The Explainable Adaptive Zero Trust Framework (EAZTF) is introduced, a cloud-native security layer that continuously reevaluates the legitimacy of API actions throughout a session and is evaluated against four adversarial evasion strategies.
Abstract
Cloud environments built on Amazon Web Services face a structural security vulnerability: once a credential passes authentication, the resulting session is often treated as trusted for its entire duration. This assumption fails when credentials are stolen. We introduce the Explainable Adaptive Zero Trust Framework (EAZTF), a cloud-native security layer that continuously reevaluates the legitimacy of API actions throughout a session. EAZTF combines Isolation Forest and XGBoost to evaluate eight CloudTrail and IAM-derived behavioral features in real time and produce a Trust Risk Score (TRS) that determines whether a session continues, requires step-up MFA, or is restricted. Each decision is accompanied by a SHAP or LIME explanation, providing human-readable audit records for security analysis and compliance. The framework is also evaluated against four adversarial evasion strategies: credential theft, behavioral mimicry, API rate evasion, and privilege escalation. Experiments on an 8,500-record synthetic CloudTrail dataset show that Isolation Forest achieves 94.4% precision, 91.2% recall, and an F1 score of 0.928. Across the four adversarial scenarios, the mean detection rate is 91.0%, with behavioral mimicry being the most difficult at 83.9%. SHAP analysis identifies IP reputation, login-time deviation, and API call velocity as the three dominant features. A structured NIST SP 800-207 self-assessment gives EAZTF a mean compliance score of 93%, compared with 38% for a traditional perimeter baseline. Mean time to detect decreases from hours to under one minute. Because the evaluation uses synthetic data, these results should be interpreted as indicative rather than validated production performance.
A novel defense framework is introduced that leverages a Zero-Trust architecture (ZTA) design to be incorporated within the XAI explanation supply chain and ensures the integrity of the generated explanation and evaluates how ExplainGuard can effectively neutralize state- of-the-art explanation manipulation attacks whi...
Maraz Mia, Shovan Roy, M. M. A. Pritom et al.· 0 citations
Enterprise SaaS platforms have emerged as key components in today's digital transformation programs by improving efficiency, scalability, and distributed workforce support. Traditional perimeter-based security measures are inadequate in safeguarding critical data stored in enterprise environments due to their distribut...
Nallappagari Venkatarami Reddy· 2026 7th International Confe...· 0 citations
Service uptime monitoring infrastructure is a high-value target for data-integrity attacks: a single compromised or dishonest monitoring provider can fabricate availability records, retroactively suppress outage evidence, or silently alter historical data, and clients today have no cryptographic means of detecting such...
M. Anusuya, Chayadevi M. L., S. C. et al.· International Journal of Adv...· 0 citations
The Internet of Vehicles (IoV) requires robust trust management to enable safe, autonomous transportation in dynamic, large-scale environments. Existing approaches face key limitations, including centralized vulnerabilities, static reputation models, privacy risks, and scalability bottlenecks. This article presents a t...
E. Aloufi· IEEE Internet of Things Jour...· 0 citations
Permissioned blockchain systems have emerged as a cornerstone for enterprise-grade distributed applications due to their controlled participation, high throughput, and deterministic consensus protocols. However, existing security mechanisms in such systems are still mostly static, based on pre-defined rules and determi...
S. S., S. S, A. M et al.· 2026 7th International Confe...· 0 citations
TrustShiftProbe is introduced, an evaluation and defense framework with four contributions: a stateful temporal threat model of the agent-server lifecycle as a benign conditioning phase followed by an adversarial defection at a trust horizon, and a language-agnostic attack engine that instantiates each variant as a com...
Mehrdad Rostamzadeh, Sidhant Narula, Mohammad Ghasemigol et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.