International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1722890

1722890 Vol 10 · Issue 3 Download Paper

From Intrusion Detection to Cyberattack Anticipation: A Critical Review of Self-Evolving AI for Pre-Attack Prediction in IoT-Enabled Critical Infrastructure

Opeyemi Priscilla Akinyemi Damilare Timothy Ogunjobi Obiorah Joseph Nwaisaac Rahmatallahi Ajike Aderounmu Benjamin Osaze Enobakhare

Subject area: Science,Engineering and Technology  ·  Area of research: Technology

DOI: 10.64388/IREV10I3-1722890

Abstract

The growing integration of Internet of Things technologies into critical infrastructure has expanded cyberattack surfaces while increasing the potential consequences of security failures across essential services. Artificial intelligence has substantially improved intrusion and anomaly detection, yet much of this progress remains reactive, identifying malicious activity only after observable evidence of an attack has emerged. This critical review examines whether self-evolving AI can support a transition from intrusion detection to reliable pre-attack anticipation in IoT-enabled critical infrastructure. It distinguishes detection, early warning, forecasting, and anticipation and critically evaluates the role of continual learning, online adaptation, concept drift management, adaptive ensembles, evolutionary approaches, and distributed learning in addressing evolving cyber threats. The review finds that adaptive AI provides important mechanisms for maintaining responsiveness under changing threat and network conditions, but adaptation alone does not constitute predictive intelligence. Evidence for genuine anticipation remains limited by reliance on retrospective benchmark datasets, uncertain pre-attack signals, weak temporal validation, restricted generalizability, and limited evaluation in operational critical infrastructure. Continuous adaptation also introduces challenges involving catastrophic forgetting, adversarial manipulation, false alarms, explainability, computational constraints, and model validation. Progress toward trustworthy anticipation therefore requires prospective temporal evaluation, realistic cross-domain validation, calibrated uncertainty, adversarially robust adaptation, and meaningful human oversight. Future cybersecurity AI should be judged not only by how accurately it detects attacks, but also by whether it can reliably and sufficiently far in advance identify actionable attack risk to enable preventive intervention.

Keywords

Cyberattack prediction; Self evolving AI; Internet of Things; Critical infrastructure; Intrusion detection; Continual learning; Cybersecurity

References

[1] Alshamrani, A., Myneni, S., Chowdhary, A., & Huang, D. (2019). A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities. IEEE Communications Surveys & Tutorials, 21(2), 1851–1877. https://doi.org/10.1109/COMST.2019.2891891

[2] Engelen, G., Rimmer, V., & Joosen, W. (2021). Troubleshooting an intrusion detection dataset: The CICIDS2017 case study. In 2021 IEEE Security and Privacy Workshops (SPW) (pp. 7–12). IEEE. https://doi.org/10.1109/SPW53761.2021.00009

[3] Feng, Y., Huang, R., Zhao, W., Yin, P., & Li, Y. (2025). A survey on coordinated attacks against cyber–physical power systems: Attack, detection, and defense methods. Electric Power Systems Research, 241, 111286. https://doi.org/10.1016/j.epsr.2024.111286

[4] Gama, J., Žliobaitė, I., Bifet, A., Pechenizkiy, M., & Bouchachia, A. (2014). A survey on concept drift adaptation. ACM Computing Surveys, 46(4), Article 44. https://doi.org/10.1145/2523813

[5] Guo, Y. (2023). A review of machine learning-based zero-day attack detection: Challenges and future directions. Computer Communications, 198, 175–185. https://doi.org/10.1016/j.comcom.2022.11.001

[6] He, K., Kim, D. D., & Asghar, M. R. (2023). Adversarial machine learning for network intrusion detection systems: A comprehensive survey. IEEE Communications Surveys & Tutorials, 25(1), 538–566. https://doi.org/10.1109/COMST.2022.3233793

[7] Hernandez-Ramos, J. L., Karopoulos, G., Chatzoglou, E., Kouliaridis, V., Marmol, E., Gonzalez-Vidal, A., & Kambourakis, G. (2025). Intrusion detection based on federated learning: A systematic review. ACM Computing Surveys, 57(12), Article 309. https://doi.org/10.1145/3731596

