LAPS: LLM-based ABAC Policy Synthesis from Unstructured Text

Access control policies constitute a critical component for the security of any information system. However, it is a challenging task to articulate them with high accuracy in an automated manner due to their complexity and heterogeneity. In this paper, we introduce a methodology that uses large language models (LLMs) to transform unstructured documents containing organizational policy decisions in the form of summaries, discussions, minutes of meetings, etc., into structured, Actionable Security Policies (ASPs). The proposed framework named LAPS (LLM-based ABAC Policy Synthesis) explores the capabilities of LLMs and applies them effectively with the help of prompt engineering. It provides an end-to-end design for converting informally specified information available in heterogeneous formats like pdf, docx and txt into structured Attribute-based Access Control (ABAC) policies. LAPS generates its output in xacml format, besides also producing a policy table along with a graphical representation of the same. Performance of LAPS has been studied using the fuzzy matrix evaluation metric, which shows high attribute-value alignment of the generated policies with the reference input. Additionally, BERTScore is used to validate semantic closeness between the output and the source text. Together, these results establish the feasibility of LAPS as a practical tool for ABAC policy synthesis from unstructured text. We make LAPS freely available as a web-based application for use by the research community.

Paper

Full text

PDF

LAPS: LLM-based ABAC Policy Synthesis from Unstructured Text

Semantic Scholar · Computer Science · 2026

Abstract

Access control policies constitute a critical component for the security of any information system. However, it is a challenging task to articulate them with high accuracy in an automated manner due to their complexity and heterogeneity. In this paper, we introduce a methodology that uses large language models (LLMs) to transform unstructured documents containing organizational policy decisions in the form of summaries, discussions, minutes of meetings, etc., into structured, Actionable Security Policies (ASPs). The proposed framework named LAPS (LLM-based ABAC Policy Synthesis) explores the capabilities of LLMs and applies them effectively with the help of prompt engineering. It provides an end-to-end design for converting informally specified information available in heterogeneous formats like pdf, docx and txt into structured Attribute-based Access Control (ABAC) policies. LAPS generates its output in xacml format, besides also producing a policy table along with a graphical representation of the same. Performance of LAPS has been studied using the fuzzy matrix evaluation metric, which shows high attribute-value alignment of the generated policies with the reference input. Additionally, BERTScore is used to validate semantic closeness between the output and the source text. Together, these results establish the feasibility of LAPS as a practical tool for ABAC policy synthesis from unstructured text. We make LAPS freely available as a web-based application for use by the research community.

References (12)

Similar papers

© 2026 NYSGPT2525 LLC