Explainable AI for Adaptive Security in Regulated Environments: A Unified Framework Integrating Federated Risk-Based Authentication and Privacy-Preserving On-Premises LLM Deployment

Authors

  • Ashok Kumar Department of IT, College of Technology, G. B. Pant University of Agriculture and Technology, Pantnagar, Uttarakhand, India
  • Utku Kose Department of Computer Engineering, Suleyman Demirel University, Isparta, Turkey. Affiliated Researcher, University of North Dakota, USA

DOI:

https://doi.org/10.63503/j.ijaimd.2026.274

Keywords:

Explainable AI; Federated Learning; Risk-Based Authentication; Healthcare Cybersecurity; On-Premises LLM; Oracle APEX; Privacy-Preserving AI; SHAP; Adaptive MFA; XAI Compliance; Low-Code Security; Transformer Models; Behavioral Biometrics; Data Sovereignty; Differential Privacy; AI Safety; Machine Ethics.

Abstract

Healthcare and public-sector organizations face a compounding security imperative: protecting sensitive personal data against adaptive cyber threats while preserving the operational fluency that practitioners require in time-critical workflows. This paper proposes a unified Explainable AI (XAI) security framework that synthesizes federated learning-enhanced Dynamic Risk-Based Authentication (FL-RBA) with privacy-preserving on-premises Large Language Model (LLM) deployment into a cohesive, compliance-native paradigm. The framework introduces SHAP-based rationale generation to address the interpretability gap inherent in transformer-based authentication scoring, producing audit-ready decision trails that satisfy HIPAA and GDPR requirements. Pilot evidence from a live healthcare deployment demonstrates a 95% high-risk interception rate, 2.5% false-positive rate, and sub-1.2-second decision latency. On-premises LLM integration eliminates all external data transmission while delivering clinical intelligence capabilities comparable to cloud-based alternatives. The unified model provides a replicable blueprint for regulated organizations seeking to operationalize AI without compromising data sovereignty or regulatory alignment.

References

[1] IBM Security, "Cost of a Data Breach Report 2024," IBM Corp., Armonk, NY, USA, 2024. [Online]. Available: https://www.ibm.com/reports/data-breach

[2] M. Elgan, "Cost of a Data Breach in the Healthcare Industry," IBM Think Insights, 2025. [Online]. Available: https://www.ibm.com/think/insights/cost-of-a-data-breach-healthcare-industry

[3] C. D. Hylender, P. Langlois, A. Pinto, and S. Widup, "2025 Data Breach Investigations Report," Verizon Business, Basking Ridge, NJ, USA, 2025.

[4] R. Murray-Watson, "State of Healthcare Cybersecurity," The HIPAA Journal, 2025. [Online]. Available: https://www.hipaajournal.com/healthcare-cybersecurity/

[5] A. Syed, "Dynamic Risk-Based Authentication Using AI Scoring Models in Healthcare Applications," J. Artif. Intell. Cloud Comput., vol. 4, no. 5, pp. 1–10, Oct. 2025, doi: 10.47363/JAICC/2025(4)492.

[6] A. Syed, "Low-Code, High Privacy: Leveraging Open-Source LLMs for On-Premises AI in Oracle APEX," Int. J. Multidiscip. Res. (IJFMR), vol. 6, no. 5, Sep.–Oct. 2024.

[7] S. Wiefling, L. Lo Iacono, and M. Dürmuth, "Is This Really You? An Empirical Study on Risk-Based Authentication Applied in the Wild," in IFIP Advances in Information and Communication Technology. Cham: Springer, 2019, pp. 134–148.

[8] J. Singh, C. Patel, and N. K. Chaudhary, "Resilient Risk-Based Adaptive Authentication and Authorization (RAD-AA) Framework," in Proc. ICISPD. Singapore: Springer Nature, 2023, pp. 371–385.

[9] A. S. Chauhan and D. K. Kumar, "Adaptive Authentication Using Machine Learning," in Proc. Int. Conf. Innovative Computing and Communication, 2024, doi: 10.2139/ssrn.4932261.

[10] A. Wairagade, A. Ahuja, and N. Gupta, "Comprehensive Comparative Assessment of AI Driven Adaptive and Risk Based Authentication Strategies in Cloud Computing," in Proc. 2024 Int. Conf. ITIKD, IEEE, 2025, pp. 1–6.

