Adversarial Machine Learning in Cybersecurity: A Survey of Attacks, Defenses, and Robustness Evaluation
DOI:
https://doi.org/10.69968/ijisem.2026v5i3210-217Keywords:
Adversarial Machine Learning, Cybersecurity, Adversarial Attacks, Defense Mechanisms, Robustness EvaluationAbstract
The rise of artificial intelligence (AI) and machine learning (ML) in cybersecurity has made Adversarial Machine Learning (AML) a key field of research. Though ML-based systems are more effective in intrusion detection, malware analysis, spam filtering and authentication, they are also susceptible to adversarial attacks that modify input samples, modify ML models or alter training data. The review explores the key adversarial attack classes: poisoning, evasion, model extraction, model inversion, and membership inference and also white-box, black-box, and grey-box threat models. It also provides an introduction to important defence methods like adversarial training, feature squeezing, defensive distillation, robust optimisation, detection-based methods, and ensemble learning. In addition, robustness evaluation metrics, benchmark datasets and attack assessment techniques to measure model robustness are highlighted. Lastly, the emerging trends are discussed in order to find future research directions in the field of creating trustworthy and resilient AI-based cybersecurity systems, such as Explainable AI, Federated Learning, Large Language Models, Autonomous Cyber defence, and Regulatory structures.
References
[1] N. Mohamed, “Artificial intelligence and machine learning in cybersecurity: a deep dive into state-of-the-art techniques and future paradigms Nachaat,” Knowl. Inf. Syst., vol. 67, 2025, doi: 10.1007/s10115-025-02429-y.
[2] E. Kesavan, “Internet of Things (IoT): A Review of Security Challenges and Solutions,” Int. J. Innov. Sci. Eng. Manag., vol. 2, no. 4, pp. 65–71, 2023, doi: 10.69968/ijisem.2023v2i465-71.
[3] L. A. M. Hernández, S. P. Arteaga, A. L. S. Orozco, and L. J. G. Villalba, “Adversarial Attacks on Machine Learning Models for Network Traffic Filtering,” Eng. Proc., 2026.
[4] S. Rahman, S. Pal, A. Habib, L. Pan, and C. Karmakar, “Attack-data independent defence mechanism against adversarial attacks on ECG signal,” Comput. Networks, vol. 258, p. 111027, 2025, doi: 10.1016/j.comnet.2024.111027.
[5] P. Dixit and P. B. Singh, “The Impact of Artificial Intelligence on Various Sectors: Benefits, Challenges, and Future Prospects,” Interantional J. Sci. Res. Eng. Manag., vol. 3, no. 2, pp. 140–144, 2024, doi: 10.69968/ijisem.2024v3si2140-144.
[6] M. U. Tariq, “Defense Mechanisms Against Adversarial Attacks Strengthening AI Security in Cy ersecurity Applications,” in Challenges and Solutions for Cybersecurity and Adversarial Machine Learning, 2025, pp. 199–201. doi: 10.4018/979-8-3373-2200-1.ch007.
[7] A. D. Lahe, G. G. Parrkhed, and B. L. Rathi, “A Study on Security Challenges in Machine Learning,” Int. J. Sci. Res. Comput. Sci. Eng. Inf. Technol., pp. 166–176, 2023.
[8] E. Alshahrani, D. Alghazzawi, R. Alotaibi, and O. Rabie, “Adversarial attacks against supervised machine learning based network intrusion detection systems,” PLoS One, pp. 1–14, 2022, doi: 10.1371/journal.pone.0275971.
[9] P. Xiong, S. Buffett, S. Iqbal, P. Lamontagne, M. Mamun, and H. Molyneaux, “Towards a Robust and Trustworthy Machine Learning System Development: An Engineering Perspective,” arXiv, pp. 1–58, 2022.
[10] M. Penmetsa, J. R. Bhumireddy, R. Chalasani, S. R. Vangala, R. M. Polam, and B. Kamarthapu, “Adversarial Machine Learning in Cybersecurity: A Review on Defending Against AI-Driven Attacks,” Eur. J. Appl. Sci. Eng. Technol., vol. 3, no. 4, pp. 4–14, 2025, doi: 10.59324/ejaset.2025.3(4).01.
