The article discusses the transformative impact of Generative AI (GenAI) to the field of vulnerability assessment (VA) and risk management (RM) right from the beginning of their life cycle to the end in cybersecurity (CS). Through a systematic review of over 100 publications (2021-2025), we develop a comprehensive taxonomy classifying GenAI's dual offensive and defensive applications in VA/RM. The survey spells out the dominant techniques of GenAI and also points towards challenging aspects, which include security, explainability, and trustworthiness. The resultant findings reinforce the belief that GenAI could help resolve many traditional VA/RM challenges, thus providing fertile ground for research and practice in this area.

Mirtaheri, S.L., Movahed, N., Shahbazian, R., Pascucci, V., Pugliese, A. (2026). Cybersecurity in the age of generative AI: A systematic taxonomy of AI-powered vulnerability assessment and risk management. FUTURE GENERATION COMPUTER SYSTEMS, 175 [10.1016/j.future.2025.108107].

Cybersecurity in the age of generative AI: A systematic taxonomy of AI-powered vulnerability assessment and risk management

Shahbazian R.;
2026-01-01

Abstract

The article discusses the transformative impact of Generative AI (GenAI) to the field of vulnerability assessment (VA) and risk management (RM) right from the beginning of their life cycle to the end in cybersecurity (CS). Through a systematic review of over 100 publications (2021-2025), we develop a comprehensive taxonomy classifying GenAI's dual offensive and defensive applications in VA/RM. The survey spells out the dominant techniques of GenAI and also points towards challenging aspects, which include security, explainability, and trustworthiness. The resultant findings reinforce the belief that GenAI could help resolve many traditional VA/RM challenges, thus providing fertile ground for research and practice in this area.
2026
Mirtaheri, S.L., Movahed, N., Shahbazian, R., Pascucci, V., Pugliese, A. (2026). Cybersecurity in the age of generative AI: A systematic taxonomy of AI-powered vulnerability assessment and risk management. FUTURE GENERATION COMPUTER SYSTEMS, 175 [10.1016/j.future.2025.108107].
File in questo prodotto:
File Dimensione Formato  
cyber_compressed.pdf

accesso aperto

Tipologia: Versione Editoriale
Dimensione 9.56 MB
Formato Adobe PDF
9.56 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10447/696228
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact