A comprehensive review of machine learning applications in cybersecurity : identifying gaps and advocating for cybersecurity auditing
Loading...
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Springer
Abstract
The rapid growth of increasingly sophisticated and complex cyber threats has intensified interest in, and reliance on, artificial intelligence (AI), particularly machine learning (ML), within the cybersecurity landscape. ML has demonstrated robust potential to enhance cybersecurity capabilities, including threat detection, anomaly identification, predictive analytics, and automated response; however, practical ML implementation in cybersecurity remains in an early stage, often inconsistent, fragmented, and insufficiently developed. Consequently, ongoing research is essential to identify emerging developments, expand areas of inquiry, and propose improvements to existing approaches. This study provides a comprehensive review of recent ML applications in cybersecurity. Using the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) methodology, the study systematically evaluates the feasibility, effectiveness, and limitations of current approaches. The review reveals several critical gaps, including narrow application scopes, suboptimal algorithm performance in real-world environments, insufficient and imbalanced datasets, and inadequate integration with Security Information and Event Management (SIEM) and Intrusion Prevention Systems (IPS). Additional concerns include ethical dilemmas and governance challenges, all of which limit the operational reliability of ML-driven cybersecurity solutions. The findings emphasize the need to refine ML models, improve interoperability with existing security infrastructures, and strengthen evaluation frameworks. Importantly, the study advocates aligning modern ML-driven innovations with cybersecurity auditing, emphasizing cybersecurity audits' role in assessing ML readiness, validating control effectiveness, and promoting responsible, transparent, and risk-based adoption of ML technologies in cybersecurity environments.
Description
DATA AVAILABILITY : No datasets were generated or analysed during the current study.
Keywords
Artificial intelligence (AI), Machine learning, Preferred reporting items for systematic review and meta-analysis (PRISMA), Security information and event management (SIEM), Intrusion prevention systems (IPS), Cybersecurity, Cybersecurity auditing, Cybersecurity threats, Cybersecurity tools, Advanced cyber threats, Systematic review
Sustainable Development Goals
SDG-09: Industry, innovation and infrastructure
SDG-08: Decent work and economic growth
SDG-08: Decent work and economic growth
Citation
Rananga, N., Venter, H.S. A comprehensive review of machine learning applications in cybersecurity: identifying gaps and advocating for cybersecurity auditing. International Journal of Information Security 25, 101: 1-22 (2026). https://doi.org/10.1007/s10207-026-01266-6.