[11] H. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. Y. Arcas, "Communication-Efficient Learning of Deep Networks from Decentralized Data," in Proc. 20th Int. Conf. Artif. Intell. Stat. (AISTATS), 2017.

[12] H. Fereidouni, A. S. Hafid, D. Makrakis, and Y. Baseri, "F-RBA: A Federated Learning-based Framework for Risk-based Authentication," arXiv:2412.12324, Dec. 2024.

[13] C. Mazzocca, N. Romandini, M. Colajanni, and R. Montanari, "FRAMH: A Federated Learning Risk-Based Authorization Middleware for Healthcare," IEEE Trans. Comput. Social Syst., vol. 10, pp. 1679–1690, 2023.

[14] Y. Baseri, A. S. Hafid, D. Makrakis, and H. Fereidouni, "Privacy-Preserving Federated Learning Framework for Risk-Based Adaptive Authentication," arXiv, 2025.

[15] A. Ali, V. Snášel, and J. Platoš, "Health-FedNet: A Privacy-Preserving Federated Learning Framework for Scalable and Secure Healthcare Analytics," Results Eng., vol. 27, Art. no. 106484, 2025.

[16] U. Kose, "A Futuristic View on Explainable Artificial Intelligence," in Proc. INFUS 2021, Lecture Notes in Networks and Systems. Cham: Springer, 2021.

[17] A. Adadi and M. Berrada, "Peeking Inside the Black-Box: A Survey on Explainable Artificial Intelligence (XAI)," IEEE Access, vol. 6, pp. 52138–52160, 2018.

[18] S. M. Lundberg and S.-I. Lee, "A Unified Approach to Interpreting Model Predictions," in Proc. 31st Conf. Neural Inf. Process. Syst. (NeurIPS), 2017, pp. 4765–4774.

[19] T. Miller, "Explanation in Artificial Intelligence: Insights from the Social Sciences," Artif. Intell., vol. 267, pp. 1–38, 2019.

[20] D. Saraswat et al., "Explainable AI for Healthcare 5.0: Opportunities and Challenges," IEEE Access, vol. 10, pp. 84486–84517, 2022.

[21] M. J. Al Ansari, Y. Al Ahmed, and H. H. El Bahnaswi, "Balancing Usability and Protection in AI and Data Security," in Proc. 2024 11th Int. Conf. Software Defined Systems (SDS), IEEE, 2024, pp. 80–88.

[22] Meta, "Introducing Meta Llama 3," Meta AI Blog, Apr. 2024. [Online]. Available: https://ai.meta.com/blog/meta-llama-3/

[23] A. Q. Jiang et al., "Mixtral of Experts," arXiv:2401.04088, Jan. 2024.

[24] Gemma Team, "Gemma: Open Models Based on Gemini Research and Technology," Google Technical Report, Feb. 2024.

[25] S. Pati, "Privacy Preservation for Federated Learning in Health Care," Patterns, vol. 5, Art. no. 100974, 2024.

[26] B. Gubitosa, "Self-Hosted LLM: A 5-Step Deployment Guide," Plural Blog, Jan. 2024. [Online]. Available: https://www.plural.sh/blog/self-hosting-large-language-models/

[27] S. Rose, O. Borchert, S. Mitchell, and S. Connelly, "Zero Trust Architecture," NIST SP 800-207, National Institute of Standards and Technology, 2020, doi: 10.6028/nist.sp.800-207.

[28] Q. Yang, Y. Liu, T. Chen, and Y. Tong, "Federated Machine Learning: Concept and Applications," ACM Trans. Intell. Syst. Technol., vol. 10, no. 2, pp. 1–19, 2019.

Downloads

Published

31-08-2026

How to Cite

Kumar, A., & Kose, U. (2026). Explainable AI for Adaptive Security in Regulated Environments: A Unified Framework Integrating Federated Risk-Based Authentication and Privacy-Preserving On-Premises LLM Deployment. International Journal on Engineering Artificial Intelligence Management, Decision Support, and Policies, 3(2), 29–39. https://doi.org/10.63503/j.ijaimd.2026.274

Issue

Section

Research Articles