Explainable Machine Learning-Based Security and Privacy Protection Framework for Internet of Medical Things Systems

arXiv:2403.09752 · cs.CR, cs.AI · Submitted 2026-08-07 · Read on arXiv

Ayoub Si-ahmed, Mohammed Ali Al-Garadi, Narhimene Boustia

Blida 1 University · PROXYLAN SPA · CERIST · Emory University

cs.CR, cs.AI

Submitted: 2026-08-07

Updated: 2026-08-11

Comments: 40 pages, 13 figures, 6 tables, journal paper

Code: https://github.com/ayoub1609/bispap

License: http://creativecommons.org/licenses/by-nc-nd/4.0/

Importance score: 49/100

The gist: The paper introduces an "Explainable Machine Learning-Based Security and Privacy Protection Framework for Internet of Medical Things (IoMT) Systems" designed to address the critical security and

Terminology

Summary

The paper introduces an Explainable Machine Learning-Based Security and Privacy Protection Framework for Internet of Medical Things (IoMT) Systems designed to address the critical security and privacy challenges inherent in healthcare technology. While IoMT enables a transition from reactive treatment to proactive prevention, its benefits are countered by significant security challenges that endanger the lives of its users due to the sensitivity and value of the processed data. These challenges include Man-In-The-Middle (MITM) attacks, human error, network interference, or hardware malfunctions, and the inherent opacity of many ML models, often referred to as ’blackbox’ models, which lack transparency in their decision-making processes.

To mitigate these issues, the authors propose a new framework for Intrusion Detection Systems (IDS) that "leverages Artificial Neural Networks (ANN) for intrusion detection while utilizing Federated Learning (FL) for privacy preservation. Additionally, eXplainable Artificial Intelligence (XAI) methods are incorporated to enhance model explanation and interpretation."

Methodology

The proposed IoMT architecture is composed of three distinct layers: the Data Acquisition Layer, the Personal Server Layer, and the Medical Server Layer.

  1. Local Training Process: The framework utilizes supervised learning via ANN for real-time anomaly detection. The ANN architecture employs the rectified linear unit (ReLU)... as the activation function for the hidden layer and the sigmoid activation function... for the output layer. For optimization, the Adam optimizer... is chosen for its efficiency, and cross-entropy is employed as the loss function. The model uses He-Initialization... for weight initialization due to its compatibility with ReLU.

  2. Federated Learning (FL) Process: To preserve privacy, the framework allows the sharing of locally trained model weights on end-devices instead of raw data. This reduces bandwidth consumption and alleviates network congestion, thereby facilitating system scalability. The hospital server orchestrates the development of the global model and aggregates the local model parameters received from participating devices using the Federated Averaging (FedAvg) algorithm.

  3. eXplainable AI (XAI) Process: To address the black box nature of ANN, the framework incorporates the The SHapley Additive exPlanations (SHAP) method to provide a transparent, auditable record of the model’s decision-making logic for each prediction. This provides both local and global scopes of explanation by attributing a value that represents a median marginal contribution to the prediction across all possible feature combinations.

Experimental Evaluation and Results

The framework was evaluated using four distinct datasets containing network and medical data: NSL-KDD, UNSW-NB15, ToN-IoT, and WUSTL-EHMS. The researchers analyzed the impact of various FL parameters, including the number of participating clients, the client participation fraction, and the number of local training epochs.

The results offer compelling evidence that the FL method performs comparably to the centralized method, demonstrating high performance. Specifically, the comparison shows that training models on separate data partitions generalizes as effectively as training a global model on the entire dataset. Furthermore, the SHAP analysis confirmed that both learning paradigms consistently identify the same domain-relevant features as the primary contributors to attack detection, demonstrating that the decentralized training process does not alter the underlying decision rationale of the intrusion detection model.

Ethical and Regulatory Contributions

The framework is designed to align with international standards such as HIPAA, GDPR, WHO and ISO/IEC 27001 and ISO/IEC 27701. It addresses ethical imperatives through:

  • Data Protection and Privacy: Leveraging FL for IDS, ensuring that patient data remains localized on their devices.

