Intelligent Systems Security: AI-Driven Approaches for Attacks, Detection & Explainability

A Special Issue of Computers (ISSN 2073-431X) belonging to the section "ICT Infrastructures for Cybersecurity".

Deadline for manuscript submissions: 31 December 2026 | Viewed by 2866

Editor


E-Mail Website
Guest Editor
Department of Computer Science, University of Almería, Ctra Sacramento, s/n, 04120 Almería, Spain
Interests: systems security; AI-enhanced security methodologies; traditional security techniques (signature recognition, rule-based detection); pentesting; intrusion detection system (IDS); zero-day threat detection; attack execution analysis; IDS training and datasets; explainable artificial intelligence (XAI) for security; transparent security models; automated decision-making in cybersecurity

Special Issue Information

Dear Colleagues,

We are pleased to invite you to contribute to the Special Issue "Intelligent Systems Security: AI-Driven Approaches for Attacks, Detection & Explainability".

As cyber threats grow increasingly sophisticated and pervasive, the security of systems has become a critical concern demanding innovative and robust solutions. Traditional security methodologies, while foundational, are often insufficient to counter the evolving landscape of modern attacks, including zero-day threats and advanced persistent threats. Concurrently, the integration of Artificial Intelligence (AI) into security frameworks offers unprecedented opportunities for enhanced detection, real-time response, and automated decision-making. However, the opacity of many AI models presents new challenges in trust, accountability, and interpretability.

This Special Issue aims to explore the synergistic convergence of traditional systems security and AI-enhanced approaches, with a particular focus on the entire security lifecycle. We seek contributions that bridge the gap between established techniques—such as security audits (pentesting), attack detection, signature recognition , rule-based intrusion detection and reverse engineering—and cutting-edge AI methodologies for advanced threat detection. Special emphasis will be placed on the role of Explainable AI (XAI) in developing transparent, interpretable models that not only detect attacks but also provide clear rationale for security decisions, fostering trust in automated systems.

We welcome original research articles, comprehensive reviews, and case studies that advance the field of intelligent systems security through innovative methodologies and practical implementations.

Selected topics include (but are not limited to) the following:

  • Systems security and AI-enhanced methodologies;
  • Traditional security techniques (pentesting, signature recognition, rule-based detection, reverse engineering);
  • Security lifecycle management from detection to response;
  • Intrusion detection systems (IDSs);
  • IDS training and datasets;
  • Zero-day threat detection and analysis;
  • Attack execution analysis and threat modeling;
  • Explainable AI (XAI) for security interpretation;
  • Transparent security models and trustworthy AI;
  • Automated decision-making in cybersecurity;
  • AI-driven threat intelligence and incident response;
  • Adversarial machine learning and robust AI defenses;
  • Human–AI collaboration in security operations.

Prof. Dr. J. Gómez
Guest Editor

Manuscript Submission Information

Manuscripts should be submitted online at www.mdpi.com by registering and logging in to this website. Once you are registered, click here to go to the submission form. Manuscripts can be submitted until the deadline. All submissions that pass pre-check are peer-reviewed. Accepted papers will be published continuously in the journal (as soon as accepted) and will be listed together on the special issue website. Research articles, review articles as well as short communications are invited. For planned papers, a title and short abstract (about 250 words) can be sent to the Editorial Office for assessment.

Submitted manuscripts should not have been published previously, nor be under consideration for publication elsewhere (except conference proceedings papers). All manuscripts are thoroughly refereed through a single-anonymized peer-review process. A guide for authors and other relevant information for submission of manuscripts is available on the Instructions for Authors page. Computers is an international peer-reviewed open access monthly journal published by MDPI.

Please visit the Instructions for Authors page before submitting a manuscript. The Article Processing Charge (APC) for publication in this open access journal is 1800 CHF (Swiss Francs). Submitted papers should be well formatted and use good English. Authors may use MDPI's English editing service prior to publication or during author revisions.

Keywords

  • systems security
  • AI-enhanced security methodologies
  • traditional security techniques
  • pentesting
  • intrusion detection systems (IDSs)
  • zero-day threat detection
  • attack execution analysis
  • reverse engineering
  • explainable AI (XAI) for security
  • transparent security models
  • automated decision-making in cybersecurity
  • security lifecycle management
  • AI-driven threat detection
  • adversarial machine learning
  • human–AI collaboration in security
  • trustworthy AI Systems
  • real-time incident response

Benefits of Publishing in a Special Issue

  • Ease of navigation: Grouping papers by topic helps scholars navigate broad scope journals more efficiently.
  • Greater discoverability: Special Issues support the reach and impact of scientific research. Articles in Special Issues are more discoverable and cited more frequently.
  • Expansion of research network: Special Issues facilitate connections among authors, fostering scientific collaborations.
  • External promotion: Articles in Special Issues are often promoted through the journal's social media, increasing their visibility.
  • Reprint: MDPI Books provides the opportunity to republish successful Special Issues in book format, both online and in print.

Further information on MDPI's Special Issue policies can be found here.

