Adversarial Defense in Cybersecurity: A Systematic Review of GANs for Threat Detection and Mitigation
Organizations: Department of Computer Science and Technology, University of Science and Technology Beijing · Department of Computer Science, Blekinge Institute of Technology
Abstract
Machine learning-based cybersecurity systems are highly vulnerable to adversarial attacks, while Generative Adversarial Networks (GANs) act as both powerful attack enablers and promising defenses. This survey systematically reviews GAN-based adversarial defenses in cybersecurity (2021--August 31, 2025), consolidating recent progress, identifying gaps, and outlining future directions. Using a PRISMA-compliant systematic literature review protocol, we searched five major digital libraries. From 829 initial records, 185 peer-reviewed studies were retained and synthesized through quantitative trend analysis and thematic taxonomy development. We introduce a four-dimensional taxonomy spanning defensive function, GAN architecture, cybersecurity domain, and adversarial threat model. GANs improve detection accuracy, robustness, and data utility across network intrusion detection, malware analysis, and IoT security. Notable advances include WGAN-GP for stable training, CGANs for targeted synthesis, and hybrid GAN models for improved resilience. Yet, persistent challenges remain such as instability in training, lack of standardized benchmarks, high computational cost, and limited explainability. GAN-based defenses demonstrate strong potential but require advances in stable architectures, benchmarking, transparency, and deployment. We propose a roadmap emphasizing hybrid models, unified evaluation, real-world integration, and defenses against emerging threats such as LLM-driven cyberattacks. This survey establishes the foundation for scalable, trustworthy, and adaptive GAN-powered defenses.
Figures & tables
| Contributions | Scope | Primary focus and limitation | |||||
| Study | Systematic Protocol | Structured Taxonomy | Quantitative Synthesis | Quality / Reproducibility | Deployment Analysis | GAN Focus | |
| [ 67 ] | ✓ | ✗ | ✗ | ✗ | ✗ | Broad AML landscape; GANs peripheral. | |
| [ 68 ] | ✓ | ✗ | ✗ | ✗ | ✗ | Defender-oriented AML taxonomy; mainly image classification. | |
| [ 73 ] | ✓ | ✗ | ✗ | ✗ | ✗ | AML in text processing; modality-specific and not GAN-centered. | |
| [ 49 ] | ✓ | ✓ | ✗ | ✓ | ✗ | Systematic AML-defense taxonomy; GANs treated as one family. | |
| [ 74 ] | ✓ | ✗ | ✗ | AML for NIDS; no cross-domain GAN-defense synthesis. | |||
| Primary discovery source | 2021 | 2022 | 2023 | 2024 | 2025 | 2026 a | Total | % |
| IEEE Xplore | 1 | 0 | 4 | 4 | 6 | 5 | 20 | 6.9 |
| ACM Digital Library | 0 | 1 | 0 | 0 | 2 | 0 | 3 | 1.0 |
| ScienceDirect | 0 | 0 | 0 | 2 | 0 | 0 | 2 | 0.7 |
| MDPI | 1 | 3 | 6 | 8 | 5 | 3 | 26 | 9.0 |
| SpringerLink | 0 | 2 | 1 | 4 | 3 | 2 | 12 | 4.2 |
| Scopus | 19 | 32 | 40 | 49 | 50 | 13 | 203 | 70.2 |
| Dimension | Analytical question | Primary categories | Key References |
|---|---|---|---|
| D1: Defensive function | What does the GAN do? | F1 Data augmentation and class balancing; F2 adversarial hardening and robustness; F3 anomaly and threat detection; F4 privacy-aware synthesis and collaboration; F5 domain adaptation; F6 deception, testing, or recovery | [ 86 , 21 , 24 , 25 , 87 ] |
| D2: GAN architecture | How is it realized? | A1 Standard GAN; A2 convolutional GAN; A3 conditional GAN; A4 Wasserstein GAN; A5 reconstruction-oriented GAN; A6 temporal GAN; A7 graph GAN; A8 hybrid GAN | [ 14 , 81 , 15 , 16 , 82 ] |
| D3: Cybersecurity domain | Where is it applied? | C1 Network and enterprise security; C2 malware and endpoint security; C3 IoT, IIoT, and edge security; C4 cloud, SDN, NFV, and edge security; C5 ICS, CPS, and smart infrastructure; C6 wireless, mobile, and vehicular security; C7 web, email, financial, and social security; C8 identity, biometrics, and authentication; C9 cross-domain cybersecurity | [ 88 , 22 , 89 , 90 ] |
| D4: Threat or data condition | Which security risk or data limitation is addressed? | T1 Data scarcity and class imbalance; T2 evasion and adversarial manipulation; T3 poisoning and model integrity; T4 unknown threats and concept drift; T5 distribution shift and domain shift; T6 privacy leakage; T7 general or unspecified threat condition | [ 67 , 39 , 22 , 91 ] |
| D5: Evidence and deployment context | Under what conditions is it validated? | E1 Offline single-dataset proof of concept; E2 strengthened offline validation; E3 external, temporal, open-set, transfer, or adversarial validation; E4 deployment-oriented testbed, distributed/federated, or resource-aware validation; E5 sustained real-world operational deployment | [ 53 , 92 , 93 , 94 ] |
| Defensive function | C1 Network | C2 Malware | C3 IoT/IIoT | C4 Cloud/SDN | C5 ICS/CPS | C6 Wireless/mobile | C7 Web/financial | C8 Identity | C9 Cross-domain | Total |
|---|---|---|---|---|---|---|---|---|---|---|
| F1 Data augmentation and class balancing | 24 | 2 | 3 | 1 | 0 | 1 | 10 | 1 | 2 | 44 |
| F2 Adversarial hardening and robustness | 7 | 8 | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 21 |
| F3 Anomaly and threat detection | 95 | 12 | 32 | 7 | 15 | 7 | 20 | 4 | 8 | 200 |
| F4 Privacy-aware synthesis and collaboration | 8 | 0 | 4 | 0 | 0 | 0 | 1 | 0 | 1 | 14 |
| F5 Domain adaptation | 2 | 1 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 3 |
| F6 Deception, testing, or recovery | 1 | 0 | 1 | 0 | 2 | 1 | 0 | 0 | 2 | 7 |
| Dimension | Category with largest difference | Full corpus | Experimental subset | (pp) |
|---|---|---|---|---|
| D1 | Data augmentation and class balancing | 44/289 (15.22%) | 38/231 (16.45%) | 1.23 |
| D2 | Standard GAN | 193/289 (66.78%) | 149/231 (64.50%) | 2.28 |
| D3 | Web, email, financial, and social security | 31/289 (10.73%) | 23/231 (9.96%) | 0.77 |
| D4 | Data scarcity and class imbalance | 43/289 (14.88%) | 39/231 (16.88%) | 2.00 |
| D5 | E3: External, temporal, or adversarial validation | 108/289 (37.37%) | 83/231 (35.93%) | 1.44 |
| Indicator | % | Indicator | % | ||
|---|---|---|---|---|---|
| Dataset/data source identified | 231 | 100.0 | Comparator reported | 207 | 89.6 |
| GAN configuration | 230 | 99.6 | Explicit ablation | 31 | 13.4 |
| Downstream model/baseline information | 230 | 99.6 | Repeated runs | 16 | 6.9 |
| Evaluation metrics | 220 | 95.2 | Random seed explicitly reported | 2 | 0.9 |
| Preprocessing | 202 | 87.4 | Dispersion reported | 52 | 22.5 |
| Numerical result | 194 | 84.0 | Confidence interval | 9 | 3.9 |
| Function | Defensible synthesis | Principal evidence boundary | Minimum evaluation requirement |
|---|---|---|---|
| Augmentation (F1; ) | GAN-generated minority samples can improve class-sensitive performance within controlled pipelines, but no common effect magnitude is estimable. | Changes in classifiers, preprocessing, class ratios, or partitions frequently prevent attribution specifically to GAN augmentation. | Generate from training data only; retain real test data and the same detector; compare with no augmentation and conventional resampling. |
