Jul 2026· DMPedia Lecture Notes in Computer Science & Engineering· pp. 254-275· 0 citations· 12 references
TL;DR
A GenAI-driven adaptive cybersecurity mesh architecture designed for real-time threat detection in distributed intelligent communication environments and demonstrates improved detection accuracy, reduced false positives, and lower response latency compared to baseline signature-based and centralised ML-based IDS models.
Abstract
Intelligent communication systems integrating Internet of Things (IoT), cyber-physical infrastructures, edge computing, and next-generation communication protocols have significantly expanded the attack surface of modern digital ecosystems. Traditional intrusion detection systems (IDS) remain predominantly centralised, signature-based, and insufficiently adaptive to evolving multi-vector and zero-day threats. This paper proposes a GenAI-driven adaptive cybersecurity mesh architecture designed for real-time threat detection in distributed intelligent communication environments. The proposed framework integrates zero-trust security principles with a distributed mesh of edge security nodes coordinated through a policy orchestration layer. A generative AI-based adaptive threat modelling engine continuously synthesises contextual attack patterns and enhances anomaly detection across network, application, and behavioural layers. A formal cross-layer risk-scoring model fuses heterogeneous security signals to generate dynamic threat-confidence indices. The system is evaluated in a simulated intelligent communication environment comprising heterogeneous nodes, mixed legitimate traffic, and multiple attack scenarios, including DDoS, man-in-the-middle, and protocol-exploitation attacks. Experimental results demonstrate improved detection accuracy, reduced false positives, and lower response latency compared to baseline signature-based and centralised ML-based IDS models. The proposed architecture offers a scalable and adaptive security paradigm suitable for next-generation intelligent communication infrastructures.
The rapid growth of interconnected digital infrastructures, cloud computing environments, Internet of Things devices, and enterprise networking systems has significantly increased the frequency, complexity, and sophistication of cyberattacks targeting organizational information assets. Traditional cybersecurity mechanisms based primarily on signature detection and static rule-based monitoring are becoming increasingly ineffective against modern attack strategies such as zero-day exploits, advanced persistent threats, insider attacks, ransomware campaigns, and polymorphic malware. In this context, adaptive threat intelligence frameworks integrated with behavior-based analytics have emerged as a promising approach for enhancing real-time cyberattack detection and proactive security response capabilities. This research investigates the design and implementation of an adaptive threat intelligence framework capable of identifying malicious activities through continuous behavioral analysis, anomaly detection, and dynamic threat assessment techniques. The study focuses on how behavioral analytics can improve cybersecurity resilience by monitoring user activities, network communication patterns, system interactions, application behavior, and endpoint activities to identify deviations from established normal operational baselines. Unlike traditional detection approaches that depend heavily on predefined signatures, behavior-based analytics enables the identification of previously unknown threats and evolving attack vectors through machine learning algorithms, predictive analytics, and intelligent pattern recognition models. The proposed framework integrates adaptive learning mechanisms that continuously update threat intelligence repositories based on real-time attack behaviors, thereby improving detection accuracy and minimizing response delays. The research further examines the role of artificial intelligence, big data analytics, and automated incident response systems in strengthening cyber defense infrastructures across enterprise environments. In addition to operational advantages, the study critically evaluates challenges associated with implementing adaptive threat intelligence systems, including false-positive generation, data privacy concerns, computational complexity, adversarial machine learning attacks, scalability limitations, and integration difficulties within heterogeneous network architectures. The research methodology incorporates quantitative analysis, simulated attack scenarios, case study evaluations, and expert assessments to measure the effectiveness of behavior-based threat detection techniques in identifying malicious activities across dynamic cybersecurity environments. Findings from the study indicate that adaptive threat intelligence frameworks significantly enhance threat visibility, accelerate incident response, reduce detection latency, and improve organizational preparedness against sophisticated cyber threats when compared to conventional security monitoring systems. The research also emphasizes the importance of continuous learning models, human oversight, ethical cybersecurity governance, and secure data management practices to ensure sustainable and reliable implementation of intelligent threat detection systems. The study concludes that behavior-based adaptive cybersecurity frameworks represent a critical advancement in modern cyber defense strategies by enabling organizations to detect, analyze, and respond to emerging cyber threats in real time while maintaining operational continuity, information security, and digital infrastructure resilience in increasingly hostile cyber environments.
S. Tamilselvi· Journal of Intelligent Decis...· 0 citations
Cloud-enabled Intelligent Transportation Systems (ITS) leverage Vehicle-to-Everything (V2X) communications to support scalable data processing and real-time traffic management. However, this integration significantly expands the cyber-physical attack surface. Conventional intrusion detection systems (IDSs) that rely on static signatures or offline-trained models are often ill-suited to counter adaptive attackers. This paper presents the Adaptive Stackelberg Defense Scheme (ASDS), a proactive intrusion detection system that models attacker-defender interactions as a hierarchical Bayesian Stackelberg game with incomplete information. ASDS employs Bayesian filtering to jointly estimate system states and attacker types in real time, enabling adaptive defense strategies. Evaluated against False Data Injection (FDI), Denial-of-Service (DoS), and spoofing attacks, ASDS achieves detection accuracy between 94% and 98%, false positive rates ranging from 0.02 to 0.08, and response latency under 50 ms. These results underscore its effectiveness in securing cloud-enabled ITS environments.
