Author
Listed:
- Moïse Iradukunda Ingabire
(College of Engineering, Carnegie Mellon University Africa, Kigali BP 6150, Rwanda)
- Jema David Ndibwile
(College of Engineering, Carnegie Mellon University Africa, Kigali BP 6150, Rwanda)
Abstract
Manual compliance auditing in cloud environments consumes up to 40% of IT security budgets annually, yet existing approaches verify control presence rather than effectiveness , leaving institutions vulnerable to adversarial evasion. This paper presents an AI-augmented hybrid ML–LLM compliance auditing system evaluated on Rwanda’s National Cyber Security Authority (NCSA) Minimum Cybersecurity Standards (169 controls across 14 families). The system combines leakage-free XGBoost multi-label classification with GPT-4o-mini semantic log analysis, grounded in a formal effectiveness model. Key findings: (1) XGBoost v2 achieves 85.45% macro-F1 on leakage-free synthetic data (Wilson 95% CI = [84.9%, 86.0%]); an initial 86.3% data-leakage rate artificially inflated prior results to 99.99% and was identified and corrected in this revision; (2) GPT-4o-mini achieves 92.3% macro accuracy across four log types ( n = 628, 37.5% real enterprise data, Wilson CI = [89.9%, 94.3%]); (3) adversarial validation across five MITRE ATT&CK scenarios yields 92.8% macro detection with 0.0% false-positive rate on real SSH/PAM compliant logs ( n = 75); (4) a cross-dataset generalization analysis confirms 87.6% F1 on real SSH logs but identifies a 37.8-percentage-point out-of-vocabulary gap for Windows and HTTP log types, motivating the hybrid architecture; (5) the combined hybrid system (XGBoost for in-vocabulary logs, GPT-4o-mini for out-of-vocabulary) achieves 85.1% F1 with 6.4% false-positive rate on 180 real-world logs. The system runs at 2.0 CPU cores, 2.66 GB RAM, on $50/month cloud hosting (Apple M1 Pro baseline; storage and maintenance excluded), producing audit reports in 2–5 s depending on log volume and policy document size, demonstrating that effectiveness-based compliance auditing is accessible without enterprise-grade infrastructure.
Suggested Citation
Moïse Iradukunda Ingabire & Jema David Ndibwile, 2026.
"AI-Augmented Compliance Auditing for Cloud Systems: A Hybrid ML–LLM Approach,"
Future Internet, MDPI, vol. 18(6), pages 1-24, June.
Handle:
RePEc:gam:jftint:v:18:y:2026:i:6:p:329-:d:1969593
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:6:p:329-:d:1969593. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address
(email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.