Explainable Machine Learning-Based Security and Privacy Protection Framework for Internet of Medical Things Systems
Ayoub Si-ahmed, Mohammed Ali Al-Garadi, Narhimene Boustia
Blida 1 University · PROXYLAN SPA · CERIST · Emory University
cs.CR, cs.AI
Submitted: 2026-08-07
Updated: 2026-08-11
Comments: 40 pages, 13 figures, 6 tables, journal paper
Code: https://github.com/ayoub1609/bispap
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
Importance score: 49/100
The gist: The paper introduces an "Explainable Machine Learning-Based Security and Privacy Protection Framework for Internet of Medical Things (IoMT) Systems" designed to address the critical security and
Terminology
Summary
The paper introduces an Explainable Machine Learning-Based Security and Privacy Protection Framework for Internet of Medical Things (IoMT) Systems
designed to address the critical security and privacy challenges inherent in healthcare technology. While IoMT enables a transition from reactive treatment to proactive prevention,
its benefits are countered by significant security challenges that endanger the lives of its users due to the sensitivity and value of the processed data.
These challenges include Man-In-The-Middle (MITM) attacks,
human error, network interference, or hardware malfunctions,
and the inherent opacity of many ML models, often referred to as ’blackbox’ models,
which lack transparency in their decision-making processes.
To mitigate these issues, the authors propose a new framework for Intrusion Detection Systems (IDS) that "leverages Artificial Neural Networks (ANN) for intrusion detection while utilizing Federated Learning (FL) for privacy preservation. Additionally, eXplainable Artificial Intelligence (XAI) methods are incorporated to enhance model explanation and interpretation."
Methodology
The proposed IoMT architecture is composed of three distinct layers: the Data Acquisition Layer, the Personal Server Layer, and the Medical Server Layer.
-
Local Training Process: The framework utilizes supervised learning via ANN for
real-time anomaly detection.
The ANN architecture employs therectified linear unit (ReLU)... as the activation function for the hidden layer
and thesigmoid activation function... for the output layer.
For optimization, theAdam optimizer... is chosen for its efficiency,
andcross-entropy is employed as the loss function.
The model usesHe-Initialization... for weight initialization due to its compatibility with ReLU.
-
Federated Learning (FL) Process: To preserve privacy, the framework
allows the sharing of locally trained model weights on end-devices instead of raw data.
Thisreduces bandwidth consumption and alleviates network congestion, thereby facilitating system scalability.
The hospital serverorchestrates the development of the global model
andaggregates the local model parameters received from participating devices using the Federated Averaging (FedAvg) algorithm.
-
eXplainable AI (XAI) Process: To address the
black box
nature of ANN, the framework incorporatesthe The SHapley Additive exPlanations (SHAP) method
toprovide a transparent, auditable record of the model’s decision-making logic for each prediction.
This providesboth local and global scopes of explanation
byattributing a value that represents a median marginal contribution to the prediction across all possible feature combinations.
Experimental Evaluation and Results
The framework was evaluated using four distinct datasets containing network and medical data
: NSL-KDD, UNSW-NB15, ToN-IoT, and WUSTL-EHMS. The researchers analyzed the impact of various FL parameters, including the number of participating clients, the client participation fraction, and the number of local training epochs.
The results offer compelling evidence that the FL method performs comparably to the centralized method, demonstrating high performance.
Specifically, the comparison shows that training models on separate data partitions generalizes as effectively as training a global model on the entire dataset.
Furthermore, the SHAP analysis confirmed that both learning paradigms consistently identify the same domain-relevant features as the primary contributors to attack detection,
demonstrating that the decentralized training process does not alter the underlying decision rationale of the intrusion detection model.
Ethical and Regulatory Contributions
The framework is designed to align with international standards such as HIPAA, GDPR, WHO and ISO/IEC 27001 and ISO/IEC 27701.
It addresses ethical imperatives through:
-
Data Protection and Privacy:
Leveraging FL for IDS, ensuring that patient data remains localized on their devices.
-
Transparency:
Integrating XAI methods such as SHAP... [to] provide clear and interpretable explanations for the model’s decisions.
