Research Article

Robust Machine Learning Models for Cybersecurity in Critical Infrastructures: A Systematic Review, Empirical Synthesis, and Framework Proposal

by  Stephen Kofi Dotse, Samuel Yao Sebuabe, Is-Haq Kofi Mohammed
journal cover
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Issue 138
Published: August 2026
Authors: Stephen Kofi Dotse, Samuel Yao Sebuabe, Is-Haq Kofi Mohammed
10.5120/ijcaa4c5c149f86b
PDF

Stephen Kofi Dotse, Samuel Yao Sebuabe, Is-Haq Kofi Mohammed . Robust Machine Learning Models for Cybersecurity in Critical Infrastructures: A Systematic Review, Empirical Synthesis, and Framework Proposal. International Journal of Computer Applications. 187, 138 (August 2026), 31-39. DOI=10.5120/ijcaa4c5c149f86b

                        @article{ 10.5120/ijcaa4c5c149f86b,
                        author  = { Stephen Kofi Dotse,Samuel Yao Sebuabe,Is-Haq Kofi Mohammed },
                        title   = { Robust Machine Learning Models for Cybersecurity in Critical Infrastructures: A Systematic Review, Empirical Synthesis, and Framework Proposal },
                        journal = { International Journal of Computer Applications },
                        year    = { 2026 },
                        volume  = { 187 },
                        number  = { 138 },
                        pages   = { 31-39 },
                        doi     = { 10.5120/ijcaa4c5c149f86b },
                        publisher = { Foundation of Computer Science (FCS), NY, USA }
                        }
                        %0 Journal Article
                        %D 2026
                        %A Stephen Kofi Dotse
                        %A Samuel Yao Sebuabe
                        %A Is-Haq Kofi Mohammed
                        %T Robust Machine Learning Models for Cybersecurity in Critical Infrastructures: A Systematic Review, Empirical Synthesis, and Framework Proposal%T 
                        %J International Journal of Computer Applications
                        %V 187
                        %N 138
                        %P 31-39
                        %R 10.5120/ijcaa4c5c149f86b
                        %I Foundation of Computer Science (FCS), NY, USA
Abstract

ML-based intrusion detection systems for critical infrastructure work well in controlled research settings. The gap between that and reliable operation against adversaries who probe, adapt, and know the detection layer is where this paper focuses. We reviewed 44 primary sources via a PRISMA-adapted protocol covering ensemble learning, GNNs, transformer architectures, deep reinforcement learning, adversarial defences, concept drift adaptation, federated learning, and XAI across three CI sectors: energy and water, healthcare IoMT, and intelligent transportation. The main findings: ensemble hybrids are the most deployable near-term architecture. Certified robustness methods are theoretically principled but fall short of operational security guarantees under realistic CI threat models, as Cullen et al. (2025) demonstrated at ICML. SHAP and LIME measurably improve analyst trust but enable adversaries to reconstruct model decision boundaries with over 90% success; this paper calls that tension the Adversarial XAI Paradox, and no reviewed study resolves it. Transportation sector evaluation is the weakest of the three, with no public V2X-specific benchmark comparable to SWaT or CICIoMT2024. We identify five testable research gaps, construct a five-layer framework aligned to NIST CSF 2.0, and close with specific recommendations.

