Skip to content
Review Open access

Survey on Artificial Intelligence for Cyber Threat Detection and Response in Cloud Environments

Jun 2026 · International Journal for Research in Applied Science and Engineering Technology · Vol 14, pp. 3312-3320 · 0 citations

TL;DR

This survey provides a structured synthesis of the current state of the art, identifying key research directions for the next generation of intelligent, autonomous cloud security systems.

Abstract

The rapid expansion of cloud computing infrastructures has fundamentally transformed how organizations manage and deploy digital services, simultaneously introducing a complex and evolving attack surface that traditional security mechanisms fail to adequately address. This survey examines the convergence of artificial intelligence (AI) and autonomous cybersecurity with a focus on cloud environments. We systematically review thirteen recent papers spanning five core research themes: AI-driven threat detection and classification, explainable AI (XAI) for cybersecurity transparency, autonomous response and mitigation strategies, real-time cyber threat attribution, and AI-enhanced education for cybersecurity workforce development. Our analysis highlights the state-of-the-art techniques including Graph Neural Networks (GNNs), transformerbased attention mechanisms, Federated Deep Learning (FDL), reinforcement learning, and multi-modal data fusion, all applied to the challenge of building self-healing, autonomous cloud defense systems. We further discuss persistent challenges such as dataset quality, model interpretability, adversarial robustness, and the gap between academic research and real-world deployment. This survey provides a structured synthesis of the current state of the art, identifying key research directions for the next generation of intelligent, autonomous cloud security systems

Read PDF

Similar papers

Review Open access Aug 2026

Artificial Intelligence and Cyber Defense: Navigating Emerging Threats in an Interconnected World

Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat intelligence platforms, and automated incident response tools, enabling organizations to identify and neutralize threats with greater speed and precision. However, the same interconnectedness that drives digital transformation—spanning IoT ecosystems, cloud infrastructures, and 5G networks—has also expanded the attack surface available to malicious actors, giving rise to increasingly sophisticated, adaptive, and often AI-enabled threats such as adversarial machine learning attacks, deepfake-driven social engineering, and automated supply chain exploits. This paper examines the dual role of AI as both a defensive asset and a potential vector of risk within modern cybersecurity ecosystems. Drawing on a review of existing AI-driven security solutions, comparative analysis of AI-based versus traditional defense mechanisms, and case study evaluation, the study assesses the effectiveness, limitations, and ethical implications of AI integration in cyber defense. Findings indicate that while AI substantially improves threat detection accuracy and response times, challenges related to explainability, adversarial vulnerability, and regulatory oversight remain significant barriers to widespread adoption. The paper concludes with practical recommendations for organizations and policymakers seeking to harness AI's defensive potential while mitigating its associated risks, emphasizing the need for explainable AI frameworks, human-AI collaboration, and adaptive governance structures in an increasingly interconnected digital age.

Nicolas Guzman Camacho · 0 citations
Open access Aug 2026

Artificial Intelligence-Based Cyber Threat Detection and Response for Critical Infrastructure Security

The rapid digital transformation of critical infrastructure has significantly increased its exposure to complex and continuously evolving cyber threats, creating an urgent need for intelligent and adaptive cybersecurity solutions. Conventional security mechanisms, such as signature-based and rule-based intrusion detection systems, often struggle to identify novel attack patterns and provide timely responses to emerging threats. To address these limitations, this study proposes an artificial intelligence (AI)-driven framework for cyber threat detection and automated response that strengthens the security, resilience, and operational reliability of critical infrastructure environments. The experimental evaluation demonstrates that AI-based techniques substantially outperform traditional cybersecurity methods in terms of detection performance. Conventional rule-based systems achieve an average detection accuracy of approximately 68%, whereas machine learning and deep learning models improve the accuracy to nearly 80% and 88%, respectively. The proposed AI-driven framework delivers the highest performance, achieving an overall detection accuracy of approximately 94%. This superior performance highlights its capability to accurately identify both previously known attacks and sophisticated zero-day threats. Beyond detection accuracy, the study evaluates response time, which plays a crucial role in limiting the impact of cyber incidents. The findings reveal that the proposed AI-enabled response mechanism reduces the average response time to approximately 35 seconds, compared with around 150 seconds for manual response processes and 90 seconds for conventional rule-based automation. Such improvements enable faster threat containment, minimize operational disruption, and enhance the resilience of critical infrastructure systems. The framework also demonstrates notable improvements in reducing false positive alerts. The AI-driven approach achieves a false positive rate of approximately 5%, significantly lower than the 20% observed in signature-based systems and the 12% reported for anomaly-based detection methods. By minimizing false alarms, the proposed framework improves the efficiency of security operations, reduces alert fatigue among cybersecurity analysts, and enables security teams to prioritize genuine threats more effectively.

Reily Kaium, Lizi Alasa, K. Robert et al. · 0 citations
Open access Jul 2026

Innovative AI-Driven Intelligent Attack Detection, Prediction, and Autonomous Response for Next-Generation Cyber Security

This chapter explores innovative AI technologies, including Machine Learning, Deep Learning, Reinforcement Learning, Explainable AI, and Generative AI, for intelligent attack detection, prediction, and mitigation and discusses current challenges, implementation limitations, and future research directions.

S. Mohanarangan, G. Shoba, D. Karthika et al. · 0 citations
Open access 2026

A Multi-Layer Deep Learning Framework for Intelligent Cyber Attack Prevention

The findings demonstrate that the proposed multi-layer deep learning framework significantly improves cyberattack detection accuracy, reduces false-positive alerts, enhances real-time response capabilities, and strengthens proactive cybersecurity defense mechanisms.

A. Owolabi · 0 citations
Open access Aug 2026

An Explainable AI-Driven Cyber Threat Intelligence Framework for Proactive and Adaptive Cyberattack Detection

XAI-CTI is presented, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection that achieves state-of-the-art detection accuracy and reduces analyst investigation time.

R. Yadav, M.Kala Devi, Chodey et al. · 0 citations
Review Open access Aug 2026

AI-ENHANCED INFORMATION SECURITY FRAMEWORKS FOR CLOUD-ENABLED IOT NETWORKS: A COMPREHENSIVE REVIEW

This review paper critically examines the integration of Artificial Intelligence (AI) and Machine Learning (ML) techniques to enhance information security within Cloud-IoT networks, focusing on hybrid Deep Learning models (CNN-LSTM), predictive analytics, and automated threat response mechanisms.

R. Saravanakumar, V.Anuratha, M.Elamparithi · 0 citations