This study investigates the optimization of AI-driven anomaly detection and automated response orchestration for cyber defense across four critical United States sectors: military networks, critical infrastructure including SCADA/ICS systems, corporate enterprises, and financial institutions. As AI-enabled cyberattacks grow in sophistication, defensive capabilities must evolve commensurately; however, no existing framework adequately addresses the divergent operational constraints across these sectors while leveraging common AI technologies. This study employed a sequential explanatory mixed-methods design with quantitative priority, utilizing four publicly available benchmark datasets (UNSW-NB15, CICIDS2017, NSL-KDD, CTU-13) comprising over 300,000 network traffic records. Three machine learning architectures—Random Forest, XGBoost, and Multi-Layer Perceptron—were systematically evaluated through 5-fold stratified cross-validation with SMOTE applied within folds to address class imbalance. Sector-specific optimization imposed operational constraints reflecting real-world requirements: military (FPR ≤ 1%), critical infrastructure (FPR ≤ 0.1%), corporate (FPR ≤ 5%), and financial (FPR ≤ 2%). Results revealed that XGBoost achieved superior detection performance with a mean F1-score of 0.969, AUC-ROC of 0.9996, and the lowest false positive rate (0.39%) across all datasets. The most significant finding was a 136% threshold differential between military and critical infrastructure deployments, far exceeding the hypothesized 15% difference and providing strong empirical support for sector-specific optimization rather than universal deployment configurations. The study proposes a tiered automated response orchestration framework aligned with NIST Cybersecurity Framework 2.0 functions and CISA guidance. Findings inform evidence-based policy recommendations for national cybersecurity stakeholders including the Department of Defense, Department of Homeland Security, and sector-specific regulatory agencies, enabling resource prioritization, cross-sector knowledge transfer, and development of differentiated automation policies for AI-driven cyber defense.
Laszlo Pokorny (Sat,) studied this question.