[11] S. S. R. Banait, A. C. M, M. Sen, D. Mondal, D. Dhabliya, and J. R. R. Kumar, Advancements in Defense Mechanisms against Adversarial Attacks in Computer Vision, vol. 1, no. 1. Association for Computing Machinery, 2024. doi: 10.1145/3745812.3745886.
[12] J. C. Palomares-salas, S. Aguado-gonzález, and J. M. Sierra-Fernández, “Robustness of Machine Learning and Deep Learning Models for Power Quality Disturbance Classification: A Cross-Platform Analysis,” Appl. Sci., pp. 1–16, 2025.
[13] J. Zhang, J. Li, and Z. Yang, “Dynamic robustness evaluation for automated model selection in operation,” Inf. Softw. Technol., vol. 178, p. 107603, 2025, doi: 10.1016/j.infsof.2024.107603.
[14] S. Pal et al., “Vulnerabilities in Machine Learning for cybersecurity: Current trends and future research directions Shantanu,” J. Inf. Secur. Appl., vol. 96, p. 104269, 2026, doi: 10.1016/j.jisa.2025.104269.
[15] J. YU, A. V. SHVETSOV, and S. H. ALSAMHI, “Leveraging Machine Learning for Cybersecurity Resilience in Industry 4.0: Challenges and Future Directions,” IEEE Access, vol. 12, pp. 159579–159596, 2024, doi: 10.1109/ACCESS.2024.3482987.
[16] K. Razzaq and M. Shah, “Emerging Trends in Cybersecurity: Machine Learning as a Game-Changer in Next Generation Cybersecurity Applications,” F1000Research, vol. 15, no. 276, 2026.
[17] J. Sharma, “Cyber Crime Causes and prevention: An Analysis,” Int. J. Innov. Sci. Eng. Manag., vol. 4, no. 3, pp. 66–72, 2025, doi: 10.69968/ijisem.2025v4i366-72.
[18] A. Singh and N. Shanker, “Redefining Cybercrimes in light of Artificial Intelligence: Emerging threats and Challenges,” Int. J. Innov. Sci. Eng. Manag., vol. 3, no. 2, pp. 192–201, 2024, doi: 10.69968/ijisem.2024v3si2192-201.
[19] S. Joshi, “Review of Gen AI Models for Financial Risk Management: Architectural Frameworks and Implementation Strategies,” Int. J. Innov. Sci. Eng. Manag., vol. 4, no. 3, pp. 207–222, 2025, doi: 10.69968/ijisem.2025v4i2207-222.
[20] B. TEKESTE, K. AL-HUSSAENI, B. C. M. FUNG, I. ALAWADHI, and C. FACHKHA, “Adversarial Machine Learning: A 20-Year Survey of Attacks, Defenses, and Standards,” IEEE Access, vol. 14, pp. 69778–69812, 2026, doi: 10.1109/ACCESS.2026.3690620.
[21] S. Singh and A. Gupta, “Adversarial Attacks on Machine Learning Models in Cybersecurity: A Systematic Literature Review,” J. Artif. Intell. Res. Adv., vol. 13, no. 1, pp. 23–38, 2026.
[22] V. Kakkad, P. Chung, H. Hibshi, and M. Woo, “Comparative Insights on Adversarial Machine Learning from Industry and Academia: A User-Study Approach,” arXiv, 2026.
[23] F. V. Jedrzejewski, L. Thode, J. Fischbach, T. Gorschek, D. Mendez, and N. Lavesson, “Adversarial Machine Learning in Industry: A Systematic Literature Review,” Comput. Secur., vol. 145, p. 103988, 2024, doi: 10.1016/j.cose.2024.103988.
[24] I. Rosenberg, A. Shabtai, Y. Elovici, and L. Rokach, “Adversarial Machine Learning Attacks and Defense Methods in the Cyber Security Domain,” ACM Comput. Surv., vol. 54, no. 5, 2021.
[25] L. A. Babatunde et al., “Adversarial Machine Learning in Cybersecurity: Vulnerabilities and Defense Strategies,” J. Front. Multidiscip. Res., vol. 01, no. 02, pp. 31–45, 2020.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Ujjwal Deshmukh

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Re-users must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use. This license allows for redistribution, commercial and non-commercial, as long as the original work is properly credited.





