuth2Open Authorization 2.0
OMBOffice of Management and Budget (United States)
PRISMA®Preferred Reporting Items for Systematic Reviews and Meta-Analyses
PSIProliferation Security Initiative

References

  1. Cummings, M.L.; Roff, H.M.; Cukier, K.; Parakilas, J.; Bryce, H. Artificial Intelligence and International Affairs: Disruption Anticipated; Chatham House Report; The Royal Institute of International Affairs: London, UK, 2018; Available online: https://www.chathamhouse.org/sites/default/files/publications/research/2018-06-14-artificial-intelligence-international-affairs-cummings-roff-cukier-parakilas-bryce.pdf (accessed on 18 January 2026).
  2. Kunertova, D. The war in Ukraine shows the game-changing effect of drones depends on the game. Bull. At. Sci. 2023, 79, 95–102. [Google Scholar] [CrossRef]
  3. Kim, S.Y.; Park, Y.J. Artificial intelligence and emerging technologies in cybersecurity: Challenges and opportunities. Cyber Secur. Appl. 2023, 2, 100031. [Google Scholar] [CrossRef]
  4. Russell, S.; Hauert, S.; Altman, R.; Veloso, M. Lethal autonomous weapons. Nature 2015, 521, 415–416. [Google Scholar] [CrossRef] [PubMed]
  5. Oakes, B.; Richards, D.; Barr, J.; Ralph, J.F. Double Deep Q Networks for Sensor Management in Space Situational Awareness. arXiv 2022, arXiv:2205.14041. [Google Scholar] [CrossRef]
  6. Ige, T.; Kolade, A.; Kolade, O. Enhancing border security and countering terrorism through computer vision: A field of artificial intelligence. In Lecture Notes in Networks and Systems; Springer: Cham, Switzerland, 2023; pp. 656–666. [Google Scholar] [CrossRef]
  7. Kim, J.; Lee, C.; Chung, D.; Cho, Y.; Kim, J.; Jang Y, W.; Park, S. Field experiment of autonomous ship navigation in canal and surrounding nearshore environments. J. Field Robot. 2024, 41, 470–489. [Google Scholar] [CrossRef]
  8. Amoore, L. Biometric borders: Governing mobilities in the war on terror. Political Geogr. 2006, 25, 336–351. [Google Scholar] [CrossRef]
  9. Sauer, F. Stepping back from the brink: Why multilateral regulation of autonomy in weapons systems is difficult, yet imperative and feasible. Int. Rev. Red. Cross 2020, 102, 235–259. [Google Scholar] [CrossRef]
  10. Horowitz, M.C.; Scharre, P.; Saravalle, A. Artificial Intelligence and International Security; Center for a New American Security (CNAS): Washington, DC, USA, 2018; Available online: https://www.cnas.org/publications/reports/artificial-intelligence-and-international-security (accessed on 19 January 2026).
  11. Bracken, P.; Bremmer, I.; Gordon, D. (Eds.) Managing Strategic Surprise: Lessons From Risk Management and Risk Assessment, 1st ed.; Cambridge University Press: Cambridge, UK, 2008; Available online: https://www.cambridge.org/core/product/identifier/9780511755880/type/book (accessed on 11 November 2025).
  12. Bhatt, G.K.; Bhatt, V.; Srivastava, A.K.; Shukla, A. Big data analytics for national security: A survey. In Proceedings of the 2020 International Conference on Intelligent Engineering and Management (ICIEM), London, UK, 17–19 June 2020; pp. 519–525. [Google Scholar] [CrossRef]
  13. Flor-Unda, O.; Puga, D.; Alomoto, H.; Eguez, G. Evolution of technology for national security: Advances and contributions of artificial intelligence. Res. Sq. 2025; preprint. [CrossRef] [PubMed]
  14. Masó, J.; Serral, I.; Domingo-Marimon, C.; Zabala, A. Earth observations for sustainable development goals monitoring based on essential variables and driver-pressure-state-impact-response indicators. Int. J. Digit. Earth 2020, 13, 217–235. [Google Scholar] [CrossRef]
  15. Avtar, R.; Kouser, A.; Kumar, A.; Singh, D.; Misra, P.; Gupta, A.; Yunus, A.P.; Kumar, P.; Johnson, B.A.; Dasgupta, R.; et al. Remote sensing for international peace and security: Its role and implications. Remote Sens. 2021, 13, 439. [Google Scholar] [CrossRef]
  16. Sreejith, S.G. The fallen envoy: The rise and fall of astronaut in international space law. Space Policy 2019, 47, 130–139. [Google Scholar] [CrossRef]
  17. Xiao, K.; Li, P.; Wang, G.; Li, Z.; Chen, Y.; Xie, Y.; Fang, Y. A preliminary research on space situational awareness based on event cameras. arXiv 2022, arXiv:2203.13093. [Google Scholar] [CrossRef]
  18. Holzinger, M.J.; Jah, M.K. Challenges and potential in space domain awareness. J. Guid. Control Dyn. 2018, 41, 15–18. [Google Scholar] [CrossRef]
  19. Adityayuda, A.; Supriyadi, A.A.; Arief, S. Development of a Remote Sensing System for Real-Time Detection of Military Threats. In Proceedings of the 2024 IEEE Asia-Pacific Conference on Geoscience, Electronics and Re-mote Sensing Technology (AGERS); IEEE: New York, NY, USA, 2024; pp. 257–268. [Google Scholar] [CrossRef]
  20. Miccinesi, L.; Beni, A.; Pieraccini, M. UAS-Borne Radar for Remote Sensing: A Review. Electronics 2022, 11, 3324. [Google Scholar] [CrossRef]
  21. Fontana, S.; Di Lauro, F. An overview of sensors for long-range missile defense. Sensors 2022, 22, 9871. [Google Scholar] [CrossRef]
  22. Weeden, B.; Samson, V. (Eds.) Global Counterspace Capabilities: An Open Source Assessment; Secure World Foundation: Broomfield, Colorado, 2022; Available online: https://swfound.org/media/207350/swf_global_counterspace_april2022.pdf (accessed on 19 January 2026).
  23. Caltagirone, F.; Capuzi, A.; De Luca, G.F.; De Luca, G.F.; Scorzafava, E.; Leonardi, R.; Rivola, S.; Fagioli, S.; Angino, G.; Labbate, M.; et al. The COSMO-SkyMed dual use earth observation program: Development, qualification, and results of the commissioning of the overall constellation. IEEE J. Sel. Top. Appl. Earth Obs. Remote Sens. 2014, 7, 2754–2762. [Google Scholar] [CrossRef]
  24. Stathakis, D. Satellite remote sensing for defense and national security. Remote Sens. 2021, 13, 925. [Google Scholar] [CrossRef]
  25. Scholl, M.; Suloway, T. Introduction to Cybersecurity for Commercial Satellite Operations; NIST IR 8270; National Institute of Standards and Technology (NIST): Gaithersburg, MD, USA, 2023. Available online: https://nvlpubs.nist.gov/nistpubs/ir/2023/NIST.IR.8270.pdf (accessed on 19 January 2026).
