{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:17:43Z","timestamp":1783437463981,"version":"3.54.6"},"reference-count":62,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2025,3,12]],"date-time":"2025-03-12T00:00:00Z","timestamp":1741737600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,3,12]],"date-time":"2025-03-12T00:00:00Z","timestamp":1741737600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"Research Fund KU Leuven"},{"name":"Flemish Research Programme Cybersecurity"},{"name":"Belgian SPF BOSA","award":["06.40.32.33.00.10"],"award-info":[{"award-number":["06.40.32.33.00.10"]}]},{"name":"Belgian SPF BOSA","award":["06.40.32.33.00.10"],"award-info":[{"award-number":["06.40.32.33.00.10"]}]},{"name":"Belgian SPF BOSA","award":["06.40.32.33.00.10"],"award-info":[{"award-number":["06.40.32.33.00.10"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2025,4]]},"DOI":"10.1007\/s10207-025-01003-5","type":"journal-article","created":{"date-parts":[[2025,3,12]],"date-time":"2025-03-12T14:13:32Z","timestamp":1741788812000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Certified unlearning for a trustworthy machine learning-based access control administration"],"prefix":"10.1007","volume":"24","author":[{"given":"Javier","family":"Mart\u00ednez\u00a0Llamas","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Davy","family":"Preuveneers","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,3,12]]},"reference":[{"key":"1003_CR1","doi-asserted-by":"crossref","unstructured":"Abadi, M., Chu, A., Goodfellow, I., McMahan, HB., Mironov, I., Talwar, K., Zhang, L.: Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, pp. 308\u2013318. (2016)","DOI":"10.1145\/2976749.2978318"},{"key":"1003_CR2","doi-asserted-by":"crossref","unstructured":"Alohaly, M., Takabi, H., Blanco, E.: Towards an automated extraction of abac constraints from natural language policies. In: IFIP international conference on ICT systems security and privacy protection, pp. 105\u2013119. Springer (2019)","DOI":"10.1007\/978-3-030-22312-0_8"},{"key":"1003_CR3","unstructured":"Amazon, Kaggle.: Amazon.com - Employee access challenge. https:\/\/www.kaggle.com\/competitions\/amazon-employee-access-challenge\/data (2014). Accessed 31 Oct 2023"},{"key":"1003_CR4","doi-asserted-by":"crossref","unstructured":"Argento, L., Margheri, A., Paci, F., Sassone, V., Zannone, N.: Towards adaptive access control. In: IFIP annual conference on data and applications security and privacy, pp. 99\u2013109. Springer (2018)","DOI":"10.1007\/978-3-319-95729-6_7"},{"key":"1003_CR5","unstructured":"Balle, B., Wang, YX.: Improving the gaussian mechanism for differential privacy: analytical calibration and optimal denoising. In: International conference on machine learning, pp. 394\u2013403. PMLR (2018)"},{"key":"1003_CR6","doi-asserted-by":"crossref","unstructured":"Bauer, L., Cranor, LF., Reeder, RW., Reiter, MK., Vaniea, K.: Real life challenges in access-control management. In: Proceedings of the SIGCHI conference on human factors in computing systems, pp. 899\u2013908. (2009)","DOI":"10.1145\/1518701.1518838"},{"issue":"1","key":"1003_CR7","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1952982.1952984","volume":"14","author":"L Bauer","year":"2011","unstructured":"Bauer, L., Garriss, S., Reiter, M.K.: Detecting and resolving policy misconfigurations in access-control systems. ACM Trans. Inf. Syst. Secur. (TISSEC) 14(1), 1\u201328 (2011)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"1003_CR8","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1007\/s10506-020-09270-4","volume":"29","author":"A Bibal","year":"2021","unstructured":"Bibal, A., Lognoul, M., De Streel, A., Fr\u00e9nay, B.: Legal requirements on explainability in machine learning. Artif. Intell. Law 29, 149\u2013169 (2021)","journal-title":"Artif. Intell. Law"},{"key":"1003_CR9","doi-asserted-by":"crossref","unstructured":"Bourtoule, L., Chandrasekaran, V., Choquette-Choo, CA., Jia, H., Travers, A., Zhang, B., Lie, D., Papernot, N.: Machine unlearning. In: 2021 IEEE symposium on security and privacy (SP), pp. 141\u2013159. IEEE (2021)","DOI":"10.1109\/SP40001.2021.00019"},{"key":"1003_CR10","unstructured":"Brophy, J., Lowd, D.: Machine unlearning for random forests. In: International conference on machine learning, pp. 1092\u20131104. PMLR (2021)"},{"key":"1003_CR11","doi-asserted-by":"crossref","unstructured":"Cao, Y., Yang, J.: Towards making systems forget with machine unlearning. In: 2015 IEEE symposium on security and privacy, pp. 463\u2013480. IEEE (2015)","DOI":"10.1109\/SP.2015.35"},{"key":"1003_CR12","unstructured":"Chaudhuri, K., Monteleoni, C., Sarwate, AD.: Differentially private empirical risk minimization. J. Mach. Learn. Res. 12(3) (2011)"},{"key":"1003_CR13","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1613\/jair.953","volume":"16","author":"NV Chawla","year":"2002","unstructured":"Chawla, N.V., Bowyer, K.W., Hall, L.O., Kegelmeyer, W.P.: Smote: synthetic minority over-sampling technique. J. Artif. Intell. Res. 16, 321\u2013357 (2002)","journal-title":"J. Artif. Intell. Res."},{"key":"1003_CR14","unstructured":"Department for Science, Innovation and Technology: A pro-innovation approach to AI regulation. https:\/\/www.gov.uk\/government\/publications\/ai-regulation-a-pro-innovation-approach\/white-paper (2023). Accessed 31 Oct 2023"},{"key":"1003_CR15","doi-asserted-by":"crossref","unstructured":"Dwork, C.: Differential privacy. In: International colloquium on automata, languages, and programming, pp. 1\u201312. Springer (2006)","DOI":"10.1007\/11787006_1"},{"key":"1003_CR16","doi-asserted-by":"crossref","unstructured":"Dwork, C., McSherry, F., Nissim, K., Smith, A.: Calibrating noise to sensitivity in private data analysis. In: Theory of cryptography: third theory of cryptography conference, TCC 2006, New York, NY, USA, March 4-7, 2006. Proceedings 3, pp. 265\u2013284. Springer (2006)","DOI":"10.1007\/11681878_14"},{"key":"1003_CR17","unstructured":"European Commission: On artificial intelligence\u2013a European approach to excellence and trust. https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:52020DC0065 (2020). Accessed 31 Oct 2023"},{"key":"1003_CR18","unstructured":"European Parliament, Council of the European Union: General data protection regulation (GDPR). https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj (2016). Accessed 31 Oct 2023"},{"key":"1003_CR19","unstructured":"Ferraiolo, D., Cugini, J., Kuhn, DR., et\u00a0al.: Role-based access control (rbac): Features and motivations. In: Proceedings of 11th annual computer security application conference, pp. 241\u201348. (1995)"},{"key":"1003_CR20","doi-asserted-by":"crossref","unstructured":"Fisler, K., Krishnamurthi, S., Meyerovich, LA., Tschantz, MC.: Verification and change-impact analysis of access-control policies. In: Proceedings of the 27th international conference on Software engineering, pp. 196\u2013205. (2005)","DOI":"10.1109\/ICSE.2005.1553562"},{"issue":"4","key":"1003_CR21","doi-asserted-by":"crossref","first-page":"128","DOI":"10.1016\/S1364-6613(99)01294-2","volume":"3","author":"RM French","year":"1999","unstructured":"French, R.M.: Catastrophic forgetting in connectionist networks. Trends Cognit. Sci. 3(4), 128\u2013135 (1999)","journal-title":"Trends Cognit. Sci."