Artificial Intelligence (AI) has quickly proven its relevance in the current state of the cybersecurity environment,
primarily because of its ability to help organizations identify possible threats more quickly and efficiently. By constantly
analyzing large amounts of data related to the security environment, AI-powered detection systems can detect unusual
patterns of behavior that could potentially go unnoticed. This has greatly improved the monitoring process and the early
identification of threats. However, the increasing dependence on automated detection systems also poses a possible threat, as
organizations become more reliant on these systems and may feel more secure than they actually are. This paper will discuss
the risks posed by these dependencies through the analysis of the current literature available in the academic community, as
well as through a great deal of experience in the cybersecurity environment. It will cover topics such as automation bias,
adversarial attacks, and the probabilistic nature of algorithmic decision-making, all of which pose possible risks to the current
state of the security environment. To counter these risks, this paper will propose a Controlled Trust Scheme that aims to
strike a balance between the efficiency of machine-based systems and human oversight. The findings show that the
effectiveness of the current cybersecurity environment not only depends on technological development but also on proper
governance to ensure that the confidence of the organization is in line with its actual preparedness.
[1] S. J. Russell and P. Norvig, Artificial Intelligence: A Modern Approach, 3rd ed. Upper Saddle River, NJ, USA:
Prentice Hall, 2010.
[2] I. Goodfellow, Y. Bengio and A. Courville, Deep Learning. Cambridge, MA, USA: MIT Press, 2016.
[3] R. Sommer and V. Paxson, “Outside the closed world: On using machine learning for network intrusion detection,” in
Proc. IEEE Symposium on Security and Privacy, 2010.
[4] Verizon, “2023 Data Breach Investigations Report (DBIR),” Verizon Enterprise, 2023.
[5] E. B. Karbab, M. Debbabi, A. Derhab and D. Mouheb, “MalDozer: Automatic framework for Android malware
detection using deep learning,” Digital Investigation, vol. 24, pp. S48–S59, 2018.
[6] N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive dataset for network intrusion detection systems,” in Proc.
Military Communications and Information Systems Conference (MilCIS), 2015.
[7] M. A. Ferrag, L. Maglaras, H. Janicke, J. Jiang and T. Shu, “Authentication protocols for Internet of Things: A
comprehensive survey,” Security and Communication Networks, 2017.
[8] A. Javaid, Q. Niyaz, W. Sun and M. Alam, “A deep learning approach for network intrusion detection system,” in
Proc. EAI International Conference on Bio-inspired Information and Communications Technologies (EAI
ICST), 2016.
[9] S. Axelsson, “Intrusion detection systems: A survey and taxonomy,” Technical Report, Chalmers University of
Technology, 2000.
[10] G. Creech and J. Hu, “A semantic approach to host-based intrusion detection systems using contiguous and
discontiguous system call patterns,” IEEE Transactions on Computers, 2014.
[11] D. E. Denning, “An intrusion-detection model,” IEEE Transactions on Software Engineering, vol. SE-13, no. 2,
pp. 222–232, 1987.
[12] K. Scarfone and P. Mell, “Guide to intrusion detection and prevention systems (IDPS),” NIST Special Publication
800-94, 2007.
[13] B. Biggio and F. Roli, “Wild patterns: Ten years after the rise of adversarial machine learning,” Pattern
Recognition, vol. 84, pp. 317–331, 2018.
[14] N. Papernotet al., “The limitations of deep learning in adversarial settings,” in Proc. IEEE European Symposium
on Security and Privacy, 2016.
[15] A. Kurakin, I. Goodfellow and S. Bengio, “Adversarial examples in the physical world,” in Proc. International
Conference on Learning Representations (ICLR) Workshop, 2017.
[16] M. Skitka, K. Mosier and M. Burdick, “Does automation bias decision-making?” International Journal of
Human-Computer Studies, vol. 51, no. 5, pp. 991–1006, 1999.
[17] B. Lyell and D. Coiera, “Automation bias and verification complexity: A systematic review,” Journal of the
American Medical Informatics Association, 2017.
[18] ENISA, “ENISA Threat Landscape 2023,” European Union Agency for Cybersecurity, 2023.
[19] U.S. Government Accountability Office, “Data protection: Actions taken by Equifax and federal agencies,” GAO
Report, 2018.
[20] P. Cichonski, T. Millar, T. Grance and K. Scarfone, “Computer Security Incident Handling Guide,” NIST Special
Publication 800-61 Rev. 2, 2012.