{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,21]],"date-time":"2026-06-21T14:34:42Z","timestamp":1782052482871,"version":"3.54.5"},"reference-count":111,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2024,12,23]],"date-time":"2024-12-23T00:00:00Z","timestamp":1734912000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,4,30]]},"abstract":"<jats:p>Administrator-centered access control failures can cause data breaches, putting organizations at risk of financial loss and reputation damage. Existing graphical policy configuration tools and automated policy generation frameworks attempt to help administrators configure and generate access control policies by avoiding such failures. However, graphical policy configuration tools are prone to human errors, making them unusable. On the other hand, automated policy generation frameworks are prone to erroneous predictions, making them unreliable. Therefore, to find ways to improve their usability and reliability, we conducted a Systematic Literature Review analyzing 49 publications. The thematic analysis of the publications revealed that graphical policy configuration tools are developed to write and visualize policies manually. Moreover, automated policy generation frameworks are developed using machine learning (ML) and natural language processing (NLP) techniques to automatically generate access control policies from high-level requirement specifications. Despite their utility in the access control domain, limitations of these tools, such as the lack of flexibility, and limitations of frameworks, such as the lack of domain adaptation, negatively affect their usability and reliability, respectively. Our study offers recommendations to address these limitations through real-world applications and recent advancements in the NLP domain, paving the way for future research.<\/jats:p>","DOI":"10.1145\/3706057","type":"journal-article","created":{"date-parts":[[2024,11,28]],"date-time":"2024-11-28T12:03:29Z","timestamp":1732795409000},"page":"1-37","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["SoK: Access Control Policy Generation from High-level Natural Language Requirements"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-7932-5204","authenticated-orcid":false,"given":"Sakuna Harinda","family":"Jayasundara","sequence":"first","affiliation":[{"name":"School of Computer Science, University of Auckland, Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0059-0376","authenticated-orcid":false,"given":"Nalin Asanka","family":"Gamagedara Arachchilage","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Auckland, Auckland, New Zealand and School of Computing Technologies, RMIT University, Melbourne, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6987-0803","authenticated-orcid":false,"given":"Giovanni","family":"Russello","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Auckland, Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,23]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/3589608.3593844"},{"key":"e_1_3_2_3_2","unstructured":"Meta AI. 2024. Introducing Llama 3.1: Our most capable models to date. https:\/\/ai.meta.com\/blog\/meta-llama-3-1"},{"key":"e_1_3_2_4_2","first-page":"847","volume-title":"International Conference on Soft Computing and Pattern Recognition","author":"Alohaly Manar","year":"2021","unstructured":"Manar Alohaly and Daniel Takabi. 2021. A hybrid policy engineering approach for attribute-based access control (ABAC). In International Conference on Soft Computing and Pattern Recognition. Springer, 847\u2013857."},{"key":"e_1_3_2_5_2","volume-title":"Twelfth Symposium on Usable Privacy and Security (SOUPS 2016)","author":"Alohaly Manar","year":"2016","unstructured":"Manar Alohaly and Hassan Takabi. 2016. Better privacy indicators: A new approach to quantification of privacy policies. In Twelfth Symposium on Usable Privacy and Security (SOUPS 2016)."},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3205977.3205984"},{"issue":"1","key":"e_1_3_2_7_2","first-page":"1","article-title":"Automated extraction of attributes from natural language attribute-based access control (ABAC) policies","volume":"2","author":"Alohaly Manar","year":"2019","unstructured":"Manar Alohaly, Hassan Takabi, and Eduardo Blanco. 2019. Automated extraction of attributes from natural language attribute-based access control (ABAC) policies. Cybersecurity 2, 1 (2019), 1\u201325.","journal-title":"Cybersecurity"},{"key":"e_1_3_2_8_2","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1007\/978-3-030-22312-0_8","volume-title":"IFIP International Conference on ICT Systems Security and Privacy Protection","author":"Alohaly Manar","year":"2019","unstructured":"Manar Alohaly, Hassan Takabi, and Eduardo Blanco. 2019. Towards an automated extraction of ABAC constraints from natural language policies. In IFIP International Conference on ICT Systems Security and Privacy Protection. Springer, 105\u2013119."},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/1031607.1031672"},{"issue":"1","key":"e_1_3_2_10_2","first-page":"437","article-title":"Ontology-based security policy translation","volume":"5","author":"Basile Cataldo","year":"2010","unstructured":"Cataldo Basile, Antonio Lioy, Salvatore Scozzi, and Marco Vallini. 2010. Ontology-based security policy translation. Journal of Information Assurance and Security 5, 1 (2010), 437\u2013445.","journal-title":"Journal of Information Assurance and Security"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/1518701.1518838"},{"key":"e_1_3_2_12_2","first-page":"405","volume-title":"International Conference on Human-Computer Interaction","author":"Bertard Anja","year":"2020","unstructured":"Anja Bertard and Jennifer-Kathrin Kopp. 2020. Using Sugiyama-styled graphs to directly manipulate role-based access control configurations. In International Conference on Human-Computer Interaction. Springer, 405\u2013412."},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.5555\/1596409.1596416"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/1280680.1280693"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1037\/13620-004"},{"key":"e_1_3_2_16_2","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1145\/1073001.1073005","volume-title":"Proceedings of the 2005 Symposium on Usable Privacy and Security","author":"Brodie Carolyn","year":"2005","unstructured":"Carolyn Brodie, Clare-Marie Karat, John Karat, and Jinjuan Feng. 2005. Usable security and privacy: A case study of developing privacy management tools. In Proceedings of the 2005 Symposium on Usable Privacy and Security. 35\u201343."},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/1143120.1143123"},{"key":"e_1_3_2_18_2","unstructured":"J. Brooke and others. 1996. SUS-A quick and dirty usability scale. Usability Evaluation in Industry 189 194 (1996) 4--7."},{"issue":"9","key":"e_1_3_2_19_2","first-page":"835","article-title":"\u2018R-what?\u2019 Development of a role-based access control policy-writing tool for e-scientists","volume":"35","author":"Brostoff Sacha","year":"2005","unstructured":"Sacha Brostoff, M. Angela Sasse, David Chadwick, James Cunningham, Uche Mbanaso, and Sassa Otenko. 2005. \u2018R-what?\u2019 Development of a role-based access control policy-writing tool for e-scientists. Software: Practice and Experience 35, 9 (2005), 835\u2013856.","journal-title":"Software: Practice and Experience"},{"key":"e_1_3_2_20_2","first-page":"20","volume-title":"Proceedings of the Second Symposium on Usable Privacy and Security","author":"Cao Xiang","year":"2006","unstructured":"Xiang Cao and Lee Iverson. 2006. Intentional access management: Making access control usable for end-users. In Proceedings of the Second Symposium on Usable Privacy and Security. 20\u201331."},{"key":"e_1_3_2_21_2","first-page":"2493","article-title":"Natural language processing (almost) from scratch","volume":"12","author":"Collobert Ronan","year":"2011","unstructured":"Ronan Collobert, Jason Weston, L\u00e9on Bottou, Michael Karlen, Koray Kavukcuoglu, and Pavel Kuksa. 2011. Natural language processing (almost) from scratch. Journal of Machine Learning Research 12, Article (2011), 2493\u20132537.","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2011.36"},{"key":"e_1_3_2_23_2","article-title":"Neural open information extraction","author":"Cui Lei","year":"2018","unstructured":"Lei Cui, Furu Wei, and Ming Zhou. 2018. Neural open information extraction. arXiv preprint arXiv:1805.04270 (2018).","journal-title":"arXiv preprint arXiv:1805.04270"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-024-45563-x"},{"key":"e_1_3_2_25_2","first-page":"119","volume-title":"Requirements Engineering: Foundation for Software Quality: 24th International Working Conference, REFSQ 2018, Utrecht, The Netherlands, March 19-22, 2018, Proceedings 24","author":"Dalpiaz Fabiano","year":"2018","unstructured":"Fabiano Dalpiaz, Ivor van der Schalk, and Garm Lucassen. 2018. Pinpointing ambiguity and incompleteness in requirements engineering via information visualization and NLP. In Requirements Engineering: Foundation for Software Quality: 24th International Working Conference, REFSQ 2018, Utrecht, The Netherlands, March 19-22, 2018, Proceedings 24. Springer, 119\u2013135."},{"key":"e_1_3_2_26_2","first-page":"1","article-title":"A systematic mapping study on automated analysis of privacy policies","author":"Alamo Jose M. del","year":"2022","unstructured":"Jose M. del Alamo, Danny S. Guaman, Boni Garc\u00eda, and Ana Diez. 2022. A systematic mapping study on automated analysis of privacy policies. Computing (2022), 1\u201324.","journal-title":"Computing"},{"key":"e_1_3_2_27_2","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1016\/j.compind.2018.08.007","article-title":"A systematic review of augmented reality content-related techniques for knowledge transfer in maintenance applications","volume":"103","author":"Amo I\u00f1igo Fern\u00e1ndez del","year":"2018","unstructured":"I\u00f1igo Fern\u00e1ndez del Amo, John Ahmet Erkoyuncu, Rajkumar Roy, Riccardo Palmarini, and Demetrius Onoufriou. 2018. A systematic review of augmented reality content-related techniques for knowledge transfer in maintenance applications. Computers in Industry 103 (2018), 47\u201371.","journal-title":"Computers in Industry"},{"key":"e_1_3_2_28_2","volume-title":"24th Large Installation System Administration Conference (LISA 10)","author":"Delaet Thomas","year":"2010","unstructured":"Thomas Delaet, Wouter Joosen, and Bart Vanbrabant. 2010. A survey of system configuration tools. In 24th Large Installation System Administration Conference (LISA 10)."},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3469886"},{"key":"e_1_3_2_30_2","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. BERT: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018).","journal-title":"arXiv preprint arXiv:1810.04805"},{"key":"e_1_3_2_31_2","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1109\/SPW.2016.16","volume-title":"2016 IEEE Security and Privacy Workshops (SPW)","author":"Fatema Kaniz","year":"2016","unstructured":"Kaniz Fatema, Christophe Debruyne, Dave Lewis, Declan OSullivan, John P. Morrison, and Abdullah-Al Mazed. 2016. A semi-automated methodology for extracting access control rules from the European data protection directive. In 2016 IEEE Security and Privacy Workshops (SPW). IEEE, 25\u201332."},{"key":"e_1_3_2_32_2","volume-title":"Conducting Research Literature Reviews: From the Internet to Paper","author":"Fink Arlene","year":"2019","unstructured":"Arlene Fink. 2019. Conducting Research Literature Reviews: From the Internet to Paper. Sage publications."},{"key":"e_1_3_2_33_2","unstructured":"Firstpost. 2024. AI companies are finally looking at small language models and expect to make big bucks. https:\/\/www.firstpost.com\/tech\/ai-companies-are-finally-looking-at-small-language-models-and-expect-to-make-big-bucks-13772823.html"},{"key":"e_1_3_2_34_2","first-page":"378","article-title":"Assessing the reliability, validity and adaptability of PSSUQ","author":"Fruhling Ann","year":"2005","unstructured":"Ann Fruhling and Sang Lee. 2005. Assessing the reliability, validity and adaptability of PSSUQ. AMCIS 2005 Proceedings (2005), 378.","journal-title":"AMCIS 2005 Proceedings"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.3390\/info13020083"},{"key":"e_1_3_2_36_2","first-page":"171","volume-title":"IFIP Annual Conference on Data and Applications Security and Privacy","author":"Heaps John","year":"2021","unstructured":"John Heaps, Ram Krishnan, Yufei Huang, Jianwei Niu, and Ravi Sandhu. 2021. Access control policy generation from user stories using machine learning. In IFIP Annual Conference on Data and Applications Security and Privacy. Springer, 171\u2013188."},{"key":"e_1_3_2_37_2","first-page":"256","volume-title":"Proceedings of Machine Translation Summit XVIII: Research Track","author":"Ho Anh Khoa Ngo","year":"2021","unstructured":"Anh Khoa Ngo Ho and Fran\u00e7ois Yvon. 2021. Optimizing word alignments with better subword tokenization. In Proceedings of Machine Translation Summit XVIII: Research Track. 256\u2013269."