From Generative AI to Agentic Cyber Defense: A Comprehensive Review of Multi-Agent Artificial Intelligence for Autonomous Cybersecurity
Main Article Content
Abstract
Artificial intelligence (AI) has become a key enabler of modern cybersecurity by enhancing threat detection, vulnerability assessment, malware analysis, and incident response. The evolution from machine learning (ML) and deep learning (DL) to Large Language Models (LLMs) and generative AI has significantly improved automated security analysis, natural language interaction, and cyber threat intelligence. However, current generative AI systems remain largely reactive, relying on human guidance and offering limited capabilities for autonomous planning, reasoning, memory management, and collaborative decision-making. Recent advances in Agentic Artificial Intelligence (Agentic AI) introduce autonomous intelligent agents that can perceive their environment, use external tools, coordinate with other agents, and execute complex multi-step tasks with minimal human intervention. These capabilities have created new opportunities for automating cybersecurity functions, including Security Operations Centres (SOCs), threat hunting, malware analysis, phishing detection, vulnerability management, digital forensics, and incident response. This paper reviews the evolution from generative AI to Agentic AI and examines the role of multi-agent architectures in autonomous cyber defence. It provides a thorough overview of current trends, a taxonomy of existing methods by agents' architecture, collaboration, reasoning, and application domains, and the main issues, challenges, research directions, and open questions for designing trustworthy, explainable, and robust autonomous cybersecurity systems.
Article Details
Section

This work is licensed under a Creative Commons Attribution 4.0 International License.