Natural language processing (NLP)-based frameworks for cyber threat intelligence and early prediction of cyberattacks in industry 4.0: a systematic literature review
| dc.contributor.author | Albarrak, Majed | |
| dc.contributor.author | Salonitis, Konstantinos | |
| dc.contributor.author | Jagtap, Sandeep | |
| dc.date.accessioned | 2026-02-05T12:21:25Z | |
| dc.date.available | 2026-02-05T12:21:25Z | |
| dc.date.freetoread | 2026-02-05 | |
| dc.date.issued | 2026-01-02 | |
| dc.date.pubOnline | 2026-01-06 | |
| dc.description | This article belongs to the Special Issue Advances in Cyber Security | |
| dc.description.abstract | This study provides a systematic overview of Natural Language Processing (NLP)-based frameworks for Cyber Threat Intelligence (CTI) and the early prediction of cyberattacks in Industry 4.0. As digital transformation accelerates through the integration of IoT, SCADA, and cyber-physical systems, manufacturing environments face an expanding and complex cyber threat landscape. Following the PRISMA 2020 systematic review protocol, 80 peer-reviewed studies published between 2015 and 2025 were analyzed across IEEE Xplore, Scopus, and Web of Science to identify methods that employ NLP for CTI extraction, reasoning, and predictive modelling. The review finds that transformer-based architectures, knowledge graph reasoning, and social media mining are increasingly used to convert unstructured data into actionable intelligence, thereby enabling earlier detection and forecasting of cyber threats. Large Language Models (LLMs) demonstrate strong potential for anticipating attack sequences, while domain-specific models enhance industrial relevance. Persistent challenges include data scarcity, domain adaptation, explainability, and real-time scalability in operational-technology environments. The review concludes that NLP is reshaping Industry 4.0 cybersecurity from reactive defense toward predictive, adaptive, and intelligence-driven protection, and it highlights the need for interpretable, domain-specific, and resource-efficient frameworks to secure Industry 4.0 ecosystems. | |
| dc.description.journalName | Applied Sciences | |
| dc.identifier.citation | Albarrak M, Salonitis K, Jagtap S. (2026) Natural language processing (NLP)-based frameworks for cyber threat intelligence and early prediction of cyberattacks in industry 4.0: a systematic literature review. Applied Sciences, Volume 16, Issue 2, January 2026, Article number 619 | en_UK |
| dc.identifier.eissn | 2076-3417 | |
| dc.identifier.elementsID | 867729 | |
| dc.identifier.issn | 2076-3417 | |
| dc.identifier.issueNo | 2 | |
| dc.identifier.paperNo | 619 | |
| dc.identifier.uri | https://doi.org/10.3390/app16020619 | |
| dc.identifier.uri | https://dspace.lib.cranfield.ac.uk/handle/1826/24845 | |
| dc.identifier.volumeNo | 16 | |
| dc.language | English | |
| dc.language.iso | en | |
| dc.publisher | MDPI | |
| dc.publisher.uri | https://www.mdpi.com/2076-3417/16/2/619 | |
| dc.rights | Attribution 4.0 International | en |
| dc.rights.uri | http://creativecommons.org/licenses/by/4.0/ | |
| dc.subject | 4605 Data Management and Data Science | en_UK |
| dc.subject | 46 Information and Computing Sciences | en_UK |
| dc.subject | 4602 Artificial Intelligence | en_UK |
| dc.subject | Networking and Information Technology R&D (NITRD) | en_UK |
| dc.subject | Machine Learning and Artificial Intelligence | en_UK |
| dc.subject | natural language processing | en_UK |
| dc.subject | cyber threat intelligence | en_UK |
| dc.subject | manufacturing cybersecurity | en_UK |
| dc.subject | Industry 4.0 | en_UK |
| dc.subject | social media intelligence | en_UK |
| dc.subject | MITRE ATT&CK | en_UK |
| dc.subject | proactive security | en_UK |
| dc.title | Natural language processing (NLP)-based frameworks for cyber threat intelligence and early prediction of cyberattacks in industry 4.0: a systematic literature review | en_UK |
| dc.type | Article | |
| dcterms.dateAccepted | 2026-01-01 |
