Explainable AI for Adaptive Security in Regulated Environments: A Unified Framework Integrating Federated Risk-Based Authentication and Privacy-Preserving On-Premises LLM Deployment
DOI:
https://doi.org/10.63503/j.ijaimd.2026.274Keywords:
Explainable AI; Federated Learning; Risk-Based Authentication; Healthcare Cybersecurity; On-Premises LLM; Oracle APEX; Privacy-Preserving AI; SHAP; Adaptive MFA; XAI Compliance; Low-Code Security; Transformer Models; Behavioral Biometrics; Data Sovereignty; Differential Privacy; AI Safety; Machine Ethics.Abstract
Healthcare and public-sector organizations face a compounding security imperative: protecting sensitive personal data against adaptive cyber threats while preserving the operational fluency that practitioners require in time-critical workflows. This paper proposes a unified Explainable AI (XAI) security framework that synthesizes federated learning-enhanced Dynamic Risk-Based Authentication (FL-RBA) with privacy-preserving on-premises Large Language Model (LLM) deployment into a cohesive, compliance-native paradigm. The framework introduces SHAP-based rationale generation to address the interpretability gap inherent in transformer-based authentication scoring, producing audit-ready decision trails that satisfy HIPAA and GDPR requirements. Pilot evidence from a live healthcare deployment demonstrates a 95% high-risk interception rate, 2.5% false-positive rate, and sub-1.2-second decision latency. On-premises LLM integration eliminates all external data transmission while delivering clinical intelligence capabilities comparable to cloud-based alternatives. The unified model provides a replicable blueprint for regulated organizations seeking to operationalize AI without compromising data sovereignty or regulatory alignment.
References
[1] IBM Security, "Cost of a Data Breach Report 2024," IBM Corp., Armonk, NY, USA, 2024. [Online]. Available: https://www.ibm.com/reports/data-breach
[2] M. Elgan, "Cost of a Data Breach in the Healthcare Industry," IBM Think Insights, 2025. [Online]. Available: https://www.ibm.com/think/insights/cost-of-a-data-breach-healthcare-industry
[3] C. D. Hylender, P. Langlois, A. Pinto, and S. Widup, "2025 Data Breach Investigations Report," Verizon Business, Basking Ridge, NJ, USA, 2025.
[4] R. Murray-Watson, "State of Healthcare Cybersecurity," The HIPAA Journal, 2025. [Online]. Available: https://www.hipaajournal.com/healthcare-cybersecurity/
[5] A. Syed, "Dynamic Risk-Based Authentication Using AI Scoring Models in Healthcare Applications," J. Artif. Intell. Cloud Comput., vol. 4, no. 5, pp. 1–10, Oct. 2025, doi: 10.47363/JAICC/2025(4)492.
[6] A. Syed, "Low-Code, High Privacy: Leveraging Open-Source LLMs for On-Premises AI in Oracle APEX," Int. J. Multidiscip. Res. (IJFMR), vol. 6, no. 5, Sep.–Oct. 2024.
[7] S. Wiefling, L. Lo Iacono, and M. Dürmuth, "Is This Really You? An Empirical Study on Risk-Based Authentication Applied in the Wild," in IFIP Advances in Information and Communication Technology. Cham: Springer, 2019, pp. 134–148.
[8] J. Singh, C. Patel, and N. K. Chaudhary, "Resilient Risk-Based Adaptive Authentication and Authorization (RAD-AA) Framework," in Proc. ICISPD. Singapore: Springer Nature, 2023, pp. 371–385.
[9] A. S. Chauhan and D. K. Kumar, "Adaptive Authentication Using Machine Learning," in Proc. Int. Conf. Innovative Computing and Communication, 2024, doi: 10.2139/ssrn.4932261.
[10] A. Wairagade, A. Ahuja, and N. Gupta, "Comprehensive Comparative Assessment of AI Driven Adaptive and Risk Based Authentication Strategies in Cloud Computing," in Proc. 2024 Int. Conf. ITIKD, IEEE, 2025, pp. 1–6.
