electronics-logo

Journal Browser

Journal Browser

Artificial Intelligence in Cybersecurity: Practices, Challenges, and Innovations

A special issue of Electronics (ISSN 2079-9292). This special issue belongs to the section "Computer Science & Engineering".

Deadline for manuscript submissions: 15 January 2027 | Viewed by 14513

Editors


E-Mail Website
Guest Editor
Department of Computer Science, Oakland University, Rochester, MI 48309-447, USA
Interests: natural language processing (NLP); machine learning (ML); deep learning (DL) applications; health security; AI security; quantum technology to identify software vulnerabilities
Special Issues, Collections and Topics in MDPI journals

E-Mail Website
Guest Editor
Department of Computer Science, Oakland University, Rochester, MI 48309-447, USA
Interests: data mining; deep learning; machine learning; geospatial intelligence; applied data science

Special Issue Information

Dear Colleagues,

The intersection of Artificial Intelligence (AI) and cybersecurity has emerged as a critical frontier in addressing the evolving complexities of the digital landscape. This Special Issue, entitled “Artificial Intelligence in Cybersecurity: Practices, Challenges, and Innovations”, aims to provide a platform for researchers and practitioners to explore how AI can be effectively employed to strengthen cybersecurity measures.

We welcome contributions that highlight innovative practices such as AI-driven threat intelligence systems, predictive analytics for identifying vulnerabilities, and automated responses to evolving cyber threats. Additionally, we encourage groundbreaking research on the development of novel AI methodologies and their real-world applications in areas such as malware detection, anomaly detection, and secure AI deployment.

This Special Issue also emphasizes the importance of adaptive learning systems capable of remaining updated at all times regarding new vulnerabilities. Authors are encouraged to present datasets addressing newly developed threats in software and other domains. The significant contributions of machine learning and its subfields—natural language processing and computer vision—are critical for automating vulnerability detection and mitigation.

We aim to advance technologies within AI and its subfields, including machine learning, deep learning, natural language processing, and computer vision, to address pressing issues in cyberspace. This involves developing robust and efficient algorithms, designing novel data preprocessing techniques, collecting and curating relevant datasets, and exploring innovative approaches for cybersecurity.

By addressing practices, challenges, and innovations, this Special Issue aspires to advance the discourse and inspire new directions in the field of AI-powered cybersecurity.

Dr. Mst Shapna Akter
Dr. Sai Deepthi Yeddula
Guest Editors

Manuscript Submission Information

Manuscripts should be submitted online at www.mdpi.com by registering and logging in to this website. Once you are registered, click here to go to the submission form. Manuscripts can be submitted until the deadline. All submissions that pass pre-check are peer-reviewed. Accepted papers will be published continuously in the journal (as soon as accepted) and will be listed together on the special issue website. Research articles, review articles as well as short communications are invited. For planned papers, a title and short abstract (about 250 words) can be sent to the Editorial Office for assessment.

Submitted manuscripts should not have been published previously, nor be under consideration for publication elsewhere (except conference proceedings papers). All manuscripts are thoroughly refereed through a single-anonymized peer-review process. A guide for authors and other relevant information for submission of manuscripts is available on the Instructions for Authors page. Electronics is an international peer-reviewed open access semimonthly journal published by MDPI.

Please visit the Instructions for Authors page before submitting a manuscript. The Article Processing Charge (APC) for publication in this open access journal is 2400 CHF (Swiss Francs). Submitted papers should be well formatted and use good English. Authors may use MDPI's English editing service prior to publication or during author revisions.