[8] Kirkpatrick, J., Pascanu, R., Rabinowitz, N., Veness, J., Desjardins, G., Rusu, A. A., Milan, K., Quan, J., Ramalho, T., Grabska-Barwinska, A., Hassabis, D., Clopath, C., Kumaran, D., & Hadsell, R. (2017). Overcoming catastrophic forgetting in neural networks. Proceedings of the National Academy of Sciences, 114(13), 3521–3526. https://doi.org/10.1073/pnas.1611835114

[9] Klaise, J., Van Looveren, A., Cox, C., Vacanti, G., & Coca, A. (2020). Monitoring and explainability of models in production. Workshop on Challenges in Deploying and Monitoring Machine Learning Systems, ICML 2020. https://doi.org/10.48550/arXiv.2007.06299

[10] Li, S., Kwon, Y. D., Lee, L.-H., & Hui, P. (2025). MetaCLBench: Meta continual learning benchmark on resource-constrained edge devices. arXiv preprint. https://doi.org/10.48550/arXiv.2504.00174

[11] Liu, H., Wang, Y., Fan, W., Liu, X., Li, Y., Jain, S., Liu, Y., Jain, A. K., & Tang, J. (2021). Trustworthy AI: A computational perspective. ACM Transactions on Intelligent Systems and Technology, 14(1), 1–59. https://doi.org/10.48550/arXiv.2107.06641

[12] Liu, Y., & Guo, Y. (2024). CL-AP²: A composite learning approach to attack prediction via attack portraying. Journal of Network and Computer Applications, 230, 103963. https://doi.org/10.1016/j.jnca.2024.103963

[13] Makhmudov, F., Juraev, G., Yusupov, O., Nasriddinova, P., & Kilichev, D. (2026). Drift-aware online ensemble learning for real-time cybersecurity in Internet of Medical Things networks. Machine Learning and Knowledge Extraction, 8(3), Article 67. https://doi.org/10.3390/make8030067

[14] Neupane, S., Ables, J., Anderson, W., Mittal, S., Rahimi, S., Banicescu, I., & Seale, M. (2022). Explainable Intrusion Detection Systems (X-IDS): A survey of current methods, challenges, and opportunities. IEEE Access, 10, 112392–112415. https://doi.org/10.1109/ACCESS.2022.3216617

[15] Ottun, A. R. O., & Flores, H. (2025). Trustworthy AI in practice: A comprehensive review of human oversight and human-in-the-loop approaches. TechRxiv. https://doi.org/10.36227/techrxiv.176118749.93102582/v1

[16] Parisi, G. I., Kemker, R., Part, J. L., Kanan, C., & Wermter, S. (2019). Continual lifelong learning with neural networks: A review. Neural Networks, 113, 54–71. https://doi.org/10.1016/j.neunet.2019.01.012

[17] Pinto, A., Herrera, L.-C., Donoso, Y., & Gutiérrez, J. A. (2023). Survey on intrusion detection systems based on machine learning techniques for the protection of critical infrastructure. Sensors, 23(5), 2415. https://doi.org/10.3390/s23052415

[18] Pirca, A. M., & Lallie, H. S. (2023). An empirical evaluation of the effectiveness of attack graphs and MITRE ATT&CK matrices in aiding cyber attack perception amongst decision-makers. Computers & Security, 130, 103254. https://doi.org/10.1016/j.cose.2023.103254

[19] Sen, S. (2015). A survey of intrusion detection systems using evolutionary computation. In Bio-Inspired Computation in Telecommunications (pp. 73–94). Morgan Kaufmann. https://doi.org/10.1016/B978-0-12-801538-4.00004-5

[20] Thein, T. T., Shiraishi, Y., & Morii, M. (2024). Personalized federated learning-based intrusion detection system: Poisoning attack and defense. Future Generation Computer Systems, 153, 182–192. https://doi.org/10.1016/j.future.2023.11.028

[21] Zhai, P., Zhang, M., & Wang, X. (2026). Prediction-based attack detection and mitigation mechanism in power systems. Scientific Reports, 16, Article 13252. https://doi.org/10.1038/s41598-026-44076-5