},{"key":"e_1_3_2_38_2","first-page":"2790","volume-title":"International Conference on Machine Learning","author":"Houlsby Neil","year":"2019","unstructured":"Neil Houlsby, Andrei Giurgiu, Stanislaw Jastrzebski, Bruna Morrone, Quentin De Laroussilhe, Andrea Gesmundo, Mona Attariyan, and Sylvain Gelly. 2019. Parameter-efficient transfer learning for NLP. In International Conference on Machine Learning. PMLR, 2790\u20132799."},{"key":"e_1_3_2_39_2","article-title":"LoRA: Low-rank adaptation of large language models","author":"Hu Edward J.","year":"2021","unstructured":"Edward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen. 2021. LoRA: Low-rank adaptation of large language models. arXiv preprint arXiv:2106.09685 (2021).","journal-title":"arXiv preprint arXiv:2106.09685"},{"key":"e_1_3_2_40_2","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1145\/1408664.1408675","volume-title":"Proceedings of the 4th Symposium on Usable Privacy and Security","author":"Inglesant Philip","year":"2008","unstructured":"Philip Inglesant, M. Angela Sasse, David Chadwick, and Lei Lei Shi. 2008. Expressions of expertness: The virtuous circle of natural language for access control policy specification. In Proceedings of the 4th Symposium on Usable Privacy and Security. 77\u201388."},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/1837110.1837121"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/POLICY.2010.28"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/1124772.1124787"},{"key":"e_1_3_2_44_2","article-title":"Human factors in security research: Lessons learned from 2008-2018","author":"Kaur Mannat","year":"2021","unstructured":"Mannat Kaur, Michel van Eeten, Marijn Janssen, Kevin Borgolte, and Tobias Fiebig. 2021. Human factors in security research: Lessons learned from 2008-2018. arXiv preprint arXiv:2103.13287 (2021).","journal-title":"arXiv preprint arXiv:2103.13287"},{"issue":"2004","key":"e_1_3_2_45_2","first-page":"1","article-title":"Procedures for performing systematic reviews","volume":"33","author":"Kitchenham Barbara","year":"2004","unstructured":"Barbara Kitchenham. 2004. Procedures for performing systematic reviews. Keele, UK, Keele University 33, 2004 (2004), 1\u201326.","journal-title":"Keele, UK, Keele University"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/775265.775268"},{"key":"e_1_3_2_47_2","doi-asserted-by":"crossref","first-page":"1444","DOI":"10.18653\/v1\/D15-1169","volume-title":"Proceedings of the 2015 Conference on Empirical Methods in Natural Language Processing","author":"Lewis Mike","year":"2015","unstructured":"Mike Lewis, Luheng He, and Luke Zettlemoyer. 2015. Joint A* CCG parsing and semantic role labelling. In Proceedings of the 2015 Conference on Empirical Methods in Natural Language Processing. 1444\u20131454."},{"key":"e_1_3_2_48_2","doi-asserted-by":"crossref","first-page":"366","DOI":"10.1109\/MILCOM.2015.7357470","volume-title":"MILCOM 2015-2015 IEEE Military Communications Conference","author":"Li Ang","year":"2015","unstructured":"Ang Li, Qinghua Li, Vincent C. Hu, and Jia Di. 2015. Evaluating the capability and performance of access control policy verification tools. In MILCOM 2015-2015 IEEE Military Communications Conference. IEEE, 366\u2013371."},{"key":"e_1_3_2_49_2","article-title":"Evaluating quantized large language models","author":"Li Shiyao","year":"2024","unstructured":"Shiyao Li, Xuefei Ning, Luning Wang, Tengxuan Liu, Xiangsheng Shi, Shengen Yan, Guohao Dai, Huazhong Yang, and Yu Wang. 2024. Evaluating quantized large language models. arXiv preprint arXiv:2402.18158 (2024).","journal-title":"arXiv preprint arXiv:2402.18158"},{"key":"e_1_3_2_50_2","first-page":"104","volume-title":"2017 International Conference on Software Security and Assurance (ICSSA)","author":"Liu Xiao","year":"2017","unstructured":"Xiao Liu, Brett Holden, and Dinghao Wu. 2017. Automated synthesis of access control lists. In 2017 International Conference on Software Security and Assurance (ICSSA). IEEE, 104\u2013109."},{"key":"e_1_3_2_51_2","unstructured":"Yinhan Liu Myle Ott Naman Goyal Jingfei Du Mandar Joshi Danqi Chen Omer Levy Mike Lewis Luke Zettlemoyer and Veselin Stoyanov. 2019. RoBERTa: A Robustly Optimized BERT Pretraining Approach. arxiv:1907.11692 [cs.CL]"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.5555\/311445"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2005.04.009"},{"key":"e_1_3_2_54_2","first-page":"425","article-title":"Appendix B: iTrust electronic health care system case study","author":"Meneely Andrew","year":"2012","unstructured":"Andrew Meneely, Ben Smith, and Laurie Williams. 