References
  • Alharbi, A. A., Alharby, M., & Hanandeh, A. A. (2025). Securing healthcare systems and optimizing data analytics through IoMT threat detection. AIMS Mathematics, 10(11), 25274--25306. https://doi.org/10.3934/math.20251119
  • Arslan, R., Özseven, T., Aydın, M. M., & Çelik, Y. (2026). Cybersecurity in intelligent transportation systems: A comparative study on AI-based anomaly detection and threat analysis. Mechatronics and Intelligent Transportation Systems, 5(1), 11--30. https://doi.org/10.56578/mits050102
  • Batishchev, D., & Saad, M. (2025). The black box problem: AI decision-making in critical infrastructure and its implications [Preprint]. Preprints.org. https://doi.org/10.20944/preprints202511.2276.v1
  • Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5--32. https://doi.org/10.1023/A:1010933404324
  • Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153--1176. https://doi.org/10.1109/COMST.2015.2494502
  • Carlini, N., & Wagner, D. (2017). Towards evaluating the robustness of neural networks. In Proceedings of the 2017 IEEE Symposium on Security and Privacy (pp. 39--57). https://doi.org/10.1109/SP.2017.49
  • Censinet, American Hospital Association, Health-ISAC, Health Sector Coordinating Council, Scottsdale Institute, & University of Texas at Austin. (2026). The 2026 healthcare cybersecurity benchmarking study. https://www.censinet.com
  • Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 785--794). https://doi.org/10.1145/2939672.2939785
  • Cisco Systems. (2025). 2025 Cisco cybersecurity readiness index. https://www.cisco.com
  • Cohen, J., Rosenfeld, E., & Kolter, J. Z. (2019). Certified adversarial robustness via randomized smoothing. In Proceedings of the 36th ICML (PMLR Vol. 97, pp. 1310--1320).
  • Cullen, A. C., Montague, P., Erfani, S. M., & Rubinstein, B. I. P. (2025). Position: Certified robustness does not (yet) imply model security. In Proceedings of the 42nd ICML (PMLR Vol. 267, pp. 81185--81198). https://proceedings.mlr.press/v267/cullen25a.html
  • Dadkhah, S., Carlos Pinto Neto, E., Ferreira, R., Molokwu, R. C., Sadeghi, S., & Ghorbani, A. A. (2024). CICIoMT2024: A multi-protocol dataset for assessing IoMT device security. Internet of Things, 28, 101351. https://doi.org/10.1016/j.iot.2024.101351
  • European Data Protection Supervisor. (2025). TechDispatch #1/2025 -- Federated learning. https://www.edps.europa.eu
  • Gamage, T. P. D., Gutierrez, J. A., & Ray, S. K. (2025). The role of graph neural networks, transformers, and reinforcement learning in network threat detection: A systematic literature review. Electronics, 14(21), 4163. https://doi.org/10.3390/electronics14214163
  • Goodfellow, I. J., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In Proceedings of ICLR 2015. arXiv. https://arxiv.org/abs/1412.6572
  • Grand View Research. (2025). Cybersecurity in critical infrastructure protection market report 2025--2033. https://www.grandviewresearch.com
  • IBM Security. (2024). Cost of a data breach report 2024. IBM.
  • Kasprzyk, Z., & Rychlicki, M. (2025). Comparative analysis of machine learning algorithms for sustainable attack detection in intelligent transportation systems using long-range sensor network technology. Sustainability, 17(20), 8985. https://doi.org/10.3390/su17208985
  • Khan, N., Ahmad, K., Al-Fuqaha, A., & Khalil, I. (2025). Explainable AI-based intrusion detection systems for Industry 5.0 and adversarial XAI: A systematic review. Information, 16(12), 1036. https://doi.org/10.3390/info16121036
  • Lavaur, L., & Busnel, Y. (2025). Tutorial: Federated learning and network security [Tutorial, IEEE ICDCS 2025]. https://hal.science/hal-05288649v1
  • Lundberg, S. M., & Lee, S.-I. (2017). A unified approach to interpreting model predictions. In Advances in NeurIPS 30 (pp. 4765--4774).
  • Lütjens, B., Everett, M., & How, J. P. (2020). Certified adversarial robustness for deep reinforcement learning. PMLR, 100, 1328--1337. https://proceedings.mlr.press/v100/lutjens20a.html
  • Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2018). Towards deep learning models resistant to adversarial attacks. In Proceedings of ICLR 2018. https://arxiv.org/abs/1706.06083
  • Mathur, A. P., & Tippenhauer, N. O. (2016). SWaT: A water treatment testbed for research and training on ICS security. In 2016 International Workshop on Cyber-physical Systems for Smart Water Networks (pp. 31--36). https://doi.org/10.1109/CySWater.2016.7469060
