Jul 2026· International Journal of Computer Science and Engineering· Vol 14, pp. 29-38· 0 citations
TL;DR
This chapter explores innovative AI technologies, including Machine Learning, Deep Learning, Reinforcement Learning, Explainable AI, and Generative AI, for intelligent attack detection, prediction, and mitigation and discusses current challenges, implementation limitations, and future research directions.
Abstract
The rapid evolution of intelligent cyber-attacks has challenged traditional cybersecurity mechanisms, necessitating the adoption of Artificial Intelligence (AI)-driven defense strategies. Advanced threats such as ransomware, zero-day exploits, Advanced Persistent Threats (APTs), and AI-powered phishing campaigns require adaptive and autonomous security solutions capable of real-time detection and response. This chapter explores innovative AI technologies, including Machine Learning, Deep Learning, Reinforcement Learning, Explainable AI, and Generative AI, for intelligent attack detection, prediction, and mitigation. A unified AI-driven cybersecurity framework is proposed that integrates threat intelligence, behavioural analytics, anomaly detection, explainable decision-making and autonomous incident response to enhance cyber resilience. A case study demonstrates the practical implementation of the framework in an enterprise environment. The chapter also discusses current challenges, implementation limitations, and future research directions, providing researchers and practitioners with insights into developing scalable, trustworthy, and next-generation AI-enabled cybersecurity systems.
XAI-CTI is presented, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection that achieves state-of-the-art detection accuracy and reduces analyst investigation time.
R. Yadav, M.Kala Devi, Chodey et al.· Journal of Intelligent Decis...· 0 citations
The findings indicate that AI-powered cyber defense significantly enhances threat detection, reduces response time, and improves overall cyber resilience compared to traditional security models, highlighting its critical role in next-generation cybersecurity infrastructures.
Chinedu Eze· International Journal of App...· 0 citations
The rapid digital transformation of critical infrastructure has significantly increased its exposure to complex and continuously evolving cyber threats, creating an urgent need for intelligent and adaptive cybersecurity solutions. Conventional security mechanisms, such as signature-based and rule-based intrusion detection systems, often struggle to identify novel attack patterns and provide timely responses to emerging threats. To address these limitations, this study proposes an artificial intelligence (AI)-driven framework for cyber threat detection and automated response that strengthens the security, resilience, and operational reliability of critical infrastructure environments. The experimental evaluation demonstrates that AI-based techniques substantially outperform traditional cybersecurity methods in terms of detection performance. Conventional rule-based systems achieve an average detection accuracy of approximately 68%, whereas machine learning and deep learning models improve the accuracy to nearly 80% and 88%, respectively. The proposed AI-driven framework delivers the highest performance, achieving an overall detection accuracy of approximately 94%. This superior performance highlights its capability to accurately identify both previously known attacks and sophisticated zero-day threats. Beyond detection accuracy, the study evaluates response time, which plays a crucial role in limiting the impact of cyber incidents. The findings reveal that the proposed AI-enabled response mechanism reduces the average response time to approximately 35 seconds, compared with around 150 seconds for manual response processes and 90 seconds for conventional rule-based automation. Such improvements enable faster threat containment, minimize operational disruption, and enhance the resilience of critical infrastructure systems. The framework also demonstrates notable improvements in reducing false positive alerts. The AI-driven approach achieves a false positive rate of approximately 5%, significantly lower than the 20% observed in signature-based systems and the 12% reported for anomaly-based detection methods. By minimizing false alarms, the proposed framework improves the efficiency of security operations, reduces alert fatigue among cybersecurity analysts, and enables security teams to prioritize genuine threats more effectively.
Reily Kaium, Lizi Alasa, K. Robert et al.· The Eastasouth Journal of In...· 0 citations
Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat intelligence platforms, and automated incident response tools, enabling organizations to identify and neutralize threats with greater speed and precision. However, the same interconnectedness that drives digital transformation—spanning IoT ecosystems, cloud infrastructures, and 5G networks—has also expanded the attack surface available to malicious actors, giving rise to increasingly sophisticated, adaptive, and often AI-enabled threats such as adversarial machine learning attacks, deepfake-driven social engineering, and automated supply chain exploits. This paper examines the dual role of AI as both a defensive asset and a potential vector of risk within modern cybersecurity ecosystems. Drawing on a review of existing AI-driven security solutions, comparative analysis of AI-based versus traditional defense mechanisms, and case study evaluation, the study assesses the effectiveness, limitations, and ethical implications of AI integration in cyber defense. Findings indicate that while AI substantially improves threat detection accuracy and response times, challenges related to explainability, adversarial vulnerability, and regulatory oversight remain significant barriers to widespread adoption. The paper concludes with practical recommendations for organizations and policymakers seeking to harness AI's defensive potential while mitigating its associated risks, emphasizing the need for explainable AI frameworks, human-AI collaboration, and adaptive governance structures in an increasingly interconnected digital age.
Nicolas Guzman Camacho· Journal of Artificial Intell...· 0 citations
This review includes a systematic synthesis of the studies on self-evolving cyber defense with a focus on the merging of artificial intelligence, autonomy, and adversarial learning, as well as autonomous defense systems enabled by reinforcement learning and multi-agent systems.
Babatunde AbdulAzeez Alli, Taoheed Abiodun Yusuf, Jefferson Ederhion et al.· Journal of Computer Virology...· 0 citations
Cybersecurity systems face significant challenges in detecting sophisticated cyber threats, predicting future attacks, and executing rapid response actions in dynamic network environments. To address these limitations, this study proposes XAI-HDRL, an Explainable AI-Driven Hybrid Deep Reinforcement Learning Framework for Real-Time Cyber Threat Detection, Prediction, and Automated Response. The proposed framework integrates Artificial Protozoa Optimization (APO) for optimal feature selection, CNN-BiLSTM for accurate threat detection, LIME for model explainability and transparent decision-making, Proximal Policy Optimization (PPO)-based Deep Reinforcement Learning for automated response generation, and a Transformer-based Threat Prediction Module for proactive cyberattack forecasting. The framework was evaluated using the CICIDS2017 dataset and simulated in the NS-3 network simulator integrated with Python/TensorFlow. Experimental results were compared with SentinelAI-IDS, CNN-LSTM, and Explainable Deep Learning-based Threat Detection System (XDLTDS). The proposed XAI-HDRL achieved a Threat Prediction Accuracy of 98.84%, Attack Mitigation Rate of 97.52%, Resource Utilization of 91.37%, and Network Throughput of 978.45 Mbps, while reducing Detection Time to 18.63 ms and Response Time to 12.47 ms. Compared with the strongest baseline (XDLTDS), the proposed framework improved Threat Prediction Accuracy by 5.73%, Attack Mitigation Rate by 8.29%, Resource Utilization by 10.08%, and Network Throughput by 11.82%, while reducing Detection Time and Response Time by 41.72% and 47.94%, respectively. These findings demonstrate that XAI-HDRL provides a highly effective, explainable, and autonomous cybersecurity solution capable of enhancing real-time threat intelligence, predictive defense, and automated incident response for next-generation network security infrastructures.
A. Raj, Sasanko Sekhar Gantayat, K. Venkatesh et al.· 2026 7th International Confe...· 0 citations