CFP last date
21 September 2026
Reseach Article

Robust Machine Learning Models for Cybersecurity in Critical Infrastructures: A Systematic Review, Empirical Synthesis, and Framework Proposal

by Stephen Kofi Dotse, Samuel Yao Sebuabe, Is-haq Kofi Mohammed
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Number 138
Year of Publication: 2026
Authors: Stephen Kofi Dotse, Samuel Yao Sebuabe, Is-haq Kofi Mohammed
10.5120/ijcaa4c5c149f86b

Stephen Kofi Dotse, Samuel Yao Sebuabe, Is-haq Kofi Mohammed . Robust Machine Learning Models for Cybersecurity in Critical Infrastructures: A Systematic Review, Empirical Synthesis, and Framework Proposal. International Journal of Computer Applications. 187, 138 ( Aug 2026), 31-39. DOI=10.5120/ijcaa4c5c149f86b

@article{ 10.5120/ijcaa4c5c149f86b,
author = { Stephen Kofi Dotse, Samuel Yao Sebuabe, Is-haq Kofi Mohammed },
title = { Robust Machine Learning Models for Cybersecurity in Critical Infrastructures: A Systematic Review, Empirical Synthesis, and Framework Proposal },
journal = { International Journal of Computer Applications },
issue_date = { Aug 2026 },
volume = { 187 },
number = { 138 },
month = { Aug },
year = { 2026 },
issn = { 0975-8887 },
pages = { 31-39 },
numpages = {9},
url = { https://ijcaonline.org/archives/volume187/number138/robust-machine-learning-models-for-cybersecurity-in-critical-infrastructures-a-systematic-review-empirical-synthesis-and-framework-proposal/ },
doi = { 10.5120/ijcaa4c5c149f86b },
publisher = {Foundation of Computer Science (FCS), NY, USA},
address = {New York, USA}
}
%0 Journal Article
%1 2026-08-31T03:10:12+05:30
%A Stephen Kofi Dotse
%A Samuel Yao Sebuabe
%A Is-haq Kofi Mohammed
%T Robust Machine Learning Models for Cybersecurity in Critical Infrastructures: A Systematic Review, Empirical Synthesis, and Framework Proposal
%J International Journal of Computer Applications
%@ 0975-8887
%V 187
%N 138
%P 31-39
%D 2026
%I Foundation of Computer Science (FCS), NY, USA
Abstract

ML-based intrusion detection systems for critical infrastructure work well in controlled research settings. The gap between that and reliable operation against adversaries who probe, adapt, and know the detection layer is where this paper focuses. We reviewed 44 primary sources via a PRISMA-adapted protocol covering ensemble learning, GNNs, transformer architectures, deep reinforcement learning, adversarial defences, concept drift adaptation, federated learning, and XAI across three CI sectors: energy and water, healthcare IoMT, and intelligent transportation. The main findings: ensemble hybrids are the most deployable near-term architecture. Certified robustness methods are theoretically principled but fall short of operational security guarantees under realistic CI threat models, as Cullen et al. (2025) demonstrated at ICML. SHAP and LIME measurably improve analyst trust but enable adversaries to reconstruct model decision boundaries with over 90% success; this paper calls that tension the Adversarial XAI Paradox, and no reviewed study resolves it. Transportation sector evaluation is the weakest of the three, with no public V2X-specific benchmark comparable to SWaT or CICIoMT2024. We identify five testable research gaps, construct a five-layer framework aligned to NIST CSF 2.0, and close with specific recommendations.