},{"key":"1003_CR22","doi-asserted-by":"crossref","unstructured":"Gilpin, LH., Bau, D., Yuan, BZ., Bajwa, A., Specter, M., Kagal, L.: Explaining explanations: an overview of interpretability of machine learning. In: 2018 IEEE 5th International conference on data science and advanced analytics (DSAA), pp. 80\u201389. IEEE (2018)","DOI":"10.1109\/DSAA.2018.00018"},{"key":"1003_CR23","unstructured":"Ginart, A., Guan, M., Valiant, G., Zou, JY.: Making ai forget you: data deletion in machine learning. Adv Neural Inf Process Syst. 32 (2019)"},{"key":"1003_CR24","unstructured":"Google, AI.: Google responsible AI practices. https:\/\/ai.google\/responsibility\/responsible-ai-practices\/ (2023). Accessed 31 Oct 2023"},{"key":"1003_CR25","first-page":"11516","volume":"35","author":"L Graves","year":"2021","unstructured":"Graves, L., Nagisetty, V., Ganesh, V.: Amnesiac machine learning. Proc. AAAI Conf. Artif. Intell. 35, 11516\u201311524 (2021)","journal-title":"Proc. AAAI Conf. Artif. Intell."},{"key":"1003_CR26","doi-asserted-by":"crossref","unstructured":"Gumma, V., Mitra, B., Dey, S., Patel, PS., Suman, S., Das, S.: Pammela: policy administration methodology using machine learning. arXiv preprint arXiv:2111.07060 (2021)","DOI":"10.5220\/0011272400003283"},{"key":"1003_CR27","unstructured":"Guo, C., Goldstein, T., Hannun, A., Van Der\u00a0Maaten, L.: Certified data removal from machine learning models. arXiv preprint arXiv:1911.03030 (2019)"},{"key":"1003_CR28","unstructured":"Hleg, A.: Ethics guidelines for trustworthy ai. B-1049 Brussels (2019)"},{"key":"1003_CR29","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.IR.8360","volume-title":"Machine learning for access control policy verification","author":"V Hu","year":"2021","unstructured":"Hu, V.: Machine learning for access control policy verification. Tech. rep, Technical Report (2021)"},{"issue":"12","key":"1003_CR30","first-page":"80","volume":"49","author":"VC Hu","year":"2016","unstructured":"Hu, V.C., Kuhn, R.: Access control policy verification. Computer 49(12), 80\u201383 (2016)","journal-title":"Computer"},{"issue":"2","key":"1003_CR31","first-page":"85","volume":"48","author":"VC Hu","year":"2015","unstructured":"Hu, V.C., Kuhn, D.R., Ferraiolo, D.F., Voas, J.: Attribute-based access control. Computer 48(2), 85\u201388 (2015)","journal-title":"Computer"},{"key":"1003_CR32","doi-asserted-by":"crossref","unstructured":"Huang, L., Joseph, AD., Nelson, B., Rubinstein, BI., Tygar, JD.: Adversarial machine learning. In: Proceedings of the 4th ACM workshop on security and artificial intelligence, pp. 43\u201358. (2011)","DOI":"10.1145\/2046684.2046692"},{"key":"1003_CR33","unstructured":"IBM Research: Trustworthy AI | IBM Research. https:\/\/research.ibm.com\/topics\/trustworthy-ai (2023). Accessed 31 Oct 2023"},{"key":"1003_CR34","unstructured":"Izzo, Z., Smart, MA., Chaudhuri, K., Zou, J.: Approximate data deletion from machine learning models. In: International conference on artificial intelligence and statistics, pp. 2008\u20132016. PMLR (2021)"},{"key":"1003_CR35","doi-asserted-by":"crossref","unstructured":"Jagielski, M., Oprea, A., Biggio, B., Liu, C., Nita-Rotaru, C., Li, B.: Manipulating machine learning: poisoning attacks and countermeasures for regression learning. In: 2018 IEEE symposium on security and privacy (SP), pp. 19\u201335. IEEE (2018)","DOI":"10.1109\/SP.2018.00057"},{"issue":"4","key":"1003_CR36","doi-asserted-by":"crossref","first-page":"242","DOI":"10.1109\/TDSC.2007.70225","volume":"5","author":"S Jha","year":"2008","unstructured":"Jha, S., Li, N., Tripunitara, M., Wang, Q., Winsborough, W.: Towards formal verification of role-based access control policies. IEEE Trans. Dependable Secur. Comput. 