Applying Miles's Seven-Gap Taxonomy to AI-Enabled Cyber Defense: A Framework for Doctoral Research Proposal Development

Authors

  • Mukaila Ishola Adediran Nasarawa State University, Keffi (NSUK)
  • Gilbert I.O. Aimufua Nasarawa State University, Keffi (NSUK)
  • Mohammed Zakari Doko Corps Information Technology Office, Federal Road Safety National Headquarters, Abuja

Keywords:

Conceptual Framework, Methodological Framework, Artificial Intelligence, Cyber Defense, Cybersecurity, Research Gaps, Taxonomy, Framework Validation

Abstract

Artificial intelligence has become one of the most important tools in modern cyber defense, giving security teams capabilities in intrusion detection, malware classification, threat intelligence, and automated incident response that traditional rule-based systems simply can't match. Yet even as research in this area grows quickly, the field still lacks a reliable way to pinpoint where knowledge is missing, disputed, or simply untested. This paper builds and lays out a conceptual and methodological framework for identifying, validating, and prioritizing research gaps in AI-enabled cyber defense. As far as we know, this is the first time a domain-specific version of a systematic research-gap taxonomy has been developed for this literature, adapting Miles's (2017) seven-component taxonomy - the Evidence Gap, Knowledge Gap, Practical-Knowledge Gap, Methodological Gap, Empirical Gap, Theoretical Gap, and Population Gap - to fit this field. Beyond simply defining these seven components, the paper offers a concrete methodology for putting the framework into practice: a synthesis-based process for populating each gap category using systematic reviews, a validation protocol for primary studies with clearly defined search and inclusion criteria, data quality and analytical rigor procedures to ensure the evidence is properly checked and interpreted, a straightforward scoring method for prioritizing gaps, an evaluation of the framework itself using Nickerson et al.'s (2013) taxonomy-quality criteria, and an additional validity analysis covering the framework's content, construct, criterion, and reliability validity. To test the framework, we applied it to a purposive sample of nine primary studies across four subdomains of AI-driven cyber defense: network intrusion detection, malware detection, automated threat intelligence extraction, and incident-response practice. This is a broader validation effort than any previous gap-identification framework in this literature has attempted, as far as we're aware. We also stress-tested the resulting prioritization by running a sensitivity analysis across three different weighting schemes, rather than presenting just one fixed ranking. The framework is then compared against four existing gap-identification models to show how it fits within the broader landscape. The paper closes with practical templates for turning a framework-identified gap into a clear, citable gap statement, along with a discussion of the framework's limitations, potential sources of bias, and the responsibilities that come with using it.

DOI: https://doi.org/10.5281/zenodo.21996931

Downloads

Published

2026-08-18