References
  1. Alharbi, A. A., Alharby, M., & Hanandeh, A. A. (2025). Securing healthcare systems and optimizing data analytics through IoMT threat detection. AIMS Mathematics, 10(11), 25274--25306. https://doi.org/10.3934/math.20251119
  2. Arslan, R., Özseven, T., Aydın, M. M., & Çelik, Y. (2026). Cybersecurity in intelligent transportation systems: A comparative study on AI-based anomaly detection and threat analysis. Mechatronics and Intelligent Transportation Systems, 5(1), 11--30. https://doi.org/10.56578/mits050102
  3. Batishchev, D., & Saad, M. (2025). The black box problem: AI decision-making in critical infrastructure and its implications [Preprint]. Preprints.org. https://doi.org/10.20944/preprints202511.2276.v1
  4. Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5--32. https://doi.org/10.1023/A:1010933404324
  5. Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153--1176. https://doi.org/10.1109/COMST.2015.2494502
  6. Carlini, N., & Wagner, D. (2017). Towards evaluating the robustness of neural networks. In Proceedings of the 2017 IEEE Symposium on Security and Privacy (pp. 39--57). https://doi.org/10.1109/SP.2017.49
  7. Censinet, American Hospital Association, Health-ISAC, Health Sector Coordinating Council, Scottsdale Institute, & University of Texas at Austin. (2026). The 2026 healthcare cybersecurity benchmarking study. https://www.censinet.com
  8. Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 785--794). https://doi.org/10.1145/2939672.2939785
  9. Cisco Systems. (2025). 2025 Cisco cybersecurity readiness index. https://www.cisco.com
  10. Cohen, J., Rosenfeld, E., & Kolter, J. Z. (2019). Certified adversarial robustness via randomized smoothing. In Proceedings of the 36th ICML (PMLR Vol. 97, pp. 1310--1320).
  11. Cullen, A. C., Montague, P., Erfani, S. M., & Rubinstein, B. I. P. (2025). Position: Certified robustness does not (yet) imply model security. In Proceedings of the 42nd ICML (PMLR Vol. 267, pp. 81185--81198). https://proceedings.mlr.press/v267/cullen25a.html
  12. Dadkhah, S., Carlos Pinto Neto, E., Ferreira, R., Molokwu, R. C., Sadeghi, S., & Ghorbani, A. A. (2024). CICIoMT2024: A multi-protocol dataset for assessing IoMT device security. Internet of Things, 28, 101351. https://doi.org/10.1016/j.iot.2024.101351
  13. European Data Protection Supervisor. (2025). TechDispatch #1/2025 -- Federated learning. https://www.edps.europa.eu
  14. Gamage, T. P. D., Gutierrez, J. A., & Ray, S. K. (2025). The role of graph neural networks, transformers, and reinforcement learning in network threat detection: A systematic literature review. Electronics, 14(21), 4163. https://doi.org/10.3390/electronics14214163
  15. Goodfellow, I. J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In Proceedings of ICLR 2015. arXiv. https://arxiv.org/abs/1412.6572
  16. Grand View Research. (2025). Cybersecurity in critical infrastructure protection market report 2025--2033. https://www.grandviewresearch.com
  17. IBM Security. (2024). Cost of a data breach report 2024. IBM.
  18. Kasprzyk, Z., & Rychlicki, M. (2025). Comparative analysis of machine learning algorithms for sustainable attack detection in intelligent transportation systems using long-range sensor network technology. Sustainability, 17(20), 8985. https://doi.org/10.3390/su17208985
  19. Khan, N., Ahmad, K., Al-Fuqaha, A., & Khalil, I. (2025). Explainable AI-based intrusion detection systems for Industry 5.0 and adversarial XAI: A systematic review. Information, 16(12), 1036. https://doi.org/10.3390/info16121036
  20. Lavaur, L., & Busnel, Y. (2025). Tutorial: Federated learning and network security [Tutorial, IEEE ICDCS 2025]. https://hal.science/hal-05288649v1
  21. Lundberg, S. M., & Lee, S.-I. (2017). A unified approach to interpreting model predictions. In Advances in NeurIPS 30 (pp. 4765--4774).
  22. Lütjens, B., Everett, M., & How, J. P. (2020). Certified adversarial robustness for deep reinforcement learning. PMLR, 100, 1328--1337. https://proceedings.mlr.press/v100/lutjens20a.html
  23. Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2018). Towards deep learning models resistant to adversarial attacks. In Proceedings of ICLR 2018. https://arxiv.org/abs/1706.06083
  24. Mathur, A. P., & Tippenhauer, N. O. (2016). SWaT: A water treatment testbed for research and training on ICS security. In 2016 International Workshop on Cyber-physical Systems for Smart Water Networks (pp. 31--36). https://doi.org/10.1109/CySWater.2016.7469060
