Skip to content
Review Open access

Artificial Intelligence for Cybersecurity: A Scoping Survey of Paradigms, Applications, and Emerging Trends

Aug 2026 · Algorithms · Vol 19, pp. 653 · 0 citations · 75 references

TL;DR

A structured taxonomy is proposed to organize various dimensions of AI-driven cybersecurity; review them critically; and finally, discuss key challenges, open problems, and emerging trends.

Abstract

The rapid evolution of cyberattacks, coupled with the increasing capacity of computing environments and the emergence of artificial intelligence (AI), has significantly complicated the security landscape. While existing studies largely emphasize improving AI model performance for individual cybersecurity tasks, this survey shifts the focus toward operationalizing the deployment rationale and understanding when, where, and why different AI paradigms should be deployed, the capabilities they offer; and the challenges that must be addressed to enable trustworthy and effective real-world cyber defense. This paper aims to provide researchers and practitioners with a comprehensive reference for understanding the evolving role of AI in cybersecurity and the challenges that must be addressed to develop trustworthy and resilient AI-driven cyber defense systems. In this paper, we propose a structured taxonomy to organize various dimensions of AI-driven cybersecurity; review them critically; and finally, discuss key challenges, open problems, and emerging trends.

Read PDF

Similar papers

Review Open access 2026

Evolving Cyber Threat Intelligence: A Systematic Review and Comparative Analysis

To improve cybersecurity across industries, Cyber Threat Intelligence (CTI) is becoming increasingly crucial. This systematic review explores how CTI practices are evolving in response to advancements in Artificial Intelligence (AI), particularly in the context of Large Language Models (LLMs). We examined 61 peer-reviewed studies using the PRISMA methodology, which demonstrates a strict selection procedure founded on specified inclusion, exclusion, and quality standards. This approach aligns with the scope of similar systematic reviews in the field of cyber threat intelligence. The review provides a comparative synthesis of CTI research capabilities across threat detection and prediction, attribution, forecasting, and automated reporting. We classify these approaches into three categories: conventional methods, those enhanced by AI and Machine Learning, and those based on LLMs. Our findings indicate that LLMs offer significant advantages in contextual reasoning, processing unstructured threat intelligence, and generating actionable mitigation plans. However, challenges such as model explainability, data privacy, system interoperability, and standardization impede their integration into operational environments. In addition to highlighting the potential and practical limitations of LLMs in CTI, this study identifies research gaps and proposes methods to create scalable, secure, and flexible CTI systems that support real-time cyber defense.

Hilalah Alturkistani, Abdul Ghafar Jaafar, S. Chuprat et al. · 0 citations
Review Aug 2026

An Analysis of Explainable Artificial Intelligence for Intelligent Cybersecurity Applications

Proactive cyber defenses, AI-powered threat detection systems, and automated reactions are changing the face of cybersecurity in the modern era. In security-critical applications, however, Explainable Artificial Intelligence (XAI) is in high demand due to the need to improve trust, transparency, and decision-making in light of the fact that traditional AI models are not transparent. Intelligent threat detection and response mechanisms, key cybersecurity applications, the most recent advances in the area of XAI-based security solutions, and the fundamentals of explainable AI are all covered in detail in this survey. Highlighting the most prominent explainability methods including SHAP, LIME, Grad-CAM, and counterfactual explanations, this article delves into their applications in several security domains, including cloud security, IoT security, fraud detection, intrusion detection, phishing, spam, cloud security, and identity and access management. The comparative analysis of recent studies is used to emphasize current accomplishments, problems, and new research areas. The results show that XAI can improve the transparency, trustworthiness and effectiveness of AI-based cybersecurity systems, in addition to highlighting a range of privacy, adversarial robustness, scalability and evaluation challenges that warrant further research to ensure reliable deployment in the real world.

Mr. Raman Kumar · 0 citations
2026

ARTIFICIAL INTELLIGENCE SYSTEMS IN CYBERSECURITY

In the modern digital world, where cyber-attacks are becoming increasingly sophisticated and widespread, the use of artificial intelligence in the field of cybersecurity is extremely relevant. The issue of cybersecurity is gaining more and more importance, and conducting relevant research is a necessary aspect of ensuring security in the digital space. In this regard, we propose an article that examines the role of artificial intelligence, innovations, challenges, and prospects for its development in the field of cybersecurity. The use of artificial intelligence to automate the processes of detecting, analyzing, and responding to cyber threats, as well as its practical significance for increasing the level of security in the digital space and the effectiveness of protection against cyber threats, is also investigated. The leading approaches for this study are trend analysis and expert assessments, which allow for a comprehensive examination of the directions for the development of artificial intelligence in the field of cybersecurity, the advantages and challenges of its implementation, as well as potential opportunities and threats to information security.

