CORTEXA
← Browse
crossrefElectronics2026-06-25Cited by 0

A Tri-Axis Systematic Literature Review of AI-Powered Cyber Defense: ATT&CK-Aligned Analysis of Cyberattacks, Machine Learning Methods, and Datasets

Mohammad Chizari, Abu Alam, Qublai Khan Ali Mirza, Hassan Chizari

The increasing complexity and sophistication of cyberattacks have made machine learning (ML) and artificial intelligence (AI) central to modern cyber defense. However, existing surveys typically examine attacks, ML methods, or datasets separately, limiting understanding of how methodological choices align with adversarial behaviours and benchmark availability. This paper presents a systematic literature review (SLR) of AI- and ML-based cyber defense studies published between 2019 and 2025, framed as an ATT&CK-aligned tri-axis synthesis of cyberattacks, machine learning methods, and datasets. Across 99 primary studies, the review maps 312 attack labels to MITRE ATT&CK tactics and techniques, categorises the ML methods applied, and organizes 96 datasets into a refined taxonomy spanning NIDD, IoT-NIDD, malware, Spam and Phishing, ICS, Insider Threat, custom-collected, and other datasets. Rather than treating attacks, ML methods, and datasets as separate descriptive dimensions, the review analyses them jointly through a tri-axis cross-reference framework, enabling the identification of benchmark dependence, methodological concentration, and underexplored attack–method–dataset intersections that are not visible in single-axis or model-centred surveys. The synthesis shows that the literature is strongly concentrated on externally visible attacks associated with Impact, Initial Access, and Execution, that ensemble and deep learning models dominate high-frequency detection settings, and that dataset usage remains heavily skewed toward a small set of public benchmarks, particularly CSE-CIC-IDS2017, UNSW-NB15, and NSL-KDD. This review further identifies persistent blind spots, including limited coverage of post-compromise ATT&CK behaviours, sparse use of ICS and insider-threat datasets, and weak support for multi-stage or multi-dataset evaluation. These findings provide a more focused and actionable evidence base for future ML-based cyber defense research.

View free PDFSource page

Related papers

crossrefElectronics2022-05-19Cited by 13

Smart Home: Deep Learning as a Method for Machine Learning in Recognition of Face, Silhouette and Human Activity in the Service of a Safe Home

George Vardakis, George Tsamis, Eleftheria Koutsaki, Kondylakis Haridimos, Nikos Papadakis

Despite the general improvement of living conditions and the ways of building buildings, the sense of security in or around them is often not satisfactory for their users, resulting in the search and implementation of increasingly effective protection measures. The insecurity tha…

View free PDFSource page
crossrefElectronics2023-12-25Cited by 90

A Comprehensive Review of DeepFake Detection Using Advanced Machine Learning and Fusion Methods

Gourav Gupta, Kiran Raja, Manish Gupta, Tony Jan, Scott Thompson Whiteside, Mukesh Prasad

Recent advances in Generative Artificial Intelligence (AI) have increased the possibility of generating hyper-realistic DeepFake videos or images to cause serious harm to vulnerable children, individuals, and society at large with misinformation. To overcome this serious problem,…

View free PDFSource page
crossrefElectronics2024-03-07Cited by 4

Machine Learning First Response to COVID-19: A Systematic Literature Review of Clinical Decision Assistance Approaches during Pandemic Years from 2020 to 2022

Goizalde Badiola-Zabala, Jose Manuel Lopez-Guede, Julian Estevez, Manuel Graña

Background: The declaration of the COVID-19 pandemic triggered global efforts to control and manage the virus impact. Scientists and researchers have been strongly involved in developing effective strategies that can help policy makers and healthcare systems both to monitor the s…

View free PDFSource page
crossrefElectronics2024-04-26Cited by 74

Exhaustive Study into Machine Learning and Deep Learning Methods for Multilingual Cyberbullying Detection in Bangla and Chittagonian Texts

Tanjim Mahmud, Michal Ptaszynski, Fumito Masui

Cyberbullying is a serious problem in online communication. It is important to find effective ways to detect cyberbullying content to make online environments safer. In this paper, we investigated the identification of cyberbullying contents from the Bangla and Chittagonian langu…

View free PDFSource page
crossrefElectronics2021-07-21Cited by 17

Secure Cyber Defense: An Analysis of Network Intrusion-Based Dataset CCD-IDSv1 with Machine Learning and Deep Learning Models

Niraj Thapa, Zhipeng Liu, Addison Shaver, Albert Esterline, Balakrishna Gokaraju, Kaushik Roy

Anomaly detection and multi-attack classification are major concerns for cyber defense. Several publicly available datasets have been used extensively for the evaluation of Intrusion Detection Systems (IDSs). However, most of the publicly available datasets may not contain attack…

View free PDFSource page
crossrefElectronics2025-05-23Cited by 6

Sentiment Analysis of Digital Banking Reviews Using Machine Learning and Large Language Models

Raghad Alawaji, Abdulrahman Aloraini

Sentiment analysis, in the context of digital banking reviews, aims to assess customer satisfaction and support service enhancement. Despite increasing attention to sentiment analysis across domains, Arabic banking reviews remain underexplored. To bridge this gap, we introduce a…

View free PDFSource page