Home / Current Issue / Paper 1722890
From Intrusion Detection to Cyberattack Anticipation: A Critical Review of Self-Evolving AI for Pre-Attack Prediction in IoT-Enabled Critical Infrastructure
Subject area: Science,Engineering and Technology · Area of research: Technology
Abstract
The growing integration of Internet of Things technologies into critical infrastructure has expanded cyberattack surfaces while increasing the potential consequences of security failures across essential services. Artificial intelligence has substantially improved intrusion and anomaly detection, yet much of this progress remains reactive, identifying malicious activity only after observable evidence of an attack has emerged. This critical review examines whether self-evolving AI can support a transition from intrusion detection to reliable pre-attack anticipation in IoT-enabled critical infrastructure. It distinguishes detection, early warning, forecasting, and anticipation and critically evaluates the role of continual learning, online adaptation, concept drift management, adaptive ensembles, evolutionary approaches, and distributed learning in addressing evolving cyber threats. The review finds that adaptive AI provides important mechanisms for maintaining responsiveness under changing threat and network conditions, but adaptation alone does not constitute predictive intelligence. Evidence for genuine anticipation remains limited by reliance on retrospective benchmark datasets, uncertain pre-attack signals, weak temporal validation, restricted generalizability, and limited evaluation in operational critical infrastructure. Continuous adaptation also introduces challenges involving catastrophic forgetting, adversarial manipulation, false alarms, explainability, computational constraints, and model validation. Progress toward trustworthy anticipation therefore requires prospective temporal evaluation, realistic cross-domain validation, calibrated uncertainty, adversarially robust adaptation, and meaningful human oversight. Future cybersecurity AI should be judged not only by how accurately it detects attacks, but also by whether it can reliably and sufficiently far in advance identify actionable attack risk to enable preventive intervention.
Keywords
Cyberattack prediction; Self evolving AI; Internet of Things; Critical infrastructure; Intrusion detection; Continual learning; Cybersecurity
How to cite this paper
@article{1722890,
author = {Opeyemi Priscilla Akinyemi, Damilare Timothy Ogunjobi, Obiorah Joseph Nwaisaac, Rahmatallahi Ajike Aderounmu, Benjamin Osaze Enobakhare},
title = {From Intrusion Detection to Cyberattack Anticipation: A Critical Review of Self-Evolving AI for Pre-Attack Prediction in IoT-Enabled Critical Infrastructure},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {1040-1053},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722890.pdf},
abstract = {The growing integration of Internet of Things technologies into critical infrastructure has expanded cyberattack surfaces while increasing the potential consequences of security failures across essential services. Artificial intelligence has substantially improved intrusion and anomaly detection, yet much of this progress remains reactive, identifying malicious activity only after observable evidence of an attack has emerged. This critical review examines whether self-evolving AI can support a transition from intrusion detection to reliable pre-attack anticipation in IoT-enabled critical infrastructure. It distinguishes detection, early warning, forecasting, and anticipation and critically evaluates the role of continual learning, online adaptation, concept drift management, adaptive ensembles, evolutionary approaches, and distributed learning in addressing evolving cyber threats. The review finds that adaptive AI provides important mechanisms for maintaining responsiveness under changing threat and network conditions, but adaptation alone does not constitute predictive intelligence. Evidence for genuine anticipation remains limited by reliance on retrospective benchmark datasets, uncertain pre-attack signals, weak temporal validation, restricted generalizability, and limited evaluation in operational critical infrastructure. Continuous adaptation also introduces challenges involving catastrophic forgetting, adversarial manipulation, false alarms, explainability, computational constraints, and model validation. Progress toward trustworthy anticipation therefore requires prospective temporal evaluation, realistic cross-domain validation, calibrated uncertainty, adversarially robust adaptation, and meaningful human oversight. Future cybersecurity AI should be judged not only by how accurately it detects attacks, but also by whether it can reliably and sufficiently far in advance identify actionable attack risk to enable preventive intervention.},
keywords = {Cyberattack prediction; Self evolving AI; Internet of Things; Critical infrastructure; Intrusion detection; Continual learning; Cybersecurity},
month = {September},
}