The Effectiveness of Machine Learning Techniques in Anomaly Detection for Cyberattack Prevention: Systematic Literature Review 2020-2025

Authors

  • Arie Budiansyah Universitas Syiah Kuala, Indonesia
  • Zulfan Universitas Syiah Kuala, Indonesia
  • Nizamuddin Universitas Syiah Kuala, Indonesia
  • Rudi Arif Candra Politeknik Aceh Selatan, Indonesia
  • Dirja Nur Ilham Politeknik Aceh Selatan, Indonesia
  • Nazaruddin Universitas Syiah Kuala, Indonesia

DOI:

https://doi.org/10.47709/brilliance.v5i1.6124

Keywords:

Machine Learning, Anomaly Detection, Cybersecurity, Cyberattacks, Systematic Literature Review

Abstract

As digital technology evolves, cyberattacks are becoming more diverse and difficult to detect. Conventional detection methods are often incapable of recognizing new and sophisticated attack patterns. Therefore, machine learning techniques are starting to be widely used because of their ability to study data patterns and detect unusual or anomalous activities. This study aims to systematically examine the effectiveness of various machine learning techniques in detecting anomalies as an effort to prevent cyberattacks. The research was conducted using the Systematic Literature Review (SLR) method on 20 scientific articles from reputable journals published between 2020 and 2025. The articles were selected through a search, selection, and analysis process following PRISMA guidelines. The results of the study show that algorithms such as Random Forest and Decision Tree consistently provide accurate detection results, especially in network systems and the Internet of Things (IoT). Meanwhile, deep learning techniques such as CNN and LSTM show high performance in handling large and complex data. However, challenges are still found in terms of data imbalances, high computing requirements, and lack of model interpretability. The conclusions of this study show that machine learning techniques are very promising for anomaly detection in cybersecurity, but an adaptive and easy-to-explain approach is needed. Researchers are further advised to develop models that are more efficient, transparent, and able to adapt to evolving cyber threats.

References

Abdelkhalek, A., & Mashaly, M. (2023). Addressing the class imbalance problem in network intrusion detection systems using data resampling and deep learning. In Journal of Supercomputing (Vol. 79, Issue 10). Springer US. https://doi.org/10.1007/s11227-023-05073-x

Aljawarneh, S. A., & Vangipuram, R. (2020). GARUDA: Gaussian dissimilarity measure for feature representation and anomaly detection in Internet of things. The Journal of Supercomputing, 76(6), 4376–4413. https://doi.org/10.1007/s11227-018-2397-3

Aljohani, A. (2023). Predictive Analytics and Machine Learning for Real-Time Supply Chain Risk Mitigation and Agility. Sustainability (Switzerland), 15(20). https://doi.org/10.3390/su152015088

Alzahrani, R. J., & Alzahrani, A. (2021). Security analysis of ddos attacks using machine learning algorithms in networks traffic. Electronics (Switzerland), 10(23). https://doi.org/10.3390/electronics10232919

Ashfaq, T., Khalid, R., Yahaya, A. S., Aslam, S., Azar, A. T., Alsafari, S., & Hameed, I. A. (2022). A Machine Learning and Blockchain Based Efficient Fraud Detection. 1–20.

Avci, O., Abdeljaber, O., Kiranyaz, S., Hussein, M., Gabbouj, M., & Inman, D. J. (2021). A review of vibration-based damage detection in civil structures: From traditional methods to Machine Learning and Deep Learning applications. Mechanical Systems and Signal Processing, 147, 107077. https://doi.org/10.1016/j.ymssp.2020.107077

Cheong Lien Sung, D., M.R., G. R., & P Mathur, A. (2022). Design-knowledge in learning plant dynamics for detecting process anomalies in water treatment plants. Computers & Security, 113, 102532. https://doi.org/https://doi.org/10.1016/j.cose.2021.102532

Dasgupta, D., Akhtar, Z., & Sen, S. (2022). Machine learning in cybersecurity: a comprehensive survey. Journal of Defense Modeling and Simulation, 19(1), 57–106. https://doi.org/10.1177/1548512920951275

Diro, A., Chilamkurti, N., Nguyen, V. D., & Heyne, W. (2021). A comprehensive study of anomaly detection schemes in iot networks using machine learning algorithms. Sensors, 21(24), 1–13. https://doi.org/10.3390/s21248320

Dutta, V., Chora?, M., Pawlicki, M., & Kozik, R. (2020). A deep learning ensemble for network anomaly and cyber-attack detection. Sensors (Switzerland), 20(16), 1–20. https://doi.org/10.3390/s20164583

ElSayed, M. S., Le-Khac, N. A., Albahar, M. A., & Jurcut, A. (2021). A novel hybrid model for intrusion detection systems in SDNs based on CNN and a new regularization technique. Journal of Network and Computer Applications, 191(July), 103160. https://doi.org/10.1016/j.jnca.2021.103160

Fiorelli, R., Peralías, E., Méndez-Romero, R., Rajabali, M., Kumar, A., Zahedinejad, M., Åkerman, J., Moradi, F., Serrano-Gotarredona, T., & Linares-Barranco, B. (2023). CMOS Front End for Interfacing Spin-Hall Nano-Oscillators for Neuromorphic Computing in the GHz Range. Electronics (Switzerland), 12(1), 1–18. https://doi.org/10.3390/electronics12010230