How to cite this paper

Opeyemi Priscilla Akinyemi, Damilare Timothy Ogunjobi, Obiorah Joseph Nwaisaac, Rahmatallahi Ajike Aderounmu, Benjamin Osaze Enobakhare "From Intrusion Detection to Cyberattack Anticipation: A Critical Review of Self-Evolving AI for Pre-Attack Prediction in IoT-Enabled Critical Infrastructure" Iconic Research And Engineering Journals Volume 10 Issue 3 2026 Page 1040-1053 https://doi.org/10.64388/IREV10I3-1722890
Opeyemi Priscilla Akinyemi, Damilare Timothy Ogunjobi, Obiorah Joseph Nwaisaac, Rahmatallahi Ajike Aderounmu, Benjamin Osaze Enobakhare "From Intrusion Detection to Cyberattack Anticipation: A Critical Review of Self-Evolving AI for Pre-Attack Prediction in IoT-Enabled Critical Infrastructure" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026, doi: https://doi.org/10.64388/IREV10I3-1722890
Opeyemi Priscilla Akinyemi, Damilare Timothy Ogunjobi, Obiorah Joseph Nwaisaac, Rahmatallahi Ajike Aderounmu, Benjamin Osaze Enobakhare (2026). From Intrusion Detection to Cyberattack Anticipation: A Critical Review of Self-Evolving AI for Pre-Attack Prediction in IoT-Enabled Critical Infrastructure. Iconic Research And Engineering Journals, 10(3). doi: https://doi.org/10.64388/IREV10I3-1722890
Opeyemi Priscilla Akinyemi, Damilare Timothy Ogunjobi, Obiorah Joseph Nwaisaac, Rahmatallahi Ajike Aderounmu, Benjamin Osaze Enobakhare "From Intrusion Detection to Cyberattack Anticipation: A Critical Review of Self-Evolving AI for Pre-Attack Prediction in IoT-Enabled Critical Infrastructure" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026. Crossref, https://doi.org/10.64388/IREV10I3-1722890
@article{1722890,
      author = {Opeyemi Priscilla Akinyemi, Damilare Timothy Ogunjobi, Obiorah Joseph Nwaisaac, Rahmatallahi Ajike Aderounmu, Benjamin Osaze Enobakhare},
      title = {From Intrusion Detection to Cyberattack Anticipation: A Critical Review of Self-Evolving AI for Pre-Attack Prediction in IoT-Enabled Critical Infrastructure},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {3},
      pages = {1040-1053},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722890.pdf},
      abstract = {The growing integration of Internet of Things technologies into critical infrastructure has expanded cyberattack surfaces while increasing the potential consequences of security failures across essential services. Artificial intelligence has substantially improved intrusion and anomaly detection, yet much of this progress remains reactive, identifying malicious activity only after observable evidence of an attack has emerged. This critical review examines whether self-evolving AI can support a transition from intrusion detection to reliable pre-attack anticipation in IoT-enabled critical infrastructure. It distinguishes detection, early warning, forecasting, and anticipation and critically evaluates the role of continual learning, online adaptation, concept drift management, adaptive ensembles, evolutionary approaches, and distributed learning in addressing evolving cyber threats. The review finds that adaptive AI provides important mechanisms for maintaining responsiveness under changing threat and network conditions, but adaptation alone does not constitute predictive intelligence. Evidence for genuine anticipation remains limited by reliance on retrospective benchmark datasets, uncertain pre-attack signals, weak temporal validation, restricted generalizability, and limited evaluation in operational critical infrastructure. Continuous adaptation also introduces challenges involving catastrophic forgetting, adversarial manipulation, false alarms, explainability, computational constraints, and model validation. Progress toward trustworthy anticipation therefore requires prospective temporal evaluation, realistic cross-domain validation, calibrated uncertainty, adversarially robust adaptation, and meaningful human oversight. Future cybersecurity AI should be judged not only by how accurately it detects attacks, but also by whether it can reliably and sufficiently far in advance identify actionable attack risk to enable preventive intervention.},
      keywords = {Cyberattack prediction; Self evolving AI; Internet of Things; Critical infrastructure; Intrusion detection; Continual learning; Cybersecurity},
      month = {September},
      doi = {https://doi.org/10.64388/IREV10I3-1722890}
  }