Skip to content
Preprint

Explainable Adaptive Zero Trust Framework for AWS with Adversarial Robustness Evaluation

Aug 2026 · 0 citations · 18 references
Computer Science

TL;DR

The Explainable Adaptive Zero Trust Framework (EAZTF) is introduced, a cloud-native security layer that continuously reevaluates the legitimacy of API actions throughout a session and is evaluated against four adversarial evasion strategies.

Abstract

Cloud environments built on Amazon Web Services face a structural security vulnerability: once a credential passes authentication, the resulting session is often treated as trusted for its entire duration. This assumption fails when credentials are stolen. We introduce the Explainable Adaptive Zero Trust Framework (EAZTF), a cloud-native security layer that continuously reevaluates the legitimacy of API actions throughout a session. EAZTF combines Isolation Forest and XGBoost to evaluate eight CloudTrail and IAM-derived behavioral features in real time and produce a Trust Risk Score (TRS) that determines whether a session continues, requires step-up MFA, or is restricted. Each decision is accompanied by a SHAP or LIME explanation, providing human-readable audit records for security analysis and compliance. The framework is also evaluated against four adversarial evasion strategies: credential theft, behavioral mimicry, API rate evasion, and privilege escalation. Experiments on an 8,500-record synthetic CloudTrail dataset show that Isolation Forest achieves 94.4% precision, 91.2% recall, and an F1 score of 0.928. Across the four adversarial scenarios, the mean detection rate is 91.0%, with behavioral mimicry being the most difficult at 83.9%. SHAP analysis identifies IP reputation, login-time deviation, and API call velocity as the three dominant features. A structured NIST SP 800-207 self-assessment gives EAZTF a mean compliance score of 93%, compared with 38% for a traditional perimeter baseline. Mean time to detect decreases from hours to under one minute. Because the evaluation uses synthetic data, these results should be interpreted as indicative rather than validated production performance.

View source

Similar papers

Preprint Aug 2026

ExplainGuard: A Zero Trust Framework for Post-Hoc Explanation Integrity Guarantees in Blackbox XAI Models

A novel defense framework is introduced that leverages a Zero-Trust architecture (ZTA) design to be incorporated within the XAI explanation supply chain and ensures the integrity of the generated explanation and evaluates how ExplainGuard can effectively neutralize state- of-the-art explanation manipulation attacks whi...

Maraz Mia, Shovan Roy, M. M. A. Pritom et al. · 0 citations
Conference Jul 2026

TrustWorkday: A Zero-Trust Security and Compliance Architecture for Enterprise SaaS Platforms

Enterprise SaaS platforms have emerged as key components in today's digital transformation programs by improving efficiency, scalability, and distributed workforce support. Traditional perimeter-based security measures are inadequate in safeguarding critical data stored in enterprise environments due to their distribut...

Nallappagari Venkatarami Reddy · 0 citations
Open access 2026

Cryptographic Attestation Against Integrity Attacks in Service Monitoring: A Threat Model and Verifiable Architecture

Service uptime monitoring infrastructure is a high-value target for data-integrity attacks: a single compromised or dishonest monitoring provider can fabricate availability records, retroactively suppress outage evidence, or silently alter historical data, and clients today have no cryptographic means of detecting such...

M. Anusuya, Chayadevi M. L., S. C. et al. · 0 citations
Sep 2026

Context-Aware and Privacy-Preserving Trust Management Framework for Internet of Vehicles: Formal Models, Adaptive Consensus, and Real-World Validation

The Internet of Vehicles (IoV) requires robust trust management to enable safe, autonomous transportation in dynamic, large-scale environments. Existing approaches face key limitations, including centralized vulnerabilities, static reputation models, privacy risks, and scalability bottlenecks. This article presents a t...

E. Aloufi · 0 citations
Conference Jul 2026

Explainable AI-Enabled Adaptive Pre-Validation Framework for Trust-Oriented Security in Permissioned Blockchains

Permissioned blockchain systems have emerged as a cornerstone for enterprise-grade distributed applications due to their controlled participation, high throughput, and deterministic consensus protocols. However, existing security mechanisms in such systems are still mostly static, based on pre-defined rules and determi...

S. S., S. S, A. M et al. · 0 citations
Preprint Aug 2026

TrustShiftProbe: Characterizing, Benchmarking, and Defending Staged Trust Attacks on MCP Servers

TrustShiftProbe is introduced, an evaluation and defense framework with four contributions: a stateful temporal threat model of the agent-server lifecycle as a benign conditioning phase followed by an adversarial defection at a trust horizon, and a language-agnostic attack engine that instantiates each variant as a com...

Mehrdad Rostamzadeh, Sidhant Narula, Mohammad Ghasemigol et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.