Skip to content

AI-Driven Threat Detection Architecture

Oct 2026 · CRC Press eBooks
Network Security and Intrusion Detection

Abstract

The rapid proliferation of digital infrastructure, spanning cloud computing, the Internet of Things (IoT), edge networks, and mobile platforms, has dramatically expanded the attack surface available to cybercriminals. Traditional signature-based intrusion detection systems, while effective against known threats, are fundamentally inadequate in the face of zero-day exploits, advanced persistent threats (APTs), encrypted malicious traffic, and evolving ransomware campaigns. This chapter presents a comprehensive examination of AI-driven threat detection architectures as the next-generation response to these escalating cybersecurity challenges. It explores the full spectrum of the threat landscape, encompassing DDoS attacks, botnets, APTs, and cloud-specific vulnerabilities, before detailing the layered architectural framework through which AI-based detection systems operate, from raw data collection at the network and endpoint layer, through preprocessing and feature extraction, to model inference and automated response. A range of machine learning and deep learning methodologies is evaluated, including supervised classifiers such as decision trees, random forests, k-nearest neighbors, and convolutional neural networks, as well as unsupervised approaches like autoencoders and graph neural networks. Benchmark datasets, including CICIDS2017 and UNSW-NB15, are used to assess comparative model performance across accuracy, precision, recall, and F1-score. The chapter further addresses the deployment challenges of AI-based intrusion detection, including class imbalance, adversarial evasion, concept drift, computational cost, privacy concerns, and surveys emerging research directions such as federated learning, explainable AI, large language model integration, and the long-term vision of autonomous security operations centers. Together, these discussions establish a technical and strategic foundation for building intelligent, scalable, and resilient cybersecurity systems in modern enterprise environments.

View source

Similar papers

#computer vision Review Sep 2017

Agile Software Development Methods: Review and Analysis

This publication proposes a definition and a classification of agile software development approaches and analyses ten software development methods that can be characterized as being "agile" against the defined criterion.

P. Abrahamsson, O. Salo, Jussi Ronkainen et al. · 727 citations · ⚡54
#computer vision Jun 2008

The impact of agile practices on communication in software development

The study shows that agile practices improve both informal and formal communication, but indicates that, in larger development situations involving multiple external stakeholders, a mismatch of adequate communication mechanisms can sometimes even hinder the communication.

M. Pikkarainen, Jukka Haikara, O. Salo et al. · 401 citations · ⚡48
#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54

Related blog posts

Microsoft Research Blog Jul 13, 2026

Verifying Rust cryptography in SymCrypt, from standards to code

Cryptographic code supports vital protections in modern computing systems. Learn how a new method helps verify code as developers write it while preserving speed and adaptability as it gets implemented and evolves. The post Verifying Rust cryptography in SymCrypt, from standards to code appeared first on Microsoft Research.

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.