  26. Hammarbäck, J.; Alfredson, J.; Johansson, B.J.E.; Lundberg, J. My synthetic wingman must understand me: Modelling intent for future manned–unmanned teaming. Cogn. Technol. Work 2024, 26, 107–126. [Google Scholar] [CrossRef]
  27. Troemel, M.; Dorn, C.; Holtmann, J. AI-based predictive security analytics for autonomous systems. In Proceedings of the 2023 IEEE International Conference on Cyber Security and Resilience (CSR), Venice, Italy, 31 July–2 August 2023; pp. 348–353. [Google Scholar] [CrossRef]
  28. Martin, J.; Esteban, S. Relative Estimation and Control for Loyal Wingman MUM-T. Aerospace 2025, 12, 680. [Google Scholar] [CrossRef]
  29. Dong, H.; Akan, Ö.B. DebriSense: Terahertz-based Integrated Sensing and Communications (ISAC) for debris detection and classification in the Internet of Space (IoS). arXiv 2024, arXiv:2408.13552. [Google Scholar] [CrossRef]
  30. Casaril, F.; Galletta, L. Space cybersecurity governance: Assessing policies and frameworks in view of the fu-ture European space legislation. J. Cybersecur. 2025, 11, tyaf013. [Google Scholar] [CrossRef]
  31. Sun, S.; Xue, Q.; Xing, X.; Zhao, H.; Zhang, F. Remote sensing image interpretation for coastal zones: A review. Remote Sens. 2024, 16, 4701. [Google Scholar] [CrossRef]
  32. Samaila, Y.A.; Sebastian, P.; Singh, N.S.S.; Shuaibu, A.N.; Ali, S.S.A.; Amosa, T.I.; Abro, G.M.; Shuaibu, I. Video Anomaly Detection: A Systematic Review of Issues and Prospects. SSRN Electron. J. 2023, 591, 127726. [Google Scholar] [CrossRef]
  33. Rodger, M.; Guida, R. Classification-Aided SAR and AIS Data Fusion for Space-Based Maritime Surveil-lance. Remote Sens. 2021, 13, 104. [Google Scholar] [CrossRef]
  34. Belenguer-Plomer, M.A.; Barrilero, O.; Saameño, P.; Mendes, I.; Lazzarini, M.; Albani, S.; El Beyrouthy, N.; Al Sayah, M.; Rueche, N.; Edjossan-Sossou, A.M.; et al. Remote sensing as a sentinel for safeguarding European critical infrastructure in the face of natural disasters. Appl. Sci. 2025, 15, 8908. [Google Scholar] [CrossRef]
  35. Blasch, E.; Pham, K.; Chong, C.-Y.; Nguyen, T. National security applications of machine learning and artificial intelligence. In Proceedings of the 2021 IEEE Aerospace Conference, Big Sky, MT, USA, 6–13 March 2021; pp. 1–8. [Google Scholar] [CrossRef]
  36. Danks, D.G.; London, A.J. Algorithmic bias in autonomous systems. In Proceedings of the 26th International Joint Conference on Artificial Intelligence (IJCAI-17), Melbourne, Australia, 19–25 August 2017; pp. 4691–4697. [Google Scholar] [CrossRef] [PubMed]
  37. Craglia, J.; Feichter, M.; Formichella, R.; Gallego, A.; Goodman, A.; Gould, F.; Sherrill, P. Geospatial intelligence for national security: Applications of satellite imagery and machine learning. Int. J. Appl. Earth Obs. Geoinf. 2022, 107, 102691. [Google Scholar] [CrossRef]
  38. Kott, A.; Linkov, I. (Eds.) Cyber Resilience of Systems and Networks; Springer: Cham, Switzerland, 2019; Available online: https://link.springer.com/book/10.1007/978-3-319-77492-3 (accessed on 11 January 2026).
  39. Wang, X.F.; Meng, F.R.; Li, Z.H.; Wu, K.Y.; Kong, D.K. Construction and application of intelligent and all-factor territorial development regulation model. In Proceedings of the 2022 2nd International Conference on Big Data Engineering and Education (BDEE), Chengdu, China, 5–7 August 2022; pp. 61–66. Available online: https://ieeexplore.ieee.org/document/9980879/ (accessed on 11 January 2026).
  40. Prasad, D.K.; Prasath, C.K.; Rajan, D.; Rachmawati, L.; Rajabally, E.; Quek, C. Maritime situational awareness using adaptive multi-sensor management under hazy conditions. arXiv 2017, arXiv:1702.00754. [Google Scholar] [CrossRef]
  41. Feldt, W.; Rossberg, J.; Strauch, F. Maritime security—Technology and systems overview. In Proceedings of the Oceans IEEE Conference, Bergen, Norway, 10–14 June 2013. [Google Scholar] [CrossRef]
  42. Liss, C. Maritime security: Problems and prospects for national security policymakers. In The Palgrave Handbook of National Security; Clarke, M., Henschke, A., Sussex, M., Legrand, T., Eds.; Palgrave Macmillan: Cham, Switzerland, 2022; pp. 329–349. Available online: https://link.springer.com/10.1007/978-3-030-53494-3_14 (accessed on 20 January 2026).
  43. Das, H. India’s maritime security governance challenges: A decade after ‘26/11’. Marit. Aff. J. Natl. Marit. Found. India 2018, 14, 106–119. [Google Scholar] [CrossRef]
  44. Kim, S.K. Maritime security initiatives in East Asia: Assessment and the way forward. Ocean Dev. Int. Law. 2011, 42, 227–244. [Google Scholar] [CrossRef]
  45. Jatmiko, B. The Role of Navies in Maritime Security in Southeast Asia; IDSS Paper No. 071/2022; S. Rajaratnam School of International Studies (RSIS): Singapore, 2022; Available online: https://rsis.edu.sg/rsis-publication/idss/ip22071-the-role-of-navies-in-maritime-security-in-southeast-asia/ (accessed on 11 January 2026).
