
The cybersecurity landscape in 2026 has undergone a fundamental transformation driven by the dual forces of escalating adversarial sophistication and the rapid maturation of artificial intelligence technologies. This survey provides a comprehensive examination of how AI is reshaping cyber defense across two core dimensions that are critical for modern security operations: AI-driven threat detection and response, and AI-powered security infrastructure and resilience. For each dimension, this study clarifies foundational concepts, identifies where risks emerge along the security lifecycle, and summarizes stage-targeted mitigation strategies powered by machine learning, deep learning, and large language models. The analysis extends to specialized domains including network security, malware analysis, phishing and social engineering defense, cloud and container security, and IoT and edge security, offering detailed technical insights into the role of AI across diverse cybersecurity environments. A unified evaluation framework is presented to emphasize both detection effectiveness and operational resilience, supported by practical metrics and benchmark considerations. In addition, three case studies demonstrate the capabilities and limitations of AI-augmented cybersecurity systems in critical infrastructure, healthcare, and supply chain environments. The paper concludes by discussing key challenges such as adversarial AI, explainability limitations, real-time scalability constraints, regulatory and ethical concerns, and the growing AI arms race between attackers and defenders. This survey aims to serve as a practical and research-oriented reference for professionals and scholars building AI-augmented cybersecurity systems in a rapidly evolving threat landscape.
The cybersecurity landscape in 2026 has undergone a fundamental transformation driven by the dual forces of escalating adversarial sophistication and the rapid maturation of artificial intelligence technologies. This survey provides a comprehensive examination of how AI is reshaping cyber defense across two core dimensions that are critical for modern security operations: AI-driven threat detection and response, and AI-powered security infrastructure and resilience. For each dimension, this study clarifies foundational concepts, identifies where risks emerge along the security lifecycle, and summarizes stage-targeted mitigation strategies powered by machine learning, deep learning, and large language models. The analysis extends to specialized domains including network security, malware analysis, phishing and social engineering defense, cloud and container security, and IoT and edge security, offering detailed technical insights into the role of AI across diverse cybersecurity environments. A unified evaluation framework is presented to emphasize both detection effectiveness and operational resilience, supported by practical metrics and benchmark considerations. In addition, three case studies demonstrate the capabilities and limitations of AI-augmented cybersecurity systems in critical infrastructure, healthcare, and supply chain environments. The paper concludes by discussing key challenges such as adversarial AI, explainability limitations, real-time scalability constraints, regulatory and ethical concerns, and the growing AI arms race between attackers and defenders. This survey aims to serve as a practical and research-oriented reference for professionals and scholars building AI-augmented cybersecurity systems in a rapidly evolving threat landscape.
Cybernetics/ethics, cybersecurity, Cybernetics/standards, Cyberbullying
Cybernetics/ethics, cybersecurity, Cybernetics/standards, Cyberbullying
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
