A Taxonomy of Intelligent Intrusion Detection Systems For Cybersecurity Using Large Language Models And Agent-Based Artificial Intelligence

Abstract
Intrusion Detection Systems (IDS) play a critical role in modern cybersecurity, yet traditional and early artificial intelligence-based approaches remain limited by their reliance on predefined patterns, lack of contextual understanding, and high false positive rates. Recent advances in large language models (LLMs) and agent-based artificial intelligence introduce new capabilities that extend IDS beyond conventional detection toward reasoning, contextual awareness, and adaptive response. This work presents a taxonomy of intelligent intrusion detection systems for cybersecurity using LLMs and agent-based AI, organizing the design space across five dimensions: detection intelligence, functional role, system autonomy, data modality, and response capability. A unified architectural framework is also introduced, integrating LLM-based reasoning with agent-driven decision-making to support detection, explanation, and response. The paper highlights key advantages, including improved contextual correlation, explainability, and adaptive incident response, while addressing challenges related to reliability, security, operational constraints, and evaluation. It further outlines future directions toward autonomous, memory-augmented, and multi-agent IDS for complex environments.
© 2026 Samson Quaye, Maurice Dawson, Enkel Hoxha, published by Nicolae Balcescu Land Forces Academy
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.