A. B. Temirova, Kyadai B. Tsechoeva · 0 citations
Review Open access Aug 2026

Artificial Intelligence and Cyber Defense: Navigating Emerging Threats in an Interconnected World

Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat intelligence platforms, and automated incident response tools, enabling organizations to identify and neutralize threats with greater speed and precision. However, the same interconnectedness that drives digital transformation—spanning IoT ecosystems, cloud infrastructures, and 5G networks—has also expanded the attack surface available to malicious actors, giving rise to increasingly sophisticated, adaptive, and often AI-enabled threats such as adversarial machine learning attacks, deepfake-driven social engineering, and automated supply chain exploits. This paper examines the dual role of AI as both a defensive asset and a potential vector of risk within modern cybersecurity ecosystems. Drawing on a review of existing AI-driven security solutions, comparative analysis of AI-based versus traditional defense mechanisms, and case study evaluation, the study assesses the effectiveness, limitations, and ethical implications of AI integration in cyber defense. Findings indicate that while AI substantially improves threat detection accuracy and response times, challenges related to explainability, adversarial vulnerability, and regulatory oversight remain significant barriers to widespread adoption. The paper concludes with practical recommendations for organizations and policymakers seeking to harness AI's defensive potential while mitigating its associated risks, emphasizing the need for explainable AI frameworks, human-AI collaboration, and adaptive governance structures in an increasingly interconnected digital age.

Nicolas Guzman Camacho · 0 citations
Review Open access Aug 2026

Emerging Trends, Challenges, and Future Directions in Cybersecurity

The dual-use nature of AI, the expanding attack surfaces of cloud computing and the IoT, the evolution of Zero Trust architectures, and the forthcoming disruption of quantum computing to classical public key cryptography are causing rapid, structural shifts in the cybersecurity landscape. This study integrates and builds upon relevant literature of the aforementioned technologies and organizes the AI focused offense and defense, identity-based security, ransomware, cloud-native security, post-quantum cryptography (PQC), supply chain security, IoT/OT security, XDR platform security, and other security frameworks. We review and analyze the gaps that reduce the efficacy of security and defense postures, which include the labor gap in cybersecurity, inconsistent laws and frameworks, aging technologies, the complexity of AI and its governance, and alert fatigue from over-utilization of multiple tools. We identify autonomous security and defense, agile cryptography, AI red team exercises, human-AI defense, and a variety of models using graph theory and network theory to design and implement resilient architectures to mitigate cyber threats, as potential areas for future exploration and research. We aim to provide researchers and practitioners a comprehensive overview of the current cybersecurity environment for the year 2026.

Vishvesh Revoori, Vasudev Karthik Ravindran, Shubham Agarwal · 0 citations
Review Open access Aug 2026

The Role of Artificial Intelligence in Strengthening Modern Cybersecurity Systems

Modern organizations face an expanding threat landscape of sophisticated malware, automated intrusions, and large-scale data breaches that outpace traditional signature-based defenses. This paper examines the role of artificial intelligence (AI) in strengthening modern cybersecurity systems and provides a structured and comprehensive synthesis of the field, covering the foundations and taxonomy of AI techniques, their application to proactive detection, incident response, and security operations across networks, endpoints, and cloud, and the benefits, challenges, sector specific applications, evaluation methods, ethical and workforce considerations, and the emerging role of generative artificial intelligence. The review finds that artificial intelligence enables proactive threat detection, anomaly identification, and the automation of analysis and response at a scale beyond human capacity, yet its effectiveness is constrained by adversarial machine learning, data quality and drift, false positives, opacity, and the dual use of generative models by attackers. It concludes that the most effective and responsible deployments integrate artificial intelligence with established controls, ground it in sound data and governance, and preserve human oversight, and it offers recommendations and identifies open challenges for researchers, practitioners, and policymakers.

N. Hussain · 0 citations