5(4), 242\u2013255 (2008)","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"1003_CR37","unstructured":"Karimi, L., Abdelhakim, M., Joshi, J.: Adaptive abac policy learning: a reinforcement learning approach. arXiv preprint arXiv:2105.08587 (2021)"},{"issue":"13","key":"1003_CR38","doi-asserted-by":"crossref","first-page":"3521","DOI":"10.1073\/pnas.1611835114","volume":"114","author":"J Kirkpatrick","year":"2017","unstructured":"Kirkpatrick, J., Pascanu, R., Rabinowitz, N., Veness, J., Desjardins, G., Rusu, A.A., Milan, K., Quan, J., Ramalho, T., Grabska-Barwinska, A., et al.: Overcoming catastrophic forgetting in neural networks. Proc. Natl Acad. Sci. 114(13), 3521\u20133526 (2017)","journal-title":"Proc. Natl Acad. Sci."},{"key":"1003_CR39","doi-asserted-by":"crossref","unstructured":"Kuhn, D.R., Hu, V., Ferraiolo, D.F., Kacker, R.N., Lei, Y.: Pseudo-exhaustive testing of attribute based access control rules. In: 2016 IEEE Ninth international conference on software testing, pp. 51\u201358. IEEE, Verification and Validation Workshops (ICSTW) (2016)","DOI":"10.1109\/ICSTW.2016.35"},{"issue":"9","key":"1003_CR40","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3555803","volume":"55","author":"B Li","year":"2023","unstructured":"Li, B., Qi, P., Liu, B., Di, S., Liu, J., Pei, J., Yi, J., Zhou, B.: Trustworthy AI: from principles to practices. ACM Comput. Surv. 55(9), 1\u201346 (2023)","journal-title":"ACM Comput. Surv."},{"key":"1003_CR41","doi-asserted-by":"crossref","unstructured":"Liu, A., Du, X., Wang, N.: Efficient access control permission decision engine based on machine learning. Secur. Commun. Netw. 2021 (2021)","DOI":"10.1155\/2021\/3970485"},{"key":"1003_CR42","doi-asserted-by":"crossref","unstructured":"Llamas, JM., Preuveneers, D., Joosen, W.: Effective machine learning-based access control administration through unlearning. In: 2023 IEEE European symposium on security and privacy workshops (EuroS &PW), pp. 50\u201357. IEEE (2023)","DOI":"10.1109\/EuroSPW59978.2023.00011"},{"key":"1003_CR43","unstructured":"Madry, A., Makelov, A,. Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"issue":"6","key":"1003_CR44","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3457607","volume":"54","author":"N Mehrabi","year":"2021","unstructured":"Mehrabi, N., Morstatter, F., Saxena, N., Lerman, K., Galstyan, A.: A survey on bias and fairness in machine learning. ACM Comput. Surv. (CSUR) 54(6), 1\u201335 (2021)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"1003_CR45","unstructured":"Meta: Responsible AI - AI at Meta. https:\/\/ai.meta.com\/responsible-ai\/ (2023). Accessed 31 Oct 2023"},{"key":"1003_CR46","unstructured":"Montanez, K.: Amazon access samples. UCI machine learning repository, DOI: https:\/\/doi.org\/10.24432\/C5JW2K. (2011)"},{"key":"1003_CR47","unstructured":"Neel, S., Roth, A., Sharifi-Malvajerdi, S.: Descent-to-delete: gradient-based methods for machine unlearning. In: Algorithmic learning theory, pp. 931\u2013962. PMLR (2021)"},{"key":"1003_CR48","doi-asserted-by":"crossref","unstructured":"Ng, AY.: Feature selection, l 1 vs. l 2 regularization, and rotational invariance. In: Proceedings of the twenty-first international conference on Machine learning, pp. 78 (2004)","DOI":"10.1145\/1015330.1015435"},{"key":"1003_CR49","doi-asserted-by":"crossref","unstructured":"Nobi, MN., Krishnan, R., Huang, Y., Sandhu, R.: Administration of machine learning based access control. In: Computer security\u2013ESORICS 2022: 27th European symposium on research in computer security, Copenhagen, Denmark, September 26\u201330, 2022, Proceedings, Part II, pp. 189\u2013210. Springer (2022a)","DOI":"10.1007\/978-3-031-17146-8_10"},{"key":"1003_CR50","doi-asserted-by":"crossref","unstructured":"Nobi, MN., Krishnan, R., Huang, Y., Shakarami, M., Sandhu, R.: Toward deep learning based access control. In: Proceedings of the twelveth ACM conference on data and application security and privacy, pp. 143\u2013154. (2022b)","DOI":"10.1145\/3508398.3511497"},{"key":"1003_CR51","unstructured":"OpenAI: Our approach to AI safety. https:\/\/openai.com\/blog\/our-approach-to-ai-safety (2023). Accessed 31 Oct 