Jadwal Sholat

Memuat jadwal sholat…

Ilmu Komputer & AI editorial

Open AccessOA2026

Artificial Intelligence for Real-Time Cyber Threat Classification and Emerging Threat Detection: A Structured Review of Methods, Datasets, Challenges, and Research Directions

A structured review synthesizing over 50 peer-reviewed studies on AI-driven real-time cyber threat classification and emerging threat detection, contrasting conventional and modern techniques, and identifying open challenges and research directions.
Jaswanth Garugu· International Journal for Research in Applied Science and Engineering Technology· 2026· DOI 10.22214/ijraset.2026.84615

The core problem

The rapid adoption of cloud computing, the Internet of Things (IoT), fifth-generation (5G) communication, and edge computing has significantly expanded the cyber-attack surface, enabling threats that are larger in scale, faster, and more complex. Traditional detection techniques—relying on signatures, rules, and statistical analysis—remain effective for known attacks but are limited in detecting zero-day exploits, polymorphic malware, and advanced persistent threats. Consequently, artificial intelligence (AI) has been increasingly adopted for adaptive and real-time cyber threat analysis. This review evaluates the evolution of AI-driven methodologies for real-time cyber threat classification and emerging threat detection, drawing from over fifty peer-reviewed studies identified through a structured search of leading scholarly databases. Rather than treating studies in isolation, the literature is synthesized based on detection objectives, computational techniques, datasets, evaluation metrics, deployment environments, and acknowledged limitations. The review juxtaposes conventional detection methods with machine learning, deep learning, explainable AI (XAI), reinforcement learning,

Innovation

The reviewed literature reveals a diverse landscape of AI-driven approaches for real-time cyber threat classification and emerging threat detection. Machine learning and deep learning techniques are widely applied, with deep learning models often achieving high detection rates for complex attack patterns. However, performance varies significantly across studies due to differences in datasets, feature engineering, and evaluation protocols. Explainable AI (XAI) methods are increasingly integrated to enhance model interpretability, addressing a critical need for trust and adoption in security operations. Reinforcement learning shows promise for adaptive defense strategies, while federated learning enables privacy-preserving collaborative training across distributed data sources. Graph neural networks (GNNs) effectively capture relational structures in network traffic, improving detection of sophisticated attacks. Large language models (LLMs) and generative AI are emerging for threat intelligence analysis and synthetic data generation, though their application in real-time detection is still nascent. Commonly used datasets include NSL-KDD, UNSW-NB15, CICIDS2017, and IoT-specific datase
The rapid adoption of cloud computing, the Internet of Things (IoT), fifth-generation (5G) communication, and edge computing has significantly expanded the cyber-attack surface, enabling threats that are larger in scale, faster, and more complex. Traditional detection techniques—relying on signatures, rules, and statistical analysis—remain effective for known attacks but are limited in detecting zero-day exploits, polymorphic malware, and advanced persistent threats. Consequently, artificial intelligence (AI) has been increasingly adopted for adaptive and real-time cyber threat analysis. This review evaluates the evolution of AI-driven methodologies for real-time cyber threat classification and emerging threat detection, drawing from over fifty peer-reviewed studies identified through a structured search of leading scholarly databases. Rather than treating studies in isolation, the literature is synthesized based on detection objectives, computational techniques, datasets, evaluation metrics, deployment environments, and acknowledged limitations. The review juxtaposes conventional detection methods with machine learning, deep learning, explainable AI (XAI), reinforcement learning, federated learning, graph neural networks (GNNs), large language models (LLMs), and generative AI. It emphasizes frequently utilized cybersecurity datasets and evaluation practices, as well as ongoing challenges related to class imbalance, adversarial manipulation, computational overhead, model interpretability, privacy concerns, and inadequate validation in real-world scenarios. The reviewed literature indicates that AI-based methodologies often demonstrate superior detection capabilities for intricate and previously unseen attack patterns compared to traditional methods; however, direct performance comparisons are complicated due to discrepancies in datasets, experimental designs, and evaluation protocols. Moreover, a limited number of proposed models have been evaluated under authentic operational circumstances. In light of these observations, the review identifies significant research gaps and outlines prospective paths for developing explainable, privacy-conscious, computationally efficient, and readily deployable AI-enabled cyber-defence systems.
The review follows a structured approach to synthesize the literature on AI for real-time cyber threat classification and emerging threat detection. A systematic search of leading scholarly databases was conducted, yielding over fifty peer-reviewed studies. The inclusion criteria focused on studies that proposed, evaluated, or reviewed AI-based methods for real-time threat detection, classification, or emerging threat identification. The selected studies were analyzed and categorized along several dimensions: detection objectives (e.g., binary classification, multi-class classification, anomaly detection), computational techniques (e.g., machine learning, deep learning, XAI, reinforcement learning, federated learning, GNNs, LLMs, generative AI), datasets used, evaluation metrics (e.g., accuracy, precision, recall, -score, false positive rate), deployment environments (e.g., cloud, edge, IoT), and acknowledged limitations. This structured synthesis allows for a comparative analysis of the strengths and weaknesses of different approaches and highlights gaps in the current research. The review also examines the datasets commonly employed in the field, noting their characteristics and limitations, and discusses evaluation practices, including the challenges of comparing results across studies due to varying experimental setups. The methodology emphasizes a critical assessment of the state of the art, aiming to provide a comprehensive overview that informs future research directions.

Why it matters

The synthesis of the literature underscores the transformative potential of AI in cyber threat detection but also highlights critical challenges that must be addressed for real-world deployment. The superiority of AI over traditional methods is evident in handling novel and evolving threats, yet the lack of standardized evaluation and real-world validation complicates claims of effectiveness. The diversity of datasets and metrics prevents meaningful cross-study comparisons, and many datasets do not reflect current attack landscapes. Class imbalance remains a pervasive issue, often leading to biased models that favor majority classes. Adversarial manipulation poses a significant threat to AI models, as attackers can craft inputs to evade detection. Computational overhead is a concern for real-time applications, particularly at the edge, where resources are constrained. Model interpretability is crucial for security analysts to trust and act on AI decisions, driving the adoption of XAI techniques. Privacy concerns arise when training on sensitive data, motivating federated learning approaches. The review identifies several research gaps: the need for standardized benchmarks and evaluation frameworks, the development of robust models against adversarial attacks, the design of lightweight models for edge deployment, the integration of explainability without sacrificing performance, and the establishment of privacy-preserving collaborative learning. Future directions include leveraging generative AI for synthetic attack data, employing LLMs for automated threat intelligence, and combining multiple AI paradigms (e.g., GNNs with reinforcement learning) for adaptive defense. Ultimately, the goal is to develop AI-enabled cyber-defence systems that are explainable, privacy-conscious, computationally efficient, and readily deployable in operational settings.

Who should read this

CS practitioners and researchers

Opening member content…