Abstract
Internet of Medical Things (IoMT) networks generate heterogeneous and privacy-sensitive traffic, while severe class imbalance can further complicate intrusion detection across healthcare institutions. This paper evaluates a federated intrusion detection framework that combines a CNN-BiLSTM-Attention classifier with FedAvg aggregation, node-level SMOTE, and SHAP-based explainability. Three simulated hospital nodes train local models and exchange only model weights, while raw training samples remain local. The framework is evaluated on the full ECU-IoHT dataset and a computationally constrained subset comprising 10 of 169 CICIoT2023 CSV files. On ECU-IoHT, the proposed model achieved 94.02% accuracy, a weighted F1-score of 0.9540, ROC-AUC of 0.9975, MCC of 0.8771, and a false alarm rate of 0.0043. For the rare DoS class, recall reached 0.91, but precision was 0.11, indicating a substantial false-positive trade-off. On the evaluated CICIoT2023 subset, the model achieved 62.13% accuracy, weighted precision of 0.7691, ROC-AUC of 0.9410, and a false alarm rate of 0.0301. In the reported SHAP analysis, Length and Protocol produced the largest displayed effects for the No Attack class. These results show that federated training, local class balancing, and post-hoc explanation can be combined in the evaluated IoMT intrusion detection process while keeping raw samples local. Broader validation requires non-IID clients, evaluation on all 169 CICIoT2023 CSV files, repeated runs, formal privacy mechanisms, and component-level ablations.
Keywords
Introduction
Interconnected medical devices have expanded the amount of clinical and operational data exchanged inside healthcare networks. The same connectivity also increases the attack surface [1]. During the early COVID-19 response, the World Health Organization reported that cyberattacks directed at the organization were more than five times higher than during the same period of the previous year [2]. Such incidents motivate intrusion detection that can operate on heterogeneous medical-device traffic without requiring unrestricted pooling of institutional data. IoMT environments include devices such as heart-rate sensors, blood-pressure monitors, and temperature sensors, often using different protocols and hardware capabilities. Signature-based intrusion detection is limited when attack behavior is previously unseen or changes over time. Machine learning (ML)-based intrusion detection systems (IDSs) can learn traffic patterns directly from data, but their deployment in healthcare introduces additional requirements. In particular, training data may be distributed across institutions, attack classes can be strongly imbalanced, and security teams may need an explanation for high-impact alerts.
Recent papers have addressed this problem partially. Ghourabi [1] combined LightGBM and BERT-Transformer and reported approximately 99% accuracy, with results approaching 100% in some evaluated settings across ECU-IoHT, ToN-IoT, Edge-IIoTset, and EMBER. Mosaiyebzadeh et al. [3] proposed SECIoHT-FL, which combines federated learning, differential privacy, and SHAP explainability in an IoHT setting and reported 95.48% accuracy. These studies provide strong baselines, but the reviewed literature leaves a narrower question unresolved: how can federated IoMT intrusion detection address severe class imbalance locally while also providing feature-level explanations?
This paper evaluates that question using a CNN-BiLSTM-Attention model trained with FedAvg. The main contributions are as follows:
A federated IDS is evaluated with three simulated hospital nodes so that raw training samples remain local and only model weights are aggregated.
SMOTE is applied independently to the training partition at each node before local optimization. This design targets the severe imbalance in ECU-IoHT, where the DoS Attack class contains 639 samples compared with 77,920 Smurf Attack samples.
SHAP KernelExplainer is applied to the final global model, using a k-means summarized background derived from 500 test instances and explanations for 50 selected test samples.
The framework is evaluated on ECU-IoHT and on 10 of 169 CICIoT2023 partitions. On ECU-IoHT it achieves 94.02% accuracy, 0.9975 ROC-AUC, and 0.0043 FAR; on the evaluated CICIoT2023 subset it achieves 62.13% accuracy and 0.0301 FAR.
The remainder of the paper is organized as follows. Section 2 reviews ML IDS methods, IoMT security datasets, federated IDS approaches, and work on class imbalance and explainability. Section 3 summarizes the research gaps that motivate the framework. Section 4 introduces the technical components used by the method. Section 5 describes the datasets, preprocessing, federated setup, model architecture, SMOTE procedure, SHAP integration, and evaluation metrics. Section 6 presents the experimental results and limitations. Section 7 concludes the paper.
Table [tab:related-work] compares representative recent IDS approaches with the proposed framework.
Table . Comparison of related work.
N/R = not reported. For the proposed framework, “4 / 33” denotes four ECU-IoHT attack types and 33 CICIoT2023 attack types.
