السنة عنوان البحث نشر البحث
2026 From Signatures to Intelligence: A Review of AI-Driven Intrusion Detection Systems AtoZ Science Journal
Intrusion Detection Systems (IDS) have evolved over four decades from static, signature-matching engines into adaptive, learning-based defenses capable of confronting increasingly sophisticated cyber threats. This review provides a structured synthesis of that trajectory, drawing on peer-reviewed and archival sources published predominantly between 2016 and 2026. We first characterize the structural limitations of classical signature-based and anomaly-based detection, before examining the rise of classical machine learning and, subsequently, deep learning architectures—including convolutional, recurrent, attention-based, autoencoder, and hybrid CNN-LSTM designs— that have substantially improved detection accuracy on benchmark traffic. We then examine four paradigms actively reshaping the field: federated learning, which enables collaborative, privacy-preserving model training across distributed network domains; explainable AI, which addresses the opacity of deep detectors through post-hoc techniques such as SHAP and LIME; graph neural networks and transformer architectures, which exploit relational and long-range contextual structure in network traffic; and the nascent integration of large language models into detection and reasoning pipelines. The review further consolidates the adversarial machine learning literature documenting how evasion and poisoning attacks can undermine AI-based detectors, surveys domain-specific deployments in IoT, automotive, and software-defined networking contexts, and catalogues the benchmark datasets that underpin empirical evaluation in the field. Illustrative visualizations and comparative tables synthesize the reviewed evidence. The review concludes that no single paradigm simultaneously maximizes accuracy, interpretability, privacy, and robustness, and it outlines open challenges—concept drift, adversarial robustness, dataset realism, and computational cost at the network edge—that should guide the next generation of AI-driven IDS research. Keywords: intrusion detection systems; machine learning; deep learning; federated learning; explainable AI; adversarial machine learning