  25. Muzibuddin, S., Reddy, T. D. G., Reddy, V. J. S. P., & Srimani, K. (2026). Enhancing critical infrastructure security using USAD for unsupervised anomaly detection. IJERT, 15(3). https://www.ijert.org
  26. National Institute of Standards and Technology. (2023). AI risk management framework (AI RMF 1.0) (NIST AI 100-1). https://doi.org/10.6028/NIST.AI.100-1
  27. National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29
  28. Oriaro, S., & Mishra, S. (2025). Improving cybersecurity through explainable artificial intelligence: A systematic literature review. Issues in Information Systems, 26(3), 387--400. https://iacis.org/iis/2025/3_iis_2025_387-400.pdf
  29. Page, M. J., et al. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372, n71. https://doi.org/10.1136/bmj.n71
  30. Palo Alto Networks. (2024). 2025 cybersecurity predictions. Unit 42. https://www.paloaltonetworks.com
  31. Papernot, N., McDaniel, P., Sinha, A., & Wellman, M. P. (2018). SoK: Security and privacy in machine learning. In Proceedings of IEEE EuroS&P 2018 (pp. 399--414). https://doi.org/10.1109/EuroSP.2018.00035
  32. Pfrommer, S., Anderson, B. G., & Sojoudi, S. (2023a). Projected randomized smoothing for certified adversarial robustness. Transactions on Machine Learning Research. https://openreview.net/forum?id=FObkvLwNSo
  33. Pfrommer, S., Anderson, B., Piet, J., & Sojoudi, S. (2023b). Asymmetric certified robustness via feature-convex neural networks. In Advances in NeurIPS 36 (pp. 52365--52400). https://proceedings.neurips.cc
  34. Pfrommer, S. I. (2025). Safety, robustness, and interpretability in machine learning [Doctoral dissertation, UC Berkeley]. EECS Tech Report UCB/EECS-2025-67. https://www2.eecs.berkeley.edu
  35. Prasad, P. W. C., Sayeed, M. S., Nguyen, D.-M., Hutabarat, D. P., & Mohiuddin, G. M. (2026). Explainable AI: Enhancing decision-making in the detection of cyber threats. Frontiers in Computer Science, 8, 1762332. https://doi.org/10.3389/fcomp.2026.1762332
  36. Ribeiro, M. T., Singh, S., & Guestrin, C. (2016). "Why should I trust you?": Explaining the predictions of any classifier. In Proceedings of the 22nd ACM KDD (pp. 1135--1144). https://doi.org/10.1145/2939672.2939778
  37. Sebopelo, R. B. (2026). Trinity-Controller ADWIN: An accuracy-guided sensitivity control framework for streaming intrusion detection. Journal of Information Systems and Informatics, 8(1), 501--529. https://doi.org/10.63158/journalisi.v8i1.1421
  38. Singh, A., Duvvada, S. R., Nisha, R. S., Parthiban, K., Niveditha, S. R., & Vineesha, M. (2025). A hybrid defense framework for critical infrastructure. In Proceedings of ICRDICCT'25 (pp. 820--826). SciTePress. https://doi.org/10.5220/0013944300004919
  39. Sitawarin, C. (2024). New perspectives on adversarially robust machine learning systems [Doctoral dissertation, UC Berkeley]. EECS Tech Report UCB/EECS-2024-10. https://www2.eecs.berkeley.edu
  40. Sophos. (2024). The state of ransomware in healthcare 2024. Sophos Ltd.
  41. Sunkara, G. (2025). Explainable AI for cyber threat intelligence: Enhancing analyst trust. Open Access Research Journal of Science and Technology, 14(2), 29--40.
  42. Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., Kaiser, L., & Polosukhin, I. (2017). Attention is all you need. In Advances in NeurIPS 30 (pp. 5998--6008).
  43. Verizon. (2024). 2024 data breach investigations report. Verizon Business.
  44. Wickramasinghe Brahmana, C. S., Marino, D., De Silva, D., & Manic, M. (2025). Editorial: Machine learning for cybersecurity. Frontiers in Artificial Intelligence, 8, 1640609. https://doi.org/10.3389/frai.2025.1640609
  45. Yang, L., & Shami, A. (2023). A multi-stage automated online network data stream analytics framework for IIoT systems. IEEE Transactions on Industrial Informatics, 19(2), 2107--2116. https://doi.org/10.1109/TII.2022.3212003
  46. Yin, J., Xie, W., Liang, G., Zhang, L., & Zhang, X. (2025). Concept drift detection and adaptation method for IoT security framework. China Communications, 22(12), 137--147. https://doi.org/10.23919/JCC.fa.2022-0379.202512.
  47. Zhevnenko, D., Makarov, I., Kovalenko, A., Meshchaninov, F., Kozhukhov, A., Travnikov, V., Ippolitov, M., Yashunin, K., & Katser, I. (2026). Benchmarking IoT time-series anomaly detection with event-level augmentations [Preprint]. arXiv. https://arxiv.org/abs/2602.15457.
Index Terms

Computer Science
Information Sciences

Keywords

Critical infrastructure cybersecurity machine learning robustness adversarial ML explainable AI concept drift intrusion detection graph neural networks certified robustness NIST CSF 2.0