Complete Article
The complete article, including all figures, tables, equations and algorithms, is available in the official publication PDF.
Conclusion
This paper evaluated a federated intrusion-detection framework for IoMT healthcare networks in which raw training samples remain local to simulated nodes. The framework combines a CNN-BiLSTM-Attention classifier, FedAvg aggregation, node-level SMOTE, and SHAP KernelExplainer. In the simulated federated setup, only model weights are exchanged, while raw training data remain at the three virtual nodes. On ECU-IoHT, the proposed model achieved 94.02% accuracy, 0.9975 ROC-AUC, 0.0043 FAR, and 0.91 recall for the rare DoS Attack class. On the evaluated CICIoT2023 subset, it achieved 62.13% accuracy and 0.0301 FAR, compared with 31.29% accuracy and 0.0626 FAR for LightGBM in the same evaluated subset experiment. The CICIoT2023 result is based on 10 of 169 CSV files and should therefore be treated as a computationally constrained subset result. No formal update-level privacy guarantee is claimed because differential privacy and secure aggregation were not implemented.
Future work should deploy the framework across physically distributed infrastructure, evaluate non-IID client partitions, evaluate all 169 CICIoT2023 CSV files on dedicated hardware, and add repeated-seed, no-SMOTE, and architecture-component ablations. These experiments would separate the contributions of local oversampling, the hybrid network architecture, and federated aggregation more clearly while providing a stronger estimate of deployment behavior.
References
- A. Ghourabi, “A security model based on LightGBM and Transformer to protect health care systems from cyberattacks, ” IEEE Access, vol. 10, pp. 48 890-48 903, 2022, doi: 10.1109/ACCESS.2022.3172432
- World Health Organization, “WHO reports fivefold increase in cyber attacks, urges vigilance, ” Apr. 23, 2020. Accessed: Aug. 16, 2026. [Online]. Available: WHO news release (https://www.who.int/news/item/23-04-2020-who-reports-fivefold-increase-in-cyber-attacks-urges-vigilance).
- F. Mosaiyebzadeh, S. Pouriyeh, M. Han, L. Liu, Y. Xie, L. Zhao, and D. M. Batista, “Privacy-preserving federated learning-based intrusion detection system for IoHT devices, ” Electronics, vol. 14, no. 1, Art. no. 67, 2025, doi: 10.3390/electronics14010067
- G. Ke, Q. Meng, T. Finley, T. Wang, W. Chen, W. Ma, Q. Ye, and T.-Y. Liu, “LightGBM: A highly efficient gradient boosting decision tree, ” in Advances in Neural Information Processing Systems, vol. 30, 2017, pp. 3146-3154.
- D. Jin, Y. Lu, J. Qin, Z. Cheng, and Z. Mao, “SwiftIDS: Real-time intrusion detection system based on LightGBM and parallel intrusion detection mechanism, ” Computers & Security, vol. 97, Art. no. 101984, 2020, doi: 10.1016/j.cose.2020.101984
- J. Liu, Y. Gao, and F. Hu, “A fast network intrusion detection system using adaptive synthetic oversampling and LightGBM, ” Computers & Security, vol. 106, Art. no. 102289, 2021, doi: 10.1016/j.cose.2021.102289
- J. Devlin, M.-W. Chang, K. Lee, and K. Toutanova, “BERT: Pre-training of deep bidirectional transformers for language understanding, ” in Proc. 2019 Conf. North American Chapter of the Association for Computational Linguistics: Human Language Technologies (NAACL-HLT), vol. 1, Minneapolis, MN, USA, Jun. 2019, pp. 4171-4186, doi: 10.18653/v1/N19-1423
- J. Gao, “Network intrusion detection method combining CNN and BiLSTM in cloud computing environment, ” Computational Intelligence and Neuroscience, vol. 2022, Art. no. 7272479, 2022, doi: 10.1155/2022/7272479
- A. Halbouni, T. S. Gunawan, M. H. Habaebi, M. Halbouni, M. Kartiwi, and R. Ahmad, “CNN-LSTM: Hybrid deep neural network for network intrusion detection system, ” IEEE Access, vol. 10, pp. 99 837-99 849, 2022, doi: 10.1109/ACCESS.2022.3206425
- S. Sadhwani, M. A. H. Khan, R. Muthalagu, P. M. Pawar, and K. Suresh, “A hybrid BiLSTM-CNN approach for intrusion detection for IoT applications, ” Scientific Reports, vol. 16, Art. no. 155, 2026, doi: 10.1038/s41598-025-29079-y
- B. A. Agbor, B. U.-A. Stephen, P. Asuquo, U. O. Luke, and V. Anaga, “Hybrid CNN-BiLSTM-DNN approach for detecting cybersecurity threats in IoT networks, ” Computers, vol. 14, no. 2, Art. no. 58, 2025, doi: 10.3390/computers14020058
- J. Yin, B. Hou, J. Dai, and Y. Zu, “A CNN-BiLSTM method based on attention mechanism for class-imbalanced abnormal traffic detection, ” in Proc. 2024 6th International Conference on Computer Vision and Deep Learning (CVDL), Changsha, China, Jan. 2024, pp. 1-6, doi: 10.1145/3653781.3653807
- A. A. Hady, A. Ghubaish, T. Salman, D. Unal, and R. Jain, “Intrusion detection system for healthcare systems using medical and network data: A comparison study, ” IEEE Access, vol. 8, pp. 106 576-106 584, 2020, doi: 10.1109/ACCESS.2020.3000421
- M. Ahmed, S. Byreddy, A. Nutakki, L. F. Sikos, and P. Haskell-Dowland, “ECU-IoHT: A dataset for analyzing cyberattacks in Internet of Health Things, ” Ad Hoc Networks, vol. 122, Art. no. 102621, 2021, doi: 10.1016/j.adhoc.2021.102621
- M. A. Ferrag, O. Friha, D. Hamouda, L. Maglaras, and H. Janicke, “Edge-IIoTset: A new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning, ” IEEE Access, vol. 10, pp. 40 281-40 306, 2022, doi: 10.1109/ACCESS.2022.3165809
- T. M. Booij, I. Chiscop, E. Meeuwissen, N. Moustafa, and F. T. H. den Hartog, “ToN_IoT: The role of heterogeneity and the need for standardization of features and attack types in IoT network intrusion data sets, ” IEEE Internet of Things Journal, vol. 9, no. 1, pp. 485-496, Jan. 2022, doi: 10.1109/JIOT.2021.3085194
- E. C. P. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, and A. A. Ghorbani, “CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment, ” Sensors, vol. 23, no. 13, Art. no. 5941, 2023, doi: 10.3390/s23135941
- S. R. Hassan, M. U. Tanveer, S. Prajapat, and M. Shabaz, “A comprehensive survey on intrusion detection in Internet of Medical Things: Datasets, federated learning, blockchain, and future research directions, ” ICT Express, vol. 11, no. 6, pp. 1291-1310, 2025, doi: 10.1016/j.icte.2025.11.005
- B. Olanrewaju-George and B. Pranggono, “Federated learning-based intrusion detection system for the Internet of Things using unsupervised and supervised deep learning models, ” Cyber Security and Applications, vol. 3, Art. no. 100068, 2025, doi: 10.1016/j.csa.2024.100068
- S. A. Mahmud, N. Islam, Z. Islam, Z. Rahman, and S. T. Mehedi, “Privacy-preserving federated learning-based intrusion detection technique for cyber-physical systems, ” Mathematics, vol. 12, no. 20, Art. no. 3194, 2024, doi: 10.3390/math12203194
- K. Yang, J. Wang, and M. Li, “An improved intrusion detection method for IIoT using attention mechanisms, BiGRU, and Inception-CNN, ” Scientific Reports, vol. 14, Art. no. 19339, 2024, doi: 10.1038/s41598-024-70094-2
- H. R. Sayegh, W. Dong, and A. M. Al-Madani, “Enhanced intrusion detection with LSTM-based model, feature selection, and SMOTE for imbalanced data, ” Applied Sciences, vol. 14, no. 2, Art. no. 479, 2024, doi: 10.3390/app14020479
- Z. Fan, S. Sohail, F. Sabrina, and X. Gu, “Sampling-based machine learning models for intrusion detection in imbalanced dataset, ” Electronics, vol. 13, no. 10, Art. no. 1878, 2024, doi: 10.3390/electronics13101878
- A. Hafid, M. Rahouti, and M. Aledhari, “Optimizing intrusion detection in IoMT networks through interpretable and cost-aware machine learning, ” Mathematics, vol. 13, no. 10, Art. no. 1574, 2025, doi: 10.3390/math13101574
- M. Georgiades and F. Hussain, “An explainable AI approach for interpretable cross-layer intrusion detection in Internet of Medical Things, ” Electronics, vol. 14, no. 16, Art. no. 3218, 2025, doi: 10.3390/electronics14163218