A hybrid fuzzy logic-driven behavioral intrusion detection architecture integrating fuzzy clustering and adaptive machine learning for Zero-Trust networks
Abstract
In current Zero-Trust architectures, detecting behavioral intrusions has become critical because traditional rule-based access control systems struggle to combat polymorphic, low-and-slow, and identity-spoofing attacks. Although machine learning technologies have advanced intrusion detection through behavioral pattern modeling, the inherent ambiguity in behavioral patterns and overlapping feature distributions still degrade classification accuracy and increase false positives, especially with traditional supervised models that rely on deterministic boundary conditions. Recent approaches have focused primarily on feature extraction, pre-trained deep learning models, or rule-based validation and have not addressed uncertainty quantification, highlighting a gap between real-time inference and trust-based access enforcement. To address these issues, this paper introduces a hybrid fuzzy logic-driven behavioral intrusion detection architecture that combines fuzzy clustering with adaptive machine learning models: decision tree, logistic regression, random forest, support vector machine (SVM), and extreme gradient boosting, to improve Zero-Trust decision-making. Experimental results show that combining fuzzy membership scores with divergence scores significantly improves the SVM's predictive performance on overlapping behavioral segments in the test data, outperforming other models and achieving 98.00% accuracy, 96.50% F1-score, 97.20% recall, and 97.00% area under the curve. This research integrates uncertainty-aware fuzzy computing with continuous Zero-Trust authorization, enabling dynamic trust recalibration rather than validation against a fixed threshold. The proposed solution will better categorize high-risk events, reducing operational disruptions for legitimate users. This research also contributes to the United Nations Sustainable Development Goals (SDGs), particularly SDG 9 (Industry, Innovation, and Infrastructure) and SDG 16 (Peace, Justice, and Strong Institutions), by enhancing digital infrastructure security through intelligent, adaptive cybersecurity mechanisms.