Skip to content
Conference

Towards Privacy-Preserving and Continual Intrusion Detection Systems in Internet of Medical Things

Jul 2026 · International Conference on Smart Communications and Networking · pp. 1-6 · 0 citations · 20 references

Abstract

The rapid expansion of the Internet of Medical Things (IoMT) introduces critical vulnerabilities into healthcare infrastructures, demanding the development of enhanced cybersecurity strategies. This domain faces significant challenges arising from emerging and previously unknown attacks, combined with the decentralized nature of network traffic data, which is rarely shared due to stringent privacy constraints. To address these challenges, we propose a Federated Class Incremental Learning (FCIL) framework for Network Intrusion Detection System (NIDS) in the IoMT domain, enabling the continuous recognition of new attacks leveraging distributed data without exposing sensitive information. Findings on the CIC-IoMT24 dataset show that combining the incremental approach $\text{BiC}^{+}$ with the federated aggregation algorithm FedDyn achieves 71% F1 score in fine-grained misuse detection. While exhibiting a 14% F1 drop compared to the ideal centralized training-from-scratch, our approach ensures data privacy and computational efficiency.

View source

Similar papers

Conference Open access 2026

An Intelligent Intrusion Detection and Privacy-Preserving Architecture for the Internet of Medical Things (IoMT)

This work proposes an intelligent, lightweight Tiny LSTM–GRU hybrid IDS on the edge to monitor device-generated behavioral patterns in real time, with minimal computational and energy overhead, and proposes an adaptive FedProx-based weighted federated learning framework.

Emmanuel Udok, B. Stephen, U. Luke et al. · 0 citations
Aug 2026

Federated Anomaly Detection for IoMT Networks: Privacy‐Preserving Design, Lightweight Implementation, and Runtime Evaluation

The rapid integration of Internet of Things (IoT) in the healthcare domain has led to the emergence of the Internet of Medical Things (IoMT), which introduces significant benefits in patient monitoring and real‐time medical services. However, IoMT networks are inherently vulnerable due to resource constraints, heterogeneous devices, and sensitivity of medical data. In this paper, we propose a novel federated learning‐based anomaly detection system (Fed‐ADS) designed specifically for IoMT networks. Our system leverages local training of lightweight ML models on resource‐constrained IoMT devices and employs secure model aggregation at the gateway to preserve privacy and avoid centralized data collection. To address real‐world challenges, we implement and evaluate our system on a real IoMT testbed using Raspberry Pi devices under various attack scenarios. Furthermore, we examine the impact of privacy‐preserving techniques such as differential privacy on detection accuracy and system overhead. The runtime evaluation shows that our approach achieves high detection accuracy (over 94%) with minimal CPU and memory usage (under 3%), making it suitable for practical deployment in medical environments.

Mahdi Ajdani, Maziar Asmani, Asif Ali Laghari · 0 citations
Open access Jul 2026

FET-FIDS: a federated enhanced transformer-based framework for privacy-preserving network intrusion detection.

The rising rate of interconnected systems, cloud infrastructures, edge environments, and distributed network architectures have greatly exposed the vulnerability of the current digital infrastructures. This has exposed them to more advanced cybercrimes like denial-of-service attacks, malware injections, and data leaks. Also, there are sophisticated persistent threats that add more security burdens to such systems. The traditional Intrusion Detection Systems (IDS) are conventionally designed around central data collection and model training which result in the loss of privacy, a severely limited scale, a huge load on communications and a single point of failure. These constraints are even more deplorable in large and heterogeneous networks. To solve these issues, federated learning-based IDS models are suggested, but the existing practices fail to converge quickly, do not scale to non-IID data distributions and have an increased computation and communication cost which restricts its application. To overcome these issues, this paper proposes a Federated Enhanced Transformer-based Intrusion Detection System (FET-FIDS), a privacy-preserving and decentralized system of security, where federated learning is combined with Transformer-based self-attention. In the proposed architecture, a group of clients are introduced, each client is responsible for being trained on local network traffic data using FET-FIDS model. This method will help the system to learn intrusion patterns that are usually complicated to be learnt only in collaborative training. The locally trained model updates are then securely combined in a centralized server using adaptive federated averaging without having access to the raw data and, therefore, preserving their confidentiality of the data. The proposed architecture is effective in distributed and heterogeneous environments where under the experimental conditions taken into account in this study, its scalability, robustness and communication performance are improved. Using the provided means of wide-scale experimental analysis, the proposed FET-FIDS gives accuracy of 97.82%. It demonstrated that the proposed method is more effective, in terms of the detection, stability, and convergence behavior, than the existing centralized and federated IDS models. Further, it is shown that the framework can effectively deal with non-IID data distribution and the extensibility of the approach to different types of distributed network environment.