Keywords

  • AI-driven threat intelligence systems
  • predictive analytics for cybersecurity
  • automated cyber threat response
  • malware detection using machine learning technique
  • anomaly detection in cybersecurity
  • adaptive learning systems for vulnerability mitigation
  • natural language processing for threat detection
  • computer vision in cybersecurity applications
  • secure deployment of AI models
  • cybersecurity dataset development and curation

Benefits of Publishing in a Special Issue

  • Ease of navigation: Grouping papers by topic helps scholars navigate broad scope journals more efficiently.
  • Greater discoverability: Special Issues support the reach and impact of scientific research. Articles in Special Issues are more discoverable and cited more frequently.
  • Expansion of research network: Special Issues facilitate connections among authors, fostering scientific collaborations.
  • External promotion: Articles in Special Issues are often promoted through the journal's social media, increasing their visibility.
  • Reprint: MDPI Books provides the opportunity to republish successful Special Issues in book format, both online and in print.

Further information on MDPI's Special Issue policies can be found here.

Published Papers (7 papers)

Order results
Result details
Select all
Export citation of selected articles as:

Research

Jump to: Review

52 pages, 4614 KB  
Article
A Tri-Axis Systematic Literature Review of AI-Powered Cyber Defense: ATT&CK-Aligned Analysis of Cyberattacks, Machine Learning Methods, and Datasets
by Mohammad Chizari, Abu Alam, Qublai Khan Ali Mirza and Hassan Chizari
Electronics 2026, 15(13), 2804; https://doi.org/10.3390/electronics15132804 - 25 Jun 2026
Viewed by 513
Abstract
The increasing complexity and sophistication of cyberattacks have made machine learning (ML) and artificial intelligence (AI) central to modern cyber defense. However, existing surveys typically examine attacks, ML methods, or datasets separately, limiting understanding of how methodological choices align with adversarial behaviours and [...] Read more.
The increasing complexity and sophistication of cyberattacks have made machine learning (ML) and artificial intelligence (AI) central to modern cyber defense. However, existing surveys typically examine attacks, ML methods, or datasets separately, limiting understanding of how methodological choices align with adversarial behaviours and benchmark availability. This paper presents a systematic literature review (SLR) of AI- and ML-based cyber defense studies published between 2019 and 2025, framed as an ATT&CK-aligned tri-axis synthesis of cyberattacks, machine learning methods, and datasets. Across 99 primary studies, the review maps 312 attack labels to MITRE ATT&CK tactics and techniques, categorises the ML methods applied, and organizes 96 datasets into a refined taxonomy spanning NIDD, IoT-NIDD, malware, Spam and Phishing, ICS, Insider Threat, custom-collected, and other datasets. Rather than treating attacks, ML methods, and datasets as separate descriptive dimensions, the review analyses them jointly through a tri-axis cross-reference framework, enabling the identification of benchmark dependence, methodological concentration, and underexplored attack–method–dataset intersections that are not visible in single-axis or model-centred surveys. The synthesis shows that the literature is strongly concentrated on externally visible attacks associated with Impact, Initial Access, and Execution, that ensemble and deep learning models dominate high-frequency detection settings, and that dataset usage remains heavily skewed toward a small set of public benchmarks, particularly CSE-CIC-IDS2017, UNSW-NB15, and NSL-KDD. This review further identifies persistent blind spots, including limited coverage of post-compromise ATT&CK behaviours, sparse use of ICS and insider-threat datasets, and weak support for multi-stage or multi-dataset evaluation. These findings provide a more focused and actionable evidence base for future ML-based cyber defense research. Full article
Show Figures

