Traditional ML models have limited adaptability to evolving attack behaviors
Research gap analysis derived from 3 computer_science papers in our local library.
The gap
Traditional ML models have limited adaptability to evolving attack behaviors. Conventional cybersecurity solutions are often unable to detect emerging attack patterns. There is a need for a comprehensive framework that integrates traditiona
Evidence profile
Sourced from the future work and stated research gap of the source papers, classified as general, spanning 3 journals.
Research trend
Established — well-defined area with open sub-problems.
Supporting evidence — 3 representative gaps
- An Explainable Ensemble Machine Learning Framework for Phishing Website Detection with Robustness and Deployment Readiness Evaluation (2026) · International Journal of Creative and Open Research in Engineering and Management · doi
In order to further increase the reli-ability of the proposed method in the context of future cyber security scenarios, potential research topics include: •Adversarial Training: The implementation of advanced security measures manipulation feature manipulation and adversaries targeting the ML- based detection. techniques used by against •Real-Time Intelligence:
generalfuture workKeywords: security manipulation order further increase reli ability proposed context future cyber scenarios potential topics include - A CTI-Enriched GCN-LSTM Architecture for Multiclass Cyberattack Classification in Critical Infrastructure (2026) · Applied Sciences · doi
This study presents a foundational proof-of-concept for a novel detection model that integrates Cyber Threat Intelligence (CTI) and classifies cyberattacks using the MITRE ATT&CK framework, leveraging GCNs to enhance anomaly detection in Critical Infrastruc- ture (CI). Rather than asserting a universal defense mechanism, our research provides a robust architectural blueprint that addresses the evolving cyber threat landscape within specific dual-modality environments. The main contributions of this work are as follows: First, we developed a CTI-enhanced detection model that demonstrates the potential to improve contextual awareness, aiding in the detection of known threats and allowing for better response actions. Second, our use of the MITRE ATT&CK framework ensures a structured and standardized method for attack classification, providing a deeper understanding of adversary tactics. The operational importance of this multiclass approach is significant: for a security analyst, a binary ‘anomaly’ alert is of limited value. In contrast, an alert from our model specifying, for instance, ‘T0879—Damage to Property’ provides immediate, actionable intelligence about the adversary’s intent, enabling a prioritized incident response. Third, the application of GNNs allows the model to capture complex relationships within network traffic data, improving its ability to isolate sophisticated cyber threats while reducing false positives. Furthermore, we integrated post hoc interpretability features to help identify potential attack sources, adding a crucial layer of transparency to the detection process. The experimental results, demonstrated on the SWaT testbed, indicate the efficacy of our approach within this specific context. The model’s robustness is highlighted by its high macro F1-score of 0.9151 on a highly imbalanced dataset. This metric gives equal weight to all classes, proving the model’s capability to detect underrepresented attack types rather than overfitting to the majority ‘No_Attack’ class. However, the reliance on a single benchmark dataset—necessitated by the model’s strict requirement for synchronized IT-network traffic and OT-physical sensor telemetry— constitutes a primary limitation of this study. Consequently, broad claims regarding the model’s universal effectiveness across diverse CI sectors cannot yet be fully substantiated. To ensure these findings are transparent and independently reproducible, the exact net- work topology, optimal hyperparameters, and training pipelines have been rigorously documented and open-sourced. Future research will focus on several critical pathways. First, while the current ar- chitecture successfully classifies anomalies into high-level MITRE ATT&CK tactics, future iterations will aim to achieve sub-tactic, technique-level granularity. Advancing the model to automatically distinguish between specific techniques—such as differentiating a gen- eralized ‘Modify Parameter’ (T0836) attack from a specific
generalfuture workKeywords: model detection attack specific cyber mitre within threat intelligence classifies framework anomaly critical rather universal - CYBER THREAT FORECASTING: THE TRANSITION FROM TRADITIONAL ML TO GENERATIVE AI APPROACHES (2026) · American Journal of AI Cyber Computing Management · doi
Traditional ML models have limited adaptability to evolving attack behaviors. Conventional cybersecurity solutions are often unable to detect emerging attack patterns. There is a need for a comprehensive framework that integrates traditional machine learning techniques with advanced Generative AI models for cyber threat forecasting.
generalstated research gapevidence 5/5Keywords: traditional models have limited adaptability evolving attack behaviors
Questions about this gap
Explore this gap further
Run this gap as a query across open scholarly engines for the latest related literature.
Working on this gap? Review it with us.
AI Review reads your manuscript in one pass with 8 specialist agents, calibrated on 69K+ real peer reviews.
Tools for your next paper
Related gaps in Computer Science
- Much research in glaucoma detection, most has reliedMuch research in glaucoma detection, most has relied on discrete CNNs and simplified clustering techniques, leading to inconsistent results …
- Further optimization for rare arrhythmias, largerFurther optimization for rare arrhythmias, larger datasets, and real-world prospective validation are warranted, ECG-XPLAIM’s scalability, o…
- Conventional convolutional neural networksConventional convolutional neural networks have limitations in modeling long-range contextual information. Simple feature concatenation or d…
- The need for more accurate and robust machine learningThe need for more accurate and robust machine learning models for predicting compressive strength of waste aggregate concrete blocks. The la…