{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T02:17:07Z","timestamp":1771467427483,"version":"3.50.1"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032006295","type":"print"},{"value":"9783032006301","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-032-00630-1_6","type":"book-chapter","created":{"date-parts":[[2025,8,8]],"date-time":"2025-08-08T13:37:09Z","timestamp":1754660229000},"page":"88-105","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Adversarial Robustness of\u00a0Machine Learning-Based Access Control"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1946-4660","authenticated-orcid":false,"given":"Javier Mart\u00ednez","family":"Llamas","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthias Van","family":"Hoof","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6279-4430","authenticated-orcid":false,"given":"Davy","family":"Preuveneers","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,8,9]]},"reference":[{"key":"6_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"523","DOI":"10.1007\/978-3-030-58951-6_26","volume-title":"Computer Security \u2013 ESORICS 2020","author":"A Abu Jabal","year":"2020","unstructured":"Abu Jabal, A., Bertino, E., Lobo, J., Law, M., Russo, A., Calo, S., Verma, D.: Polisma - A framework for learning attribute-based access control policies. In: Chen, L., Li, N., Liang, K., Schneider, S. (eds.) ESORICS 2020. LNCS, vol. 12308, pp. 523\u2013544. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58951-6_26"},{"key":"6_CR2","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1007\/978-3-030-22312-0_8","volume-title":"ICT Systems Security and Privacy Protection","author":"M Alohaly","year":"2019","unstructured":"Alohaly, M., Takabi, H., Blanco, E.: Towards an automated extraction of ABAC constraints from natural language policies. In: Dhillon, G., Karlsson, F., Hedstr\u00f6m, K., Z\u00faquete, A. (eds.) SEC 2019. IAICT, vol. 562, pp. 105\u2013119. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-22312-0_8"},{"key":"6_CR3","unstructured":"Amazon, Kaggle: Amazon.com - Employee access challenge (2014). https:\/\/www.kaggle.com\/competitions\/amazon-employee-access-challenge\/data. Accessed 20 Jan 2025"},{"key":"6_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/978-3-319-95729-6_7","volume-title":"Data and Applications Security and Privacy XXXII","author":"L Argento","year":"2018","unstructured":"Argento, L., Margheri, A., Paci, F., Sassone, V., Zannone, N.: Towards adaptive access control. In: Kerschbaum, F., Paraboschi, S. (eds.) DBSec 2018. LNCS, vol. 10980, pp. 99\u2013109. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-95729-6_7"},{"key":"6_CR5","doi-asserted-by":"crossref","unstructured":"Bauer, L., Cranor, L.F., Reeder, R.W., Reiter, M.K., Vaniea, K.: Real life challenges in access-control management. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, pp. 899\u2013908 (2009)","DOI":"10.1145\/1518701.1518838"},{"issue":"1","key":"6_CR6","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1952982.1952984","volume":"14","author":"L Bauer","year":"2011","unstructured":"Bauer, L., Garriss, S., Reiter, M.K.: Detecting and resolving policy misconfigurations in access-control systems. ACM Trans. Inf. Syst. Secur. (TISSEC) 14(1), 1\u201328 (2011)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"6_CR7","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"387","DOI":"10.1007\/978-3-642-40994-3_25","volume-title":"Machine Learning and Knowledge Discovery in Databases","author":"B Biggio","year":"2013","unstructured":"Biggio, B., Corona, I., Maiorca, D., Nelson, B., \u0160rndi\u0107, N., Laskov, P., Giacinto, G., Roli, F.: Evasion attacks against machine learning at test time. In: Blockeel, H., Kersting, K., Nijssen, S., \u017delezn\u00fd, F. (eds.) ECML PKDD 2013. LNCS (LNAI), vol. 8190, pp. 387\u2013402. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-40994-3_25"},{"key":"6_CR8","unstructured":"Carlini, N., et al.: On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705 (2019)"},{"key":"6_CR9","unstructured":"Cartella, F., Anunciacao, O., Funabiki, Y., Yamaguchi, D., Akishita, T., Elshocht, O.: Adversarial attacks for tabular data: application to fraud detection and imbalanced data. arXiv preprint arXiv:2101.08030 (2021)"},{"issue":"2","key":"6_CR10","first-page":"150","volume":"2","author":"CC Chang","year":"2006","unstructured":"Chang, C.C., Lin, I.C., Liao, C.T.: An access control system with time-constraint using support vector machines. Int. J. Netw. Secur. 2(2), 150\u2013159 (2006)","journal-title":"Int. J. Netw. Secur."},{"key":"6_CR11","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1613\/jair.953","volume":"16","author":"NV Chawla","year":"2002","unstructured":"Chawla, N.V., Bowyer, K.W., Hall, L.O., Kegelmeyer, W.P.: Smote: synthetic minority over-sampling technique. J. Artif. Intell. Res. 16, 321\u2013357 (2002)","journal-title":"J. Artif. Intell. Res."},{"key":"6_CR12","doi-asserted-by":"crossref","unstructured":"Cotrini, C., Weghorn, T., Basin, D.: Mining ABAC rules from sparse logs. In: 2018 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 31\u201346. IEEE (2018)","DOI":"10.1109\/EuroSP.2018.00011"},{"key":"6_CR13","unstructured":"Ferraiolo, D., Cugini, J., Kuhn, D.R., et\u00a0al.: Role-based access control (RBAC): features and motivations. In: Proceedings of 11th Annual Computer Security Application Conference, pp. 241\u201348 (1995)"},{"key":"6_CR14","doi-asserted-by":"crossref","unstructured":"Frank, M., Basin, D., Buhmann, J.M.: A class of probabilistic models for role engineering. In: Proceedings of the 15th ACM conference on Computer and communications security, pp. 299\u2013310 (2008)","DOI":"10.1145\/1455770.1455809"},{"key":"6_CR15","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"6_CR16","doi-asserted-by":"crossref","unstructured":"Gumma, V., Mitra, B., Dey, S., Patel, P.S., Suman, S., Das, S.: Pammela: policy administration methodology using machine learning. arXiv preprint arXiv:2111.07060 (2021)","DOI":"10.5220\/0011272400003283"},{"key":"6_CR17","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"6_CR18","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.IR.8360","volume-title":"Machine learning for access control policy verification","author":"VC Hu","year":"2021","unstructured":"Hu, V.C., Hu, V.C.: Machine learning for access control policy verification. US Department of Commerce, National Institute of Standards and Technology (2021)"},{"issue":"2","key":"6_CR19","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1109\/MC.2015.33","volume":"48","author":"VC Hu","year":"2015","unstructured":"Hu, V.C., Kuhn, D.R., Ferraiolo, D.F., Voas, J.: Attribute-based access control. Computer 48(2), 85\u201388 (2015)","journal-title":"Computer"},{"key":"6_CR20","doi-asserted-by":"crossref","unstructured":"Huang, L., Joseph, A.D., Nelson, B., Rubinstein, B.I., Tygar, J.D.: Adversarial machine learning. In: Proceedings of the 4th ACM Workshop on Security and Artificial Intelligence, pp. 43\u201358 (2011)","DOI":"10.1145\/2046684.2046692"},{"key":"6_CR21","doi-asserted-by":"crossref","unstructured":"Jagielski, M., Oprea, A., Biggio, B., Liu, C., Nita-Rotaru, C., Li, B.: Manipulating machine learning: Poisoning attacks and countermeasures for regression learning. In: 2018 IEEE symposium on security and privacy (SP), pp. 19\u201335. IEEE (2018)","DOI":"10.1109\/SP.2018.00057"},{"key":"6_CR22","unstructured":"Karimi, L., Abdelhakim, M., Joshi, J.: Adaptive ABAC policy learning: a reinforcement learning approach. arXiv preprint arXiv:2105.08587 (2021)"},{"key":"6_CR23","doi-asserted-by":"crossref","unstructured":"Kireev, K., Kulynych, B., Troncoso, C.: Adversarial robustness for tabular data through cost and utility awareness. arXiv preprint arXiv:2208.13058 (2022)","DOI":"10.14722\/ndss.2023.24924"},{"key":"6_CR24","doi-asserted-by":"crossref","unstructured":"Liu, A., Du, X., Wang, N.: Efficient access control permission decision engine based on machine learning. Secur. Commun. Netw. 2021, 3970485 (2021)","DOI":"10.1155\/2021\/3970485"},{"key":"6_CR25","doi-asserted-by":"crossref","unstructured":"Llamas, J.M., Preuveneers, D., Joosen, W.: Effective machine learning-based access control administration through unlearning. In: 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS &PW), pp. 50\u201357. IEEE (2023)","DOI":"10.1109\/EuroSPW59978.2023.00011"},{"key":"6_CR26","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"key":"6_CR27","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.108377","volume":"242","author":"Y Mathov","year":"2022","unstructured":"Mathov, Y., Levy, E., Katzir, Z., Shabtai, A., Elovici, Y.: Not all datasets are born equal: On heterogeneous tabular data and adversarial examples. Knowl. Based Syst. 242, 108377 (2022)","journal-title":"Knowl. Based Syst."