Skip to content
Open access

Autonomous Cyber Defense Learning Using Reinforcement and Threat Intelligence

2026 · Direct Research Journal of Engineering and Information Technology · 0 citations

TL;DR

The findings demonstrate that integrating reinforcement learning with threat intelligence can provide a highly adaptive and proactive cyber defense mechanism suitable for modern network environments.

Abstract

The increasing sophistication, frequency, and scale of cyberattacks have created significant challenges for conventional cybersecurity systems. Traditional security solutions such as firewalls, signature-based intrusion detection systems, and antivirus software are largely reactive and depend on predefined rules and known attack patterns. Consequently, these systems often struggle to detect and respond effectively to emerging threats such as Advanced Persistent Threats (APTs), zero-day attacks, ransomware, botnets, and insider attacks. Recent advancements in Artificial Intelligence (AI), particularly Reinforcement Learning (RL), have demonstrated the potential to create autonomous systems capable of learning and adapting to dynamic environments. Simultaneously, Cyber Threat Intelligence (CTI) provides valuable contextual information regarding threat actors, attack techniques, vulnerabilities, and indicators of compromise. This study proposes an Autonomous Cyber Defense Framework that integrates Reinforcement Learning and Threat Intelligence to enhance threat detection, decision-making, and automated response capabilities. The framework employs a Deep Q-Network (DQN) agent that continuously learns optimal defense actions through interaction with network environments while utilizing threat intelligence feeds to improve situational awareness. Experimental evaluation was conducted using benchmark cybersecurity datasets, including CICIDS2017 for Intrusion Detection, UNSW-NB15 for attack classification, CTU-13 for botnet detection and Custom Threat Feeds for threat intelligence. The results indicate that the proposed framework achieved a precision rate of 98.4%, a recall rate of 98.2%, an F1-score of 98.3%, and a threat mitigation rate of 96.8%. False positive rate of 1.9, False negative rate of 1.5 and Response rate of 41%, significantly outperforming traditional machine learning and signature-based security approaches. The findings demonstrate that integrating reinforcement learning with threat intelligence can provide a highly adaptive and proactive cyber defense mechanism suitable for modern network environments.

Read PDF

Similar papers

Conference Aug 2026

Self-Healing Cybersecurity Framework using Generative Artificial Intelligence for Autonomous Network Recovery

Traditional cybersecurity technologies have difficulty adapting to the increasing sophistication and numbers of cyberattacks. Typically, traditional technologies use manual interventions and static rules to defend against cyberattacks; therefore, they are limited in their ability to adapt and respond quickly to changin...

Manik Rakhra, T. Sarkar, Renupal Sood et al. · 0 citations
Review Open access Aug 2026

Artificial Intelligence and Cyber Defense: Navigating Emerging Threats in an Interconnected World

Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat inte...

Nicolas Guzman Camacho · 0 citations
Conference Open access Oct 2026

Adaptive AI-Driven Cybersecurity: From Reactive Detection to Predictive and Continuously Learning Defense

Modern cyber threats evolve faster than static, signature-driven defenses can respond, creating a need for security architectures that can continuously observe, interpret, predict, and adapt to changing attack behavior. This talk presents an adaptive AI-driven cybersecurity approach that combines real-time security tel...

Kalyana Krishna Kondapalli · 0 citations
#federated learning Open access Aug 2026

An Explainable AI-Driven Cyber Threat Intelligence Framework for Proactive and Adaptive Cyberattack Detection

XAI-CTI is presented, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection that achieves state-of-the-art detection accuracy and reduces analyst investigation time.

R. Yadav · 0 citations
Review Open access Aug 2026

AI-DRIVEN THREAT DETECTION AND AUTOMATED RESPONSE IN MODERN CYBERSECURITY SYSTEMS: A SYSTEMATIC REVIEW AND FRAMEWORK

A conceptual framework is proposed that combines detection, explanation, and orchestrated response in a continuous feedback loop that is suitable for zero trust and IoT-enabled critical-infrastructure environments that will allow for continuous retraining of the model.

Jayesh Dalmet · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.