Abstract
The article analyzes, from the standpoint of artificial intelligence models, the problem of detecting cyberattacks in real time and responding to them in an automated manner. Drawing on the 2025-2026 global reports of IBM and the Ponemon Institute, the regulatory and legal acts of the Republic of Uzbekistan in the field of cybersecurity, and national and foreign scientific sources, the gap between the propagation speed of an attack and the response speed of an organization is assessed quantitatively. The novelty of the model lies in combining, within a single architecture, a cost-sensitive reward function, a concept drift monitoring mechanism, an adversarial robustness module, and a federated learning scheme among sectoral SOCs. The stages of implementing the proposed solution under the conditions of Uzbekistan are aligned with the deadlines of the Cybersecurity Strategy for 2026-2030.
This work is licensed under a Creative Commons Attribution 4.0 International License.
