Document Type

Article

Publication Date

2026

DOI

10.1049/ise2/7123849

Publication Title

IET Information Security

Volume

2026

Issue

1

Pages

7123849

Abstract

Attribute-Based Access Control (ABAC) frameworks coordinate access requests based on subject, object, and environment attributes, as well as policy rules, and are widely used in corporate security systems. Recently, machine learning has been applied to ABAC to address policy-generation imbalances, misassigned privileges, and attribute leakages. However, existing MLBAC techniques do not consider the structural constraints and attribute interdependencies present in traditional ABAC systems. Moreover, these frameworks have not been extensively evaluated under black-box attack scenarios. To address these gaps, we propose extensions to MLBAC that integrate structural constraints, attribute dynamism, and attribute weighting into the MLBAC objective function. Additionally, we study the behavior of these extended MLBAC models under black-box adversarial attacks. We implemented the framework using five deep-learning models: RNN, LSTM, Deep Belief Network (DBN), TabTransformer, and DeepFM, on both synthetic and real-world datasets. Our findings show that the DBN model consistently achieves the best performance, while the black-box adversarial attacks reveal general vulnerabilities across MLBAC systems. These outcomes highlight the need for more robust defense mechanisms in future research. Accordingly, we propose several potential mitigation strategies against black-box attacks.

Rights

© 2026 Olusesi Balogun et al.

This is an open access article under the terms of the Creative Commons Attribution 4.0 International (CC BY 4.0) License, which permits use, distribution and reproduction in any medium, provided the original work is properly cited.

Data Availability

Article states: "The data that support the results of this research work are available upon request from the corresponding author."

Original Publication Citation

Balogun, O., GhasemiGol, M., Cai, Z., & Takabi, D. (2026). Toward secure and practical machine learning-based access control: A framework with real-world constraints and adversarial analysis. IET Information Security, 2026(1), Article 7123849. https://doi.org/10.1049/ise2/7123849

ORCID

0000-0001-6661-0942 (GhasemiGol), 0000-0003-0447-3641 (Takabi)

Share

COinS