CERESResearch Repository

Natural language processing (NLP)-based frameworks for cyber threat intelligence and early prediction of cyberattacks in industry 4.0: a systematic literature review

Loading...
Thumbnail Image

Date published

Free to read from

2026-02-05

Supervisor/s

Industry supervisor/s

Journal Title

Journal ISSN

Volume Title

Publisher

Department

Course name

ISSN

2076-3417

Format

Citation

Albarrak M, Salonitis K, Jagtap S. (2026) Natural language processing (NLP)-based frameworks for cyber threat intelligence and early prediction of cyberattacks in industry 4.0: a systematic literature review. Applied Sciences, Volume 16, Issue 2, January 2026, Article number 619

Abstract

This study provides a systematic overview of Natural Language Processing (NLP)-based frameworks for Cyber Threat Intelligence (CTI) and the early prediction of cyberattacks in Industry 4.0. As digital transformation accelerates through the integration of IoT, SCADA, and cyber-physical systems, manufacturing environments face an expanding and complex cyber threat landscape. Following the PRISMA 2020 systematic review protocol, 80 peer-reviewed studies published between 2015 and 2025 were analyzed across IEEE Xplore, Scopus, and Web of Science to identify methods that employ NLP for CTI extraction, reasoning, and predictive modelling. The review finds that transformer-based architectures, knowledge graph reasoning, and social media mining are increasingly used to convert unstructured data into actionable intelligence, thereby enabling earlier detection and forecasting of cyber threats. Large Language Models (LLMs) demonstrate strong potential for anticipating attack sequences, while domain-specific models enhance industrial relevance. Persistent challenges include data scarcity, domain adaptation, explainability, and real-time scalability in operational-technology environments. The review concludes that NLP is reshaping Industry 4.0 cybersecurity from reactive defense toward predictive, adaptive, and intelligence-driven protection, and it highlights the need for interpretable, domain-specific, and resource-efficient frameworks to secure Industry 4.0 ecosystems.

Description

This article belongs to the Special Issue Advances in Cyber Security

Software description

Software language

Git repository

Keywords

4605 Data Management and Data Science, 46 Information and Computing Sciences, 4602 Artificial Intelligence, Networking and Information Technology R&D (NITRD), Machine Learning and Artificial Intelligence, natural language processing, cyber threat intelligence, manufacturing cybersecurity, Industry 4.0, social media intelligence, MITRE ATT&CK, proactive security

DOI

Rights

Attribution 4.0 International

Funder/s

Grant number

Relationships

Relationships

Resources