2023"},{"key":"1003_CR52","doi-asserted-by":"crossref","unstructured":"Osborn, S.: Mandatory access control and role-based access control revisited. In: Proceedings of the second ACM workshop on Role-based access control, pp. 31\u201340. (1997)","DOI":"10.1145\/266741.266751"},{"key":"1003_CR53","unstructured":"OWASP Foundation: OWASP Top Ten. https:\/\/owasp.org\/www-project-top-ten\/ (2021). Accessed 01 Dec 2023"},{"key":"1003_CR54","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I.: Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 (2016)"},{"key":"1003_CR55","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1007\/s00146-020-00992-2","volume":"36","author":"H Roberts","year":"2021","unstructured":"Roberts, H., Cowls, J., Morley, J., Taddeo, M., Wang, V., Floridi, L.: The Chinese approach to artificial intelligence: an analysis of policy, ethics, and regulation. AI Soc. 36, 59\u201377 (2021)","journal-title":"AI Soc."},{"key":"1003_CR56","doi-asserted-by":"crossref","unstructured":"Sandhu, R., Munawer, Q.: How to do discretionary access control using roles. In: Proceedings of the third ACM workshop on Role-based access control, pp. 47\u201354. (1998)","DOI":"10.1145\/286884.286893"},{"key":"1003_CR57","doi-asserted-by":"crossref","unstructured":"Schelter, S., Grafberger, S., Dunning, T.: Hedgecut: maintaining randomised trees for low-latency machine unlearning. In: Proceedings of the 2021 international conference on management of Data, pp. 1545\u20131557. (2021)","DOI":"10.1145\/3448016.3457239"},{"key":"1003_CR58","unstructured":"Sekhari, A., Acharya, J., Kamath, G., Suresh, AT.: Remember what you want to forget: Algorithms for machine unlearning. Advances in Neural Information Processing Systems 34:18,075\u201318,086 (2021)"},{"issue":"4","key":"1003_CR59","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3007204","volume":"49","author":"D Servos","year":"2017","unstructured":"Servos, D., Osborn, S.L.: Current research and open problems in attribute-based access control. ACM Comput. Surv. (CSUR) 49(4), 1\u201345 (2017)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"1003_CR60","unstructured":"Warnecke, A., Pirch, L., Wressnegger, C., Rieck, K.: Machine unlearning of features and labels. arXiv preprint arXiv:2108.11577. (2021)"},{"key":"1003_CR61","doi-asserted-by":"crossref","unstructured":"Xu, T., Naing, HM., Lu, L., Zhou, Y.: How do system administrators resolve access-denied issues in the real world? In: Proceedings of the 2017 CHI conference on human factors in computing systems, pp. 348\u2013361 (2017)","DOI":"10.1145\/3025453.3025999"},{"issue":"5","key":"1003_CR62","doi-asserted-by":"crossref","first-page":"533","DOI":"10.1109\/TDSC.2014.2369048","volume":"12","author":"Z Xu","year":"2014","unstructured":"Xu, Z., Stoller, S.D.: Mining attribute-based access control policies. IEEE Trans. Dependable Secur. Comput. 12(5), 533\u2013545 (2014)","journal-title":"IEEE Trans. Dependable Secur. Comput."}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-025-01003-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-025-01003-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-025-01003-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,30]],"date-time":"2025-03-30T08:04:30Z","timestamp":1743321870000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-025-01003-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,12]]},"references-count":62,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,4]]}},"alternative-id":["1003"],"URL":"https:\/\/doi.org\/10.1007\/s10207-025-01003-5","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,12]]},"assertion":[{"value":"12 March 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"All authors declare that they have no Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"94"}}