Document details

SAFE-GUARD

Author(s): Farhadighalati, Nastaran ; Estrada-Jimenez, Luis A. ; Kalateh, Sepideh ; Nikghadam-Hojjati, Sanaz ; Barata, Jose

Date: 2026

Persistent ID: http://hdl.handle.net/10362/202304

Origin: Repositório Institucional da UNL

Subject(s): access control; behavior monitoring; healthcare data security and privacy; LLM-based security; retrieval-augmented generation (RAG); rule-based access control; Communication; Human-Computer Interaction; Computer Networks and Communications; SDG 3 - Good Health and Well-being


Description

Healthcare faces a critical challenge: protecting sensitive medical data while enabling necessary clinical access. Evolving user behaviors, dynamic clinical contexts, and strict regulatory requirements demand adaptive access control mechanisms. Despite strict regulations, healthcare remains the most breached industry, consistently facing severe security risks related to unauthorized access. Traditional access control models cannot handle contextual variations, detect credential compromise, or provide transparent decision rationales. To address this, SAFE-GUARD (Semantic Access Control Framework Employing Generative User Assessment and Rule Decisions) is proposed as a two-layer framework that combines behavioral analysis with policy enforcement. The Behavioral Analysis Layer uses Retrieval-Augmented Generation (RAG) to detect contextual anomalies by comparing current requests against historical patterns. The Rule-Based Policy Evaluation Layer independently validates organizational procedures and regulatory requirements. Access is granted only when behavioral consistency and both organizational and regulatory policies are satisfied. We evaluate SAFE-GUARD using simulated healthcare scenarios with three LLMs (GPT-4o, Claude 3.5 Sonnet, and Gemini 2.5 Flash) achieving an anomaly detection accuracy of 95.2%, 94.1%, and 91.3%, respectively. The framework effectively identifies both compromised credentials and insider misuse by detecting deviations from established behavioral patterns, significantly outperforming conventional RBAC and ABAC approaches that rely solely on static rules.

Document Type Journal article
Language English
Contributor(s) RUN; UNINOVA-Instituto de Desenvolvimento de Novas Tecnologias; CTS - Centro de Tecnologia e Sistemas; DEE - Departamento de Engenharia Electrotécnica e de Computadores; MDPI - Multidisciplinary Digital Publishing Institute
facebook logo  linkedin logo  twitter logo 
mendeley logo

Related documents

No related documents