2012. Appendix B: iTrust electronic health care system case study. Software and Systems Traceability (2012), 425.","journal-title":"Software and Systems Traceability"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1145\/3439726"},{"key":"e_1_3_2_56_2","first-page":"215","volume-title":"International Conference on Information Systems Security and Privacy","author":"Morisset Charles","year":"2018","unstructured":"Charles Morisset and David Sanchez. 2018. On building a visualisation tool for access control policies. In International Conference on Information Systems Security and Privacy. Springer, 215\u2013239."},{"key":"e_1_3_2_57_2","first-page":"117","volume-title":"ICISSP","author":"Morisset Charles","year":"2018","unstructured":"Charles Morisset and David Sanchez. 2018. VisABAC: A tool for visualising ABAC policies. In ICISSP. 117\u2013126."},{"key":"e_1_3_2_58_2","first-page":"82","volume-title":"IFIP Annual Conference on Data and Applications Security and Privacy","author":"Narouei Masoud","year":"2017","unstructured":"Masoud Narouei, Hamed Khanpour, and Hassan Takabi. 2017. Identification of access control policy sentences from natural language policy documents. In IFIP Annual Conference on Data and Applications Security and Privacy. Springer, 82\u2013100."},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1145\/3078861.3078874"},{"key":"e_1_3_2_60_2","first-page":"137","volume-title":"IFIP International Conference on Information Security Theory and Practice","author":"Narouei Masoud","year":"2015","unstructured":"Masoud Narouei and Hassan Takabi. 2015. Automatic top-down role engineering framework using natural language processing techniques. In IFIP International Conference on Information Security Theory and Practice. Springer, 137\u2013152."},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1145\/2752952.2752958"},{"issue":"3","key":"e_1_3_2_62_2","first-page":"506","article-title":"Automatic extraction of access control policies from natural language documents","volume":"17","author":"Narouei Masoud","year":"2018","unstructured":"Masoud Narouei, Hassan Takabi, and Rodney Nielsen. 2018. Automatic extraction of access control policies from natural language documents. IEEE Transactions on Dependable and Secure Computing 17, 3 (2018), 506\u2013517.","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_3_2_63_2","volume-title":"2015 International Conference on Information Systems Security and Privacy (ICISSP)","unstructured":"Henrik Nergaard, Nils Ulltveit-Moe, Terje Gj, and others. 2015. A scratch-based graphical policy editor for XACML. In 2015 International Conference on Information Systems Security and Privacy (ICISSP), IEEE, 1--9."},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.5555\/2821575"},{"key":"e_1_3_2_65_2","unstructured":"Jakob Nielsen. 2005. Ten usability heuristics. Nielsen Norman Group."},{"key":"e_1_3_2_66_2","article-title":"Machine learning in access control: A taxonomy and survey","author":"Nobi Mohammad Nur","year":"2022","unstructured":"Mohammad Nur Nobi, Maanak Gupta, Lopamudra Praharaj, Mahmoud Abdelsalam, Ram Krishnan, and Ravi Sandhu. 2022. Machine learning in access control: A taxonomy and survey. arXiv preprint arXiv:2207.01739 (2022).","journal-title":"arXiv preprint arXiv:2207.01739"},{"key":"e_1_3_2_67_2","unstructured":"OpenAI. 2023. GPT-4 Technical Report. arxiv:2303.08774 [cs.CL]"},{"key":"e_1_3_2_68_2","article-title":"Training language models to follow instructions with human feedback","author":"Ouyang Long","year":"2022","unstructured":"Long Ouyang, Jeff Wu, Xu Jiang, Diogo Almeida, Carroll L. Wainwright, Pamela Mishkin, Chong Zhang, Sandhini Agarwal, Katarina Slama, Alex Ray, et\u00a0al. 2022. Training language models to follow instructions with human feedback. arXiv preprint arXiv:2203.02155 (2022).","journal-title":"arXiv preprint arXiv:2203.02155"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1145\/3146025"},{"key":"e_1_3_2_70_2","unstructured":"Carly Page. 2023. Microsoft AI researchers accidentally exposed terabytes of internal sensitive data. https:\/\/techcrunch.com\/2023\/09\/18\/microsoft-ai-researchers-accidentally-exposed-terabytes-of-internal-sensitive-data\/"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1186\/s13643-021-01626-4"},{"key":"e_1_3_2_72_2","unstructured":"Danny Palmer. 