  46. Greig, N.C.; Hines, E.M.; Cope, S.; Liu, X. Using satellite AIS to analyze vessel speeds off the coast of Wash-ington State, U.S., as a risk analysis for cetacean-vessel collisions. Front. Mar. Sci. 2020, 7, 109. [Google Scholar] [CrossRef]
  47. Karst, J.; McGurrin, R.; Gavin, K.; Luttrell, J.; Rippy, W.; Coniglione, R.; McKenna, J.; Riedel, R. Enhancing Mari-time Domain Awareness Through AI-Enabled Acoustic Buoys for Real-Time Detection and Tracking of Fast-Moving Vessels. Sensors 2025, 25, 1930. [Google Scholar] [CrossRef] [PubMed]
  48. Roach, J.A. Initiatives to enhance maritime security at sea. Mar. Policy 2004, 28, 41–66. [Google Scholar] [CrossRef]
  49. Bueger, C.; Edmunds, T.; Stockbruegger, J. UNCLOS under fire: Recalibrating maritime security governance. Int. Comp. Law Q. 2025, 74, 85–102. [Google Scholar] [CrossRef]
  50. Urick, R.J. Principles of Underwater Sound, 3rd ed.; McGraw-Hill: New York, NY, USA, 1983. [Google Scholar]
  51. Wang, X.; Song, X.; Zhao, Y. Identification and Positioning of Abnormal Maritime Targets Based on AIS and Remote-Sensing Image Fusion. Sensors 2024, 24, 2443. [Google Scholar] [CrossRef] [PubMed]
  52. Bernabé, P.; Gotlieb, A.; Legeard, B.; Marijan, D.; Sem-Jacobsen, F.O.; Spieker, H. Detecting Intentional AIS Shutdown in Open Sea Maritime Surveillance Using Self-Supervised Deep Learning. IEEE Trans. Intelli-Gent Transp. Syst. 2024, 25, 1166–1177. [Google Scholar] [CrossRef]
  53. Maganaris, C.; Protopapadakis, E.; Doulamis, N. Outlier detection in maritime environments using AIS data and deep recurrent architectures. In Proceedings of the 17th International Conference on Pervasive Technologies Related to Assistive Environments (PETRA), Crete, Greece, 12–15 July 2024; pp. 420–427. [Google Scholar] [CrossRef]
  54. Reggiannini, M.; Salerno, E.; Bacciu, C.; D’Errico, A.; Lo Duca, A.; Marchetti, A.; Martinelli, M.; Mercurio, C.; Mis-tretta, A.; Righi, M.; et al. Remote sensing for maritime traffic understanding. Remote Sens. 2024, 16, 557. [Google Scholar] [CrossRef]
  55. Galdorisi, G.; Goshorn, R. Bridging the policy and technology gap: A process to instantiate maritime domain awareness. In Proceedings of the OCEANS 2005 MTS/IEEE, Washington, DC, USA, 17–23 September 2005; pp. 1–8. Available online: https://ieeexplore.ieee.org/document/1640097/ (accessed on 24 January 2026).
  56. Galdelli, A.; Mancini, A.; Ferrà, C.; Tassetti, A.N. A synergic integration of AIS data and SAR imagery to monitor fisheries and detect suspicious activities. Sensors 2021, 21, 2756. [Google Scholar] [CrossRef] [PubMed]
  57. Brown, C.W.; Peters, K.A.; Nyarko, K.A. (Eds.) Cases on Research and Knowledge Discovery: Homeland Security Centers of Excellence; IGI Global: Hershey, PA, USA, 2014; Available online: http://services.igi-global.com/resolvedoi/resolve.aspx?doi=10.4018/978-1-4666-5946-9 (accessed on 23 January 2026).
  58. Zhao, C.; Thies, P.; Johanning, L.; Cowles, J. ROV launch and recovery from an unmanned autonomous sur-face vessel–Hydrodynamic modelling and system integration. Ocean Eng. 2021, 232, 109019. [Google Scholar] [CrossRef]
  59. The International Institute for Strategic Studies (IISS), Asia-Pacific Regional Security Assessment 2022: Key Developments and Trends; Routledge: London, UK, 2022.
  60. Till, G.; Chew, E.; Ho, J. (Eds.) Globalisation and Defence in the Asia-Pacific, 1st ed.; Routledge: London, UK, 2008; Available online: https://www.taylorfrancis.com/books/9781134069699 (accessed on 23 January 2026).
  61. Paul, T.V.; Ripsman, N.M. Under pressure? Globalisation and the national security state. Millenn. J. Int. Stud. 2004, 33, 355–380. [Google Scholar] [CrossRef]
  62. Stockholm International Peace Research Institute (SIPRI). SIPRI Yearbook 2025: Armaments, Disarmament and International Security; Oxford University Press: Oxford, UK, 2025. [Google Scholar]
  63. Møhl, P. Biometric technologies, data and the sensory work of border control. Ethnos 2022, 87, 241–256. [Google Scholar] [CrossRef]
  64. Xu, B.; Ni, Q.; Jiang, R.; Bouridane, A.; Li, C.T.; Crookes, D.; Boussakta, S.; Hao, F.; Edirisinghe, E.A. Biometric Blockchain (BBC) Based e-Passports for Smart Border Control. In Advanced Sciences and Technologies for Security Applications; Jiang, R., Bouridane, A., Li, C.T., Crookes, D., Boussakta, S., Hao, F., Edirisinghe, E.A., Eds.; Springer International Publishing: Cham, Germany, 2022; pp. 235–248. [Google Scholar] [CrossRef]
  65. Amelung, N.; Galis, V. Border control technologies: Introduction. Sci. Cult. 2023, 32, 323–343. [Google Scholar] [CrossRef]
  66. Rollins, J.D. The End of SBInet; Center for Strategic and International Studies (CSIS): Washington, DC, USA, 2011; Available online: https://www.csis.org/analysis/end-sbinet. (accessed on 12 July 2026).
  67. Schultz, L.J.; Blanpied, G.S.; Hogan, G.E.; Myers, A.W.; Atwater, H.F.; Hengartner, N.W.; Morris, C.L. Image reconstruction and material Z discrimination via cosmic ray muon radiography. Nucl. Instrum. Methods Phys. Res. A 2004, 519, 687–694. [Google Scholar] [CrossRef]
  68. Duong, H.-T.; Le, V.-T.; Hoang, V.T. Deep learning-based anomaly detection in video surveillance: A survey. Sensors 2023, 23, 5024. [Google Scholar] [CrossRef] [PubMed]
  69. Abro, G.E.M.; Zulkifli, S.A.B.M.; Masood, R.J.; Asirvadam, V.S.; Laouiti, A. Comprehensive review of UAV detection, security, and communication advancements to prevent threats. Drones 2022, 6, 284. [Google Scholar] [CrossRef]
  70. Zhang, T.; He, C.; Ma, T.; Gao, L.; Ma, M.; Avestimehr, S. Federated Learning for Internet of Things: A Federated Learning Framework for On-device Anomaly Data Detection. arXiv 2021, arXiv:2106.07976. [Google Scholar] [CrossRef]
  71. Achuthan, K.; Ramanathan, S.; Srinivas, S.; Raman, R. Advancing cybersecurity and privacy with artificial intelligence: Current trends and future research directions. Front. Big Data 2024, 7, 1497535. [Google Scholar] [CrossRef] [PubMed]
  72. Carammia, M.; Iacus, S.M.; Wilkin, T. Forecasting asylum-related migration flows with machine learning and data at scale. Sci. Rep. 2022, 12, 1457. [Google Scholar] [CrossRef] [PubMed]
  73. Dehmer, M.; Meyer-Nieberg, S.; Mihelcic, G.; Pickl, S.; Zsifkovits, M. Collaborative risk management for national security and strategic foresight: Combining qualitative and quantitative operations research approaches. EURO J. Decis. Process. 2015, 3, 305–337. [Google Scholar] [CrossRef]
  74. Christensen, T.; Lægreid, P. The whole-of-government approach to public sector reform. Public Adm.-Tion Rev. 2007, 67, 1059–1066. [Google Scholar] [CrossRef]
  75. Fernández, G.C.; Xu, S. A case study on using deep learning for network intrusion detection. In Proceedings of the 2019 IEEE Military Communications Conference (MILCOM), Norfolk, VA, USA, 12–14 November 2019; pp. 1–6. [Google Scholar] [CrossRef]
  76. eu-LISA, Entry/Exit System (EES)—Operational Status Report, Tallinn, Estonia: European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA). 2025. Available online: https://www.eulisa.europa.eu/Publications/Reports (accessed on 21 January 2026).
