AICybOps: A Framework for Operationalizing Machine-Learning Models in Cybersecurity
Machine learning is increasingly used in cybersecurity, for example, for anomaly and intrusion detection in microservice and Internet of Things environments. Guidance on securing the machine learning operations (MLOps) lifecycle, termed MLSecOps or SecMLOps, recommends continuous monitoring, a versioned model registry, and lifecycle integration of training, evaluation, and serving. This layer is typically built per deployment, as model-specific code rather than a shared framework. We present AICybOps, a framework that systematizes these practices so the operational features and security properties a deployed model needs are provided by design. It wraps trained models behind a uniform lifecycle interface, exposes a monitor control application programming interface (API) for long-running prediction loops, re-loads models by registered name and version across hosts, and runs durable asynchronous training and evaluation, so a developer implements only the model and inherits the rest. These four design features constitute the framework’s current version; an inheritance-and-expansion criterion governs its contents and keeps it open to further security operations. Because the framework addresses a deployed model by registered version, tracks its runs automatically, and holds the registry behind the service boundary, it yields five security properties: lineage, reproducible replay, an audit trail, private provenance, and integrity of model identity.
Authors
- Sérgio Figueiredo (ORCID: https://orcid.org/0000-0002-2976-9249)
- Rubén Leal (ORCID: https://orcid.org/0000-0001-5818-4437)
Institutions
- Instituto Pedro Nunes (PT)
Publication Details
- Journal
- Journal of Cybersecurity and Privacy
- Published
- 2026-10-09
- DOI
- https://doi.org/10.3390/jcp6050175
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00