Electronic Thesis/Dissertation
 

Enhancing Risk-Based Authentication in Cloud Systems Using Reinforcement Learning Techniques

Open Access Deposited

AbstractEnhancing Risk-Based Authentication in Cloud Systems Using Reinforcement Learning Techniques The need for an appropriate balance between ensuring the security of the cloud environment while minimizing the impact on authorized users is an issue that existing authentication policies based on rule sets fail to achieve. The fact that supervised learning models can detect suspicious login attempts with a high degree of accuracy does not mean that they can take into account the effect of their decisions on the system as a whole. The paper aims to investigate whether modeling Risk-Based Authentication (RBA) as a sequential process using a Markov Decision Process enables reinforcement learning to learn an optimal authentication policy. Within this framework, the Proximal Policy Optimization (PPO) agent operates as an adaptive enforcement layer that leverages the risk scores produced by supervised classifiers and learns authentication actions such as allowing access, requiring multi-factor authentication, or blocking the request. The evaluation was performed using a 2,000,000-event subset of the Zenodo RBA dataset based on a corpus of 31.3 million real-world authentication events. Three supervised learning models were implemented as baseline classifiers. The performance of each classifier was measured against the dataset. The best performance was achieved by the stacked ensemble classifier with an F1-score of 0.9487 and Matthews Correlation Coefficient (MCC) of 0.9249. The second-best performance was achieved by the random forest classifier with an AUC-ROC of 0.9881 and precision of 0.9816. The XGBoost classifier had the best recall of 0.9332. The vii performance differences between the supervised learning models were found to be statistically significant (p < 0.001). The reinforcement learning agents were also trained using Proximal Policy Optimization with different reward settings to represent security-focused, balanced, and usability-focused enforcement objectives. The performance of the agents was measured against the dataset. The performance of the security-focused agent was found to be perfect (1.000) for malicious login attempts while achieving a 20.2% multi-factor authentication rate for legitimate users.

Author Language Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Fedah_gwu_0075A_17864.pdf Fedah_gwu_0075A_17864.pdf 2026-06-24 Open Access