A comprehensive review of machine learning applications in cybersecurity : identifying gaps and advocating for cybersecurity auditing

Loading...
Thumbnail Image

Journal Title

Journal ISSN

Volume Title

Publisher

Springer

Abstract

The rapid growth of increasingly sophisticated and complex cyber threats has intensified interest in, and reliance on, artificial intelligence (AI), particularly machine learning (ML), within the cybersecurity landscape. ML has demonstrated robust potential to enhance cybersecurity capabilities, including threat detection, anomaly identification, predictive analytics, and automated response; however, practical ML implementation in cybersecurity remains in an early stage, often inconsistent, fragmented, and insufficiently developed. Consequently, ongoing research is essential to identify emerging developments, expand areas of inquiry, and propose improvements to existing approaches. This study provides a comprehensive review of recent ML applications in cybersecurity. Using the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) methodology, the study systematically evaluates the feasibility, effectiveness, and limitations of current approaches. The review reveals several critical gaps, including narrow application scopes, suboptimal algorithm performance in real-world environments, insufficient and imbalanced datasets, and inadequate integration with Security Information and Event Management (SIEM) and Intrusion Prevention Systems (IPS). Additional concerns include ethical dilemmas and governance challenges, all of which limit the operational reliability of ML-driven cybersecurity solutions. The findings emphasize the need to refine ML models, improve interoperability with existing security infrastructures, and strengthen evaluation frameworks. Importantly, the study advocates aligning modern ML-driven innovations with cybersecurity auditing, emphasizing cybersecurity audits' role in assessing ML readiness, validating control effectiveness, and promoting responsible, transparent, and risk-based adoption of ML technologies in cybersecurity environments.

Description

DATA AVAILABILITY : No datasets were generated or analysed during the current study.

Keywords

Artificial intelligence (AI), Machine learning, Preferred reporting items for systematic review and meta-analysis (PRISMA), Security information and event management (SIEM), Intrusion prevention systems (IPS), Cybersecurity, Cybersecurity auditing, Cybersecurity threats, Cybersecurity tools, Advanced cyber threats, Systematic review

Sustainable Development Goals

SDG-09: Industry, innovation and infrastructure
SDG-08: Decent work and economic growth

Citation

Rananga, N., Venter, H.S. A comprehensive review of machine learning applications in cybersecurity: identifying gaps and advocating for cybersecurity auditing. International Journal of Information Security 25, 101: 1-22 (2026). https://doi.org/10.1007/s10207-026-01266-6.