REVIEW article
Front. Big Data
Sec. Cybersecurity and Privacy
AI-Driven Cybersecurity for Industrial Internet of Things: Architectures, Challenges, Datasets, and Future Research Directions
Vellore Institute of Technology Deemed to be University, Vellore, India
Select one of your emails
You have multiple emails registered with Frontiers:
Notify me on publication
Please enter your email address:
If you already have an account, please login
You don't have a Frontiers account ? You can register here
Abstract
While the Industrial Internet of Things (IIoT) has a wide range of applications in the modern era, including smart manufacturing, healthcare, transportation, energy, and critical infrastructure, the multitude of devices and distributed communication, alongside the convergence of cyber and physical systems, makes these environments vulnerable to more advanced cyber-attacks. Traditional signature or pattern-based security solutions continue to be ineffective against new, sneaky, and zero-day attack strategies, fueling the interest in AI-powered cybersecurity. This review aims to analyze the latest developments systematically in intelligent threat detection and defense in IIoT environments. The review critically analyzes the cybersecurity research published over the past few years (2020-2026) on cyber threats across the various layers of the IIoT architecture, publicly available cybersecurity datasets, evaluation practices, and AI-based intrusion detection methods, such as machine learning, deep learning, hybrid architectures, transformers, graph neural networks, federated learning, reinforcement learning, and explainable AI. High benchmark performance alone is not sufficient to claim cybersecurity effectiveness, as the synthesis shows persistent limitations in cross-domain generalization, computational overhead, explainability, adversarial robustness, edge deployment, and operational validation. Emerging research priorities included in this review are lightweight edge intelligence, continual and adaptive learning, explainable federated intelligence, digital-twin-enabled security, foundation-model-driven cyber intelligence, autonomous cyber defense, and trustworthy AI. This review provides a pathway toward resilient, adaptive, and operationally deployable cybersecurity solutions for next-generation IIoT and highlights the PRISMA-based identification process.
Summary
Keywords
cybersecurity, deep learning, Edge intelligence, Explainable artificial intelligence, Federated learning, Graph neural networks, Industrial Internet of Things (IIoT), Intrusion detection systems
Received
15 July 2026
Accepted
13 August 2026
Copyright
© 2026 Singhal and Kumar. This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) or licensor are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.
*Correspondence: Kakelli Anil Kumar
Disclaimer
All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article or claim that may be made by its manufacturer is not guaranteed or endorsed by the publisher.