},{"issue":"6","key":"6_CR28","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3457607","volume":"54","author":"N Mehrabi","year":"2021","unstructured":"Mehrabi, N., Morstatter, F., Saxena, N., Lerman, K., Galstyan, A.: A survey on bias and fairness in machine learning. ACM Comput. Surv. (CSUR) 54(6), 1\u201335 (2021)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"6_CR29","doi-asserted-by":"publisher","unstructured":"Montanez, K.: Amazon access samples. UCI Machine learning repository (2011). https:\/\/doi.org\/10.24432\/C5JW2K","DOI":"10.24432\/C5JW2K"},{"key":"6_CR30","unstructured":"Nobi, M.N., Gupta, M., Praharaj, L., Abdelsalam, M., Krishnan, R., Sandhu, R.: Machine learning in access control: a taxonomy and survey. arXiv preprint arXiv:2207.01739 (2022)"},{"key":"6_CR31","doi-asserted-by":"crossref","unstructured":"Nobi, M.N., Krishnan, R.: Adversarial attacks in machine learning based access control. In: Italian Conference on Big Data and Data Science (ITADATA2022) (2022)","DOI":"10.1145\/3508398.3511497"},{"key":"6_CR32","doi-asserted-by":"publisher","unstructured":"Nobi, M.N., Krishnan, R., Huang, Y., Sandhu, R.: Administration of machine learning based access control. In: Computer Security\u2013ESORICS 2022: 27th European Symposium on Research in Computer Security, Copenhagen, Denmark, September 26\u201330, 2022, Proceedings, Part II, pp. 189\u2013210. Springer (2022). https:\/\/doi.org\/10.1007\/978-3-031-17146-8_10","DOI":"10.1007\/978-3-031-17146-8_10"},{"key":"6_CR33","doi-asserted-by":"crossref","unstructured":"Nobi, M.N., Krishnan, R., Huang, Y., Shakarami, M., Sandhu, R.: Toward deep learning based access control. In: Proceedings of the Twelveth ACM Conference on Data and Application Security and Privacy, pp. 143\u2013154 (2022)","DOI":"10.1145\/3508398.3511497"},{"key":"6_CR34","unstructured":"OWASP Foundation: OWASP Top Ten (2021). https:\/\/owasp.org\/www-project-top-ten\/. Accessed 20 Jan 2025"},{"key":"6_CR35","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I.: Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 (2016)"},{"key":"6_CR36","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., Swami, A.: Practical black-box attacks against machine learning. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp. 506\u2013519 (2017)","DOI":"10.1145\/3052973.3053009"},{"key":"6_CR37","doi-asserted-by":"crossref","unstructured":"Sandhu, R., Munawer, Q.: How to do discretionary access control using roles. In: Proceedings of the Third ACM Workshop on Role-Based Access Control, pp. 47\u201354 (1998)","DOI":"10.1145\/286884.286893"},{"key":"6_CR38","unstructured":"Seger, C.: An investigation of categorical variable encoding techniques in machine learning: binary versus one-hot and feature hashing (2018)"},{"issue":"4","key":"6_CR39","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3007204","volume":"49","author":"D Servos","year":"2017","unstructured":"Servos, D., Osborn, S.L.: Current research and open problems in attribute-based access control. ACM Comput. Surv. (CSUR) 49(4), 1\u201345 (2017)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"6_CR40","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. IEEE (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"6_CR41","unstructured":"Vincent, B., Xavier, R., Jonathan, A., Thibault, L., Pascal, F., Marcin, D.: Imperceptible adversarial attacks on tabular data. arXiv preprint arXiv:1911.03274 (2019)"},{"key":"6_CR42","doi-asserted-by":"crossref","unstructured":"Xiang, C., et al.: Towards continuous access control validation and forensics. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 113\u2013129 (2019)","DOI":"10.1145\/3319535.3363191"},{"key":"6_CR43","doi-asserted-by":"crossref","unstructured":"Xu, T., Naing, H.M., Lu, L., Zhou, Y.: How do system administrators resolve access-denied issues in the real world? In: Proceedings of the 2017 CHI Conference on Human Factors in Computing Systems, pp. 348\u2013361 (2017)","DOI":"10.1145\/3025453.3025999"},{"issue":"5","key":"6_CR44","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1109\/TDSC.2014.2369048","volume":"12","author":"Z Xu","year":"2014","unstructured":"Xu, Z., Stoller, S.D.: Mining attribute-based access control policies. IEEE Trans. Dependable Secure Comput. 12(5), 533\u2013545 (2014)","journal-title":"IEEE Trans. Dependable Secure Comput."}],"container-title":["Lecture Notes in Computer Science","Availability, Reliability and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-00630-1_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T19:35:24Z","timestamp":1757360124000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-00630-1_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783032006295","9783032006301"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-00630-1_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"9 August 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ARES","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Availability, Reliability and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ghent","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Belgium","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ares-12025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2025.ares-conference.eu","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}