Figure 1

34 pages, 605 KB  
Article
AMNDA: An Adaptive Multi-Layer, Lifecycle-Aware Defense Architecture for Multi-Stage Cyberattacks with Azure-Based Validation
by Zlatan Morić, Vedran Dakić, Damir Regvart and Jasmin Redžepagić
Electronics 2026, 15(9), 1939; https://doi.org/10.3390/electronics15091939 - 3 May 2026
Cited by 1 | Viewed by 553
Abstract
Modern enterprise breaches are no longer isolated events but coordinated, multi-stage campaigns whose success depends on the defender’s inability to translate detection into timely containment. While existing frameworks—such as attack-lifecycle models, Zero Trust architectures, and detection-driven systems—provide valuable capabilities, they lack a formal [...] Read more.
Modern enterprise breaches are no longer isolated events but coordinated, multi-stage campaigns whose success depends on the defender’s inability to translate detection into timely containment. While existing frameworks—such as attack-lifecycle models, Zero Trust architectures, and detection-driven systems—provide valuable capabilities, they lack a formal mechanism for coupling inferred adversarial state with coordinated, cross-layer enforcement. This paper presents AMNDA, an Adaptive Multi-layer, stage-aware Network Defense Architecture that operationalizes lifecycle-aware defense through explicit state-to-control mapping and executable orchestration. Adversarial progression is modeled as a probabilistic state-transition process, and inferred states are systematically mapped to synchronized controls across edge protection, identity governance, internal segmentation, and behavioral detection. A formally defined orchestration function transforms detection outputs into stage-conditioned policy updates, enforcing monotonic tightening of containment as adversarial capability escalates. AMNDA is implemented and validated in a reproducible Microsoft Azure environment. Empirical results show that stage-aligned enforcement actions execute within 1.0–3.1 s, while detection latency remains the dominant constraint, with a median of 1034 s across the validation corpus. This separation reveals a critical operational insight: in modern cloud environments, the limiting factor in lifecycle defense is not enforcement capability but detection timing. The contribution of AMNDA is therefore not a new detection technique but a formal, deployable architecture that converts attack-stage inference into coordinated, low-latency containment. By bridging lifecycle modeling, Zero Trust principles, and automated orchestration, the proposed approach establishes a practical foundation for state-aware, adaptive cyber defense. Full article
Show Figures

Figure 1

19 pages, 5823 KB  
Article
A Human-Centric AI-Enabled Ecosystem for SME Cybersecurity: Cross-Sectoral Practices and Adaptation Framework for Maritime Defence
by Kitty Kioskli, Eleni Seralidou, Wissam Mallouli, Dimitrios Koutras, Pedro Tomás and Dimitrios Kallergis
Electronics 2026, 15(7), 1520; https://doi.org/10.3390/electronics15071520 - 4 Apr 2026
Viewed by 966
Abstract
Artificial intelligence (AI) is increasingly integrated into cybersecurity tools to improve threat detection, anomaly identification, and incident response. However, organisations, particularly small- and medium-sized enterprises (SMEs), often struggle to discover, evaluate, and effectively use AI-enabled cybersecurity solutions due to skills gaps, usability challenges, [...] Read more.
Artificial intelligence (AI) is increasingly integrated into cybersecurity tools to improve threat detection, anomaly identification, and incident response. However, organisations, particularly small- and medium-sized enterprises (SMEs), often struggle to discover, evaluate, and effectively use AI-enabled cybersecurity solutions due to skills gaps, usability challenges, and fragmented tool ecosystems. This paper presents the advaNced cybErsecurity awaReness ecOsystem for SMEs (NERO), a human-centric cybersecurity ecosystem that combines a cybersecurity marketplace with a competency-based training and awareness platform to support the practical adoption of advanced cybersecurity technologies. The NERO Marketplace enables structured discovery, comparison, and assessment of cybersecurity tools based on usability, operational relevance, and competency alignment. Complementing this, the NERO Training Platform delivers modular, multi-modal training aligned with the European Cybersecurity Skills Framework (ECSF) to develop the human competencies required to operate advanced cybersecurity systems. This study contributes a socio-technical framework that addresses the gap between AI tool availability and organisational readiness through ECSF role-based competency mapping and iterative design-based evaluation. The platform targets technical roles like Cybersecurity Implementer to ensure training is aligned with the operational requirements of critical infrastructure protection. Results from cross-sector SME training activities show measurable improvements in cybersecurity awareness, knowledge, and user satisfaction, with knowledge gains exceeding 30% in some modules. Finally, the paper provides a structural mapping of these cross-sectoral results to the maritime defence domain, specifically addressing legacy OT systems and intermittent connectivity constraints. Full article
Show Figures

