A subscription to JoVE is required to view this content. Sign in or start your free trial.

Method Article

An Experimental Protocol for Explainable AI-Driven Secure Cloud Data Migration Using Synthetic Healthcare Data

335 views

⸱

DOI:

10.3791/71612

⸱

August 14th, 2026

In This Article

Summary

This method presents a comprehensive explainable artificial intelligence (XAI) based framework to enable secure healthcare cloud data migration, leveraging a synthetic healthcare dataset within a controlled cloud environment. The result is a prototype that combines zero-trust security, time-based access control, and explainable anomaly detection to support migration transparency and security.

Abstract

In healthcare systems, more and more cloud data migration is being done, but this also changes the times when data transfer is probably the biggest risk in terms of security. This paper describes a reproducible protocol for explainable artificial intelligence (XAI)-based secure cloud data migration using a synthetic healthcare dataset and a controlled cloud environment. The developed framework merges zero-trust architecture, temporal least privilege, encrypted communication, centralized monitoring, and explainable anomaly detection to have a more secure, transparent, and auditable migration. The tests use a 10 GB dataset of synthetic electronic health records, comprising approximately 20 million records across 28 relational tables. The migration process was carried out on Amazon web services (AWS) using PostgreSQL databases and private virtual networks. For anomaly detection, Isolation Forest was utilized, and Shapley additive explanations (SHAP) served for the secure event interpretation. The framework was evaluated on ten separate migration attempts using metrics such as credential exposure duration, incident detection time, anomaly-detection accuracy, migration latency, and data integrity. Under the configuration tested, credential exposure was reduced from 24 h to 1 h (a 95.8% reduction), the accuracy of anomaly detection was 97.4%, incident detection time was reduced to about 15 min, and 100% data integrity was preserved through checksum validation. However, the stronger security measures resulted in an average migration latency increase of 11%. These results showcase the promise of merging explainable AI with secure cloud migration workflows for managing healthcare data.

Introduction

Cloud computing is now an integral part of healthcare systems worldwide, offering scalable storage, computational resources, and the ability to exchange health records, support decision-making systems, and enable health analytics through the cloud1,2,3. With many healthcare institutions upgrading their information systems, moving to the cloud has become a vital step for them in order to transfer their sensitive health data held in the older on-premises systems to the cloud4. Proper migration leads to easier data retrieval, running operations in a more ....

Access restricted. Please log in or start a trial to view this content.

Protocol

This study used a fully synthetic healthcare dataset generated for experimental evaluation of secure cloud data migration. No real patient data, protected health information (PHI), or identifiable healthcare records were used. Therefore, Institutional Review Board approval and informed consent were not required. All the materials used in this study are included in the Table of Materials.

1. Overview

  1. Configure a secure cloud migration environment consisting of a source layer, migration hub layer, target layer, network layer, identity and access management layer, observability layer, and explainab....

Access restricted. Please log in or start a trial to view this content.

Results

Experimental overview

The proposed explainable artificial intelligence (XAI)-enabled secure cloud data migration protocol was evaluated using a synthetic healthcare dataset comprising approximately 20 million electronic health record (EHR) records distributed across 28 relational database tables, totaling 10 GB. The experiments were conducted in an Amazon Web Services (AWS) cloud environment using Amazon RDS PostgreSQL 16, private Virtual Private Cloud (VPC) networking, TLS 1........

Access restricted. Please log in or start a trial to view this content.

Discussion

In this research, a reproducible, secure cloud database migration protocol was developed that incorporates zero-trust security principles, time-based least-privilege access control, explainable artificial intelligence (XAI), and continuous security monitoring, all within a restricted experimental setup. Using a new migration algorithm was not the intention of this paper; therefore, the authors primarily present a standardized workflow that makes it possible for researchers and practitioners to perform, assess, and reprod.......

Access restricted. Please log in or start a trial to view this content.

Disclosures

The authors declare that they have no competing financial interests, commercial relationships, or personal relationships that could have influenced the work reported in this study. The authors have no conflicts of interest to disclose. All materials required to reproduce the methodology presented in this study are publicly available in a GitHub repository. The repository is available at: https://github.com/priyankanalawade896-tech/XAI-Secure-Cloud-Data-Migration. The repository contains only synthetically generated benchmark data and does not include any real patient information, protected health information, or identifiable healthcare records.

Acknowledgements

The authors acknowledge the institutional support provided by their respective affiliated institutions during the development and evaluation of this protocol. The authors also acknowledge the use of institutional computational facilities and cloud computing resources that supported the experimental validation of the proposed secure cloud data migration framework.
This research received no external funding. The study was conducted using institutional research facilities and computational resources provided by the authors' affiliated institutions. No grant funding or financial support was received from any public, commercial, or not-for-profit funding agency.<....

Access restricted. Please log in or start a trial to view this content.

Materials

List of materials used in this article
NameCompanyCatalog NumberComments
AES EncryptionNISTAES-256Data-at-rest encryption
Amazon RDS PostgreSQLAmazon Web ServicesPostgreSQL 16Target database
Cloud PlatformAmazon Web ServicesAWSCloud infrastructure
CloudWatchAmazon Web ServicesLatest Stable ReleaseMonitoring and logging
DockerDocker Inc.27.0Containerization
FakerFaker Developers30.0Synthetic data generation
GPUNVIDIARTX 409024 GB VRAM
MatplotlibMatplotlib Developers3.9Visualization
NumPyNumPy Developers1.26Numerical processing
Operating SystemCanonicalUbuntu 22.04 LTSSystem environment
PandasPyData2.2Data processing
PostgreSQLPostgreSQL Global Development Group16Source database
PythonPython Software Foundation3.11Programming language
Scikit-learnScikit-learn Developers1.5Machine learning
SHAPSHAP Developers0.46Explainable AI
TerraformHashiCorp1.8Infrastructure provisioning
TLSIETFTLS 1.3Data-in-transit encryption
Virtual Private CloudAmazon Web ServicesVPCPrivate network environment
WorkstationDell/HPNAIntel Xeon Gold 6226R, 64 GB RAM, 1 TB SSD

References

  1. Kindervag J. Build security into your network's DNA: The Zero Trust Network Architecture. Cambridge (MA): Forrester Research; 2010.
  2. Rose S, Borchert O, Mitchell S, Connelly S. Zero Trust Architecture. NIST Special Publication 800-207. Gaithersburg (MD): National Institute of Standards and Technology; 2020. doi:10.6028/NIST.SP.800-207.
  3. Rieke N, et al. The future of digital health with federated learning. NPJ Digit Med. 2020;3:119. doi:10.1038/s41746-020-00323-1.
  4. Kairouz P, McMahan HB, Avent B, Bellet A, Bennis M, Bhagoji AN, et al. Advances and open problems in federated learning. Found Trends Mach Learn. 2021;14(1-2):1-210. doi:10....

Access restricted. Please log in or start a trial to view this content.

Reprints and Permissions

Tags

Zero Trust ArchitectureEncrypted CommunicationCentralized MonitoringAnomaly DetectionIsolation ForestShapley ExplanationsData Integrity