2021. The cybersecurity jobs crisis is getting worse and companies are making basic mistakes with hiring. https:\/\/www.zdnet.com\/article\/the-cybersecurity-jobs-crisis-is-getting-worse-and-companies-are-making-basic-mistakes-with-hiring\/"},{"key":"e_1_3_2_73_2","first-page":"1\u2013336","author":"Papaioannou Diana","year":"2016","unstructured":"Diana Papaioannou, Anthea Sutton, and Andrew Booth. 2016. Systematic Approaches to a Successful Literature Review. SAGE Publications, 2016, 1\u2013336.","journal-title":"Systematic Approaches to a Successful Literature Review"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2013.02.002"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.5555\/3455716.3455856"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1145\/1357054.1357285"},{"key":"e_1_3_2_77_2","doi-asserted-by":"crossref","first-page":"2065","DOI":"10.1145\/1978942.1979243","volume-title":"Proceedings of the SIGCHI Conference on Human Factors in Computing Systems","author":"Reeder Robert W.","year":"2011","unstructured":"Robert W. Reeder, Lujo Bauer, Lorrie F. Cranor, Michael K. Reiter, and Kami Vaniea. 2011. More than skin deep: Measuring effects of the underlying model on access-control system usability. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems. 2065\u20132074."},{"key":"e_1_3_2_78_2","first-page":"141","volume-title":"IFIP Conference on Human-Computer Interaction","author":"Reeder Robert W.","year":"2007","unstructured":"Robert W. Reeder, Clare-Marie Karat, John Karat, and Carolyn Brodie. 2007. Usability challenges in security and privacy policy-authoring interfaces. In IFIP Conference on Human-Computer Interaction. Springer, 141\u2013155."},{"issue":"2","key":"e_1_3_2_79_2","first-page":"1","article-title":"A parser to support the definition of access control policies and rules using natural languages","volume":"44","author":"Rosa Marco","year":"2020","unstructured":"Marco Rosa, Jo\u00e3o Paulo Barraca, Andr\u00e9 Zuquete, and Nelson Pacheco Rocha. 2020. A parser to support the definition of access control policies and rules using natural languages. Journal of Medical Systems 44, 2 (2020), 1\u201312.","journal-title":"Journal of Medical Systems"},{"key":"e_1_3_2_80_2","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1145\/2993901.2993903","volume-title":"Proceedings of the Sixth Workshop on Beyond Time and Errors on Novel Evaluation Methods for Visualization","author":"Saket Bahador","year":"2016","unstructured":"Bahador Saket, Alex Endert, and John Stasko. 2016. Beyond usability and performance: A review of user experience-focused evaluations in visualization. In Proceedings of the Sixth Workshop on Beyond Time and Errors on Novel Evaluation Methods for Visualization. 133\u2013142."},{"key":"e_1_3_2_81_2","first-page":"213","volume-title":"Proceedings of the 2003 Human Language Technology Conference of the North American Chapter of the Association for Computational Linguistics","author":"Sha Fei","year":"2003","unstructured":"Fei Sha and Fernando Pereira. 2003. Shallow parsing with conditional random fields. In Proceedings of the 2003 Human Language Technology Conference of the North American Chapter of the Association for Computational Linguistics. 213\u2013220."},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-89137-4_8"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1145\/1982185.1982510"},{"key":"e_1_3_2_84_2","article-title":"Simple BERT models for relation extraction and semantic role labeling","author":"Shi Peng","year":"2019","unstructured":"Peng Shi and Jimmy Lin. 2019. Simple BERT models for relation extraction and semantic role labeling. arXiv preprint arXiv:1904.05255 (2019).","journal-title":"arXiv preprint arXiv:1904.05255"},{"key":"e_1_3_2_85_2","first-page":"714","volume-title":"2020 Fourth International Conference on I-SMAC (IoT in Social, Mobile, Analytics and Cloud)(I-SMAC)","author":"Singru Rumjhum","year":"2020","unstructured":"Rumjhum Singru, Payal Bhandari, Krishna Patel, Praiakta Mane, and Chinmay Gulhane. 2020. Efficient electronic document access control management using natural language processing. In 2020 Fourth International Conference on I-SMAC (IoT in Social, Mobile, Analytics and Cloud)(I-SMAC). IEEE, 714\u2013719."