Fu, Y., Du, Y., Cao, Z., Li, Q., & Xiang, W. (2022). A Deep Learning Model for Network Intrusion Detection with Imbalanced Data. Electronics (Switzerland), 11(6), 1–13. https://doi.org/10.3390/electronics11060898

Himeur, Y., Alsalemi, A., Bensaali, F., & Amira, A. (2020). A Novel Approach for Detecting Anomalous Energy Consumption Based on Micro-Moments and Deep Neural Networks. Cognitive Computation, 12(6), 1381–1401. https://doi.org/10.1007/s12559-020-09764-y

Hindy, H., Atkinson, R., Tachtatzis, C., Colin, J. N., Bayne, E., & Bellekens, X. (2020). Utilising deep learning techniques for effective zero-day attack detection. Electronics (Switzerland), 9(10), 1–16. https://doi.org/10.3390/electronics9101684

Kumar, P., Gupta, G. P., & Tripathi, R. (2021). An ensemble learning and fog-cloud architecture-driven cyber-attack detection framework for IoMT networks. Computer Communications, 166, 110–124. https://doi.org/https://doi.org/10.1016/j.comcom.2020.12.003

Li, S., Luo, T., Wang, L., Xing, L., & Ren, T. (2022). Tourism route optimization based on improved knowledge ant colony algorithm. Complex & Intelligent Systems, 8(5), 3973–3988. https://doi.org/10.1007/s40747-021-00635-z

Li, Z., Zhu, Y., & Van Leeuwen, M. (2023). A Survey on Explainable Anomaly Detection. ACM Transactions on Knowledge Discovery from Data, 18(1). https://doi.org/10.1145/3609333

Liu, H., Lang, B., Liu, M., & Yan, H. (2018). CNN and RNN based payload classification methods for attack detection. Knowledge-Based Systems, 163. https://doi.org/10.1016/j.knosys.2018.08.036

Mohammadpour, L., Ling, T. C., Liew, C. S., & Aryanfar, A. (2022). A Survey of CNN-Based Network Intrusion Detection. Applied Sciences (Switzerland), 12(16). https://doi.org/10.3390/app12168162

Mokhtari, S., Abbaspour, A., Yen, K. K., & Sargolzaei, A. (2021). A machine learning approach for anomaly detection in industrial control systems based on measurement data. Electronics (Switzerland), 10(4), 1–13. https://doi.org/10.3390/electronics10040407

Morfino, V., & Rampone, S. (2020). Towards near-real-time intrusion detection for IoT devices using supervised learning and apache spark. Electronics (Switzerland), 9(3). https://doi.org/10.3390/electronics9030444

Ogundokun, R. O., Awotunde, J. B., Sadiku, P., Adeniyi, E. A., Abiodun, M., & Dauda, O. I. (2021). An Enhanced Intrusion Detection System using Particle Swarm Optimization Feature Extraction Technique. Procedia Computer Science, 193, 504–512. https://doi.org/10.1016/j.procs.2021.10.052

Oladimeji, D. (2021). an Intrusion Detection System for Internet of. June, 1–25.

Ozkan-Okay, M., Akin, E., Aslan, O., Kosunalp, S., Iliev, T., Stoyanov, I., & Beloev, I. (2024). A Comprehensive Survey: Evaluating the Efficiency of Artificial Intelligence and Machine Learning Techniques on Cyber Security Solutions. IEEE Access, 12(November 2023), 12229–12256. https://doi.org/10.1109/ACCESS.2024.3355547

Sanober, S., Alam, I., Pande, S., Arslan, F., Rane, K. P., Singh, B. K., Khamparia, A., & Shabaz, M. (2021). An Enhanced Secure Deep Learning Algorithm for Fraud Detection in Wireless Communication. Wireless Communications and Mobile Computing, 2021. https://doi.org/10.1155/2021/6079582

Sedik, A., Hammad, M., Abd El-Samie, F. E., Gupta, B. B., & Abd El-Latif, A. A. (2022). Efficient deep learning approach for augmented detection of Coronavirus disease. Neural Computing and Applications, 34(14), 11423–11440. https://doi.org/10.1007/s00521-020-05410-8

Ullah, I., & Mahmoud, Q. H. (2020). A two-level flow-based anomalous activity detection system for IoT networks. Electronics (Switzerland), 9(3). https://doi.org/10.3390/electronics9030530

Zu Li, H., & Boulanger, P. (2020). A survey of heart anomaly detection using ambulatory electrocardiogram (ECG). Sensors (Switzerland), 20(5). https://doi.org/10.3390/s20051461

Downloads

Published

2025-06-25

How to Cite

Budiansyah, A., Zulfan, Z., Nizamuddin, N., Candra, R. A., Ilham, D. N., & Nazaruddin, N. (2025). The Effectiveness of Machine Learning Techniques in Anomaly Detection for Cyberattack Prevention: Systematic Literature Review 2020-2025. Brilliance: Research of Artificial Intelligence, 5(1), 259–271. https://doi.org/10.47709/brilliance.v5i1.6124

Most read articles by the same author(s)

1 2 > >> 

Similar Articles

<< < 2 3 4 5 6 7 8 9 10 11 > >> 

You may also start an advanced similarity search for this article.