EXTree: Towards Supporting Explainability in Attribute-based Access Control
Shanampudi Pranaya Chowdary (Indian Institute of Technology Kharagpur, India), Shamik Sural (Indian Institute of Technology Kharagpur, India)

TL;DR
EXTree is a novel approach that enhances explainability and efficiency in Attribute-based Access Control policies by structuring them as optimized decision trees for better feedback and understanding.
Contribution
The paper introduces EXTree, a method to create ABAC policy trees that improve both evaluation speed and human interpretability, addressing a key gap in access control systems.
Findings
EXTree achieves faster policy evaluation compared to traditional methods.
Entropy-based trees provide more meaningful explanations for access denial.
Experimental results show EXTree bridges the gap between complex logic and human understanding.
Abstract
With increasing emphasis on transparency in digital governance, users expect more than silence when their access requests are denied by a system. However, authorization methods are notorious for their inability to provide any form of meaningful feedback under such situations. This paper shows a direction towards how the problem of explainability can be mitigated in the context of Attribute-based Access Control (ABAC), arguably the most researched topic in access control in recent years. We introduce EXTree, which represents ABAC policies optimized for both fast evaluation (Efficiency) and human-centric feedback (Explainability) in the form of a tree. Two strategic dimensions are investigated, namely, Feedback Evaluation Strategies - how to craft actionable explanations when access is denied, and Tree Construction Strategies - how the policy trees should be structured for efficient yet…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