  • Transparency: Integrating XAI methods such as SHAP... [to] provide clear and interpretable explanations for the model’s decisions.

  • Accountability and Bias Mitigation: Prioritizes fairness by utilizing diverse datasets and applying XAI techniques to detect and correct biases.

Improvements for AI systems

1. Integration of Graph Neural Networks (GNNs) and Temporal Transformers

  • Improvement: Replace the standard ANN architecture with a hybrid model utilizing Graph Neural Networks to capture the relational topology of IoMT device networks and Temporal Transformers to process time-series physiological data.

  • Capability: The system can detect sophisticated lateral movement attacks where a hacker moves from a low-security device (e.g., a smart thermometer) to a critical device (e.g., an insulin pump) by analyzing the relationship between nodes, while simultaneously identifying subtle, time-dependent anomalies in patient vitals that standard ANNs might miss.

2. Implementation of Differentially Private Federated Learning (DP-FL)

  • Improvement: Augment the Federated Averaging (FedAvg) process with Differential Privacy (DP) by injecting calibrated Gaussian noise into the local model updates before they are sent to the Medical Server.

  • Capability: The system can provide mathematical guarantees against Model Inversion Attacks, preventing malicious actors from reconstructing a patient's specific medical history or sensitive biometric signatures from the shared model weights.

3. Transition from Post-hoc to Ante-hoc (Intrinsic) Explainability

  • Improvement: Incorporate Attention Mechanisms and Prototype-based learning directly into the model architecture, rather than relying solely on post-hoc SHAP explanations.

  • Capability: The system can provide real-time reasoning during the inference process, allowing clinicians to see exactly which segment of a waveform or which specific sensor reading triggered an alarm as it happens, rather than waiting for a secondary SHAP calculation to interpret a black-box decision.

4. Deployment of Continual Learning with Concept Drift Detection

  • Improvement: Integrate an online learning component equipped with a Drift Detection Method (DDM) to monitor changes in data distribution.

  • Capability: The system can autonomously adapt to Concept Drift—such as changes in patient baseline health due to aging or the introduction of new medical device models—and recognize Zero-Day cyberattacks without requiring a full manual retraining cycle on the centralized server.

5. Hierarchical Federated Learning (HFL) Architecture

  • Improvement: Expand the three-layer architecture into a hierarchical structure that includes an Edge Computing Layer (e.g., hospital-grade routers/gateways) between the Personal Server and the Medical Server.

  • Capability: The system can perform high-speed, low-latency local aggregation of model updates, significantly reducing the communication overhead on the global medical network and ensuring that critical security alerts are processed at the edge of the network for near-instantaneous response.

Abstract

The Internet of Medical Things transcends traditional medical boundaries, enabling a transition from reactive treatment to proactive prevention. This innovative method revolutionizes healthcare by facilitating early disease detection and tailored care, particularly in chronic disease management, where IoMT automates treatments based on real-time health data collection. Nonetheless, its benefits are countered by significant security challenges that endanger the lives of its users due to the sensitivity and value of the processed data, thereby attracting malicious interests. Moreover, the utilization of wireless communication for data transmission exposes medical data to interception and tampering by cybercriminals. Additionally, anomalies may arise due to human error, network interference, or hardware malfunctions. In this context, anomaly detection based on Machine Learning (ML) is an interesting solution, but it comes up against obstacles in terms of explicability and privacy protection. To address these challenges, a new framework for Intrusion Detection Systems is introduced, leveraging Artificial Neural Networks for intrusion detection while utilizing Federated Learning for privacy preservation. Additionally, eXplainable Artificial Intelligence methods are incorporated to enhance model explanation and interpretation. The efficacy of the proposed framework is evaluated and compared with centralized approaches using multiple datasets containing network and medical data, simulating various attack types impacting the confidentiality, integrity, and availability of medical and physiological data. The results offer compelling evidence that the FL method performs comparably to the centralized method, demonstrating high performance. Additionally, it affords the dual advantage of safeguarding privacy and providing model explanation while adhering to ethical principles.

Sources

Related papers