Adaptive Access Control Using Compliance-Bound Reinforcement Learning
Keywords:
Layer-Wise Explainability, DRL, Audiobook Creation Exchange (AxC), Real-time enterpriseAbstract
Enterprise access control systems are a critical component of IT security that ensure users and services are accessing resources in conformance with organizational or company policies and regulatory requirements. Traditional access control mechanisms rely on static rules or role-based models, which cannot adapt to dynamic contexts such as changing user behavior, workload conditions, and evolving compliance obligations. While reinforcement learning offers adaptability, unconstrained reinforcement learning agents may optimize access decisions in ways that violate compliance policies, creating unacceptable security and regulatory risks.
This paper proposes a compliance-bound reinforcement learning framework for adaptive access control. The framework explicitly constrains the learning process using compliance boundaries derived from organizational policies and regulatory requirements. Instead of post-hoc policy enforcement, compliance constraints are integrated directly into the agent's decision-making and reward structure, ensuring that learned access strategies remain within acceptable governance limits.
Overall, self-correcting DRL allows IT management to be resilient yet responsive. With self-correcting DRL, one can have a secure, high-performing IT operation while tuning.
The simulation experiments were carried out based on enterprise-inspired Access Control schemes, simulating different user behaviors, risk levels, and policy changes. The findings prove that RL with compliance constraints has optimal performance in achieving lower violations while keeping accuracy and response time compatible. Simple visualization plots provide better intuition about policy stability, violations, performance-compliance tradeoffs, and other related aspects. Real-time enterprise scenarios also prove that AxC improves security while minimizing human intervention.
The results demonstrate that compliance-bound reinforcement learning can offer a practical solution for secure access control in contemporary enterprises.