Open AccessOpen Access||Review Article

AI Approaches for Industrial Control System Cybersecurity: A Comprehensive Review of Methodological Contexts

Olujoke Mubo Oni1, John Edet Efiong1, Abiodun Akinwale1, Olawumi Adekemi Amoo2, Ayoola Afolabi3, Emmanuel Ajayi Olajubu1

1 Department of Computer Science and Cybersecurity, Faculty of Computing Science, Obafemi Awolowo University, Ile – Ife, 220001, Osun State, Nigeria

2 Department of Software Engineering, Faculty of Computing Science, Obafemi Awolowo University, Ile – Ife, 220001, Osun State, Nigeria

3 Trustfx Framework, 25 Morningside Close, Derby DE24 9JQ, United Kingdom

Download PDF</>HTML Version

Abstract

The cyber infrastructure of Industrial Control Systems (ICSs) that monitor power grids, water treatment facilities, pipelines, and manufacturing lines has become a very complex cyber-physical systems, which now face a growing range of cyber threats, such as Stuxnet, Industroyer, TRITON, and Colonial Pipeline incident. In the era of new and sophisticated attacks, such as zero-day exploits, multi-stage intrusions and adversaries taking advantage of the unique ‘availability first' constraints of operational technology (OT), traditional signatures and rule-based defenses are proving less effective. This review is systematic, analyzing the use of artificial intelligence (AI) methodologies in ICS cybersecurity from the year 2018 to 2024. According to the guidelines of the PRISMA 2020, from the five scholarly databases, 1578 records were retrieved and 147 studies were included in the qualitative synthesis, and 102 studies were included in the quantitative comparison. The provided literature is categorized in a methodological taxonomy from classical machine learning to deep learning; from graph neural networks (GNNs) to reinforcement learning (RL); from autonomous response to intrusion detection, attack-graph analysis, malware analysis and vulnerability prioritization. Overall, the synthesis suggests that graph-based and hybrid methods yield the best detection accuracy (reported from 92% to 99.5% with less than 3% false-positive rates), whereas classical methods still seem to be the most suitable for resource-constrained applications. There are ongoing deficiencies in standardized benchmarking, adversarial robustness, safety–security co-engineering, and real-world validation. A research roadmap is advocated for guiding future research, which focuses on safe RL, federated learning, explainable GNNs, and digital-twin-based security assessment.

Keywords

Industrial control systemsCybersecurityMachine learningDeep learningGraph neural networksReinforcement learningIntrusions detectionRisk assessmentCritical infrastructure

Graphical Abstract

AI Approaches for Industrial Control System Cybersecurity: A Comprehensive Review of Methodological Contexts — graphical abstract

Novelty Statement

This study introduces a methodology-oriented taxonomy of AI for Industrial Control System (ICS) cybersecurity, integrating classical ML, deep learning, GNNs, and reinforcement learning for topology-aware detection, autonomous response, cross-technique comparison, and decision-oriented synthesis across diverse industrial control scenarios.