},{"key":"e_1_3_2_86_2","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1109\/POLICY.2012.16","volume-title":"2012 IEEE International Symposium on Policies for Distributed Systems and Networks","author":"Slankas John","year":"2012","unstructured":"John Slankas and Laurie Williams. 2012. Classifying natural language sentences for policy. In 2012 IEEE International Symposium on Policies for Distributed Systems and Networks. IEEE, 33\u201336."},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/SocialCom.2013.68"},{"issue":"3","key":"e_1_3_2_88_2","first-page":"145","article-title":"Access control policy identification and extraction from project documentation","volume":"2","author":"Slankas John","year":"2013","unstructured":"John Slankas and Laurie Williams. 2013. Access control policy identification and extraction from project documentation. SCIENCE 2, 3 (2013), 145\u2013159.","journal-title":"SCIENCE"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664280"},{"key":"e_1_3_2_90_2","first-page":"53","volume-title":"International Conference on E-Technologies","author":"Stepien Bernard","year":"2009","unstructured":"Bernard Stepien, Amy Felty, and Stan Matwin. 2009. A non-technical user-oriented display notation for XACML conditions. In International Conference on E-Technologies. Springer, 53\u201364."},{"key":"e_1_3_2_91_2","doi-asserted-by":"crossref","first-page":"150","DOI":"10.1109\/CTS.2014.6867558","volume-title":"2014 International Conference on Collaboration Technologies and Systems (CTS)","author":"Stepien Bernard","year":"2014","unstructured":"Bernard Stepien, Amy Felty, and Stan Matwin. 2014. A non-technical XACML target editor for dynamic access control systems. In 2014 International Conference on Collaboration Technologies and Systems (CTS). IEEE, 150\u2013157."},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.5555\/1706543.1706586"},{"key":"e_1_3_2_93_2","first-page":"1","volume-title":"2018 12th International Conference on Research Challenges in Information Science (RCIS)","author":"Tanoli Irfan Khan","year":"2018","unstructured":"Irfan Khan Tanoli, Marinella Petrocchi, and Rocco De Nicola. 2018. Towards automatic translation of social network policies into controlled natural language. In 2018 12th International Conference on Research Challenges in Information Science (RCIS). IEEE, 1\u201312."},{"key":"e_1_3_2_94_2","doi-asserted-by":"publisher","DOI":"10.1145\/3041048.3041054"},{"key":"e_1_3_2_95_2","unstructured":"UbiOps. 2024. OpenAI vs. open-source LLM: Which model is best for your use case? - UbiOps - AI model serving Orchestration & Training. https:\/\/ubiops.com\/openai-vs-open-source-llm\/"},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1145\/1408664.1408674"},{"key":"e_1_3_2_97_2","first-page":"7","volume-title":"SOUPS Workshop (USM)","author":"Vaniea Kami","year":"2008","unstructured":"Kami Vaniea, Qun Ni, Lorrie Cranor, and Elisa Bertino. 2008. Access control policy analysis and visualization tools for security professionals. In SOUPS Workshop (USM). 7\u201315."},{"key":"e_1_3_2_98_2","article-title":"Attention is all you need","volume":"30","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N. Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. Advances in Neural Information Processing Systems 30 (2017).","journal-title":"Advances in Neural Information Processing Systems"},{"issue":"5","key":"e_1_3_2_99_2","first-page":"360","article-title":"Understanding interobserver agreement: The kappa statistic","volume":"37","author":"Viera Anthony J.","year":"2005","unstructured":"Anthony J. Viera, Joanne M. Garrett, et\u00a0al. 2005. Understanding interobserver agreement: The kappa statistic. Fam. Med. 37, 5 (2005), 360\u2013363.","journal-title":"Fam. Med."},{"key":"e_1_3_2_100_2","doi-asserted-by":"crossref","first-page":"293","DOI":"10.1109\/EuroSPW51379.2020.00045","volume-title":"2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","author":"Vigano Luca","year":"2020","unstructured":"Luca Vigano and Daniele Magazzeni. 2020. Explainable security. In 2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). IEEE, 293\u2013300."