Autonomous Cyber Defense Learning Using Reinforcement and Threat Intelligence

Authors

  • Abimbola B. Owolabi National Open University of Nigeria. Author
  • Francis B. Osang National Open University of Nigeria. Author

Keywords:

Autonomous Cyber Defense, Reinforcement Learning, Cyber Threat Intelligence, Deep Q-Network, Artificial Intelligence, Intrusion Detection Systems.

Abstract

The increasing sophistication, frequency, and scale of cyberattacks have created significant challenges for conventional cybersecurity systems. Traditional security solutions such as firewalls, signature-based intrusion detection systems, and antivirus software are largely reactive and depend on predefined rules and known attack patterns. Consequently, these systems often struggle to detect and respond effectively to emerging threats such as Advanced Persistent Threats (APTs), zero-day attacks, ransomware, botnets, and insider attacks. Recent advancements in Artificial Intelligence (AI), particularly Reinforcement Learning (RL), have demonstrated the potential to create autonomous systems capable of learning and adapting to dynamic environments. Simultaneously, Cyber Threat Intelligence (CTI) provides valuable contextual information regarding threat actors, attack techniques, vulnerabilities, and indicators of compromise. This study proposes an Autonomous Cyber Defense Framework that integrates Reinforcement Learning and Threat Intelligence to enhance threat detection, decision-making, and automated response capabilities. The framework employs a Deep Q-Network (DQN) agent that continuously learns optimal defense actions through interaction with network environments while utilizing threat intelligence feeds to improve situational awareness. Experimental evaluation was conducted using benchmark cybersecurity datasets, including CICIDS2017 for Intrusion Detection, UNSW-NB15 for attack classification, CTU-13 for botnet detection and Custom Threat Feeds for threat intelligence. The results indicate that the proposed framework achieved a precision rate of 98.4%, a recall rate of 98.2%, an F1-score of 98.3%, and a threat mitigation rate of 96.8%. False positive rate of 1.9, False negative rate of 1.5 and Response rate of 41%, significantly outperforming traditional machine learning and signature-based security approaches. The findings demonstrate that integrating reinforcement learning with threat intelligence can provide a highly adaptive and proactive cyber defense mechanism suitable for modern network environments.

Autonomous Cyber Defense Learning Using Reinforcement and Threat Intelligence

Downloads

Published

2026-08-21

How to Cite

Owolabi, A. B., & Osang, F. B. (2026). Autonomous Cyber Defense Learning Using Reinforcement and Threat Intelligence. Direct Research Journal of Engineering and Information Technology, 14(3), 10-25. https://journals.directresearchpublisher.org/index.php/drjeit/article/view/859