Figure 1

20 pages, 13249 KB  
Article
Multimodal Dynamic Weighted Authentication Trust Evaluation Under Zero Trust Architecture
by Jianhua Gu, Jianhua Feng and Zefang Gao
Electronics 2026, 15(3), 592; https://doi.org/10.3390/electronics15030592 - 29 Jan 2026
Cited by 1 | Viewed by 796
Abstract
With the improvement of computing power in terminal devices and their widespread application in emerging technology fields, ensuring secure access to terminals has become an important challenge in the current network environment. Traditional security authentication and trust evaluation methods have many shortcomings in [...] Read more.
With the improvement of computing power in terminal devices and their widespread application in emerging technology fields, ensuring secure access to terminals has become an important challenge in the current network environment. Traditional security authentication and trust evaluation methods have many shortcomings in dealing with dynamic and complex network environments, such as limited ability to respond to new threats and inability to adjust evaluation strategies in real time. In response to these issues, this article proposes a dynamic weighted authentication trust evaluation method driven by multimodal data under zero trust architecture. The method introduces user operation risk values and time coefficients, which can dynamically reflect the behavior changes of users and devices in different times and environments, achieving more flexible and accurate trust evaluation. In order to further improve the accuracy of the evaluation, this article also uses the dynamic entropy weight method to calculate the weights of the evaluation indicators. By coupling with the evaluation values, the terminal access security authentication trust score is obtained, and the current authentication trust level is determined to ensure the overall balance of the trust evaluation results. The experimental results show that compared with traditional evaluation algorithms based on information entropy and collaborative reputation, the average error of the method proposed in this study has been reduced by 87.5% and 75%, respectively. It has significant advantages in dealing with complex network attacks, reducing security vulnerabilities, and improving system adaptability. Full article
Show Figures

Figure 1

25 pages, 14310 KB  
Article
Mouse Data Protection in Image-Based User Authentication Using Two-Dimensional Generative Adversarial Networks: Based on a WM_INPUT Message Approach
by Jinwook Kim and Kyungroul Lee
Electronics 2026, 15(2), 292; https://doi.org/10.3390/electronics15020292 - 9 Jan 2026
Viewed by 914
Abstract
With the rapid evolution of computing technologies and the increased proliferation of online services, secure remote user authentication methods have become essential. Among these methods, password-based authentication remains dominant due to its straightforward implementation and ease of use. Nevertheless, password-based systems are particularly [...] Read more.
With the rapid evolution of computing technologies and the increased proliferation of online services, secure remote user authentication methods have become essential. Among these methods, password-based authentication remains dominant due to its straightforward implementation and ease of use. Nevertheless, password-based systems are particularly prone to credential theft from keylogging attacks, making user passwords easily compromised. To address these risks, image-based authentication methods were developed, allowing users to enter passwords through mouse clicks rather than keyboard input, thereby reducing vulnerabilities associated with conventional password entry. However, subsequent studies have shown that mouse movement and click information can still be obtained using APIs such as the GetCursorPos() function or WM_INPUT message, thus undermining the intended security benefits of image-based authentication. In response, various defense strategies have sought to inject artificial or random mouse data through functions such as SetCursorPos() or by utilizing the WM_INPUT message, in an effort to disguise authentic user input. Despite these defenses, recent machine learning-based attacks have demonstrated that such naïve bogus input can be distinguished from legitimate mouse data with up to 99% classification accuracy, resulting in substantial exposure of actual user actions. To address this, a technique leveraging Generative Adversarial Networks (GAN) was introduced to produce artificial mouse data closely mimicking genuine user input, which has been shown to reduce the attack success rate by roughly 37%, offering enhanced protection for mouse-driven authentication systems. This article seeks to advance GAN-based mouse data protection by integrating multiple adversarial generative models and conducting a comprehensive evaluation of their effectiveness with respect to data processing techniques, feature selection, generation intervals, and model-specific performance differences. Our experimental findings reveal that the enhanced approach reduces attack success rates by up to 48%, marking an 11% performance gain over previous mouse data protection approaches, and providing stronger empirical support that our method offers superior protection for user authentication data compared to prior techniques. Full article
Show Figures

