Bridging the Gap Between Security and Convenience
Open Access DepositedRisk-Based Authentication Using Automated Machine Learning
Risk-based authentication (RBA) seeks an equilibrium between protection and user convenience. This investigation designs and validates a privacy-preserving RBA framework utilizing automated machine learning (AutoML). The models are trained on more than seventeen million events drawn from a large single sign-on platform. After stringent feature selection and the application of a hashed message authentication code with Secure Hash Algorithm 256 (HMAC-SHA-256) to mask user identifiers, an extreme gradient boosting (XGBoost) classifier delivered the strongest single-model performance.On a held-out test set, the model achieved a false acceptance rate of 0.005%, outperforming the 0.10% or less National Institute of Standards and Technology Authenticator Assurance Level 2 benchmark set in Special Publication 800-63B-3, and a false rejection rate of 3.24%, meeting the consensus target of less than 5%. A stacked ensemble that integrates this learner with complementary tree-based models further lowered user burden, reducing the false rejection rate to 2.11% while only slightly raising the false acceptance rate to 0.028%. Shapley additive explanations identify geolocation and hashed network provenance as the dominant risk indicators, strengthening interpretability and reinforcing regulatory compliance. Collectively, these findings show that streamlined, privacy-centric models produced through automated machine learning can yield high authentication accuracy without resorting to opaque or overly intricate architectures, offering a practical blueprint for deployment at scale.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.