-
Accountability and Bias Mitigation:
Prioritizes fairness by utilizing diverse datasets and applying XAI techniques to detect and correct biases.
Improvements for AI systems
1. Integration of Graph Neural Networks (GNNs) and Temporal Transformers
-
Improvement: Replace the standard ANN architecture with a hybrid model utilizing Graph Neural Networks to capture the relational topology of IoMT device networks and Temporal Transformers to process time-series physiological data.
-
Capability: The system can detect sophisticated
lateral movement
attacks where a hacker moves from a low-security device (e.g., a smart thermometer) to a critical device (e.g., an insulin pump) by analyzing the relationship between nodes, while simultaneously identifying subtle, time-dependent anomalies in patient vitals that standard ANNs might miss.
2. Implementation of Differentially Private Federated Learning (DP-FL)
-
Improvement: Augment the Federated Averaging (FedAvg) process with Differential Privacy (DP) by injecting calibrated Gaussian noise into the local model updates before they are sent to the Medical Server.
-
Capability: The system can provide mathematical guarantees against
Model Inversion Attacks,
preventing malicious actors from reconstructing a patient's specific medical history or sensitive biometric signatures from the shared model weights.
3. Transition from Post-hoc to Ante-hoc (Intrinsic) Explainability
-
Improvement: Incorporate Attention Mechanisms and Prototype-based learning directly into the model architecture, rather than relying solely on post-hoc SHAP explanations.
-
Capability: The system can provide
real-time reasoning
during the inference process, allowing clinicians to see exactly which segment of a waveform or which specific sensor reading triggered an alarm as it happens, rather than waiting for a secondary SHAP calculation to interpret ablack-box
decision.
4. Deployment of Continual Learning with Concept Drift Detection
-
Improvement: Integrate an online learning component equipped with a Drift Detection Method (DDM) to monitor changes in data distribution.
-
Capability: The system can autonomously adapt to
Concept Drift
—such as changes in patient baseline health due to aging or the introduction of new medical device models—and recognizeZero-Day
cyberattacks without requiring a full manual retraining cycle on the centralized server.
5. Hierarchical Federated Learning (HFL) Architecture
-
Improvement: Expand the three-layer architecture into a hierarchical structure that includes an
Edge Computing Layer
(e.g., hospital-grade routers/gateways) between the Personal Server and the Medical Server. -
Capability: The system can perform high-speed, low-latency local aggregation of model updates, significantly reducing the communication overhead on the global medical network and ensuring that critical security alerts are processed at the edge of the network for near-instantaneous response.
Abstract
The Internet of Medical Things transcends traditional medical boundaries, enabling a transition from reactive treatment to proactive prevention. This innovative method revolutionizes healthcare by facilitating early disease detection and tailored care, particularly in chronic disease management, where IoMT automates treatments based on real-time health data collection. Nonetheless, its benefits are countered by significant security challenges that endanger the lives of its users due to the sensitivity and value of the processed data, thereby attracting malicious interests. Moreover, the utilization of wireless communication for data transmission exposes medical data to interception and tampering by cybercriminals. Additionally, anomalies may arise due to human error, network interference, or hardware malfunctions. In this context, anomaly detection based on Machine Learning (ML) is an interesting solution, but it comes up against obstacles in terms of explicability and privacy protection. To address these challenges, a new framework for Intrusion Detection Systems is introduced, leveraging Artificial Neural Networks for intrusion detection while utilizing Federated Learning for privacy preservation. Additionally, eXplainable Artificial Intelligence methods are incorporated to enhance model explanation and interpretation. The efficacy of the proposed framework is evaluated and compared with centralized approaches using multiple datasets containing network and medical data, simulating various attack types impacting the confidentiality, integrity, and availability of medical and physiological data. The results offer compelling evidence that the FL method performs comparably to the centralized method, demonstrating high performance. Additionally, it affords the dual advantage of safeguarding privacy and providing model explanation while adhering to ethical principles.
Sources
- Infusing domain knowledge in AI-based "black box" models for better explainability with application in bankruptcy prediction
- Adam: A Method for Stochastic Optimization
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs