Skip to content
Review Open access

A Systematic Review of Machine Learning Techniques in Intrusion Detection Systems

2026 · Journal of Cyber Security · Vol 8, pp. 319-356 · 1 citation · 80 references

TL;DR

ML is a significant addition to intrusion detection, especially for anomaly detection and zero-day attack detection, however, the actual implementation is still limited due to the lack of detailed assessment systems and strict robustness testing.

Abstract

: Background: The evolution of modern networked systems in complexity, volume, and diversity has markedly increased the cyber-attack area. Conventional signature-based intrusion detection systems (IDS) will no longer be adequate for identifying advanced threats. A data-driven, adaptive approach that can identify malicious network activity is provided by machine learning (ML) techniques. This review aims to study, compare, and analyze ML-based approaches in IDS and improve the security defense mechanism. Methods: This systematic review followed the PRISMA 2020 guidelines. ML-based IDS peer-reviewed papers were identified from five scientific databases. Abstracts, full texts, and titles were filtered using predetermined inclusion and exclusion criteria, resulting in a sample of 53 primary studies. Data extraction included the algorithms used, the data used, and the metrics used to evaluate. Findings: The data show that most supervised ML techniques, such as decision trees, support vector machines, ensemble models, and deep learning systems (e.g., convolutional and recurrent neural networks), are predominant. In the majority of studies, high detection accuracy was obtained in controlled experimental settings. Conclusions: ML is a significant addition to intrusion detection, especially for anomaly detection and zero-day attack detection. However, the actual implementation is still limited due to the lack of detailed assessment systems and strict robustness testing. Future studies can focus on reproducibility, the use of diverse datasets, adversarial robustness, and the development of explainable ML methods.

Read PDF

Similar papers

#artificial intelligence Review Open access Sep 2026

A Systematic Literature Review on Machine Learning for Intrusion Detection Systems

The use of Artificial Intelligence (AI) and Machine Learning (ML) in cybersecurity, especially for creating Intrusion Detection Systems (IDSs), has become increasingly important. These systems are essential for detecting malicious behaviour, identifying network issues, and stopping cyberattacks in real time. Despite ex...

Ali Ahmed, Ramy Mostafa, Mahmoud H. Qutqut et al. · 0 citations
Review Open access Sep 2026

A Review of Machine Learning Techniques for Network Intrusion Detection Systems

Security researchers rely heavily on Network Intrusion Detection Systems (NIDS) to keep an eye on network traffic and notify administrators of any suspicious activities. The purpose of this paper is to offer a comprehensive overview of intrusion detection systems (IDS), including the following topics: fundamentals, kin...

Madhav Sharma · 0 citations
Review Open access Jul 2026

A Systematic Review of AI-Driven Intrusion Detection and Performance Optimization in Wireless Sensor Networks

The study analyzes the most recent progress in ML and DL methods used to develop IDS that operate in WSNs through analysis of their primary algorithms and algorithmic combinations and concludes that the DL and hybrid approaches are superior to conventional ML algorithms in handling complicated and imbalanced datasets.

Priyanka Sharma, Mohd. Suhaib Kidwai, Piyush Charan · 0 citations
Open access Aug 2026

Enhancing Network Security with a Hybrid Intrusion Detection System Using SVM

A thorough analysis of a modest version of a suggested system that use Support Vector Machines (SVM) to address networking anomaly and misuse detection in the face of insurmountable obstacles, foreseeing an all-encompassing solution to modern network security issues.

Gaurav Kishor Saxena, Shambhu Dayal Sahu · 0 citations
Review Open access Aug 2026

Advancing Intrusion Detection Systems: A Comprehensive Review of Deep Learning and Hyperparameter Optimization Techniques

In the suddenly changing realm of cyber security, Intrusion Detection Systems (IDS) are essential for protecting computer networks from harmful actions.  This survey paper offers an extensive examination of sophisticated approaches and procedures utilised in IDS, emphasising the amalgamation of deep learning (DL) and h...

H. K. · 0 citations
Review Open access Aug 2026

Exploring Optimization and Machine Learning for Effective Intrusion Detection Systems

Intrusion Detection Systems (IDS) are essential elements of contemporary cyber security frameworks, intended to identify unauthorised access and nefarious activity within networks and computer systems.  This survey examines the classification of IDS technologies, methodologies, and approaches, emphasising the benefits...

B. Yelikar, Jawed Sharfuzama Khan, A. Kanade et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.