Skip to content
Review Open access

Self-evolving cyber defense: an analytical review of AI-driven autonomous and adversarial systems

Jul 2026 · Journal of Computer Virology and Hacking Techniques · Vol 22 · 0 citations · 168 references
Computer Science

TL;DR

This review includes a systematic synthesis of the studies on self-evolving cyber defense with a focus on the merging of artificial intelligence, autonomy, and adversarial learning, as well as autonomous defense systems enabled by reinforcement learning and multi-agent systems.

Abstract

The growing complexity, size, and dynamism of cyber threats have revealed inherent weaknesses of the traditional, static cybersecurity models. Attackers nowadays take advantage of artificial intelligence, automation, and adversarial learning methods to avoid detection, create new variants of attacks, and maintain long-term intrusions. In response, cybersecurity research has turned to self-evolving cyber defense systems that can engage in constant learning, autonomous decision-making, and co-evolution with intelligent attackers. This review includes a systematic synthesis of the studies on self-evolving cyber defense with a focus on the merging of artificial intelligence, autonomy, and adversarial learning. We discuss the evolution of cyber threats, machine learning and deep learning approaches for adaptive threat detection, as well as autonomous defense systems enabled by reinforcement learning and multi-agent systems. The review also explores the adversarial machine learning as a source of emerging threats and a powerful defense foundation with focus on the co-evolution of the attackers and the defenders. In addition to algorithmic views, the paper has provided an overview of system architectures, evaluation measures, ethics and legal aspects, and real-life implementation of industrial applications in critical infrastructures, military systems, financial services, smart cities, and cyber-physical environments. The major issues concerning scalability, resistance to adaptive opponents, lack of information, and the interaction of humans and AI are addressed. Lastly, the review presents directions of future research, such as entirely autonomous defense ecosystems, hybrid neuro-symbolic systems, quantum-resilient AI security, and intelligence sharing across domains. This work brings together dispersed research in various fields to offer a reference and roadmap on how to progress to the next generation of self-evolving cyber defense systems.

Read PDF

Similar papers

Review Open access Aug 2026

Artificial Intelligence and Cyber Defense: Navigating Emerging Threats in an Interconnected World

Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat intelligence platforms, and automated incident response tools, enabling organizations to identify and neutralize threats with greater speed and precision. However, the same interconnectedness that drives digital transformation—spanning IoT ecosystems, cloud infrastructures, and 5G networks—has also expanded the attack surface available to malicious actors, giving rise to increasingly sophisticated, adaptive, and often AI-enabled threats such as adversarial machine learning attacks, deepfake-driven social engineering, and automated supply chain exploits. This paper examines the dual role of AI as both a defensive asset and a potential vector of risk within modern cybersecurity ecosystems. Drawing on a review of existing AI-driven security solutions, comparative analysis of AI-based versus traditional defense mechanisms, and case study evaluation, the study assesses the effectiveness, limitations, and ethical implications of AI integration in cyber defense. Findings indicate that while AI substantially improves threat detection accuracy and response times, challenges related to explainability, adversarial vulnerability, and regulatory oversight remain significant barriers to widespread adoption. The paper concludes with practical recommendations for organizations and policymakers seeking to harness AI's defensive potential while mitigating its associated risks, emphasizing the need for explainable AI frameworks, human-AI collaboration, and adaptive governance structures in an increasingly interconnected digital age.

Nicolas Guzman Camacho · 0 citations
Review Open access Jul 2026

Mitigating cyberattacks on autonomous vehicles: a comprehensive review of Generative Artificial Intelligence defense techniques

