Document Type
Article
Publication Date
2026
DOI
10.1049/ise2/7123849
Publication Title
IET Information Security
Volume
2026
Issue
1
Pages
7123849
Abstract
Attribute-Based Access Control (ABAC) frameworks coordinate access requests based on subject, object, and environment attributes, as well as policy rules, and are widely used in corporate security systems. Recently, machine learning has been applied to ABAC to address policy-generation imbalances, misassigned privileges, and attribute leakages. However, existing MLBAC techniques do not consider the structural constraints and attribute interdependencies present in traditional ABAC systems. Moreover, these frameworks have not been extensively evaluated under black-box attack scenarios. To address these gaps, we propose extensions to MLBAC that integrate structural constraints, attribute dynamism, and attribute weighting into the MLBAC objective function. Additionally, we study the behavior of these extended MLBAC models under black-box adversarial attacks. We implemented the framework using five deep-learning models: RNN, LSTM, Deep Belief Network (DBN), TabTransformer, and DeepFM, on both synthetic and real-world datasets. Our findings show that the DBN model consistently achieves the best performance, while the black-box adversarial attacks reveal general vulnerabilities across MLBAC systems. These outcomes highlight the need for more robust defense mechanisms in future research. Accordingly, we propose several potential mitigation strategies against black-box attacks.
Rights
© 2026 Olusesi Balogun et al.
This is an open access article under the terms of the Creative Commons Attribution 4.0 International (CC BY 4.0) License, which permits use, distribution and reproduction in any medium, provided the original work is properly cited.
Data Availability
Article states: "The data that support the results of this research work are available upon request from the corresponding author."
Original Publication Citation
Balogun, O., GhasemiGol, M., Cai, Z., & Takabi, D. (2026). Toward secure and practical machine learning-based access control: A framework with real-world constraints and adversarial analysis. IET Information Security, 2026(1), Article 7123849. https://doi.org/10.1049/ise2/7123849
Repository Citation
Balogun, O., GhasemiGol, M., Cai, Z., & Takabi, D. (2026). Toward secure and practical machine learning-based access control: A framework with real-world constraints and adversarial analysis. IET Information Security, 2026(1), Article 7123849. https://doi.org/10.1049/ise2/7123849
ORCID
0000-0001-6661-0942 (GhasemiGol), 0000-0003-0447-3641 (Takabi)
Included in
Artificial Intelligence and Robotics Commons, Cybersecurity Commons, OS and Networks Commons, Systems Engineering Commons