},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1186\/s40537-016-0043-6"},{"key":"e_1_3_2_102_2","doi-asserted-by":"publisher","DOI":"10.1145\/2601248.2601268"},{"key":"e_1_3_2_103_2","article-title":"Unveiling security, privacy, and ethical concerns of ChatGPT","author":"Wu Xiaodong","year":"2023","unstructured":"Xiaodong Wu, Ran Duan, and Jianbing Ni. 2023. Unveiling security, privacy, and ethical concerns of ChatGPT. Journal of Information and Intelligence (2023).","journal-title":"Journal of Information and Intelligence"},{"key":"e_1_3_2_104_2","first-page":"281","article-title":"On controlled natural languages: Properties and prospects.","volume":"9","author":"Wyner Adam Z.","year":"2009","unstructured":"Adam Z. Wyner, Krasimir Angelov, Guntis Barzdins, Danica Damljanovic, Brian Davis, Norbert E. Fuchs, Stefan Hoefler, Ken Jones, Kaarel Kaljurand, Tobias Kuhn, et\u00a0al. 2009. On controlled natural languages: Properties and prospects. CNL 9 (2009), 281\u2013289.","journal-title":"CNL"},{"key":"e_1_3_2_105_2","first-page":"1289","volume-title":"2022 IEEE International Conference on Bioinformatics and Biomedicine (BIBM)","author":"Xia Yutang","year":"2022","unstructured":"Yutang Xia, Shengfang Zhai, Qinting Wang, Huiting Hou, Zhonghai Wu, and Qingni Shen. 2022. Automated extraction of ABAC policies from natural-language documents in healthcare systems. In 2022 IEEE International Conference on Bioinformatics and Biomedicine (BIBM). IEEE, 1289\u20131296."},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1145\/2393596.2393608"},{"key":"e_1_3_2_107_2","doi-asserted-by":"publisher","DOI":"10.1145\/3025453.3025999"},{"key":"e_1_3_2_108_2","article-title":"PurExt: Automated extraction of the purpose-aware rule from the natural language privacy policy in IoT","volume":"2021","author":"Yang Lu","year":"2021","unstructured":"Lu Yang, Xingshu Chen, Yonggang Luo, Xiao Lan, and Li Chen. 2021. PurExt: Automated extraction of the purpose-aware rule from the natural language privacy policy in IoT. Security and Communication Networks 2021 (2021).","journal-title":"Security and Communication Networks"},{"key":"e_1_3_2_109_2","first-page":"63","volume-title":"2016 17th International Conference on Parallel and Distributed Computing, Applications and Technologies (PDCAT)","author":"Ye Xinfeng","year":"2016","unstructured":"Xinfeng Ye. 2016. Identify the semantic meaning of service rules with natural language processing. In 2016 17th International Conference on Parallel and Distributed Computing, Applications and Technologies (PDCAT). IEEE, 63\u201368."},{"issue":"10","key":"e_1_3_2_110_2","doi-asserted-by":"crossref","first-page":"1898","DOI":"10.1007\/s11431-020-1666-4","article-title":"A survey of syntactic-semantic parsing based on constituent and dependency structures","volume":"63","author":"Zhang MeiShan","year":"2020","unstructured":"MeiShan Zhang. 2020. A survey of syntactic-semantic parsing based on constituent and dependency structures. Science China Technological Sciences 63, 10 (2020), 1898\u20131920.","journal-title":"Science China Technological Sciences"},{"key":"e_1_3_2_111_2","first-page":"34","volume-title":"2021 3rd International Academic Exchange Conference on Science and Technology Innovation (IAECST)","author":"Zhu Zhipeng","year":"2021","unstructured":"Zhipeng Zhu, Zhiyu Ren, and Xuehui Du. 2021. Unstructured text ABAC attribute mining technology based on deep learning. In 2021 3rd International Academic Exchange Conference on Science and Technology Innovation (IAECST). IEEE, 34\u201339."},{"key":"e_1_3_2_112_2","doi-asserted-by":"crossref","first-page":"57","DOI":"10.1109\/SECPRI.1999.766718","volume-title":"Proceedings of the 1999 IEEE Symposium on Security and Privacy (Cat. No. 99CB36344)","author":"Zurko Mary Ellen","year":"1999","unstructured":"Mary Ellen Zurko, Rich Simon, and Tom Sanfilippo. 1999. A user-centered, modular authorization service built on an RBAC foundation. In Proceedings of the 1999 IEEE Symposium on Security and Privacy (Cat. No. 99CB36344). IEEE, 57\u201371."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3706057","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3706057","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:13Z","timestamp":1750295893000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3706057"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,23]]},"references-count":111,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,4,30]]}},"alternative-id":["10.1145\/3706057"],"URL":"https:\/\/doi.org\/10.1145\/3706057","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,23]]},"assertion":[{"value":"2023-09-25","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-11","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-23","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}