Cyber Resilience Against AI-Augmented Advanced Persistent Threats: An Adaptive Detection, Containment, and Recovery Framework for Critical Systems
-
DOI:
https://doi.org/10.67228/30713498/IJADSMC-V9I2P102Published 04-08-2026
Cyber Resilience, Advanced Persistent Threats, Artificial Intelligence, Critical Infrastructure, Adaptive Threat Detection, Threat Containment, Secure Recovery, Zero Trust Security Issue
Section
ArticlesHow to Cite
[1]S. K. Jadala, “Cyber Resilience Against AI-Augmented Advanced Persistent Threats: An Adaptive Detection, Containment, and Recovery Framework for Critical Systems”, IJADSMC, vol. 9, no. 2, pp. 15–61, Apr. 2026, doi: 10.67228/30713498/IJADSMC-V9I2P102.Abstract
The growing use of artificial intelligence in offensive cyber operations is changing the speed, precision, and adaptability of advanced persistent threats, creating serious security concerns for critical systems. AI-assisted reconnaissance, targeted social engineering, adaptive malware, automated lateral movement, and evasive command-and-control techniques can reduce the effectiveness of conventional security measures that depend heavily on static rules and predefined indicators. This study proposes an adaptive cyber resilience framework for detecting, containing, and recovering from AI-augmented advanced persistent threats in critical environments. The framework combines continuous asset and identity awareness, behavioral threat detection, dynamic risk assessment, risk-based containment, operational continuity, secure recovery, and post-incident learning. Zero Trust principles, threat intelligence, and human oversight are incorporated as supporting controls across the framework. The study also develops a threat model that maps AI-enhanced adversarial capabilities to major stages of the APT lifecycle and identifies security controls for limiting persistence, privilege escalation, lateral movement, command and control, and operational impact. Framework effectiveness is assessed through resilience-oriented measures, including detection latency, containment time, attack propagation, service availability, and recovery performance. The proposed approach shifts attention from preventing every intrusion to limiting attacker progress, preserving essential functions, and restoring trusted operations following compromise. The framework provides a structured basis for strengthening cyber resilience in critical infrastructure and other high-consequence systems exposed to increasingly adaptive threat actors.
References
[1] Alavizadeh, H., Jang-Jaccard, J., Enoch, S. Y., Al-Sahaf, H., Welch, I., Camtepe, S. A., & Kim, D. S. (2022). A survey on cyber situation-awareness systems: Framework, techniques, and insights. ACM Computing Surveys, 55(5), Article 107, 1–37. doi: 10.1145/3530809.
[2] Alshamrani, A., Myneni, S., Chowdhary, A., & Huang, D. (2019). A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities. IEEE Communications Surveys & Tutorials, 21(2), 1851–1877. doi: 10.1109/COMST.2019.2891891.
[3] Apruzzese, G., Laskov, P., Montes de Oca, E., Mallouli, W., Burdalo Rapa, L., Grammatopoulos, A. V., & Di Franco, F. (2023). The role of machine learning in cybersecurity. Digital Threats: Research and Practice, 4(1), Article 8, 1–38. doi: 10.1145/3545574.
[4] Bécue, A., Praça, I., & Gama, J. (2021). Artificial intelligence, cyber-threats and Industry 4.0: Challenges and opportunities. Artificial Intelligence Review, 54(5), 3849–3886. doi: 10.1007/s10462-020-09942-2.
[5] Björck, F., Henkel, M., Stirna, J., & Zdravkovic, J. (2015). Cyber resilience: Fundamentals for a definition. In A. Rocha, A. M. Correia, S. Costanzo, & L. P. Reis (Eds.), New contributions in information systems and technologies (Advances in Intelligent Systems and Computing, Vol. 353, pp. 311–316). Springer. doi: 10.1007/978-3-319-16486-1_31.
[6] Capuano, N., Fenza, G., Loia, V., & Stanzione, C. (2022). Explainable artificial intelligence in cybersecurity: A survey. IEEE Access, 10, 93575–93600. doi: 10.1109/ACCESS.2022.3204171.