  77. ISO/IEC 19794-5:2011; Information Technology—Biometric Data Interchange Formats—Part 5: Face Image Data. International Organization for Standardization: Geneva, Switzerland, 2011.
  78. AlDaajeh, S.H.; Saleous, H.; Alrabaee, S.; Barka, E.; Breitinger, F.; Choo, K.-K.R. The role of national cybersecu-rity strategies on the improvement of cybersecurity education. Comput. Secur. 2022, 119, 102754. [Google Scholar] [CrossRef]
  79. Moran, C.R.; Burton, J.; Christou, G. The US Intelligence Community, Global Security, and AI: From Secret Intelligence to Smart Spying. J. Glob. Secur. Stud. 2023, 8, ogad005. [Google Scholar] [CrossRef]
  80. Nye, J.S. Deterrence and Dissuasion in Cyberspace. Int. Secur. 2017, 41, 44–71. [Google Scholar] [CrossRef]
  81. Freedman, L. The Future of War: A History. Survival 2017, 59, 7–26. [Google Scholar] [CrossRef]
  82. Willett, M. Assessing Cyber Power. Survival 2019, 61, 85–90. [Google Scholar] [CrossRef]
  83. Paxson, V. Bro: A system for detecting network intruders in real-time. Comput. Netw. 1999, 31, 2435–2463. [Google Scholar] [CrossRef]
  84. Gu, G.; Fogla, P.; Dagon, D.; Lee, W.; Skoric, B. Towards an information-theoretic framework for analyzing in-trusion detection systems. In Computer Security–ESORICS 2006; Gollmann, D., Meier, J., Sabelfeld, A., Eds.; Springer: Berlin/Heidelberg, Germany, 2006; Volume 4189, pp. 527–546. [Google Scholar] [CrossRef]
  85. Wustrow, E.; Karir, M.; Bailey, M.; Jahanian, F.; Huston, G. Internet background radiation revisited. In Proceedings of the 10th ACM SIGCOMM Conference on Internet Measurement, Melbourne, Australia, 1–3 November 2010; pp. 62–74. [Google Scholar] [CrossRef]
  86. ScottHayward, S.; O’Callaghan, G.; Sezer, S. SDN security: A survey. In Proceedings of the 2013 IEEE SDN for Future Networks and Services (SDN4FNS), Trento, Italy, 11–13 November 2013; pp. 1–7. [Google Scholar] [CrossRef]
  87. Pham, C.; Tang, D.; Chinen, K.; Beuran, R. CyRIS: A cyber range instantiation system for facilitating security training. In Proceedings of the Seventh Symposium on Information and Communication Technology (SoICT ’16), Ho Chi Minh City, Vietnam, 8–9 December 2016; pp. 251–258. [Google Scholar] [CrossRef]
  88. Newhouse, W.; Keith, S.; Scribner, B.; Witte, G. National Initiative for Cybersecurity Education (NICE) Cyber-Security Workforce Framework; NIST Special Publication 800181; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2017. Available online: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800181.pdf (accessed on 11 November 2025).
  89. Chamola, V.; Kotesh, P.; Agarwal, A.; Naren; Gupta, N.; Guizani, M. A Comprehensive Review of Unmanned Aerial Vehicle Attacks and Neutralization Techniques. Ad. Hoc Netw. 2021, 111, 102324. [Google Scholar] [CrossRef] [PubMed]
  90. Yaacoub, J.-P.; Noura, H.; Salman, O.; Chehab, A. Security analysis of drone systems: Attacks, limitations, and recommendations. Internet Things 2020, 11, 100218. [Google Scholar] [CrossRef] [PubMed]
  91. Kunertova, D. Drones have boots: Learning from Russia’s war in Ukraine. Contemp. Secur. Policy 2023, 44, 576–591. [Google Scholar] [CrossRef]
  92. Rose, S.; Borchert, O.; Mitchell, S.; Connelly, S. Zero Trust Architecture; NIST Special Publication 800207; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2020. [Google Scholar] [CrossRef]
  93. Furnell, S. The cybersecuri-ty workforce and skills. Comput. Secur. 2021, 100, 102080. [Google Scholar] [CrossRef]
  94. Blanchard, A.; Taddeo, M. The ethics of artificial intelligence for intelligence analysis: A review of the key challenges with recommendations. Digit. Soc. 2023, 2, 12. [Google Scholar] [CrossRef] [PubMed]
  95. Flor-Unda, O.; Simbaña, F.; Larriva-Novo, X.; Acuña, Á.; Tipán, R.; Acosta-Vargas, P. A Comprehensive Anal-ysis of the Worst Cybersecurity Vulnerabilities in Latin America. Informatics 2023, 10, 71. [Google Scholar] [CrossRef]
  96. Bhamare, D.; Zolanvari, M.; Erbad, A.; Jain, R.; Khan, K.; Meskin, N. Cybersecurity for industrial control sys-tems: A survey. Comput. Secur. 2020, 89, 101677. [Google Scholar] [CrossRef]
  97. Raval, K.J.; Jadav, N.K.; Rathod, T.; Tanwar, S.; Vimal, V.; Yamsani, N. A survey on safeguarding critical in-frastructures: Attacks, AI security, and future directions. Int. J. Crit. Infrastruct. Prot. 2024, 44, 100647. [Google Scholar] [CrossRef]
  98. Byrne, S. 2024 Risk Map. SPS Global Insights. 2024. Available online: https://www.sps-global.com/global-insights-special-report/riskmap2024 (accessed on 11 November 2025).
  99. Jin, B.; Kim, E.; Lee, H.; Bertino, E.; Kim, D.; Kim, H. Sharing cyber threat intelligence: Does it really help? In Proceedings of the 2024 Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 26 February–1 March 2024; Available online: https://www.ndss-symposium.org/wp-content/uploads/2024-228-paper.pdf (accessed on 21 January 2026).
  100. Xia, B.; Bi, T.; Xing, Z.; Lu, Q.; Zhu, L. An Empirical Study on Software Bill of Materials: Where We Stand and the Road Ahead. In Proceedings of the 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE), Melbourne, Australia, 14–20 May 2023; pp. 2630–2642. [Google Scholar] [CrossRef]
  101. FIPS 203; Module-Lattice-Based Key-Encapsulation Mechanism Standard. National Institute of Standards and Technology: Gaithersburg, MD, USA, 2024.
