Latest Advancements in Machine Learning Applications for Cybersecurity

A Special Issue of Network (ISSN 2673-8732).

Deadline for manuscript submissions: 30 June 2027 | Viewed by 1430

Editors


E-Mail Website
Guest Editor
College of Engineering, University of Toledo, Toledo, OH 43606, USA
Interests: computer and network security; malware defense and detection; security policy development; security testbeds development; intrusion detection; enhancing the security of various critical systems; smart grids; cloud computing; software defined networks; unmanned aerial vehicle; healthcare information systems; transportation information systems
Special Issues, Collections and Topics in MDPI journals

E-Mail Website
Guest Editor
Department of Computer Science and Information Technology, College of Arts and Sciences, Western New England University, Springfield, MA 01119, USA
Interests: cybersecurity; artificial intelligence; adversarial machine learning; intrusion detection systems
Special Issues, Collections and Topics in MDPI journals

Special Issue Information

Dear Colleagues,

The increasing complexity of cyberattacks necessitates advanced, robust, and reliable security mechanisms. Machine learning (ML) has emerged as a powerful tool in the modern cybersecurity arena, enabling various network devices to operate more efficiently and reliably. As cyber threats continue to rapidly evolve in nature and complexity, there is a need for active ongoing research into ML-based cybersecurity solutions. This Special Issue aims to explore the latest advancements in ML applications for cybersecurity, emphasizing both theoretical and practical implementations.

The scope of this Special Issue includes, but is not limited to, the following topics.

  • ML-based intrusion detection/prevention;
  • Impact of adversarial machine learning (AML) in cybersecurity;
  • Anomaly and malware detection;
  • Applications of ML in Internet of Things (IoT) security;
  • Role of high-quality datasets in ML-based cybersecurity.

We invite high-quality submissions including original research articles, survey papers, and studies that present innovative approaches, evaluations, and real-world applications of ML in cybersecurity. Papers that discuss challenges, pave the way for new research avenues, and propose methodologies to improve the trustworthiness of existing ML-based cybersecurity solutions are also encouraged.

You may choose our Joint Special Issue in Electronics.

Prof. Dr. Weiqing Sun
Dr. Medha Pujari
Guest Editors

Manuscript Submission Information

Manuscripts should be submitted online at www.mdpi.com by registering and logging in to this website. Once you are registered, click here to go to the submission form. Manuscripts can be submitted until the deadline. All submissions that pass pre-check are peer-reviewed. Accepted papers will be published continuously in the journal (as soon as accepted) and will be listed together on the special issue website. Research articles, review articles as well as short communications are invited. For planned papers, a title and short abstract (about 250 words) can be sent to the Editorial Office for assessment.

Submitted manuscripts should not have been published previously, nor be under consideration for publication elsewhere (except conference proceedings papers). All manuscripts are thoroughly refereed through a single-anonymized peer-review process. A guide for authors and other relevant information for submission of manuscripts is available on the Instructions for Authors page. Network is an international peer-reviewed open access quarterly journal published by MDPI.

Please visit the Instructions for Authors page before submitting a manuscript. The Article Processing Charge (APC) for publication in this open access journal is 1200 CHF (Swiss Francs). Submitted papers should be well formatted and use good English. Authors may use MDPI's English editing service prior to publication or during author revisions.

Keywords

  • cybersecurity
  • machine learning
  • adversarial machine learning
  • intrusion detection/prevention systems
  • datasets
  • internet of things security
  • anomaly detection
  • malware detection

Benefits of Publishing in a Special Issue

  • Ease of navigation: Grouping papers by topic helps scholars navigate broad scope journals more efficiently.
  • Greater discoverability: Special Issues support the reach and impact of scientific research. Articles in Special Issues are more discoverable and cited more frequently.
  • Expansion of research network: Special Issues facilitate connections among authors, fostering scientific collaborations.
  • External promotion: Articles in Special Issues are often promoted through the journal's social media, increasing their visibility.
  • Reprint: MDPI Books provides the opportunity to republish successful Special Issues in book format, both online and in print.

Further information on MDPI's Special Issue policies can be found here.