| Detection (F3; ) | GAN-based reconstruction or anomaly scoring can support detection under the evaluated benchmark conditions. | The primary threat condition was general or unspecified in 142/161 studies (88.2%), limiting inference about unseen, temporal, or open-set threats. | Specify the threat model; use appropriate entity-, family-, time-, or domain-separated evaluation; report class-sensitive errors and false-alarm burden. |
| Hardening (F2; ) | GAN-generated adversarial examples can improve resistance to evaluated attacks within stated attacker conditions. | Evidence against unseen, transferred, or adaptive attacks remains limited, and robustness may trade off against clean-data utility. | Match attacker knowledge and budget; report clean and attacked utility; test unseen/adaptive attacks and include a matched no-GAN ablation. |
| Barrier | Observed evidence pattern | Consequence | Required evidence |
|---|---|---|---|
| Generative-model validity | Training instability, incomplete mode coverage, memorization, and statistically plausible but semantically or functionally invalid samples [ 14 , 16 , 17 , 26 , 13 ] . | Synthetic volume or favorable runs may not improve valid threat coverage. | Repeated runs, sensitivity analysis, diversity and memorization checks, domain constraints, and untouched real-data evaluation. |
| Data and benchmark validity | Public benchmarks may contain duplication, outdated attacks, simulation artifacts, unrealistic class priors, or leakage-prone partitions [ 11 , 12 ] . | Within-dataset performance may overstate transferable defensive capability. | Versioned provenance, duplicate analysis, pre-generation partitioning, and entity-, family-, device-, or time-disjoint testing. |
| Evaluation and threat validity | Although 207/231 experiments reported a comparator, only 31/231 included an explicit ablation; robustness, zero-day, privacy, and adaptation claims also depend on attacker and target-data assumptions [ 10 , 345 , 28 , 22 ] . | The claim may exceed the experiment or the observed gain may not be attributable to the GAN. | Matched no-GAN ablations, function-specific alternatives, explicit threat models, structurally unseen conditions, and claim-appropriate outcomes. |
| Reproducibility and attribution | Only 16/231 experiments reported repeated runs, 2/231 explicitly reported random seeds, and 17/231 provided a public author artifact [ 51 , 52 ] . | Results may be difficult to reconstruct or distinguish from favorable stochastic variation. | Exact data and split identifiers, complete configurations and environments, repeated runs, uncertainty, executable artifacts, and component ablation. |
| Deployment and trustworthiness | Only 61/231 experiments reported deployment-related evidence, while no publication in the corpus reached E5 sustained operational validation; privacy, drift, safety, human workload, and rollback were also unevenly assessed [ 53 , 54 , 351 , 62 , 55 ] . | Offline predictive success may not translate to continuous, distributed, safety-sensitive, or human-supervised operation. | End-to-end resource measurements, adaptive and longitudinal testing, privacy evaluation, human-centered outcomes, rollback, and sustained operational evidence. |
Appendix figures & tables2 assets
Supplementary material from the paper’s appendix.
