Skip to content
Review Open access

Machine intelligence approaches for preventing adversarial malware attacks in intrusion detection systems: A systematic review

Aug 2026 · Progress in Artificial Intelligence · 0 citations · 142 references

TL;DR

This systematic literature review provides a rigorous, transparent, and reproducible foundation for knowledge by synthesizing all available evidence on IDSs over recent years by highlighting the differences, strengths, and shortcomings from each MI-IDS approach.

Abstract

In academia, the epistemology of Adversarial Malware Attacks ( AMAs ) in the context of an Intrusion Detection System ( IDS ) has not been fully grasped. Using Machine Intelligence ( MI ), many attempts have been made to reproduce modeling techniques and methods within IDSs that can properly track, trace, and prevent AMAs from reappearing. However, there seems to be a lack of comprehensive and cohesive literature reviews in this area on which existing scholars can rely to pursue future research and broaden the field of Information Security and Networks ( ISN ) research. Motivated by the absence of a universal IDSs framework, termed a ’one-stop shop,’ this systematic review hopes to serve the research community by aligning thinking and firmly consolidating the historical knowledge and progress made in MI approaches, thereby providing a better understanding of AMAs, including their prevention and the implementation of viable and efficient IDSs. No other systematic review of this kind has yet been produced. Starting with nearly 1,000 papers and applying rigorous analysis, this study covers 132 research papers in multiple bibliographic databases since January 2020, highlighting studies on IDSs deployed for AMA detection and classification using MI learning techniques such as Machine Learning ( ML ) and Deep Learning ( DL ); methods involving feature extraction; studies discussing static, dynamic, memory, and hybrid feature analysis; and finally, studies providing experimental results and accuracy metrics from these IDSs. Throughout this comprehensive review, the emphasis is placed on highlighting the differences, strengths, and shortcomings from each MI-IDS approach, as well as providing discussions and suggestions for further exploration in future research. Following the PRISMA protocol, this systematic literature review (SLR) provides a rigorous, transparent, and reproducible foundation for knowledge by synthesizing all available evidence on IDSs over recent years.

Read PDF

Similar papers

#artificial intelligence Review Open access Sep 2026

A Systematic Literature Review on Machine Learning for Intrusion Detection Systems

The use of Artificial Intelligence (AI) and Machine Learning (ML) in cybersecurity, especially for creating Intrusion Detection Systems (IDSs), has become increasingly important. These systems are essential for detecting malicious behaviour, identifying network issues, and stopping cyberattacks in real time. Despite ex...

Ali Ahmed, Ramy Mostafa, Mahmoud H. Qutqut et al. · 0 citations
Open access Jul 2026

Explainable AI for Intrusion Detection Systems: Enhancing Trust in Automated Cyber Defense

The results showed that embedding explainability in an IDS enhances the human-AI partnership, allowing security analysts to confirm the results of their IDS, mitigate false-positive ambiguity, optimize incident response, and meet regulatory and ethical obligations.

Christian Manna Guimma · 0 citations
Review Open access 2025

A Systematic Review and Comparative Analysis of Malware Detection Techniques

The increasing sophistication and volume of malware pose a persistent and evolving threat to cybersecurity. The research paper systematically examines and compares various malware detection techniques, including traditional methods such as signature, heuristic, and anomaly detection, and more advanced methods such as b...

A. Cvetkovic, S. Adamovic, Marko Šarac · 0 citations
Review Jul 2026

Artificial Intelligence for Malware Detection in Software-Defined Networks: A Comprehensive Systematic Literature Review

The review outlines future research directions emphasizing lightweight and explainable AI models, graph neural networks, federated and continual learning, adaptive hybrid intelligence, and standardized real-world evaluation frameworks to support the development of accurate, scalable, robust, and deployable malware dete...

Sudhakar Yerme, Prabhakar L. Ramteke · 0 citations
Review Aug 2026

Machine Learning in Cyber Security: A Systematic Literature Review of Intrusion Detection, Malware Analysis, and Adversarial Robustness

A conceptual layered framework for machine-learning-based security operations that integrates detection, adversarial-robustness testing, and human-analyst oversight is proposed by outlining directions for future research.

C. Thilagavathy, Saeed Mudether Saeed Taha, Krithik M. S. et al. · 0 citations
Review Open access 2026

Adversarial Evasion in Machine-Learning-Based Network Intrusion Detection: A Systematic Review, Threat Modeling, and Research Roadmap

A Kitchenham-informed systematic literature review methodology, this review synthesizes 186 studies published between 2018 and 2026 and develops a perturbation-realism taxonomy, ranging from feature-level manipulation to executable packet-level attacks, that clarifies when reported success corresponds to deployable ris...

Huda Ali Alatawi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.