  102. National Institute of Standards and Technology (NIST). Module-Lattice-Based Digital Signature Standard (ML-DSA). In Federal Information Processing Standards Publication (FIPS) 204; U.S. Department of Commerce: Gaithersburg, MD, USA, 2024. [Google Scholar] [CrossRef]
  103. Abd Elaziz, M.; Fares, I.A.; Dahou, A.; Shrahili, M. Federated learning framework for IoT intrusion detection using tab transformer and nature-inspired hyperparameter optimization. Front. Big Data 2025, 8, 1526480. [Google Scholar] [CrossRef] [PubMed]
  104. Rana, M.; Mamun, Q.; Islam, M.R. Lightweight cryptography in IoT networks: A survey. Future Gener. Comput. Syst. 2022, 129, 77–89. [Google Scholar] [CrossRef]
  105. Bernstein, D.J.; Lange, T. Post-quantum cryptography. Nature 2017, 549, 188–194. [Google Scholar] [CrossRef] [PubMed]
  106. Sinigaglia, F.; Carbone, R.; Costa, G.; Zannone, N. A survey on multi-factor authentication for online banking in the wild. Comput. Secur. 2020, 95, 101745. [Google Scholar] [CrossRef]
  107. Mostafa, A.M.; Ezz, M.; Elbashir, M.K.; Alruily, M.; Hamouda, E.; Alsarhani, M.; Said, W. Strengthening Cloud Security: An Innovative Multi-Factor Multi-Layer Authentication Framework for Cloud User Authentication. Appl. Sci. 2023, 13, 10871. [Google Scholar] [CrossRef]
  108. Vectra AI. 2026 State of Threat Detection and Response; Vectra AI: San Jose, CA, USA, 2026; Available online: https://www.vectra.ai/resources/2026-state-of-threat-detection (accessed on 20 January 2026).
  109. Tines, Voice of the SOC Analyst; Tines: Dublin, Ireland, 2022; Available online: https://www.tines.com/reports/voice-of-the-soc-analyst/ (accessed on 20 January 2026).
  110. ISC2. 2024 Cybersecurity Workforce Study; ISC2: Alexandria, VA, USA, 2024; Available online: https://www.isc2.org/Insights/2024/10/Cybersecurity-Workforce-INSIGHTS-October-2024 (accessed on 20 January 2026).
  111. Prophet Security. 6 Key Takeaways from the AI in SOC Survey Report; Prophet Security: Atherton, CA, USA, 2025; Available online: https://www.prophetsecurity.ai/blog/6-key-takeaways-from-the-ai-in-soc-survey-report (accessed on 20 January 2026).
  112. Censinet. The Autonomous SOC: How AI Is Reshaping Cybersecurity Operations; Censinet: Boston, MA, USA, 2026; Available online: https://censinet.com/perspectives/autonomous-soc-ai-reshaping-cybersecurity-operations (accessed on 21 January 2026).
  113. Bhatt, G.K.; Bhatt, V.; Srivastava, A.K. AI-driven threat intelligence for national cybersecurity infrastructure. Comput. Secur. 2022, 115, 102639. [Google Scholar] [CrossRef]
  114. IBM Security and Ponemon Institute. Cost of a Data Breach Report 2024; IBM: Armonk, NY, USA, 2024; Available online: https://www.ibm.com/think/insights/whats-new-2024-cost-of-a-data-breach-report (accessed on 21 January 2026).
  115. Kaur, R.; Gabrijelčič, D.; Klobučar, T. Artificial intelligence for cybersecurity: Literature review and future research directions. Inf. Fusion 2023, 97, 101804. [Google Scholar] [CrossRef]
  116. Seo, S.; Moon, H.; Lee, S.; Kim, D.; Lee, J.; Kim, B.; Lee, W.; Kim, D. D3GF: A Study on Optimal Defense Perfor-mance Evaluation of Drone-Type Moving Target Defense Through Game Theory. IEEE Access 2023, 11, 59575–59598. [Google Scholar] [CrossRef]
  117. Toghraee, N.; Mala, H. To Kill a Mockingbird: Cryptanalysis of an Authenticated Key Exchange Scheme for Drones. In Proceedings of the 2024 15th International Conference on Information and Knowledge Technology (IKT), Isfahan, Iran, 24–26 December 2024; pp. 228–233. [Google Scholar]
  118. Gurucul and Cybersecurity Insiders. 2025 Pulse of the AI SOC Report; Gurucul: El Segundo, CA, USA, 2025; Available online: https://www.cybersecurity-insiders.com/wp-content/uploads/2025-Gurucul-Pulse-AI-SOC-Report-by-CSI.pdf (accessed on 22 January 2026).
  119. McIlwraith, D. Information Security Risk Management; Syngress: Burlington, MA, USA, 2006. [Google Scholar]
  120. Björck, S.; Henkel, M.; Stirna, R.; Zdravkovic, J. An analysis of cyber-security and resilience for national critical infrastructure. In Proceedings of the 2015 International Conference on Enterprise Information Systems (ICEIS), Barcelona, Spain, 27–30 April 2015; pp. 426–435. [Google Scholar] [CrossRef]
  121. Deebak, B.D.; Hwang, S.O. Intelligent drone-assisted robust lightweight multi-factor authentication for mili-tary zone surveillance in the 6G era. Comput. Netw. 2023, 225, 109664. [Google Scholar] [CrossRef]
  122. Leonardi, M.; Gerardi, F. Aircraft Mode S Transponder Fingerprinting for Intrusion Detection. Aerospace 2020, 7, 30. [Google Scholar] [CrossRef]
  123. Oncu, A.; Aydin, A.G.; Erdogan, Y.; Akdogan, A. Mode-S radar interrogation algorithm design for dense air traffic environment. Radioengineering 2022, 31, 460–467. [Google Scholar] [CrossRef]
  124. Meserole, J.S.; Moore, J.W. What is System Wide Information Management (SWIM)? IEEE Aerosp. Electron. Syst. Mag. 2007, 22, 13–19. [Google Scholar] [CrossRef]
  125. Ali, B.S.; Ochieng, W.; Majumdar, A.; Schuster, W.; Chiew, T.K. ADS-B system failure modes and models. J. Navig. 2014, 67, 995–1017. [Google Scholar] [CrossRef]
  126. Schäfer, M.; Strohmeier, M.; Lenders, V.; Martinovic, I.; Wilhelm, M. Bringing up OpenSky: A large-scale ADS-B sensor network for research. In Proceedings of the 13th ACM/IEEE International Conference on Information Processing in Sensor Networks (IPSN), Berlin, Germany, 15–17 April 2014; pp. 83–94. [Google Scholar] [CrossRef]
  127. Malanowski, M.; Kulpa, K.; Kulpa, J.; Samczynski, P.; Misiurewicz, J. Analysis of detection range of FM-based passive radar. IET Radar Sonar Navig. 2014, 8, 153–159. [Google Scholar] [CrossRef]
  128. Budroweit, J.; Drobczyk, M. Design of a Small Size, Low Profile L-Band Antenna Optimized for Space-Based ADS-B Signal Reception. In Proceedings of the 2018 IEEE Radar Conference (RadarConf), Brisbane, QLD, Australia, 27–31 August 2018. [Google Scholar] [CrossRef]
  129. Liaqat, T.; Akbar, M.; Javaid, N.; Qasim, U.; Khan, Z.A.; Javaid, Q.; Alghamdi, T.A.; Niaz, I.A. On Reliable and Efficient Data Gathering Based Routing in Underwater Wireless Sensor Networks. Sensors 2016, 16, 1391. [Google Scholar] [CrossRef] [PubMed]