Appendix
| Source | Captured | Source-adapted query |
|---|---|---|
| IEEE Xplore | 925 | ("Generative Adversarial Network" OR "GAN" OR "GANs" OR "WGAN" OR "WGAN-GP" OR "CGAN" OR "DCGAN" OR "GANomaly" OR "AnoGAN" OR "MalGAN") AND ("adversarial defense" OR "adversarial attack" OR "adversarial training" OR "data augmentation" OR "synthetic data") AND ("cybersecurity" OR "intrusion detection" OR "IDS" OR "malware" OR "IoT" OR "phishing" OR "fraud" OR "anomaly detection") |
| SCOPUS | 2,954 | TITLE-ABS-KEY ( ( "generative adversarial network*" OR "GAN-based" OR "GAN enabled" OR CGAN OR DCGAN OR WGAN OR "WGAN-GP" OR ACGAN OR AnoGAN OR GANomaly OR MalGAN OR IDSGAN OR TimeGAN OR CycleGAN ) AND ( cybersecurity OR "cyber security" OR "cyber defense" OR "cyber defence" OR "network security" OR "information security" OR "intrusion detection" OR "network intrusion" OR malware OR ransomware OR botnet OR phishing OR DDoS OR "denial of service" OR "IoT security" OR "internet of things security" OR IIoT OR "industrial control system*" OR SCADA OR "cyber physical system*" OR "cyber-physical system*" OR "smart grid security" OR "cloud security" OR "edge security" OR "wireless security" OR "vehicular network security" OR "fraud detection" OR "biometric security" OR "authentication security" ) AND ( "data augmentation" OR "class balancing" OR "class imbalance" OR "synthetic data" OR "adversarial training" OR hardening OR robustness OR "intrusion detection" OR "anomaly detection" OR "malware detection" OR "threat detection" OR "attack detection" OR "fraud detection" OR "privacy preserving" OR "privacy-preserving" OR "federated learning" OR "domain adaptation" OR deception OR honeypot* OR recovery OR mitigation OR "spoof detection" OR "anti-spoofing" ) ) AND PUBYEAR > 2020 AND PUBYEAR < 2027 AND ( LIMIT-TO ( LANGUAGE , "English" ) ) AND ( LIMIT-TO ( DOCTYPE , "cp" ) OR LIMIT-TO ( DOCTYPE , "ar" ) OR LIMIT-TO ( DOCTYPE , "ch" ) ) AND PUBYEAR > 2020 AND PUBYEAR < 2027 |
| ACM Digital Library | 1,063 | ("Generative Adversarial Network" OR "GAN" OR "GANs" OR "WGAN" OR "WGAN-GP" OR "CGAN" OR "DCGAN") AND ("cybersecurity" OR "intrusion detection" OR "IDS" OR "malware" OR "IoT" OR "phishing" OR "fraud" OR "anomaly detection") |
| ScienceDirect | 5,177 | ALL("Generative Adversarial Network" OR "GAN" OR "GANs" OR "WGAN" OR "WGAN-GP" OR "CGAN" OR "DCGAN" OR "GANomaly") AND ALL("adversarial defense" OR "adversarial attack" OR "adversarial training" OR "data augmentation" OR "synthetic data") AND ALL("cybersecurity" OR "intrusion detection" OR "IDS" OR "malware" OR "IoT" OR "phishing" OR "fraud" OR "anomaly detection") |
| MDPI | 1,278 | ("Generative Adversarial Network" OR "GAN" OR "GANs" OR "WGAN" OR "CGAN" OR "DCGAN") AND ("cybersecurity" OR "intrusion detection" OR "IDS" OR "malware" OR "IoT" OR "phishing" OR "fraud" OR "anomaly detection") |
| SpringerLink | 1,000 | ("Generative Adversarial Network" OR "GAN" OR "GANs" OR "WGAN" OR "WGAN-GP" OR "CGAN" OR "DCGAN") AND ("cybersecurity" OR "intrusion detection" OR "IDS" OR "malware" OR "IoT" OR "phishing" OR "fraud" OR "anomaly detection") |
| Worksheet | Content |
|---|---|
| 00_README | Workbook structure, denominator rules, analytical strata, worksheet roles, and OSF information. |
| 01_DASHBOARD | Graphical summary of identification, publication, taxonomy, evidence-maturity, quality, and experiment-level results. |
| 02_SEARCH_STRATEGY | Database-specific searches, captured records, validation removals, temporal exclusions, and source provenance. |
| 03--08_RAW_* | Raw bibliographic exports from IEEE Xplore, ACM Digital Library, ScienceDirect, MDPI, SpringerLink, and Scopus. |
| 09_PRISMA | PRISMA 2020 count register for database/register and other-method pathways, ending in included full-text publications and the post-inclusion split into original experimental studies and 58 other included publications. |
| 09A_SCREENING_CALIBRATION | Calibration records and consistency checks supporting the title–abstract and eligibility screening process. |