[7] Dasgupta, D., Akhtar, Z., & Sen, S. (2022). Machine learning in cybersecurity: A comprehensive survey. The Journal of Defense Modeling and Simulation, 19(1), 57–106. doi: 10.1177/1548512920951275.
[8] Ding, D., Han, Q.-L., Xiang, Y., Ge, X., & Zhang, X.-M. (2018). A survey on security control and attack detection for industrial cyber-physical systems. Neurocomputing, 275, 1674–1683. doi: 10.1016/j.neucom.2017.10.009.
[9] Duo, W., Zhou, M. C., & Abusorrah, A. (2022). A survey of cyber attacks on cyber physical systems: Recent advances and challenges. IEEE/CAA Journal of Automatica Sinica, 9(5), 784–800. doi: 10.1109/JAS.2022.105548.
[10] Dupont, B., Shearing, C., Bernier, M., & Leukfeldt, R. (2023). The tensions of cyber-resilience: From sensemaking to practice. Computers & Security, 132, 103372. doi: 10.1016/j.cose.2023.103372.
[11] Ghafir, I., Hammoudeh, M., Prenosil, V., Han, L., Hegarty, R., Rabie, K., & Aparicio-Navarro, F. J. (2018). Detection of advanced persistent threat using machine-learning correlation analysis. Future Generation Computer Systems, 89, 349–359. doi: 10.1016/j.future.2018.06.055.
[12] Potla, R. B. (2024). Optimizing extended warehouse management for make-to-order plants: Slotting, wave picking, and yard orchestration at scale. Journal of Computer Science and Technology Studies, 6(3), 181-192.
[13] Leo, C., Dykyi, A., Cortegaca, D., Begimher, D., & Jha, P. (2026). ThreatForest: Multi-Agent Attack Tree Generation with Pluggable TTP Framework Mapping. arXiv preprint arXiv:2607.27528.
[14] Giraldo, J., Urbina, D., Cárdenas, Á., Valente, J., Faisal, M., Ruths, J., Tippenhauer, N. O., Sandberg, H., & Candell, R. (2018). A survey of physics-based attack detection in cyber-physical systems. ACM Computing Surveys, 51(4), Article 76, 1–36. doi: 10.1145/3203245.
[15] Guembe, B., Azeta, A., Misra, S., Osamor, V. C., Fernandez-Sanz, L., & Pospelova, V. (2022). The emerging threat of AI-driven cyber attacks: A review. Applied Artificial Intelligence, 36(1), Article 2037254. doi: 10.1080/08839514.2022.2037254.
[16] Hasan, M. M., Islam, M. U., & Uddin, M. J. (2023). Advanced persistent threat identification with boosting and explainable AI. SN Computer Science, 4, Article 271. doi: 10.1007/s42979-023-01744-x.
[17] Humayed, A., Lin, J., Li, F., & Luo, B. (2017). Cyber-physical systems security: A survey. IEEE Internet of Things Journal, 4(6), 1802–1831. doi: 10.1109/JIOT.2017.2703172.
[18] Husák, M., Komárková, J., Bou-Harb, E., & Čeleda, P. (2019). Survey of attack projection, prediction, and forecasting in cyber security. IEEE Communications Surveys & Tutorials, 21(1), 640–660. doi: 10.1109/COMST.2018.2871866.
[19] Kaloudi, N., & Li, J. (2020). The AI-based cyber threat landscape: A survey. ACM Computing Surveys, 53(1), Article 20, 1–34. doi: 10.1145/3372823.
[20] Kayan, H., Nunes, M., Rana, O., Burnap, P., & Perera, C. (2022). Cybersecurity of industrial cyber-physical systems: A review. ACM Computing Surveys, 54(11s), Article 229, 1–35. doi: 10.1145/3510410.
[21] Kim, S., Park, K. J., & Lu, C. (2022). A survey on network security for cyber-physical systems: From threats to resilient design. IEEE Communications Surveys & Tutorials, 24(3), 1534–1573. doi: 10.1109/COMST.2022.3187531.