Figure 1

19 pages, 1303 KB  
Article
Effect of Deep Recurrent Architectures on Code Vulnerability Detection: Performance Evaluation for SQL Injection in Python
by Asta Slotkienė, Adomas Poška, Pavel Stefanovič and Simona Ramanauskaitė
Electronics 2025, 14(17), 3436; https://doi.org/10.3390/electronics14173436 - 28 Aug 2025
Cited by 1 | Viewed by 2170
Abstract
Security defects in software code can lead to situations that compromise web-based systems, data security, service availability, and the reliability of functionality. Therefore, it is crucial to detect code vulnerabilities as early as possible. During the research, the architectures of the deep learning [...] Read more.
Security defects in software code can lead to situations that compromise web-based systems, data security, service availability, and the reliability of functionality. Therefore, it is crucial to detect code vulnerabilities as early as possible. During the research, the architectures of the deep learning models, peephole LSTM, GRU-Z, and GRU-LN, their element regularizations, and their hyperparameter settings were analysed to achieve the highest performance in detecting SQL injection vulnerabilities in Python code. The results of the research showed that after investigating the effect of hyperparameters on Word2Vector embeddings and applying the most efficient one, the peephole LSTM, delivered the highest performance (F1 = 0.90)—surpassing GRU-Z (0.88) and GRU-LN (0.878)—thereby confirming that the access of the peephole connections to the cell state produces the highest performance score in the architecture of the peephole LSTM model. Comparison of the results with other research indicates that the use of the selected deep learning models and the suggested research methodology allows for improving the performance in detecting SQL injection vulnerabilities in Python-based web applications, with an F1 score reaching 0.90, which is approximately 10% higher than achieved by other researchers. Full article
Show Figures

Figure 1

Review

Jump to: Research

34 pages, 4298 KB  
Review
Modern Approaches to Software Vulnerability Detection: A Survey of Machine Learning, Deep Learning, and Large Language Models
by Md. Shazzad Hossain Shaon and Mst Shapna Akter
Electronics 2025, 14(22), 4449; https://doi.org/10.3390/electronics14224449 - 14 Nov 2025
Cited by 5 | Viewed by 7657
Abstract
Software vulnerabilities pose significant risks to the security and reliability of modern systems, making automated vulnerability detection an essential research area. Traditional static and rule-based approaches are limited in scalability and adaptability, motivating the adoption of data-driven methods. In this survey, we present [...] Read more.
Software vulnerabilities pose significant risks to the security and reliability of modern systems, making automated vulnerability detection an essential research area. Traditional static and rule-based approaches are limited in scalability and adaptability, motivating the adoption of data-driven methods. In this survey, we present a comprehensive review of Machine Learning (ML), Deep Learning (DL), and Large Language Models (LLMs) techniques for vulnerability detection. We analyze recent advances in feature representation, fine-tuning strategies, generative approaches, and prompt engineering, while highlighting their ability to capture both syntactic and semantic properties of source code. Furthermore, we examine commonly used evaluation metrics and provide a critical discussion of key challenges, including the lack of large-scale real-world datasets, limited vulnerability coverage, class imbalance, interpretability gaps, hallucination, and high computational costs. To address these issues, we outline promising future research directions, such as neuro-symbolic hybrid methods, parameter-efficient fine-tuning, continual learning, cross-language generalization, and explainable AI for vulnerability detection. Unlike previous studies, the present work explores learning paradigms from ML to LLMs using comprehensive evaluation criteria that highlight analytical capability, feature interpretability, and code-context comprehension. By combining these factors, our study addresses the methodological gap between classic feature-based approaches and current LLM-driven reasoning frameworks, providing beneficial insights to develop robust, scalable, and trustworthy software vulnerability detection systems. Full article
Show Figures

Graphical abstract

Back to TopTop