Defending the Digital Frontline: Enlisting AI to Neutralize Cyberattacks Before They Strike
Backed by the US Navy, TAMUG researcher Dr. Irfan Khan’s innovative cybersecurity system adapts in milliseconds to protect critical infrastructure and consumer devices.

Credit: Adobe Stock
The growing presence of artificial intelligence (AI) is a change that presents as many new challenges as solutions. Although AI seems friendly enough when it is summarizing articles or rewriting emails, not every AI model is trained for altruistic purposes—nor are the malicious actors that wield AI to accelerate digital attacks and hacking attempts. In this time of unprecedented and constantly evolving cybersecurity threats, Dr. Irfan Khan, Assistant Professor in the Department of Marine Engineering Technology at Texas A&M University at Galveston, offers an innovative solution: leveraging AI to stop cyberattacks before they can even happen.
“Since systems are more digitized and interconnected, our vulnerability to attacks has also grown exponentially,” said Dr. Khan. “That’s why cybersecurity is so important for our national security, our decision making, and our operations.”

Photo credit: Texas A&M University at Galveston
Examples of these attacks have proven to be as impactful as they are numerous. In June 2025, a cyberattack targeting a large food-supply distributor, led to significant grocery shortages and over $400 million in damages. In the same month, hackers accessed an Illinois Department of Transportation (DOT) account and downloaded nearly 300,000 crash reports, revealing personal and licensing data. The rise of AI-based cyberattacks is further empowering malicious actors to automate and scale their efforts while generating highly targeted malware with unprecedented tenacity.
The stakes are exponentially higher for governments due to critical energy, transportation, and financial infrastructures all relying on digital systems. Even modern maritime vessels depend heavily on interconnected automated systems for GPS navigation, cargo tracking, and propulsion. Cyber breaches at sea can effectively blind a vessel, manipulate its coordinates, or lock its engines. A widespread attack of this kind would potentially disrupt global supply chains or cause environmental disasters.
“Current human-based monitoring methods are not enough to predict cyberattacks that are unknown and will become threats in the future,” Dr. Khan noted.
To address this issue, Dr. Khan’s research has pioneered a new way to utilize AI to detect and neutralize cyberattacks before they can cause damage, even if they’re unknown. An Intelligent and Self-Sustaining Network Intrusion Detection System, or AIS-NIDS is a program that acts as an advanced behavioral analyst between devices and the internet, filtering safe network traffic from suspicious activity.
Traditional security systems typically look at “flow-level” data, which is like reading the outside of an envelope—checking where a message came from and where it is going. AIS-NIDS, digs deeper. It opens the “envelope” to look at the intricate details of the payload to catch hidden threats that traditional systems overlook. This is referred to as “packet-level” analysis, which the program conducts to examine the intricate details of data payloads where complex cyberattacks hide.
AIS-NIDS achieves this level of analysis using a dual-functionality approach powered by AI. First, a dedicated closed-set classifier identifies known threats. Second, it uses a flexible open-set classifier specializing in spotting never-before-seen “zero-day” attacks. When AIS-NIDS encounters an unfamiliar or suspicious pattern of network traffic, it quickly categorizes the threat and rapidly retrains itself to block the intrusion before it can compromise the host device. Crucially, its incremental learning and validation modules enable the system to instantly learn these new threats, update, and double-check itself autonomously, all without requiring system downtime or human intervention.
“We need to use this AI-based cybersecurity model, trained on one set of information,” said Dr. Khan. “And anything that deviates from those trained classes, it can detect those unknown attack classes and help secure our digital systems.”
Historically, threat detection has relied heavily on manual analysis, meaning that cybersecurity teams can often block a threat only after a system has already been breached and the malware’s signature has been identified. Conversely, AI can easily identify microscopic patterns and behavioral deviations that human eyes miss. Rather than waiting days for human engineers to write a patch, AIS-NIDS adapts autonomously in a matter of milliseconds—moving cybersecurity from a reactive posture to a proactive, predictive defense.
The AIS-NIDS program would be installed directly onto devices—ranging from smartphones and laptops to smart home Internet of Things (IOT) devices—as a lightweight, low-resource security layer. This highly adaptive capability has garnered support from the United States Army, which has awarded contracts to fund its development. Government agencies are highly motivated to implement these self-sustaining systems because military operations increasingly rely on secure cyber-physical systems, ranging from unmanned aerial vehicles to naval warships. In high-stakes military environments, a delayed response to a cyberattack can result in the loss of strategic assets or human lives.
If implemented, AIS-NIDS could benefit consumers and governments alike. Because it adapts locally and dynamically, it safeguards personal data and critical systems without requiring constant, data-heavy software updates. Governments would gain an unyielding shield against state-sponsored cyber warfare. By insulating defense networks and critical infrastructure with self-recovering AI defenses, the threat of an adversary disabling a power grid or intercepting military communications is profoundly mitigated.
“AIS-NIDS has a huge positive impact on both civilian and government infrastructure,” Dr. Khan explained. “So that’s why we should use this proposed model.”
As digital threats evolve into highly intelligent, automated adversaries, the importance of adaptive cybersecurity cannot be overstated. Through frameworks like AIS-NIDS, Dr. Irfan Khan’s pioneering research on AI-based cybersecurity acts as a force for good ensuring that our digital ecosystems remain secure, resilient, and prepared for the threats of tomorrow.