Skip to content

Federated Anomaly Detection for IoMT Networks: Privacy‐Preserving Design, Lightweight Implementation, and Runtime Evaluation

Aug 2026 · International Journal of Communication Systems · Vol 39 · 0 citations · 17 references

Abstract

The rapid integration of Internet of Things (IoT) in the healthcare domain has led to the emergence of the Internet of Medical Things (IoMT), which introduces significant benefits in patient monitoring and real‐time medical services. However, IoMT networks are inherently vulnerable due to resource constraints, heterogeneous devices, and sensitivity of medical data. In this paper, we propose a novel federated learning‐based anomaly detection system (Fed‐ADS) designed specifically for IoMT networks. Our system leverages local training of lightweight ML models on resource‐constrained IoMT devices and employs secure model aggregation at the gateway to preserve privacy and avoid centralized data collection. To address real‐world challenges, we implement and evaluate our system on a real IoMT testbed using Raspberry Pi devices under various attack scenarios. Furthermore, we examine the impact of privacy‐preserving techniques such as differential privacy on detection accuracy and system overhead. The runtime evaluation shows that our approach achieves high detection accuracy (over 94%) with minimal CPU and memory usage (under 3%), making it suitable for practical deployment in medical environments.

View source

Similar papers

Conference Open access 2026

An Intelligent Intrusion Detection and Privacy-Preserving Architecture for the Internet of Medical Things (IoMT)

This work proposes an intelligent, lightweight Tiny LSTM–GRU hybrid IDS on the edge to monitor device-generated behavioral patterns in real time, with minimal computational and energy overhead, and proposes an adaptive FedProx-based weighted federated learning framework.

Emmanuel Udok, B. Stephen, U. Luke et al. · 0 citations
Conference Jul 2026

Towards Privacy-Preserving and Continual Intrusion Detection Systems in Internet of Medical Things

The rapid expansion of the Internet of Medical Things (IoMT) introduces critical vulnerabilities into healthcare infrastructures, demanding the development of enhanced cybersecurity strategies. This domain faces significant challenges arising from emerging and previously unknown attacks, combined with the decentralized nature of network traffic data, which is rarely shared due to stringent privacy constraints. To address these challenges, we propose a Federated Class Incremental Learning (FCIL) framework for Network Intrusion Detection System (NIDS) in the IoMT domain, enabling the continuous recognition of new attacks leveraging distributed data without exposing sensitive information. Findings on the CIC-IoMT24 dataset show that combining the incremental approach $\text{BiC}^{+}$ with the federated aggregation algorithm FedDyn achieves 71% F1 score in fine-grained misuse detection. While exhibiting a 14% F1 drop compared to the ideal centralized training-from-scratch, our approach ensures data privacy and computational efficiency.

Gabriele Mangiacapre, F. Cerasuolo, Alfredo Nascita et al. · 0 citations
Open access Aug 2026

Federated Learning for Privacy-Preserving Anomaly Detection in Heterogeneous IoT Networks

Simulation of a Federated Learning framework for privacy-preserving anomaly detection tailored to heterogeneous IoT networks characterised by non-independent and identically distributed data, variable computational capacities, and intermittent connectivity indicates that the proposed method offers a practical, scalable, and regulation-compliant pathway toward trustworthy intrusion and anomaly detection in large-scale, heterogeneous IoT deployments.

Raushan Raj, B. L. Pal, Saurab Singh · 0 citations
Preprint Jul 2026

Federated Learning and LLM-Driven Threat Intelligence for Zero Trust IoT Architecture

A Federated Learning and LLM-Driven Threat Intelligence for Zero Trust IoT Architecture is presented, with FL for anomaly detection integrating privacy-preserving distributed learning, continuous identity verification, and LLM-driven autonomous threat response into a unified pipeline.

Amal Alshehri, Cihan Tunc · 0 citations
Aug 2026

Fed-blam: federated BERT and LLaMA for IoT malware detection

Experimental results demonstrate that the federated LLM-based models consistently outperform a multilayer perceptron baseline, with the LLaMA model achieving up to 99.9% accuracy and F1-score while generalising effectively to previously unseen device types.

Chloe Nazaruk, Rahim Taheri, Gelayol Golcarenarenji et al. · 0 citations
Review Open access Jul 2026

Federated TinyML and digital twin framework for secure and resilient IoMT-based ICU monitoring.

Results indicate that a federated TinyML architecture with lightweight patient-state tracking, validation-based ensemble filtering, differential privacy, and post-quantum-secure communication can support privacy-aware and attack-resilient ICU monitoring experiments in resource-constrained IoMT settings.

Umar Hayat Khan, Rahim Khan, Tahani Alsaedi et al. · 0 citations