Vollständiger Abstract
Worum geht es in dieser Arbeit?
Abstract Attack surface for cyber threats in healthcare environments is expanding rapidly with the increasing adoption of Internet of Things (IoT) devices. These devices are typically resource-constrained and possess limited security features, making them highly vulnerable to a wide range of network-based attacks. Furthermore, the evolving nature of cyberattacks necessitates the development of lightweight classification models capable of quickly adapting to new data to detect emerging threats effectively. In this paper, two models are proposed for detecting malicious activity in healthcare IoT networks. The first is a hierarchical two-layer model, consisting of an initial binary classifier that separates benign from malicious traffic, followed by a multi-class classifier to identify specific attack types. The second is a flat model, which directly classifies network traffic into a predefined set of classes. Both models were evaluated using two recent datasets: CIC-BCCC-NRC IoMT-2024 and Combined-IoT-IDS. Multiple ML algorithms, including Random Forest, Decision Tree, and Categorical Boosting, were tested, along with ensemble techniques. Experimental results show that both models achieved accuracies and F1-scores exceeding 99%. On the IoMT-2024 dataset, the hierarchical model reached a peak 99.61% accuracy (99% F1-score), while the flat model obtained 99.39% accuracy (99% F1-score). On the Combined-IoT-IDS dataset, both architectures achieved up to 100% accuracy and F1-scores, confirming their robust detection capabilities. Specifically, the hierarchical design achieves rapid inference speeds as low as 0.02s. The hierarchical model outperformed the flat model in memory usage; for example, the Layer 2 CatBoost model requires only 2.15 MB for storage and 0.0117 MB for RAM, whereas the flat model requires 34.40 MB and 0.1641 MB, respectively. This optimized approach, utilizing early binary filtering of benign traffic, ensures the framework’s suitability for real-time deployment in resource-constrained medical IoT environments.
Bibliografischer Nachweis
Publikationsdaten
- Autor:innen
- Dana ElRushaidat, Tuqa Sammak, Yumna Ghannam, Batool Alkhalil
- Quelle
- Discover Internet of Things
- Publikation
- 2026-01-01
- Band / Ausgabe
- Nicht angegeben
- Seiten
- Nicht angegeben
- ISSN / ISBN
- 2730-7239
- Zitationen
- 0 laut Crossref
- Referenzen
- 0 hinterlegt
Zitieren
Zitierfähiger Nachweis
Dana ElRushaidat, Tuqa Sammak, Yumna Ghannam, Batool Alkhalil (2026). Hierarchical versus flat machine learning model for intrusion detection in secure IoT healthcare environment. Discover Internet of Things. https://doi.org/10.1007/s43926-026-00491-8
Kontext
Themen, Förderung und Nutzung
Lizenzhinweise: Lizenz 1