Skip to content
Conference Open access

An Intelligent Intrusion Detection and Privacy-Preserving Architecture for the Internet of Medical Things (IoMT)

2026 · E3S Web of Conferences · 0 citations · 17 references

TL;DR

This work proposes an intelligent, lightweight Tiny LSTM–GRU hybrid IDS on the edge to monitor device-generated behavioral patterns in real time, with minimal computational and energy overhead, and proposes an adaptive FedProx-based weighted federated learning framework.

Abstract

The Internet of Medical Things (IoMT) is transforming healthcare delivery, but brings significant security and privacy challenges due to the diverse range of devices, sensitive patient data, and real-time operation requirements. Existing Intrusion Detection Systems (IDS) have improved detection and privacy through approaches such as federated learning and blockchain, yet they focus primarily on network-level attacks, overlooking device-level attacks which is the primary source of data leakage, device unavailability, and model poisoning in federated learning (FL)-based approaches. For instance, Bring Your Own Device (BYOD) introduces heterogeneity and Non-Independent and Identically Distributed data (non-IID) distributions that affect the performance of conventional FL approaches. We therefore propose an intelligent, lightweight Tiny LSTM–GRU hybrid IDS on the edge to monitor device-generated behavioral patterns in real time, with minimal computational and energy overhead. To preserve privacy and handle the issue of non-IID data across heterogeneous IoMT devices, we propose an adaptive FedProx-based weighted federated learning framework. Our proposed framework achieves an overall accuracy of 99.1% on the edge with latency between 1.8ms per sample, with a mean global accuracy of 99.4% and global loss of 0.037 during convergence, making it highly suitable for real-world IoMT deployments.

Read PDF

Similar papers

Conference Jul 2026

Towards Privacy-Preserving and Continual Intrusion Detection Systems in Internet of Medical Things

The rapid expansion of the Internet of Medical Things (IoMT) introduces critical vulnerabilities into healthcare infrastructures, demanding the development of enhanced cybersecurity strategies. This domain faces significant challenges arising from emerging and previously unknown attacks, combined with the decentralized nature of network traffic data, which is rarely shared due to stringent privacy constraints. To address these challenges, we propose a Federated Class Incremental Learning (FCIL) framework for Network Intrusion Detection System (NIDS) in the IoMT domain, enabling the continuous recognition of new attacks leveraging distributed data without exposing sensitive information. Findings on the CIC-IoMT24 dataset show that combining the incremental approach $\text{BiC}^{+}$ with the federated aggregation algorithm FedDyn achieves 71% F1 score in fine-grained misuse detection. While exhibiting a 14% F1 drop compared to the ideal centralized training-from-scratch, our approach ensures data privacy and computational efficiency.

Gabriele Mangiacapre, F. Cerasuolo, Alfredo Nascita et al. · 0 citations
Aug 2026

Federated Anomaly Detection for IoMT Networks: Privacy‐Preserving Design, Lightweight Implementation, and Runtime Evaluation

The rapid integration of Internet of Things (IoT) in the healthcare domain has led to the emergence of the Internet of Medical Things (IoMT), which introduces significant benefits in patient monitoring and real‐time medical services. However, IoMT networks are inherently vulnerable due to resource constraints, heterogeneous devices, and sensitivity of medical data. In this paper, we propose a novel federated learning‐based anomaly detection system (Fed‐ADS) designed specifically for IoMT networks. Our system leverages local training of lightweight ML models on resource‐constrained IoMT devices and employs secure model aggregation at the gateway to preserve privacy and avoid centralized data collection. To address real‐world challenges, we implement and evaluate our system on a real IoMT testbed using Raspberry Pi devices under various attack scenarios. Furthermore, we examine the impact of privacy‐preserving techniques such as differential privacy on detection accuracy and system overhead. The runtime evaluation shows that our approach achieves high detection accuracy (over 94%) with minimal CPU and memory usage (under 3%), making it suitable for practical deployment in medical environments.

Mahdi Ajdani, Maziar Asmani, Asif Ali Laghari · 0 citations
Open access 2026

Federated Learning for Privacy-preserving Internet of Things (IoT) Security: A Decentralized Intrusion Detection Framework

—The proposed study suggests a to help cope with issues related to cybersecurity in Internet of Things and Industrial Internet of Things environments without compromising privacy. The proposed framework introduces several innovative features, such as federated learning with momentum-based optimization, adaptive differential privacy, trust verification via blockchain, and Byzantine-resilient aggregation, to enhance the security, scalability, and robustness of the system compared with traditional intrusion detection systems. It also integrates supervised classification with autoencoder-based anomaly detection to detect existing and emerging cyberattacks. The proposed system was assessed with respect to the extended Industrial Internet of Things Intrusion Dataset (X-IIoT) and Network-Based Botnet Attack detection for IoT (N-BaIoT) benchmark datasets, where the environments were simulated as federated ones. The accuracy of the Hybrid Robust Federated Intrusion Detection System increased to 97.15% on X-IIoT and 97.64% on N-BaIoT with only 41 communication rounds and was resilient against up to 20% of Byzantine clients. These results showcase its efficacy to secure, private and communication-efficient intrusion detection for next generation Internet of Things and Hybrid Robust Federated Intrusion Detection System networks. 

M. Ramzan · 0 citations
Conference Open access 2026

A Two-Level Machine Learning Based-Intrusion Detection System for IoT Healthcare Application Based on Blockchain

: Smart healthcare systems offer human-centric solutions that enable the remote monitoring of patients, particularly those who are elderly, disabled, or located in geographically remote regions, thereby enhancing the quality and accessibility of medical services. These systems leverage core technologies such as the Internet of Medical Things (IoMT), blockchain, and artificial intelligence to facilitate the analysis and secure sharing of medical data among various stakeholders in the healthcare ecosystem. However, the transmission of sensitive health information over public networks raises significant security and privacy concerns. To address these issues, we propose a role-based access control protocol that restricts unauthorized access to the Ethereum blockchain and enforces rules for data usage. In addition, cryptographic primitives are employed to ensure data confidentiality. Our security framework also incorporates a two-level machine learning-based Intrusion Detection System (IDS): the first operates at the IoT gateway level to monitor IoT devices traffic, while the second is integrated within the blockchain network to detect and prevent malicious Ethereum transactions. Experimental evaluation on the Edge-IIoT and Ethereum fraud datasets demonstrates that the proposed IDS achieves high effectiveness across key metrics as accuracy, precision, recall, and F1-score. Random Forest outperforms all other algorithms, with accuracy rates of 97.12% for inside IDS and 98.2% for outside IDS. A comparison with state-of-the-art solutions demonstrates that our approach outperforms existing methods in both detection accuracy and security. Security analysis further confirms the system’s robustness against diverse cyberattacks.

M. Boujelben, M. Hentati · 0 citations
Aug 2026

A Secure Federated Learning and Blockchain Framework for E-Health Threat Detection

The proposed framework effectively integrates encryption, federated intrusion detection, explainable artificial intelligence, and blockchain security to enhance privacy, transparency, and reliability in IoMT healthcare networks.

P. Banupriya, K. Vanitha · 0 citations