PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 18, 2025Journal of Cybersecurity and Privacy9 citationsOpen Access

The Erosion of Cybersecurity Zero-Trust Principles Through Generative AI: A Survey on the Challenges and Future Directions

View Full Paper
DXDan XuIGIqbal GondalXYXun Yi

Key Points

  • Generative AI attacks contribute to the erosion of zero-trust principles, leading to increased detection failures.
  • Of 146 examined studies, 98% lacked real-world validation, emphasizing the empirical weaknesses in zero-trust architecture research.
  • The Cyber Fraud Kill Chain framework models generative techniques while identifying vulnerabilities in current zero-trust practices.
  • Existing defenses against AI threats are inadequate, calling for a comprehensive redesign of zero-trust strategies to ensure cybersecurity.

Abstract

Generative artificial intelligence (AI) and persistent empirical gaps are reshaping the cyber threat landscape faster than Zero-Trust Architecture (ZTA) research can respond. We reviewed 10 recent ZTA surveys and 136 primary studies (2022–2024) and found that 98% provided only partial or no real-world validation, leaving several core controls largely untested. Our critique, therefore, proceeds on two axes: first, mainstream ZTA research is empirically under-powered and operationally unproven; second, generative-AI attacks exploit these very weaknesses, accelerating policy bypass and detection failure. To expose this compounding risk, we contribute the Cyber Fraud Kill Chain (CFKC), a seven-stage attacker model (target identification, preparation, engagement, deception, execution, monetization, and cover-up) that maps specific generative techniques to NIST SP 800-207 components they erode. The CFKC highlights how synthetic identities, context manipulation and adversarial telemetry drive up false-negative rates, extend dwell time, and sidestep audit trails, thereby undermining the Zero-Trust principles of verify explicitly and assume breach. Existing guidance offers no systematic countermeasures for AI-scaled attacks, and that compliance regimes struggle to audit content that AI can mutate on demand. Finally, we outline research directions for adaptive, evidence-driven ZTA, and we argue that incremental extensions of current ZTA that are insufficient; only a generative-AI-aware redesign will sustain defensive parity in the coming threat cycle.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Xu et al. (2025) studied this question.

synapsesocial.com/papers/68f35bfc73f0a7d050f47cfahttps://doi.org/10.3390/jcp5040087
Ask AI
Helpful
Bookmark
Share
View Full Paper