The current role of artificial intelligence in cyberattacks: a short narrative review
Abstract
Artificial Intelligence (AI) exerts a growing impact on the field of cybersecurity, which is characterized by increasing complexity resulting from system interconnectivity, the expansion of the Internet of Things (IoT), and the rise in digital threats. While AI has been widely used to improve defense systems, its application in cyberattacks represents an emerging challenge. Malicious actors are leveraging this technology to automate offensives, adapt to defenses in real time, and exploit vulnerabilities with unprecedented efficiency, raising questions about how it is changing the dynamics of current attacks. This review examines five recent empirical studies published between 2021 and 2025 that address the offensive use of AI in cybersecurity, identifying key techniques such as automated code generation, evasion of detection mechanisms, execution of targeted attacks, and the reduced technical skill requirements for attackers. The results reveal that AI is transforming cybersecurity strategies, enabling more sophisticated and adaptive attacks that pose significant challenges to current detection tools. These threats are particularly critical in sectors such as healthcare, critical infrastructure, and public administration, where disruptions can have systemic consequences. The results point to the need to advance the development of more adaptable and scalable defense systems, as well as to identify key research gaps in areas such as explainability, regulation, and real-time detection of AI-driven threats.
References
- E. Iturbe, O. Llorente-Vazquez, A. Rego, E. Rios, and N. Toledo, “Unleashing offensive artificial intelligence: Automated attack technique code generation,” Computers & Security, vol. 147, p. 104077, Dec. 2024. doi: 10.1016/j.cose.2024.104077. Available: [https://doi.org/10.1016/j.cose.2024.104077](https://doi.org/10.1016/j.cose.2024.104077)
- C. Colther and J. P. Doussoulin, “Artificial intelligence: Driving force in the evolution of human knowledge,” Journal of Innovation and Knowledge, vol. 9, no. 4, p. 100625, 2024. doi: 10.1016/j.jik.2024.100625. Available: [https://doi.org/10.1016/j.jik.2024.100625](https://doi.org/10.1016/j.jik.2024.100625)
- A. A. Siam, M. Alazab, A. Awajan, and N. Faruqui, “A comprehensive review of AI’s current impact and future prospects in cybersecurity,” IEEE Access, vol. 13, no. December 2024, pp. 14029–14050, 2025. doi: 10.1109/ACCESS.2025.3528114.
- B. Guembe, A. Azeta, S. Misra, V. C. Osamor, L. Fernandez-Sanz, and V. Pospelova, “The emerging threat of AI-driven cyber attacks: A review,” Applied Artificial Intelligence, vol. 36, no. 1, 2022. doi: 10.1080/08839514.2022.2037254. Available: [https://doi.org/10.1080/08839514.2022.2037254](https://doi.org/10.1080/08839514.2022.2037254)
- M. Rabzelj, L. S. Južnič, M. Volk, A. Kos, M. Kren, and U. Sedlar, “Designing and evaluating a flexible and scalable HTTP honeypot platform: Architecture, implementation, and applications,” Electronics, vol. 12, no. 16, p. 3480, Aug. 2023. doi: 10.3390/electronics12163480. Available: [https://doi.org/10.3390/electronics12163480](https://doi.org/10.3390/electronics12163480)
- I. H. Sarker, Y. B. Abushark, F. Alsolami, and A. I. Khan, “IntruDTree: A machine learning based cyber security intrusion detection model,” Symmetry, vol. 12, no. 5, pp. 1–15, 2020. doi: 10.3390/SYM12050754. Available: [https://doi.org/10.3390/sym12050754](https://doi.org/10.3390/sym12050754)
- M. J. Page, J. E. McKenzie, P. M. Bossuyt, I. Boutron, T. C. Hoffmann, C. D. Mulrow, L. Shamseer, J. M. Tetzlaff, E. A. Akl, S. E. Brennan, R. Chou, J. Glanville, J. M. Grimshaw, A. Hrobjartsson, M. M. Lalu, T. Li, E. W. Loder, E. Mayo-Wilson, S. McDonald, L. A. McGuinness, L. A. Stewart, J. Thomas, A. C. Tricco, V. A. Welch, P. Whiting, and D. Moher, “The PRISMA 2020 statement: An updated guideline for reporting systematic reviews,” The BMJ, vol. 372, 2021. doi: 10.1136/bmj.n71. Available: [https://doi.org/10.1136/bmj.n71](https://doi.org/10.1136/bmj.n71)
- R. Raman, P. Calyam, and K. Achuthan, “ChatGPT or Bard: Who is a better Certified Ethical Hacker?” Computers & Security, vol. 140, p. 103804, May 2024. doi: 10.1016/j.cose.2024.103804. Available: [https://doi.org/10.1016/j.cose.2024.103804](https://doi.org/10.1016/j.cose.2024.103804)
- X. Larriva-Novo, C. Sánchez-Zas, V. A. Villagrá, A. Marín-Lopez, and J. Berrocal, “Leveraging explainable artificial intelligence in real-time cyberattack identification: Intrusion detection system approach,” Applied Sciences, vol. 13, no. 15, p. 8587, Jul. 2023. doi: 10.3390/app13158587. Available: [https://doi.org/10.3390/app13158587](https://doi.org/10.3390/app13158587)
- J. H. An, Z. Wang, and I. Joe, “A CNN-based automatic vulnerability detection,” EURASIP Journal on Wireless Communications and Networking, vol. 2023, no. 1, p. 41, May 2023. doi: 10.1186/s13638-023-02255-2. Available: [https://doi.org/10.1186/s13638-023-02255-2](https://doi.org/10.1186/s13638-023-02255-2)
License
This article is licensed under Creative Commons Attribution 4.0 International License (CC BY 4.0)