AI-driven attacks on database security: taxonomy and defense strategies

Diyar Waysi Naaman, Berivan Ahmed, Hajar Maseeh Yasin · Engineering and Technology Journal · 2025

Artificial intelligence has introduced both unprecedented capabilities and novel vulnerabilities into database environments, enabling highly adaptive attacks that can evade traditional defenses. This review surveys recent research published between 2022 and 2025 on AI-assisted database security threats and synthesizes the literature to develop a comprehensive taxonomy of emerging attack approaches. We identified five primary classes of AI-based attacks: intelligent SQL injection attacks, adversarial machine learning strategies targeting database security systems, data poisoning attacks on AI-based databases, automated reconnaissance exploits, and sociotechnical manipulations aimed at database administrators. We systematically reviewed publications on cyber defense stored in IEEE Xplore, ACM Digital Library, Science Direct, and Scopus databases. Boolean search terms were used on the databases specific to cyber defense. Findings indicate that automated SQL injection attacks can escalate the bypass rate of security systems to over 85% effectiveness. The effectiveness of rule-based defense systems degrades by 32% when pitted against sophisticated AI-adapted adversarial attacks. Conversely, machine learning-based defenses maintain a detection rate of 85 to 95%. To combat advancing techniques, a multilayer approach that includes adversarial training, anomaly-based intrusion detection, and automated user behavior analysis and reporting technology should be employed. This approach utilizes anomaly-based defenses through a monitoring model. Analysis shows that conventional database defense techniques need to be upgraded with real-time analytics, dynamic response mechanisms, and zero-day vulnerability protection to keep pace with the increasingly sophisticated nature of AI adversarial attacks on database systems.

Read the paper · More papers on PaperTik