Jul 2026· Journal of Intelligent Decision Making and Information Science· Vol 3, pp. 53-93· 0 citations· 45 references
TL;DR
An Adaptive Cybersecurity Framework (ACF) is proposed that integrates unsupervised machine learning-based anomaly detection, a risk-based Zero Trust Policy Engine, and blockchain-based immutable audit logging within a continuous adaptive feedback loop to create an ecosystem-aware adaptive cybersecurity paradigm.
Abstract
Cloud-based academic environments such as Learning Management Systems (LMS), Open Journal Systems (OJS), institutional repositories, and web applications face increasing cybersecurity challenges due to heterogeneous users, distributed services, and extensive exposure to public networks. Existing security approaches remain fragmented, where machine learning focuses on threat detection, Zero Trust Architecture (ZTA) emphasizes access control, and blockchain is primarily used for secure logging. The lack of integration among these components limits the ability of security systems to adapt dynamically to evolving cyber threats. This study proposes an Adaptive Cybersecurity Framework (ACF) that integrates unsupervised machine learning-based anomaly detection, a risk-based Zero Trust Policy Engine, and blockchain-based immutable audit logging within a continuous adaptive feedback loop. The framework was evaluated using 450,000 anonymized HTTP and Web Application Firewall (WAF) events collected from a multi-domain academic cloud environment consisting of LMS, OJS, repositories, and supporting web applications. The analysis revealed structured and repetitive attack behaviors dominated by automated endpoint probing and cross-domain propagation patterns, indicating ecosystem-level security threats. The proposed risk assessment mechanism demonstrated effective alignment between anomaly detection and policy-based decision making. Experimental results achieved an AUROC of 0.7296 for risk-based threat detection while maintaining an average decision latency of approximately 11 ms, indicating suitability for real-time deployment. Blockchain integration further provided verifiable, tamper-resistant audit trails for mitigation actions and policy enforcement activities. This study contributes an ecosystem-aware adaptive cybersecurity paradigm that bridges threat detection, policy enforcement, and auditability through a unified security architecture for Academic Cloud Environments.
Multi-cloud adoption has widened the enterprise attack surface to a degree that perimeter-based defence can no longer address. Traffic is now flowing continuously across AWS, Azure, and GCP, and the majority of deployed Zero Trust Architecture (ZTA) systems are still using static rule tables, with no ability to provide an audit trail of the reasoning behind decisions, and with logs stored in datastores that can be modified by an insider without detection. This paper proposes ZT-ChainGuard, a framework that overcomes these three limitations in one architecture that integrates an ensemble machine learning trust-scoring engine, ZTA policy enforcement and a blockchain-based audit trail. The trust-scoring engine is a two-layer stacking ensemble, with XGBoost and Random Forest as base learners, and Logistic Regression as a meta-learner, and it returns a continuous trust score, P(Attack | flow), for each network flow, which is then used to trigger the ZT policy decision at a threshold of 0.5. The explanation of each decision is provided by SHAP values at both the global and per-flow level, and each decision is stored as an immutable, SHA-256 hash-chained block. On CICIDS2017 (2.83 million flows, 14 attack classes) the framework achieves 99.90% accuracy, 99.71% F1-score, and 99.99% ROC-AUC; on ToN-IoT (2.23 million IoT records, 9 attack types) it achieves 99.81% accuracy, 99.88% F1-score, and 100% ROC-AUC. The latency of inferences is 0.006ms per sample, and the overhead of auditing the blockchain is 0.019ms per block. This performance is not just a quirk of a particular split, as it is shown to be stable across the three folds of three-fold cross validation.
V. K· Journal of Intelligent Decis...· 0 citations
BELS-IoT is proposed, a novel decentralized protection architecture that integrates a cryptocurrency-based blockchain layer with a multi-layer ensemble learning engine that rewards honest behavior and penalizes malicious activities while maintaining privacy through federated learning with blockchain-verified reputation scores.
