Cyber-attacks are becoming increasingly sophisticated, frequent and costly. UQ researchers are developing AI systems that can automatically identify suspicious activity in computer networks, helping organisations detect cyber threats earlier and strengthen resilience across critical digital infrastructure.

What’s the problem?
Modern computer networks generate enormous volumes of data, making it increasingly difficult for security teams to identify and respond to cyber threats quickly. At the same time, attackers are constantly changing their tactics, creating challenges for traditional security systems and many machine-learning models that rely on large amounts of labelled training data.
One of the biggest challenges in cybersecurity is ensuring that AI systems can continue to detect threats when networks, users and attack patterns change over time. Systems trained in one environment often perform poorly when deployed in another, limiting their effectiveness in real-world settings.
What’s UQ’s innovation?
Associate Professor Mahsa Baktashmotlagh and collaborators are developing advanced machine-learning approaches that can identify cyber threats across diverse and evolving network environments.
A key focus of the research is building domain-invariant intrusion detection systems that can recognise malicious behaviour even when attack patterns differ from the data used to train the model. By combining advances in AI, domain adaptation and machine learning, the team is developing techniques that can detect network intrusions with less dependence on large manually labelled datasets.
The broader research program explores how AI can adapt to new environments, learn from incomplete information and remain effective when facing previously unseen threats, helping create more robust cyber-defence systems.
What’s the impact?
AI-assisted cyber defence has the potential to help organisations move from reactive cybersecurity to proactive threat detection. By identifying suspicious behaviour earlier and continuously adapting to changing network conditions, these systems may help reduce disruption, financial losses and security risks.
As cyber threats continue to evolve, AI-based intrusion detection could strengthen Australia’s digital resilience and provide better protection for government systems, businesses and critical infrastructure. The research also contributes to the development of more trustworthy and adaptable AI systems that can operate effectively in real-world environments.
Did you know?
Many AI-based cyber-defence systems struggle when deployed in environments that differ from their training data. UQ researchers are developing AI techniques designed to remain effective even when network conditions and attack patterns change.
The Team
This work brings together researchers from UQ’s School of Electrical Engineering and Computer Science and the UQ Cyber Research Centre.
UQ LEAD
| AI Research Strength | Data-Centric AI |
|---|---|
| Industry Portfolio | Defence, Space & National Security |
| Key Project | AI-powered Network Intrusion Detection and Cyber Resilience |
| Key Publications | Layeghy, S., Baktashmotlagh, M. & Portmann, M. (2023). DI-NIDS: Domain Invariant Network Intrusion Detection System. Knowledge-Based Systems, 273, 110626. RELATED RESEARCH T5-CSBoost: Adversarial Perturbation Resistant LLM Fingerprinting, Kulatilleke GK, Baktashmotlagh M, Layeghy S & Portmann M (2026). arXiv preprint arXiv:2607.14113. MambaNetBurst: Direct Byte-level Network Traffic Classification without Tokenization or Pretraining. Kulatilleke GK, Baktashmotlagh M, Layeghy S & Portmann M (2026). arXiv preprint arXiv:2605.11034. |
Published 15 September 2026