  130. SESAR Joint Undertaking, U-space Concept of Operations (ConOps), 4th ed.; Publications Office of the European Union: Luxembourg, 2023. [CrossRef] [PubMed]
  131. Elia, R.; Rak, M.; Pascarella, D. Automated Identification and Evaluation of Threat Scenarios for U-Space So-lutions. ACM J. Auton. Transp. Syst. 2026, 3, 1–24. [Google Scholar] [CrossRef]
  132. Yang, Z.; Kang, X.; Gong, Y.; Wang, J. Aircraft trajectory prediction and aviation safety in ADS-B failure conditions based on neural network. Sci. Rep. 2023, 13, 19677. [Google Scholar] [CrossRef] [PubMed]
  133. Siegwart, R.; Nourbakhsh, I.R.; Scaramuzza, D. Introduction to Autonomous Mobile Robots, 2nd ed.; MIT Press: Cambridge, MA, USA, 2011. [Google Scholar]
  134. Lee, J.; Wang, H.-Q.; Kehling, J.; Roemer, J. Prognostics and health management design for rotary machinery systems—Reviews, methodology and applications. Mech. Syst. Signal Process. 2014, 42, 314–334. [Google Scholar] [CrossRef]
  135. Schneier, B. How Changing Technology Affects Security. IEEE Secur. Priv. Mag. 2012, 10, 104. [Google Scholar] [CrossRef]
  136. Malone, E.L. Climate change and national security. Weather Clim. Soc. 2013, 5, 93–95. [Google Scholar] [CrossRef]
  137. DiMase, D.; Collier, Z.A.; Heffner, K.; Linkov, I. Systems engineering framework for cyber physical security and resilience. Environ. Syst. Decis. 2015, 35, 291–300. [Google Scholar] [CrossRef]
  138. Singh, A.; Patil, D.; Omkar, S.N. Eye in the Sky: Real-time Drone Surveillance System (DSS) for Violent Individuals Identification using ScatterNet Hybrid Deep Learning Network. arXiv 2018, arXiv:1806.00746. [Google Scholar] [CrossRef]
  139. LeCun, Y.; Bengio, Y.; Hinton, G. Deep learning. Nature 2015, 521, 436–444. [Google Scholar] [CrossRef] [PubMed]
  140. Pettit, C.; Shi, X.; Han, H.; Lieske, J.; Liu, H. New development in using spatiotemporal data, methods and tools in urban and regional planning and design. Built Environ. 2019, 45, 471–478. [Google Scholar] [CrossRef]
  141. Foley, F. Why inter-agency operations break down: U.S. counterterrorism in comparative perspective. Eur. J. Int. Secur. 2016, 1, 150–175. [Google Scholar] [CrossRef]
  142. DelGrosso, B.; Arlikatti, S. Teaching critical infrastructure protection and resilience using exercises and WebEOC: An examination of UAE undergraduate students’ after-action reports. Int. J. Disaster Risk Reduct. 2022, 66, 102700. [Google Scholar] [CrossRef]
  143. Majchrzak, D.; Michalski, K.; Reginia-Zacharski, J. Readiness of the Polish crisis management system to re-spond to long-term, large-scale power shortages and failures (blackouts). Energies 2021, 14, 8286. [Google Scholar] [CrossRef]
  144. Shea, S.Y.; Donovan, S.K.; Beam, E.L.; Herstein, J.J.; Kratochvil, C.J.; Lowe, J.J.; Lowe, A.E. Developing train-ing in response to high-consequence infectious diseases and preparedness measures for the future. Health Secur. 2024, 22, 347–352. [Google Scholar] [CrossRef] [PubMed]
  145. Hickey, V.B. (Ed.) National Security Initiatives; Nova Science Publishers: New York, NY, USA, 2010. [Google Scholar]
  146. Almeida, D.; Shmarko, K.; Lomas, E. The ethics of facial recognition technologies, surveillance, and accounta-bility in an age of artificial intelligence: A comparative analysis of US, EU, and UK regulatory frameworks. AI Ethics 2022, 2, 377–387. [Google Scholar] [CrossRef] [PubMed]
  147. Chouldechova, A.; Roth, A. A snapshot of the frontiers of fairness in machine learning. Commun. ACM 2020, 63, 82–89. [Google Scholar] [CrossRef]
  148. Saura, J.R.; Soriano, D.E.R.; Palacios-Marqués, D. Assessing behavioral data science privacy issues in gov-ernment artificial intelligence deployment. Gov. Inf. Q. 2022, 39, 101679. [Google Scholar] [CrossRef]
  149. European Commission. Proposal for a Regulation on Artificial Intelligence (AI Act), COM(2021) 206 Final; European Commission: Brussels, Belgium, 2021; Available online: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52021PC0206 (accessed on 23 January 2026).
  150. National Institute of Standards and Technology (NIST). Artificial Intelligence Risk Management Framework (AI RMF 1.0); NIST AI 100-1; NIST: Gaithersburg, MD, USA, 2023. [Google Scholar] [CrossRef]
  151. Phahlamohlaka, J. Globalisation and national security issues for the state: Implications for national ICT policies. In IFIP International Federation for Information Processing; Springer: Boston, MA, USA, 2008; Volume 282, pp. 95–107. [Google Scholar] [CrossRef]
  152. Desyatnyuk, O.; Krysovatyy, A.; Ptashchenko, O.; Kyrylenko, O. Financial security in the conditions of globalization: Strategies and mechanisms for the protection of national interests. Econ. Aff. 2024, 69, 261–268. [Google Scholar] [CrossRef]
  153. Richardson, J.J.; Matson, W.B.; Peters, R.J. Innovating science policy: Restructuring S&T policy for the twenty-first century. Policy Sci. 2004, 37, 367–386. [Google Scholar] [CrossRef]
  154. Szegedy, C.; Zaremba, W.; Sutskever, I.; Bruna, J.; Erhan, D.; Goodfellow, I.; Fergus, R. Intriguing properties of neural networks. arXiv 2013, arXiv:1312.6199. [Google Scholar] [CrossRef]
  155. Meijer, A.; Rodríguez Bolívar, M.P.R. Governing the smart city: A review of the literature on smart urban governance. Int. Rev. Adm. Sci. 2016, 82, 392–408. [Google Scholar] [CrossRef]
  156. ISO/IEC 27001:2022; Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements. International Organization for Standardization: Geneva, Switzerland, 2022.
  157. van Daalen, O.L. The right to encryption: Privacy as preventing unlawful access. Comput. Law. Secur. Rev. 2023, 49, 105804. [Google Scholar] [CrossRef]
  158. Nissenbaum, H. Accountability in a computerized society. Sci. Eng. Ethics 1996, 2, 25–42. [Google Scholar] [CrossRef]
  159. National Security Archive. Defense Department, Summary of the 2018 National Defense Strategy of the United States of America; George Washington University: Washington, DC, USA, 2018; Available online: https://nsarchive.gwu.edu/document/16479-defense-department-summary-2018-national. (accessed on 12 July 2026).
  160. Taddeo, M.; Glorioso, L. (Eds.) Ethics and Policies for Cyber Operations; Springer International Publishing: Cham, Switzerland, 2017; Available online: http://link.springer.com/10.1007/978-3-319-45300-2 (accessed on 22 January 2026).