Anwar Kalghoum, Leila Azouz Saidane· SN Computer Science· 0 citations
Permissioned blockchain systems have emerged as a cornerstone for enterprise-grade distributed applications due to their controlled participation, high throughput, and deterministic consensus protocols. However, existing security mechanisms in such systems are still mostly static, based on pre-defined rules and deterministic validation logic that are not sufficient against evolving adversarial behaviours such as insider threats, transaction manipulation and stealthy anomaly patterns. This paper proposes a novel Explainable Artificial Intelligence (XAI) driven adaptive pre-validation framework, in which an intelligent dynamic decision-making layer is introduced before the blockchain transaction commitment. The framework proposes the usage of unsupervised anomaly detection (Isolation Forest), supervised ensemble classification (Random Forest), dynamic trust score, and explainability mechanisms (Shapley value-based attribution) for transparent and accountable transaction validation. Unlike traditional approaches, the system evaluates transactions in real time using behavioural patterns, prior trust, and contextual anomalies. The proposed framework provides a scalable, transparent, and adaptive security enhancement for enterprise blockchain environments by integrating explainable decision-making into the transaction validation process.
S. S, S. S, A. M et al.· 2026 7th International Confe...· 0 citations
Secure financial transactions require more than just an immutable record — they also demand privacy-preserving identity assurance (which enables secure, trusted and transparent communication), adaptive fraud intelligence (to detect fraudulent transactions), policy-aware execution (so organizations can set their own rules for data use), resilient consensus (enables multiple parties to agree on data use), and auditable records within a single low-latency pipeline. Current permissioned-blockchain solutions often have independent optimizations for authentication, access control, fraud detection, consensus and auditing; as such, these separate areas lead to fragmented security decision making, unnecessary disclosure, static endorsement policies and throughput–latency tradeoffs. The research presented here describes FinTrust-X, a cross-layer risk-adaptive permissioned blockchain architecture where the security state created by each layer is used to create the next. A Zero-Knowledge Context Adaptive Role and Trust Authentication System (ZK-CARTA) provides zero knowledge context adaptive role and trust authentication to enable verifiable credentials to be selectively disclosed based on user device/session context and dynamically authorize users to minimize identity exposure and privilege abuse. Users are provided authenticated evidence to feed a Temporal Graph Transformer (TRiG-FraudFormer) that models joint transactional, account, device, merchant, beneficiary and trust relationships to produce a calibrated fraud-risk assessment along with counter-factual explanations. Risk is converted into adaptive smart contract paths, confidence levels and endorsement requirements to minimize unnecessary verification overheads. Safety constrained reinforcement learning is applied in RA-BFTune to adaptively optimize batching, ordering and Byzantine fault tolerant consensus based on transaction risk and network-states. Continuous cryptographic audit evidence is produced in PQ-AuditTwin utilizing immutable provenance, Merkle verification and ML-DSA-based post-quantum signature generations. Feedback regarding changes/drift in previous layer inputs is returned to those layers. Targeted validation results show ROC-AUC values of .96-.98 and F1 values of .92-.95 were achieved in addition to achieving authentication times less than 30ms., 1500-2000 TPS, P95 response time < 700ms, and greater than a 90% reduction in unnecessary disclosure of sensitive data from users indicating significant improvements in confidentiality, fraud-resilience, authorization-efficiency, scalability and auditability when compared against multi-organization Fabric workloads that included injected fraud and Byzantine faults.
P. Govardhan· Journal of Intelligent Decis...· 0 citations
Overall, this review demonstrates that blockchain-based cybersecurity frameworks provide a secure, transparent, and resilient foundation for protecting smart digital environments against increasingly sophisticated cyber threats while supporting trustworthy and scalable digital transformation.
M. Kayla, Crispinus Ode, Marion Sanaipei· The Eastasouth Journal of In...· 0 citations
Experimental evaluation demonstrates up to 95% detection accuracy, a 50% reduction in response latency, and scalability to over 100,000 IoT devices without performance degradation, highlighting the suitability of SC-ARS for deployment in smart cities, industrial IoT, and decentralized critical infrastructures where trust, transparency, and real-time responsiveness are essential.
S. Bassey, B. Stephen, Emediong Bassey Obot et al.· E3S Web of Conferences· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.