  • Muzibuddin, S., Reddy, T. D. G., Reddy, V. J. S. P., & Srimani, K. (2026). Enhancing critical infrastructure security using USAD for unsupervised anomaly detection. IJERT, 15(3). https://www.ijert.org
  • National Institute of Standards and Technology. (2023). AI risk management framework (AI RMF 1.0) (NIST AI 100-1). https://doi.org/10.6028/NIST.AI.100-1
  • National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29
  • Oriaro, S., & Mishra, S. (2025). Improving cybersecurity through explainable artificial intelligence: A systematic literature review. Issues in Information Systems, 26(3), 387--400. https://iacis.org/iis/2025/3_iis_2025_387-400.pdf
  • Page, M. J., et al. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372, n71. https://doi.org/10.1136/bmj.n71
  • Palo Alto Networks. (2024). 2025 cybersecurity predictions. Unit 42. https://www.paloaltonetworks.com
  • Papernot, N., McDaniel, P., Sinha, A., & Wellman, M. P. (2018). SoK: Security and privacy in machine learning. In Proceedings of IEEE EuroS&P 2018 (pp. 399--414). https://doi.org/10.1109/EuroSP.2018.00035
  • Pfrommer, S., Anderson, B. G., & Sojoudi, S. (2023a). Projected randomized smoothing for certified adversarial robustness. Transactions on Machine Learning Research. https://openreview.net/forum?id=FObkvLwNSo
  • Pfrommer, S., Anderson, B., Piet, J., & Sojoudi, S. (2023b). Asymmetric certified robustness via feature-convex neural networks. In Advances in NeurIPS 36 (pp. 52365--52400). https://proceedings.neurips.cc
  • Pfrommer, S. I. (2025). Safety, robustness, and interpretability in machine learning [Doctoral dissertation, UC Berkeley]. EECS Tech Report UCB/EECS-2025-67. https://www2.eecs.berkeley.edu
  • Prasad, P. W. C., Sayeed, M. S., Nguyen, D.-M., Hutabarat, D. P., & Mohiuddin, G. M. (2026). Explainable AI: Enhancing decision-making in the detection of cyber threats. Frontiers in Computer Science, 8, 1762332. https://doi.org/10.3389/fcomp.2026.1762332
  • Ribeiro, M. T., Singh, S., & Guestrin, C. (2016). "Why should I trust you?": Explaining the predictions of any classifier. In Proceedings of the 22nd ACM KDD (pp. 1135--1144). https://doi.org/10.1145/2939672.2939778
  • Sebopelo, R. B. (2026). Trinity-Controller ADWIN: An accuracy-guided sensitivity control framework for streaming intrusion detection. Journal of Information Systems and Informatics, 8(1), 501--529. https://doi.org/10.63158/journalisi.v8i1.1421
  • Singh, A., Duvvada, S. R., Nisha, R. S., Parthiban, K., Niveditha, S. R., & Vineesha, M. (2025). A hybrid defense framework for critical infrastructure. In Proceedings of ICRDICCT'25 (pp. 820--826). SciTePress. https://doi.org/10.5220/0013944300004919
  • Sitawarin, C. (2024). New perspectives on adversarially robust machine learning systems [Doctoral dissertation, UC Berkeley]. EECS Tech Report UCB/EECS-2024-10. https://www2.eecs.berkeley.edu
  • Sophos. (2024). The state of ransomware in healthcare 2024. Sophos Ltd.
  • Sunkara, G. (2025). Explainable AI for cyber threat intelligence: Enhancing analyst trust. Open Access Research Journal of Science and Technology, 14(2), 29--40.
  • Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., Kaiser, L., & Polosukhin, I. (2017). Attention is all you need. In Advances in NeurIPS 30 (pp. 5998--6008).
  • Verizon. (2024). 2024 data breach investigations report. Verizon Business.
  • Wickramasinghe Brahmana, C. S., Marino, D., De Silva, D., & Manic, M. (2025). Editorial: Machine learning for cybersecurity. Frontiers in Artificial Intelligence, 8, 1640609. https://doi.org/10.3389/frai.2025.1640609
  • Yang, L., & Shami, A. (2023). A multi-stage automated online network data stream analytics framework for IIoT systems. IEEE Transactions on Industrial Informatics, 19(2), 2107--2116. https://doi.org/10.1109/TII.2022.3212003
  • Yin, J., Xie, W., Liang, G., Zhang, L., & Zhang, X. (2025). Concept drift detection and adaptation method for IoT security framework. China Communications, 22(12), 137--147. https://doi.org/10.23919/JCC.fa.2022-0379.202512.
  • Zhevnenko, D., Makarov, I., Kovalenko, A., Meshchaninov, F., Kozhukhov, A., Travnikov, V., Ippolitov, M., Yashunin, K., & Katser, I. (2026). Benchmarking IoT time-series anomaly detection with event-level augmentations [Preprint]. arXiv. https://arxiv.org/abs/2602.15457.
Index Terms
Computer Science
Information Sciences
No index terms available.
Keywords

Critical infrastructure cybersecurity machine learning robustness adversarial ML explainable AI concept drift intrusion detection graph neural networks certified robustness NIST CSF 2.0

Powered by PhDFocusTM