Emmanuel Kigmo Yonga, Mounirah Djam-Doudou, J. Emati et al.· 2026 6th International Confe...· 0 citations
This review presents a comprehensive analysis of machine learning-based intrusion detection systems, covering a wide range of techniques including supervised learning, unsupervised learning, ensemble learning, and deep learning models, and discusses critical challenges affecting the deployment of ML-based IDS.
Ranobir Hasan, H. Jamal, Kamal Kamal et al.· The Eastasouth Journal of In...· 0 citations
The rapid growth of Internet of Things (IoT) networks has increased their exposure to cyber threats, while existing Intrusion Detection Systems (IDS) remain largely reactive and resource-intensive. This paper proposes a HMCTI Framework for proactive cyberattack detection in IoT environments. The framework distributes threat intelligence across Edge, Fog, and Cloud layers, integrating behavioral drift analysis, flow-level features, and device-context information to identify attacks at their early stages. By combining lightweight anomaly detection, context-aware threat analysis, and multi-layer threat correlation, HMCTI enhances detection capability while maintaining scalability and efficiency. Experimental evaluation using the CICIoT2023 dataset assesses detection accuracy, Detection Lead Time (DLT), and resource overhead. The proposed framework provides a scalable and proactive approach for early cyberattack detection in next-generation IoT networks.
Sajjad Ahmed, Yaseen Baig, Rabi Iqbal Rana et al.· International Conference on...· 0 citations
This study examines the application of artificial intelligence-powered intrusion detection systems that leverage deep learning architectures and anomaly detection methodologies to identify malicious activities within dynamic network environments and concludes that the convergence of deep learning methodologies and anomaly detection techniques provides a robust foundation for next-generation intrusion detection systems.
M. A. Gandhi, Dinesh Baban Kute, U. Hemavathi· International journal of com...· 0 citations
Rapidly increasing numbers of devices connected to the Internet of Things have greatly changed how modern digital ecosystems operate by facilitating interoperability among industries such as healthcare, intelligent transportation systems, smart city technology and industrial automation. The increasing number of Internet connected devices has created new vulnerabilities for cyber-attacks on these devices, such as DDoS, Botnets, unauthorized access to devices and data breaches. Traditional IoT protection approaches generally fail to address these types of threats due to their limited resources, heterogeneity, and constant changes. In this regard, artificial intelligence has been proposed as a viable method to enhance cybersecurity for IoTs via AI-based systems capable of intelligent threat detection, adaptive learning, and real-time responses.
To provide a clear understanding of AI-based cybersecurity methods for IoTs, this paper presents a systematic literature review (SLR) using a structured review process that follows the PRISMA guidelines. A total of 3072 original research papers on AI-based cybersecurity methods for IoTs published in top indexing databases were obtained. Each selected paper was analysed using a systematic screening process. The studies were grouped into six distinct theme areas, including machine learning-based intrusion detection, deep learning-based anomaly detection, hybrid/ensemble security models, federated learning frameworks, explainable AI, and blockchain-enabled IoT security mechanisms.
Machine learning algorithms demonstrated high computational efficiency in detecting intrusions but lacked the flexibility to adapt to new threats. On the other hand, deep learning algorithms demonstrated a high intrusion detection capability but at a high computational cost. Hybrid/federated learning algorithms represent an emerging class that can deliver both the required accuracy and scalability while preserving user privacy. While several important advancements exist in AI-based cybersecurity methods for IoTs, many additional areas will require significant work before widespread adoption. Some examples include continued reliance on outdated benchmarks to evaluate algorithmic performance; the absence of validation testing for algorithms running in real-time environments; difficulty interpreting results generated by black-box AI-based algorithms; and a lack of collaboration among researchers studying different layers of the edge-cloud architecture.
As a result of synthesising the current state of the art in AI-based cybersecurity methods for IoTs, this paper proposes a conceptual model of an AI-based adaptive cybersecurity system for IoTs, designed to utilise edge intelligence, federated learning, and continuous feedback mechanisms to detect and respond dynamically to potential threats. This paper makes contributions to the current body of knowledge regarding the rapidly changing landscape of IoT cybersecurity by providing an organised, analytical summary of the current state of the art in AI-based cybersecurity methods for IoTs; defining specific research gaps; and providing recommendations for future research to develop scalable, understandable, and adaptable security systems for IoT environments.
M. Prasad, D. Kumar, Debasish Paul· Journal of Intelligent Decis...· 0 citations