[11] H. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. Y. Arcas, "Communication-Efficient Learning of Deep Networks from Decentralized Data," in Proc. 20th Int. Conf. Artif. Intell. Stat. (AISTATS), 2017.
[12] H. Fereidouni, A. S. Hafid, D. Makrakis, and Y. Baseri, "F-RBA: A Federated Learning-based Framework for Risk-based Authentication," arXiv:2412.12324, Dec. 2024.
[13] C. Mazzocca, N. Romandini, M. Colajanni, and R. Montanari, "FRAMH: A Federated Learning Risk-Based Authorization Middleware for Healthcare," IEEE Trans. Comput. Social Syst., vol. 10, pp. 1679–1690, 2023.
[14] Y. Baseri, A. S. Hafid, D. Makrakis, and H. Fereidouni, "Privacy-Preserving Federated Learning Framework for Risk-Based Adaptive Authentication," arXiv, 2025.
[15] A. Ali, V. Snášel, and J. Platoš, "Health-FedNet: A Privacy-Preserving Federated Learning Framework for Scalable and Secure Healthcare Analytics," Results Eng., vol. 27, Art. no. 106484, 2025.
[16] U. Kose, "A Futuristic View on Explainable Artificial Intelligence," in Proc. INFUS 2021, Lecture Notes in Networks and Systems. Cham: Springer, 2021.
[17] A. Adadi and M. Berrada, "Peeking Inside the Black-Box: A Survey on Explainable Artificial Intelligence (XAI)," IEEE Access, vol. 6, pp. 52138–52160, 2018.
[18] S. M. Lundberg and S.-I. Lee, "A Unified Approach to Interpreting Model Predictions," in Proc. 31st Conf. Neural Inf. Process. Syst. (NeurIPS), 2017, pp. 4765–4774.
[19] T. Miller, "Explanation in Artificial Intelligence: Insights from the Social Sciences," Artif. Intell., vol. 267, pp. 1–38, 2019.
[20] D. Saraswat et al., "Explainable AI for Healthcare 5.0: Opportunities and Challenges," IEEE Access, vol. 10, pp. 84486–84517, 2022.
[21] M. J. Al Ansari, Y. Al Ahmed, and H. H. El Bahnaswi, "Balancing Usability and Protection in AI and Data Security," in Proc. 2024 11th Int. Conf. Software Defined Systems (SDS), IEEE, 2024, pp. 80–88.
[22] Meta, "Introducing Meta Llama 3," Meta AI Blog, Apr. 2024. [Online]. Available: https://ai.meta.com/blog/meta-llama-3/
[23] A. Q. Jiang et al., "Mixtral of Experts," arXiv:2401.04088, Jan. 2024.
[24] Gemma Team, "Gemma: Open Models Based on Gemini Research and Technology," Google Technical Report, Feb. 2024.
[25] S. Pati, "Privacy Preservation for Federated Learning in Health Care," Patterns, vol. 5, Art. no. 100974, 2024.
[26] B. Gubitosa, "Self-Hosted LLM: A 5-Step Deployment Guide," Plural Blog, Jan. 2024. [Online]. Available: https://www.plural.sh/blog/self-hosting-large-language-models/
[27] S. Rose, O. Borchert, S. Mitchell, and S. Connelly, "Zero Trust Architecture," NIST SP 800-207, National Institute of Standards and Technology, 2020, doi: 10.6028/nist.sp.800-207.
[28] Q. Yang, Y. Liu, T. Chen, and Y. Tong, "Federated Machine Learning: Concept and Applications," ACM Trans. Intell. Syst. Technol., vol. 10, no. 2, pp. 1–19, 2019.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 International Journal on Engineering Artificial Intelligence Management, Decision Support, and Policies

This work is licensed under a Creative Commons Attribution 4.0 International License.