Published Papers (2 papers)

Order results
Result details
Select all
Export citation of selected articles as:

Research

Jump to: Other

29 pages, 4175 KB  
Article
Cognitive Network Intrusion Detection Systems: Anomaly and Malware Detection for Zero-Day Attack Resilience
by Jimmy Agung Gunawan, Moses Laksono Singgih and Raden Venantius Hari Ginardi
Network 2026, 6(2), 41; https://doi.org/10.3390/network6020041 - 18 Jun 2026
Viewed by 812
Abstract
Traditional Network Intrusion Detection Systems (NIDSs) face persistent challenges in detecting zero-day attacks due to concept drift, high false-positive rates, and limited adaptability. This research introduces a Cognitive Network Intrusion Detection System (CNIDS) whose central novelty is that effective zero-day handling does not [...] Read more.
Traditional Network Intrusion Detection Systems (NIDSs) face persistent challenges in detecting zero-day attacks due to concept drift, high false-positive rates, and limited adaptability. This research introduces a Cognitive Network Intrusion Detection System (CNIDS) whose central novelty is that effective zero-day handling does not arise from any single mechanism but from the interaction between continual representation learning, persistent vector memory, and human-aligned feedback. By reframing zero-day resilience as a continuous learning process rather than a static detection task, CNIDS emphasizes adaptive operational behavior over raw automated accuracy. The proposed framework integrates Continual Pre-Training (CPT) to align representations with evolving traffic, Supervised Fine-Tuning (SFT) to preserve precision on known attacks, and a Human-in-the-Loop Reinforcement Signal (HRS) that converts low-confidence alerts into structured learning updates. These components are unified through a vector database that functions as long-term episodic memory, enabling similarity-based reasoning and cross-dataset generalization. Ablation results show that disabling any component degrades zero-day adaptation: removing CPT increases drift sensitivity, removing vector memory prevents knowledge retention, and removing human feedback collapses learning to static inference. Using a class-exclusion zero-day protocol on NSL-KDD, UNSW-NB15, and CICIDS2017, CNIDS raises zero-day detection from 0% to 18.2% while maintaining precision above 80% and stabilizing false positives. Full article
Show Figures

Figure 1

Other

Jump to: Research

47 pages, 2380 KB  
Systematic Review
Machine Learning Applications for IoT Intrusion Detection: Network Dependencies, Dataset Limitations, and Regulatory Compliance—A Systematic Review
by Majed Alzahrani, Priyadarsi Nanda, Manoranjan Mohanty and Farag El Zegil
Network 2026, 6(3), 76; https://doi.org/10.3390/network6030076 - 10 Sep 2026
Abstract
Background: Internet of Things (IoT) deployments face complex network dependencies and persistent data limitations that constrain machine learning (ML) intrusion detection systems (IDS). Objective: To synthesise peer-reviewed machine learning IDS research for IoT, focusing on dependency-driven failure propagation and chronic data scarcity, positioned [...] Read more.
Background: Internet of Things (IoT) deployments face complex network dependencies and persistent data limitations that constrain machine learning (ML) intrusion detection systems (IDS). Objective: To synthesise peer-reviewed machine learning IDS research for IoT, focusing on dependency-driven failure propagation and chronic data scarcity, positioned against 2024–2025 EU regulatory requirements (NIS2, the Cyber Resilience Act). Eligibility criteria: Peer-reviewed empirical studies proposing or evaluating a machine learning or deep learning IoT intrusion detection method published in English from January 2018 (limited pre-2018 exceptions for seminal works). Information sources: IEEE Xplore, SpringerLink, Elsevier ScienceDirect, Scopus, Web of Science, and Google Scholar, searched on 12 February 2025. Risk of bias: Each candidate was scored against four criteria (objectives clarity, methodological soundness, reproducibility, IoT-security relevance); studies scoring at least 3 out of 4 were retained. Screening and scoring were performed by one reviewer, with a second reviewer independently checking 20 percent of records. Synthesis methods: Narrative thematic synthesis; heterogeneous metrics and incompatible datasets across studies precluded quantitative meta-analysis. Included studies: Of 427 records identified, 52 studies initially met inclusion criteria; a post hoc independently validated reconstruction of individual QA1–QA4 scores subsequently found that six did not meet the threshold or topical eligibility criteria, yielding a final 46-study corpus. Main findings: Generative adversarial networks (GANs) dominate dataset augmentation work, graph-based communication analysis addresses dependency modelling, and methods based on transformers or federated learning emerge from 2023 onward. Certainty of evidence: No formal grading (GRADE) applies to this narrative synthesis. Confidence in the corpus composition is high, following independent QA1–QA4 validation, while confidence in the thematic findings is moderate given single-reviewer screening and judgment-based classification. Conclusions: We identify three recurring gaps: real-time detection under resource constraints, dependency-aware detection, and regulatory compliance. Closing these gaps requires detection methods that treat IoT security as a networked and regulated system rather than an isolated device classification problem. Registration: Open Science Framework, 10.17605/OSF.IO/NMAK4 (registered retrospectively). No external funding supported this review. Full article
Back to TopTop