Autonomous vehicles (AVs) are rapidly becoming foundational components of intelligent transportation systems (ITS), yet their complex cyber-physical architectures expose them to a broad and continuously evolving threat landscape. Existing cybersecurity solutions struggle to keep pace with the dynamic, data-intensive nature of AV ecosystems, leaving critical vulnerabilities unaddressed across perception, communication, and decision-making subsystems. Generative Artificial Intelligence (GAI), encompassing Generative Adversarial Networks (GANs), Variational Autoencoders (VAEs), and Diffusion Models (DMs), has emerged as a powerful paradigm for both offensive simulation and defensive reinforcement, enabling synthetic data generation, adversarial attack emulation, and enhanced anomaly and intrusion detection. Yet despite growing interest in GAI for general cybersecurity, its systematic application to AV-specific security remains fragmented and underexplored. This paper addresses that gap through a PRISMA-guided systematic review of GAI-driven defense mechanisms for AV cybersecurity, synthesizing 216 peer-reviewed studies drawn from major scientific databases and published between January 2020 and February 2026. Three principal contributions are made. First, we introduce an AV-centric, three-dimensional taxonomy that classifies defenses along generative architecture, defensive function, and AV-relevant attack surface, explicitly anchoring each study to AV subsystems and operational contexts. Second, we provide a disciplined synthesis that separates study-specific performance findings from broader design insights, exposing fundamental gaps between conventional and GAI-based approaches in scalability, adaptability, and resilience. Third, we identify critical open challenges—including training instability, the absence of standardized AV security benchmarks, real-time deployment constraints, and limited explainability—and propose targeted research directions for safety-critical environments. By grounding GAI defenses within AV system layers and cyber-physical threat models, this review serves as a practitioner- and researcher-oriented reference for building robust, scalable, and trustworthy cybersecurity solutions for next-generation autonomous vehicles.

May Phyu Phyu Thaw, D. Sarwatt, Huansheng Ning et al. · 0 citations
Open access Jul 2026

Innovative AI-Driven Intelligent Attack Detection, Prediction, and Autonomous Response for Next-Generation Cyber Security

This chapter explores innovative AI technologies, including Machine Learning, Deep Learning, Reinforcement Learning, Explainable AI, and Generative AI, for intelligent attack detection, prediction, and mitigation and discusses current challenges, implementation limitations, and future research directions.

S. Mohanarangan, G. Shoba, D. Karthika et al. · 0 citations
Preprint Aug 2026

SysEvolve: An AI-native, safe, autonomous adversarial attack-defense co-evolutionary system

The rapid advancement of large language models (LLMs) has created a growing asymmetry in cybersecurity, where attack accelerates toward autonomous execution while defense remains predominantly human-intensive. Despite substantial prior work across cyber ranges, AI-driven attack, and AI-driven defense, this asymmetry persists. We trace it to a deeper root cause, that evolution itself has stalled on both sides at three layers. To overcome this, we propose co-evolution as the integrating insight, where attack and defense AI agents autonomously and safely drive each other's evolution through adversarial confrontation. Based on this insight, we present \sysevolve, comprising three co-designed components, \sysfield, \sysspear, and \sysarmor. \sysfield constructs realistic multi-host ranges. \sysspear generates efficient, safe attack schemes. \sysarmor performs real-time, interpretable defense. Together they form a self-driven adversarial loop restoring evolution at all three layers. In evaluation, \sysfield achieves zero-loss collection at 2.1\% overhead and orchestrates 257 CVEs into 1,148 ranges, \sysspear improves attack success by over 25\% over baseline LLMs, and \sysarmor achieves 10--1000$\times$ greater precision than prior systems and detects real APT attacks in production at Huawei and Sangfor. Our evaluation also reveals three findings about LLM agent capabilities. First, multi-step composition and larger topologies expose agent capability gaps hidden by single-step evaluations. Second, the bottleneck lies after initial access in post-compromise state utilization. Third, LLM agents are susceptible to environmental interference. When decoy endpoints are deployed in the range, agent timeouts triple and downstream completion disappears despite the success rates of initial accesses are unchanged.

Yuhan Meng, Shaofei Li, Jionghao Huang et al. · 0 citations
Open access 2021

AI-Driven Cyber Defense Systems Using Real-Time Analytics

The findings indicate that AI-powered cyber defense significantly enhances threat detection, reduces response time, and improves overall cyber resilience compared to traditional security models, highlighting its critical role in next-generation cybersecurity infrastructures.

Chinedu Eze · 0 citations