AI-Driven Anomaly Detection in U.S. University Networks: A Qualitative Study of Development, Implementation, and Governance
DOI:
https://doi.org/10.69987/JACS.2026.60801Keywords:
Artificial intelligence, anomaly detection, cybersecurity, higher education, university networks, IT governance, ethical AIAbstract
Despite the growing adoption of artificial intelligence (AI) to strengthen cybersecurity, qualitative research examining the development, implementation, and governance of AI-driven anomaly detection systems within U.S. higher education remains limited. Universities present a distinct cybersecurity environment due to their decentralized IT infrastructures, diverse stakeholder communities, and the need to balance security with academic openness.This study investigates the development and implementation of AI-driven anomaly detection systems for identifying abnormal network behavior in U.S. university environments. A qualitative multiple-case study design was employed, drawing on semi-structured interviews with 11 cybersecurity professionals from six U.S. universities. The interview data were analyzed using thematic analysis to address the study's research questions. The findings reveal that the adoption and operation of AI-driven anomaly detection systems are shaped by several interconnected factors, including vendor influence, governance frameworks, and ethical considerations. Participants also identified significant implementation challenges, such as false-positive alerts, the complexity of university network environments, and institutional cultures that emphasize academic freedom and privacy. Overall, the findings highlight the critical role of effective governance in ensuring the successful deployment and responsible use of AI-driven cybersecurity technologies in higher education.