Jothi Prabha Appadurai, Revoori Swetha, V. Srinivas et al. · 1 citation
Open access 2026

Federated Learning for Privacy-preserving Internet of Things (IoT) Security: A Decentralized Intrusion Detection Framework

—The proposed study suggests a to help cope with issues related to cybersecurity in Internet of Things and Industrial Internet of Things environments without compromising privacy. The proposed framework introduces several innovative features, such as federated learning with momentum-based optimization, adaptive differential privacy, trust verification via blockchain, and Byzantine-resilient aggregation, to enhance the security, scalability, and robustness of the system compared with traditional intrusion detection systems. It also integrates supervised classification with autoencoder-based anomaly detection to detect existing and emerging cyberattacks. The proposed system was assessed with respect to the extended Industrial Internet of Things Intrusion Dataset (X-IIoT) and Network-Based Botnet Attack detection for IoT (N-BaIoT) benchmark datasets, where the environments were simulated as federated ones. The accuracy of the Hybrid Robust Federated Intrusion Detection System increased to 97.15% on X-IIoT and 97.64% on N-BaIoT with only 41 communication rounds and was resilient against up to 20% of Byzantine clients. These results showcase its efficacy to secure, private and communication-efficient intrusion detection for next generation Internet of Things and Hybrid Robust Federated Intrusion Detection System networks. 

M. Ramzan · 0 citations
Open access Jul 2026

A cost-sensitive random forest framework for ARP spoofing detection in Internet of Medical Things networks

Introduction ARP spoofing poses a major security threat to Internet of Medical Things (IoMT) networks by enabling man-in-the-middle attacks that compromise the integrity of life-critical communications. Existing intrusion detection methods fail to simultaneously address temporal attack dynamics, unequal medical safety requirements, and explicit control of false negative rates. Methods This study proposes the Self-Healing IoT-Optimized Random Forest (SH-IORF) framework, which integrates temporal behavioral feature engineering, validation-guided cost-sensitive learning, and medical safety-constrained threshold optimization. To ensure methodological rigor and prevent information leakage, a stratified three-way partitioning strategy consisting of training, validation, and completely held-out testing datasets was employed. Class penalty weights and operating thresholds were determined exclusively from the validation dataset. Results Experimental evaluation on the CICIoMT2024 benchmark demonstrated that the proposed SH-IORF framework achieved 99.90% accuracy, 99.83% recall, 99.95% precision, a 0.9989 F1-score, and an AUC-ROC of 0.9996. The framework limited the false negative rate to 0.17%, satisfying the predefined medical safety constraint (FNR ≤ 0.5%), corresponding to 40 missed detections among 23,390 attack samples and 12 false alarms across 28,768 benign traffic instances. Discussion The results demonstrate that the proposed framework provides stable and safety-oriented intrusion detection capability under heterogeneous IoMT deployment conditions while maintaining strict testing independence and robust performance under rigorous evaluation settings.

Siddhartha Singhal, Kakelli Anil Kumar · 0 citations
Open access Jul 2026

SECURE FEDERATED INTRUSION DETECTION USING HOMOMORPHIC ENCRYPTION: A COMPARATIVE STUDY WITH ENSEMBLE LEARNING

The rapid growth of the Internet of Things (IoT) has also resulted in the increase of the demand in the intrusion detection systems, which can detect suspicious activity and keep the information confidential. The traditional centralized machine learning systems involve attaching the data of the distributed devices to a centralized server thus placing them at a risk of being stolen. Federated Learning (FL) may help overcome this difficulty and assist in a distributed model training process without sharing raw client data. Nevertheless, updated versions of models that are transferred in the process of training are susceptible to poisoning or inference attacks at communication and aggregation. This paper proposed a federated intrusion detection system that is secure and involves implementation of Homomorphic Encryption (HE), in this case CKKS scheme, to provide model updates protection in aggregation process. The CICIoT2023 dataset was used in extensive experimentation of the proposed framework in terms of comparing with the classical machine learning baselines and experiences in using ensembles. Our findings show that the centralized Random Forest model with optimal accuracy of 98.57% worked best and the proposed Federated Learning models worked well with the standard FL performance of 79.54% and the encrypted FL+HE model performed with an accuracy of 79.39%. These are some results that demonstrate how Homomorphic Encryption enables the security and confidentiality of model aggregation a significant effect to model detection (reducing by only 0.15 percent), which provides a strong privacy-preserving security solution to decentralized IoT networks.

Sa daf, Aasim Zafar, Mohammad Luqman · 0 citations