[22] Linkov, I., Eisenberg, D. A., Plourde, K., Seager, T. P., Allen, J., & Kott, A. (2013). Resilience metrics for cyber systems. Environment Systems and Decisions, 33(4), 471–476. doi: 10.1007/s10669-013-9485-y.
[23] Potla, R. B. (2024). A SOX/ITAR-aligned global ERP template for multi-plant manufacturers: Governance patterns and controls. J Artif Intell Mach Learn & Data Sci, 2(2), 3222-3232.
[24] Mirsky, Y., Demontis, A., Kotak, J., Shankar, R., Gelei, D., Yang, L., Zhang, X., Pintor, M., Lee, W., Elovici, Y., & Biggio, B. (2023). The threat of offensive AI to organizations. Computers & Security, 124, 103006. doi: 10.1016/j.cose.2022.103006.
[25] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. doi: 10.6028/NIST.SP.800-207.
[26] Kunaparaju, C. (2025). AI-Driven Cyber Defense Systems: Strengthening National Security through Intelligent Threat Prediction and Response. Algora, 2(1), 1-30.
[27] Ross, R., Pillitteri, V., Graubart, R., Bodeau, D., & McQuaid, R. (2021). Developing cyber-resilient systems: A systems security engineering approach (NIST Special Publication 800-160, Vol. 2, Rev. 1). National Institute of Standards and Technology. doi: 10.6028/NIST.SP.800-160v2r1.
[28] Salim, D. T., Singh, M. M., & Keikhosrokiani, P. (2023). A systematic literature review for APT detection and effective cyber situational awareness (ECSA) conceptual model. Heliyon, 9(7), e17156. doi: 10.1016/j.heliyon.2023.e17156.
[29] Sepúlveda Estay, D. A., Sahay, R., Barfod, M. B., & Jensen, C. D. (2020). A systematic review of cyber-resilience assessment frameworks. Computers & Security, 97, 101996. doi: 10.1016/j.cose.2020.101996.
[30] Sun, N., Ding, M., Jiang, J., Xu, W., Mo, X., Tai, Y., & Zhang, J. (2023). Cyber threat intelligence mining for proactive cybersecurity defense: A survey and new perspectives. IEEE Communications Surveys & Tutorials, 25(3), 1748–1774. doi: 10.1109/COMST.2023.3273282.
[31] Kunaparaju, C. (2024). The Role of Artificial Intelligence in Safeguarding Critical National Infrastructure against Cyberattacks. Journal of Electrical Systems, 20, 5403-5419.
[32] Talib, M. A., Nasir, Q., Nassif, A. B., Mokhamed, T., Ahmed, N., & Mahfood, B. (2022). APT beaconing detection: A systematic review. Computers & Security, 122, 102875. doi: 10.1016/j.cose.2022.102875.
[33] Tatam, M., Shanmugam, B., Azam, S., & Kannoorpatti, K. (2021). A review of threat modelling approaches for APT-style attacks. Heliyon, 7(1), e05969. doi: 10.1016/j.heliyon.2021.e05969.
[34] Tounsi, W., & Rais, H. (2018). A survey on technical threat intelligence in the age of sophisticated cyber attacks. Computers & Security, 72, 212–233. doi: 10.1016/j.cose.2017.09.001.
[35] Potla, R. (2023). Designing a BTP-centric integration mesh for shop-floor IoT, MES and ERP in discrete manufacturing. Journal of Artificial Intelligence, Machine Learning and Data Science, 1(2), 1-8.
[36] Yu, K., Tan, L., Mumtaz, S., Al-Rubaye, S., Al-Dulaimi, A., Bashir, A. K., & Khan, F. A. (2021). Securing critical infrastructures: Deep-learning-based threat detection in IIoT. IEEE Communications Magazine, 59(10), 76–82. doi: 10.1109/MCOM.101.2001126.
Downloads
How to Cite
[1]S. K. Jadala, “Cyber Resilience Against AI-Augmented Advanced Persistent Threats: An Adaptive Detection, Containment, and Recovery Framework for Critical Systems”, IJADSMC, vol. 9, no. 2, pp. 15–61, Apr. 2026, doi: 10.67228/30713498/IJADSMC-V9I2P102.