Ai-Powered Attacks and Mitigation Strategies for Enterprises: A Comprehensive Research Review
DOI:
https://doi.org/10.47392/IRJAEH.2026.0719Keywords:
Artificial Intelligence, Enterprise Cybersecurity, Generative AI, LLM, Prompt Injection, RAG Poisoning.Abstract
The rapid adoption of artificial intelligence (AI), large language models (LLMs), retrieval-augmented generation (RAG), and autonomous AI agents is transforming enterprise information systems, cybersecurity operations, software development, customer services, and decision-making. However, the integration of AI introduces attack surfaces that extend beyond conventional application and network vulnerabilities. Attackers can exploit identities, application programming interfaces, prompts, documents, retrieval stores, vector databases, model artifacts, agent tools, browser sessions, software pipelines, cloud credentials, and AI gateways. This research review develops a 24-path enterprise attack taxonomy from the supplied reference model and organizes the attacks across identity and access, input and context, data and retrieval, model and supply chain, agent and workflow, and infrastructure and output domains. It reviews major attack classes and proposes a defense-in-depth mitigation architecture combining zero-trust identity, least privilege, data provenance, model integrity verification, secure tool execution, continuous monitoring, adversarial testing, human oversight, and AI-specific incident response. The paper also identifies research gaps involving prompt-injection detection, agent authorization, persistent memory, model provenance, AI supply-chain assurance, and enterprise-scale security evaluation.
Downloads
Downloads
Published
Issue
Section
License
Copyright (c) 2026 International Research Journal on Advanced Engineering Hub (IRJAEH)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
.