  161. Sharikov, P.A. Evolution of American cyber security policies. World Econ. Int. Relat. 2019, 63, 51–58. [Google Scholar] [CrossRef]
  162. Low, S. Security at home: How private securitization practices increase state and capitalist control. Anthropol. Theory 2017, 17, 365–381. [Google Scholar] [CrossRef]
  163. Abello-Colak, A.; Lombard, M.; Guarneros-Meza, V. Framing urban threats: A socio-spatial analysis of urban securitisation in Latin America and the Caribbean. Urban Stud. 2023, 60, 2741–2762. [Google Scholar] [CrossRef]
  164. Tulumello, S.; Falanga, R. Homeland as a multi-scalar community: (Dis)continuities in the US security/safety discourse and practice. Environ. Plan. C Politics Space 2022, 40, 86–103. [Google Scholar] [CrossRef]
  165. Yasunaga, Y.; Watanabe, M. Application of technology roadmaps to governmental innovation policy for promoting technology convergence. Technol. Forecast. Soc. Change 2009, 76, 61–79. [Google Scholar] [CrossRef]
  166. Featherston, C.R.; O’Sullivan, E. Enabling technologies, lifecycle transitions, and industrial systems in technology foresight: Insights from advanced materials FTA. Technol. Forecast. Soc. Change 2017, 115, 261–277. [Google Scholar] [CrossRef]
  167. Liwång, H.; Andersson, K.E.; Bang, M.; Malmio, I.; Tärnholm, T. How can systemic perspectives on defence capability development be strengthened? Def. Stud. 2023, 23, 399–420. [Google Scholar] [CrossRef]
  168. Csernatoni, R.; Martins, B.O. Disruptive Technologies for Security and Defence: Temporality, Performativity and Imagination. Geopolitics 2024, 29, 849–872. [Google Scholar] [CrossRef]
  169. Bommasani, R.; Hudson, D.A.; Aditi, E.; Altman, R.; Arora, S.; Sydney, S.; Liang, P. On the opportunities and risks of foundation models. arXiv 2021, arXiv:2108.07258. [Google Scholar] [CrossRef]
  170. Cronin, A. Military-Technological Innovation in the Digital Age. In Beyond Ukraine, 1st ed.; Sweijs, T., Michaels, J.H., Eds.; Oxford University Press: Oxford, UK, 2024; pp. 183–200. Available online: https://academic.oup.com/book/58940/chapter/492991219 (accessed on 22 January 2026).
  171. Dafoe, A. AI Governance: A Research Agenda; Future of Humanity Institute, University of Oxford: Oxford, UK, 2018; Available online: https://www.fhi.ox.ac.uk/wp-content/uploads/GovAIAgenda.pdf (accessed on 22 January 2026).
  172. Koivisto, J.; Ritala, R.; Vilkko, M. Conceptual model for capability planning in a military context–A systems thinking approach. Syst. Eng. 2022, 25, 457–474. [Google Scholar] [CrossRef]
  173. Hodický, J.; Procházka, D.; Baxa, F.; Melichar, J.; Krejčík, M.; Křížek, P.; Stodola, P.; Drozd, J. Computer assisted wargame for military capability-based planning. Entropy 2020, 22, 861. [Google Scholar] [CrossRef] [PubMed]
  174. Edler, J.; Blind, K.; Kroll, H.; Schubert, T. Technology sovereignty as an emerging frame for innovation policy: Defining rationales, ends and means. Res. Policy 2023, 52, 104765. [Google Scholar] [CrossRef]
  175. Mykolaichuk, M.; Petrukha, N.; Akimova, L.; Pozniakovska, N.; Hudenko, B.; Akimov, O. Conceptual princi-ples of analysis and forecasting threats to national security in modern conditions. Sapienza Int. J. Interdiscip. Stud. 2025, 6, e25029. [Google Scholar] [CrossRef]
  176. Darmofal, D. The Political Geography of the New Deal Realignment. Am. Politics Res. 2008, 36, 934–961. [Google Scholar] [CrossRef]
  177. Townsend, Smart Cities: Big Data, Civic Hackers, and the Quest for a New Utopia; W.W. Norton & Company: New York, NY, USA, 2013.
  178. Zanella, A.; Bui, N.; Castellani, A.; Vangelista, L.; Zorzi, M. Internet of things for smart cities. IEEE Internet Things J. 2014, 1, 22–32. [Google Scholar] [CrossRef]
  179. Sindiramutty, S.R.; Jhanjhi, N.Z.; Tan, C.E.; Tee, W.J.; Lau, S.P. Modern smart cities and open research chal-lenges and issues of explainable artificial intelligence. In Advances in Computational Intelligence and Robotics; IGI Global: Hershey, PA, USA, 2024. [Google Scholar] [CrossRef]
  180. Page, M.J.; McKenzie, J.E.; Bossuyt, P.M.; Boutron, I.; Hoffmann, T.C.; Mulrow, C.D.; Shamseer, L.; Tetzlaff, J.M.; Akl, E.A.; Brennan, S.E.; et al. The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ 2021, 372, n71. [Google Scholar] [CrossRef] [PubMed]
Figure 1. Relative frequency of occurrence of terms associated with the use of technologies in strategic security infrastructures. The * symbol indicates that the search was restricted or limited in scope.
Figure 1. Relative frequency of occurrence of terms associated with the use of technologies in strategic security infrastructures. The * symbol indicates that the search was restricted or limited in scope.
Technologies 14 00446 g001
Figure 2. Workflow for Selection of Included Items.
Figure 2. Workflow for Selection of Included Items.
Technologies 14 00446 g002
Figure 3. (a) Comparative performance analysis of reactive (TLE/SGP4) and (b) predictive (ML/DL) systems across key metrics and critical space safety domains.
Figure 3. (a) Comparative performance analysis of reactive (TLE/SGP4) and (b) predictive (ML/DL) systems across key metrics and critical space safety domains.
Technologies 14 00446 g003
Figure 4. Evolution of reactive and predictive technologies in (a) space and (b) maritime security systems.
Figure 4. Evolution of reactive and predictive technologies in (a) space and (b) maritime security systems.
Technologies 14 00446 g004
Figure 5. Comparative analysis of reactive and predictive systems in maritime security: (a) operational performance, (b) autonomous navigation outcomes, and (c) traffic flow prediction accuracy.
Figure 5. Comparative analysis of reactive and predictive systems in maritime security: (a) operational performance, (b) autonomous navigation outcomes, and (c) traffic flow prediction accuracy.
Technologies 14 00446 g005
Figure 6. Performance and operational outcomes of AI-based border control and inspection systems: (a) cross-program comparison, (b) EU EES deployment results, and (c) reactive vs. predictive method evaluation.
Figure 6. Performance and operational outcomes of AI-based border control and inspection systems: (a) cross-program comparison, (b) EU EES deployment results, and (c) reactive vs. predictive method evaluation.
Technologies 14 00446 g006
Figure 7. Evolution of reactive and predictive technologies in (a) Border security and (b) Cybersecurity.
Figure 7. Evolution of reactive and predictive technologies in (a) Border security and (b) Cybersecurity.
Technologies 14 00446 g007
Figure 8. Impact of AI integration on Security Operations Centers (SOC): (a) operational improvements over reactive SOC workflows, (b) detection performance of machine learning models in cyberattack identification, and (c) return on investment and automation metrics.