Published Papers (3 papers)

Order results
Result details
Select all
Export citation of selected articles as:

Research

22 pages, 749 KB  
Article
A Multi-Agent Framework for SQL Injection Auditing with LLM-Driven Post-Exploitation and Privilege Escalation
by Julio Gómez-López, Daniel Penco-Hernández, Óscar David Gómez-López, Francisco Javier Martínez-López and Nicolás Padilla-Soriano
Computers 2026, 15(10), 658; https://doi.org/10.3390/computers15100658 - 29 Sep 2026
Viewed by 98
Abstract
Web security audits of SQL injection (SQLi) vulnerabilities still depend primarily on the analyst’s skill and knowledge to select the right tools, interpret results, and determine whether there is any vulnerability. This work presents SQLiAgent, an open-source multi-agent framework that automates the complete [...] Read more.
Web security audits of SQL injection (SQLi) vulnerabilities still depend primarily on the analyst’s skill and knowledge to select the right tools, interpret results, and determine whether there is any vulnerability. This work presents SQLiAgent, an open-source multi-agent framework that automates the complete cycle of an SQLi audit—from initial recognition to post-exploitation assisted by artificial intelligence (AI)—in order to facilitate the detection and subsequent patching of vulnerabilities. SQLiAgent integrates well-established tools from the pentesting ecosystem within a decoupled and traceable workflow, and it adds a mode assisted by large language models (LLMs) whose contribution is especially relevant in post-exploitation: automated interpretation of database schema, identification of credential tables and autonomous generation of privilege-escalation SQL statements from the inferred structure of the database. The tool has been validated on the OWASP Broken Web Applications (BWA) environment, used as a reproducible testbed that makes it possible to measure its effectiveness and to establish a baseline for comparison with other systems. The results obtained show that both modes reach 100% coverage per application and that the AI mode improves detection, locating a larger number of vulnerable pages than the non-AI mode. The incorporation of AI demonstrates a clear advantage in post-exploitation, in tasks such as the automatic generation of privilege escalation or generation of technical security reports. Full article
►▼ Show Figures

Figure 1

43 pages, 15065 KB  
Article
A Privacy-Conscious and Explainable IDS-Oriented Triage and Response Pipeline for Mobile Network Infrastructure Using Aggregated Cellular Traffic Signatures
by Özcan Dimez and Fatih Cogen
Computers 2026, 15(8), 531; https://doi.org/10.3390/computers15080531 - 16 Aug 2026
Viewed by 519
Abstract
Mobile-network operators must interpret spatial anomalies in aggregated cell-level telemetry and decide whether, where, and how to respond. This paper presents a privacy-conscious, intrusion detection system (IDS)-oriented triage and response architecture that consumes cell-level anomaly signatures and couples spatial reconstruction, short-horizon forecasting, origin [...] Read more.
Mobile-network operators must interpret spatial anomalies in aggregated cell-level telemetry and decide whether, where, and how to respond. This paper presents a privacy-conscious, intrusion detection system (IDS)-oriented triage and response architecture that consumes cell-level anomaly signatures and couples spatial reconstruction, short-horizon forecasting, origin inference, self-resolution and remaining-time estimation, adaptive gating, ETA-aware team selection, conservative redeployment, explanation, and audit logging. It is a downstream spatial-attribution and response-orchestration layer, not a packet- or flow-level attack detector. The evaluated configuration uses transparent deterministic, heuristic, and optimization-based procedures and synthetic aggregated signatures without subscriber identifiers; aggregation is treated as data minimization, not a formal privacy guarantee. Across 20 paired synthetic scenarios, the full policy reduced conditional mean response time from 37.58 to 22.86 min, total travel from 576.0 to 273.5 min, and coverage ETA from 32.28 to 26.76 min, while on-time service increased from 54.0% to 60.0%. These benefits were accompanied by lower persistent-incident coverage (91.1% to 72.1%) and a higher miss rate (8.9% to 27.9%). The inverse-origin configuration showed no repeated localization-error advantage, and conservative redeployment had only a marginal average effect. The results therefore demonstrate a configurable downstream triage trade-off under controlled synthetic conditions, not attack-classification accuracy, adversarial robustness, formal privacy, or deployment readiness. Full article
►▼ Show Figures

Figure 1

18 pages, 533 KB  
Article
A Rigorous Comparative Study of Supervised Machine Learning Techniques for Network Anomaly Detection: Empirical Insights from the UNSW-NB15 Dataset
by Nouf Alkhater
Computers 2026, 15(5), 285; https://doi.org/10.3390/computers15050285 - 1 May 2026
Cited by 3 | Viewed by 1605
Abstract
The increasing complexity of modern network infrastructures has intensified the need for reliable and efficient intrusion detection systems. While advanced deep learning approaches have demonstrated strong performance, their high computational cost and limited interpretability restrict their practical deployment in real-time environments. This study [...] Read more.
The increasing complexity of modern network infrastructures has intensified the need for reliable and efficient intrusion detection systems. While advanced deep learning approaches have demonstrated strong performance, their high computational cost and limited interpretability restrict their practical deployment in real-time environments. This study presents a systematic empirical evaluation of four supervised machine learning models—Decision Tree, Random Forest, Support Vector Machine (SVM), and XGBoost—for network anomaly detection using the UNSW-NB15 dataset. To ensure methodological rigor, a structured preprocessing pipeline and a five-fold stratified cross-validation framework were employed. Model performance was assessed using multiple evaluation metrics, including accuracy, precision, recall, F1-score, and area under the ROC curve (AUC). In addition, a feature importance analysis was conducted to identify the most influential network traffic attributes contributing to anomaly detection. The results show that ensemble-based methods outperform individual classifiers, with XGBoost achieving the best overall performance (accuracy = 0.97, AUC = 0.98) along with high stability across validation folds. The analysis further reveals that a subset of flow-based and temporal features—such as sttl, sload, and dload—plays a critical role in distinguishing between normal and malicious traffic. This study provides a rigorous, interpretable, and reproducible benchmarking framework for supervised machine learning in network anomaly detection. The findings provide practical insights for developing efficient and scalable intrusion detection systems suitable for real-world deployment. Full article
►▼ Show Figures

Figure 1

Back to TopTop