A Tri-Axis Systematic Literature Review of AI-Powered Cyber Defense: ATT&CK-Aligned Analysis of Cyberattacks, Machine Learning Methods, and Datasets

Chizari, Mohammad ORCID logoORCID: https://orcid.org/0009-0008-8627-6054, Alam, Abu ORCID logoORCID: https://orcid.org/0000-0002-5958-7905, Ali Mirza, Qublai Khan ORCID logoORCID: https://orcid.org/0000-0003-3403-2935 and Chizari, Hassan ORCID logoORCID: https://orcid.org/0000-0002-6253-1822 (2026) A Tri-Axis Systematic Literature Review of AI-Powered Cyber Defense: ATT&CK-Aligned Analysis of Cyberattacks, Machine Learning Methods, and Datasets. Electronics, 15 (13). p. 2804. doi:10.3390/electronics15132804

[thumbnail of 16440 Chizari, M et al. (2026)  A Tri-Axis Systematic Literature Review of AI-Powered Cyber Defense.pdf]
Preview
Text
16440 Chizari, M et al. (2026) A Tri-Axis Systematic Literature Review of AI-Powered Cyber Defense.pdf - Published Version
Available under License Creative Commons Attribution 4.0.

Download (4MB) | Preview

Abstract

The increasing complexity and sophistication of cyberattacks have made machine learning (ML) and artificial intelligence (AI) central to modern cyber defense. However, existing surveys typically examine attacks, ML methods, or datasets separately, limiting understanding of how methodological choices align with adversarial behaviours and benchmark availability. This paper presents a systematic literature review (SLR) of AI- and ML-based cyber defense studies published between 2019 and 2025, framed as an ATT&CK-aligned tri-axis synthesis of cyberattacks, machine learning methods, and datasets. Across 99 primary studies, the review maps 312 attack labels to MITRE ATT&CK tactics and techniques, categorises the ML methods applied, and organizes 96 datasets into a refined taxonomy spanning NIDD, IoT-NIDD, malware, Spam and Phishing, ICS, Insider Threat, custom-collected, and other datasets. Rather than treating attacks, ML methods, and datasets as separate descriptive dimensions, the review analyses them jointly through a tri-axis cross-reference framework, enabling the identification of benchmark dependence, methodological concentration, and underexplored attack–method–dataset intersections that are not visible in single-axis or model-centred surveys. The synthesis shows that the literature is strongly concentrated on externally visible attacks associated with Impact, Initial Access, and Execution, that ensemble and deep learning models dominate high-frequency detection settings, and that dataset usage remains heavily skewed toward a small set of public benchmarks, particularly CSE-CIC-IDS2017, UNSW-NB15, and NSL-KDD. This review further identifies persistent blind spots, including limited coverage of post-compromise ATT&CK behaviours, sparse use of ICS and insider-threat datasets, and weak support for multi-stage or multi-dataset evaluation. These findings provide a more focused and actionable evidence base for future ML-based cyber defense research.

Item Type: Article
Article Type: Article
Additional Information: This article belongs to the Special Issue Artificial Intelligence in Cybersecurity: Practices, Challenges, and Innovations
Uncontrolled Keywords: Cybersecurity; Systematic literature review (SLR); MITRE ATT&CK; Machine learning; deep learning; Cyberattack analysis; Intrusion detection; Dataset taxonomy; Threat detection
Subjects: H Social Sciences > HD Industries. Land use. Labor > HD28 Management. Industrial Management > HD61 Risk in industry. Risk management
Q Science > Q Science (General) > Q336 Artificial intelligence
Q Science > QA Mathematics > QA76 Computer software > QA76.9 Other topics > QA76.9.V5 Virtual computer systems
Divisions: Schools and Research Institutes > School of Business, Computing and Social Sciences
Depositing User: Kamila Niekoraniec
Date Deposited: 23 Jul 2026 10:30
Last Modified: 23 Jul 2026 10:45
URI: https://eprints.glos.ac.uk/id/eprint/16440

University Staff: Request a correction | Repository Editors: Update this record

University Of Gloucestershire

Bookmark and Share

Find Us On Social Media:

Social Media Icons Facebook Twitter YouTube Pinterest Linkedin

Other University Web Sites

University of Gloucestershire, The Park, Cheltenham, Gloucestershire, GL50 2RH. Telephone +44 (0)844 8010001.