Figure 8. Impact of AI integration on Security Operations Centers (SOC): (a) operational improvements over reactive SOC workflows, (b) detection performance of machine learning models in cyberattack identification, and (c) return on investment and automation metrics.
Technologies 14 00446 g008
Figure 9. Evolution of reactive and predictive technologies in airspace control security.
Figure 9. Evolution of reactive and predictive technologies in airspace control security.
Technologies 14 00446 g009
Figure 10. Impact of AI integration on aviation operations: (a) predictive maintenance outcomes from the Delta Airlines case study, (b) AI-enhanced air traffic controller training and autonomous FOD detection, and (c) reactive vs. predictive air traffic management performance.
Figure 10. Impact of AI integration on aviation operations: (a) predictive maintenance outcomes from the Delta Airlines case study, (b) AI-enhanced air traffic controller training and autonomous FOD detection, and (c) reactive vs. predictive air traffic management performance.
Technologies 14 00446 g010
Table 1. Quality Assessment Questions for included papers.
Table 1. Quality Assessment Questions for included papers.
Quality Assessment Questions AnswerAnswer
The document examines how predictive technological advancements contribute to strengthening a country’s defense and protection capabilities.(+1) Yes/(+0) No
Does the document explain the operational principles behind these predictive technologies?(+1) Yes/(+0) No
Does the document discuss the challenges and limitations associated with the application and deployment of these predictive technologies?(+1) Yes/(+0) No
Is the journal or conference in which the paper was
published indexed in SJR?
(+1) if it is ranked Q1, (+0.75) if it is ranked Q2,
(+0.50) if it is ranked Q3, (+0.25) if it is ranked Q4, (+0.0) if it is not ranked
Table 2. Text strings for searching related papers.
Table 2. Text strings for searching related papers.
Base/RepositoryStringNo. Studies
Web of Sciencepredictive technologies (Topic) and security infrastructure (Topic) and efficient (Topic)43
Taylor&Francis[Abstract: predictive technologies] AND [Abstract: security infrastructure] AND [Abstract: efficient]12
SCOPUS(TITLE-ABS-KEY (predictive technologies) AND TITLE-ABS-KEY (security infrastructure) AND TITLE-ABS-KEY (efficient))202
ScienceDirectTitle, abstract, keywords: predictive technologies security infrastructure efficient43
ProQuestabstract(predictive technologies) AND abstract(security infrastructure) AND abstract(efficient)83
IEEE Xplore(“Abstract”:predictive technologies) AND (“Abstract”:security infrastructure) AND (“Abstract”:efficient)48
Total studies431
Table 3. Comparative Synthesis of Reactive-to-Predictive Transitions Across Five Security Domains.
Table 3. Comparative Synthesis of Reactive-to-Predictive Transitions Across Five Security Domains.
Security DomainReactive BaselinePrimary Predictive TechnologyKey Performance GainMain Implementation Challenge
Space surveillanceTLE/SGP4-based orbital propagation; approximately 500 conjunction data messages (CDMs) processed per day; 65% detection accuracyMachine learning and deep learning for conjunction assessment, including Deep Q-Networks and Hidden Markov Models; federated multi-sensor fusion4000-fold increase in processing throughput; 92% detection accuracy; 77% reduction in false alarms; 18-fold expansion in detection coverageData sovereignty across multinational sensor networks and standardization of orbital covariance data
Maritime securityFixed SOSUS hydrophone arrays and Automatic Identification System (AIS) position reporting focused primarily on reactive vessel trackingBidirectional long short-term memory and Transformer models for AIS behavioral analysis; SAR-CNN vessel detection; Level 4 autonomous surface vessels50% reduction in maritime incidents; 56–61% reduction in traffic forecasting error when comparing support vector regression with BDLSTM-CNN models; collision avoidance accuracy above 99%Integration with legacy AISs and implementation of data lake middleware for multi-sensor fusion
Border controlRandom sampling, with approximately 15% detection and 30% operational efficiency; manual inspection, with approximately 60% detection and 20% efficiencyBiometric facial recognition compliant with ISO/IEC 19794-5; XGBoost-based risk scoring; federated IoT analytics; muon tomography for cargo inspection99.4% biometric matching accuracy in the CBP Traveler Verification Service; detection rates above 95% for integrated cargo inspection; 85% operational efficiency; 17 million travelers processed and more than 4000 overstay violations detected through the EU Entry/Exit SystemDemographic bias, including a 10- to 100-fold disparity in false-positive rates for individuals with darker skin tones, and lack of biometric data standardization
CybersecuritySignature-based network intrusion detection systems, such as Bro/Zeek; 67% of alerts left uninvestigated; approximately 10% security operations center coverageXGBoost classifiers; CyberDetect multilayer perceptron; Zero Trust architectures based on NIST SP 800-207; federated intrusion detection; FIPS 203 and FIPS 204 post-quantum security standardsXGBoost accuracy of 97.2%; CyberDetect accuracy of 98.87% and ROC-AUC of 99.10%; 100% alert investigation coverage; 50% reduction in investigation time; automation of 70% of routine tasksAdversarial evasion, producing a 15–30% decrease in model accuracy under deliberate perturbations, and limited model explainability
Airspace managementMode S radar based on reactive transponder interrogation; fixed-schedule air traffic control; manual foreign object debris inspectionResNet and YOLOv8 models for foreign object debris detection; RNN-LSTM trajectory prediction; European U-space and United States NextGen predictive air traffic management; ADS-B-based four-dimensional trajectory modelling96% foreign object debris detection accuracy; 99% reduction in maintenance cancellations in the Delta APEX case; 85–96% air traffic management effectiveness compared with 10–25% for reactive approaches; potential mitigation of approximately USD 4.5 billion in annual foreign object debris-related costsTension between controller authority and increasing system autonomy, together with the cyber resilience of ADS-B communication links
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Flor-Unda, O.; Puga, D.; Alomoto, H.; Eguez, G.; Chango, X.; Fabara, D.; Villao, F.; Toapanta, C. Technological Evolution of Strategic Security Infrastructure: Transitioning from Reactive Models to Predictive Intelligence. Technologies 2026, 14, 446. https://doi.org/10.3390/technologies14070446

AMA Style

Flor-Unda O, Puga D, Alomoto H, Eguez G, Chango X, Fabara D, Villao F, Toapanta C. Technological Evolution of Strategic Security Infrastructure: Transitioning from Reactive Models to Predictive Intelligence. Technologies. 2026; 14(7):446. https://doi.org/10.3390/technologies14070446

Chicago/Turabian Style

Flor-Unda, Omar, David Puga, Hugo Alomoto, Gabriela Eguez, Xavier Chango, David Fabara, Freddy Villao, and Carlos Toapanta. 2026. "Technological Evolution of Strategic Security Infrastructure: Transitioning from Reactive Models to Predictive Intelligence" Technologies 14, no. 7: 446. https://doi.org/10.3390/technologies14070446

APA Style

Flor-Unda, O., Puga, D., Alomoto, H., Eguez, G., Chango, X., Fabara, D., Villao, F., & Toapanta, C. (2026). Technological Evolution of Strategic Security Infrastructure: Transitioning from Reactive Models to Predictive Intelligence. Technologies, 14(7), 446. https://doi.org/10.3390/technologies14070446

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop