Anomaly detect ionin internet of medical things using deep learning
2025
0 views
0 downloads
Advisor: Prof. Dr. Devrim Akgün
Abstract (EN)
The increasing adoption of the Internet of Medical Things (IoMT) in healthcare systems offers transformative benefits in patient monitoring, real-time diagnostics and automated medical services. However, this growing integration of interconnected medical devices into healthcare infrastructures simultaneously opens up critical cybersecurity vulnerabilities. IoMT environments are particularly vulnerable due to their device heterogeneity, constrained computational capabilities and the high-stakes nature of patient data and services. Traditional signature-based intrusion detection systems (IDS) fall short in handling modern and evolving network threats, particularly zero-day attacks and subtle anomalous behavior that may not match known malicious patterns. Consequently, there is a pressing need for intelligent anomaly detection solutions that are capable of learning complex attack patterns from network data in IoMT contexts. This thesis presents a comprehensive investigation into machine learning (ML) and deep learning (DL) approaches for network-based anomaly detection using the CICIoMT2024 dataset, one of the most comprehensive benchmark datasets in this field. The goal is to evaluate and compare the effectiveness of different algorithms in classifying network traffic into normal and various anomalous categories, thereby providing a strong baseline for future IoMT security frameworks. The dataset includes traffic from diverse IoMT devices and comprises 18 distinct attack classes in addition to benign data. Our experiments are structured around three classification tasks: binary classification (benign vs. anomalous), 6-class classification (aggregated attack categories) and 19-class classification (fine-grained attacks). In the baseline evaluation, traditional machine learning models such as Logistic Regression, Random Forest and AdaBoost were trained using standard pipeline techniques involving data cleaning, class balancing, and performance metrics evaluation. For the binary classification task, Random Forest performed exceptionally well, achieving an accuracy of 0.98 along with high precision and recall, demonstrating that classical models are still highly effective for simple anomaly detection tasks where the decision boundaries are more clearly separable. To address more complex classification tasks, deep learning architectures were introduced. These included Dense Neural Networks (DNN), 1D Convolutional Neural Networks (Conv1D), Recurrent Neural Networks (RNN), Long Short-Term Memory (LSTM) networks and Attention mechanisms. Furthermore, we proposed hybrid deep learning models that combine RNN layers with LSTM units and Attention mechanisms. The hybrid model architecture, specifically the RNN + LSTM + Attention stack, demonstrated superior performance in handling multivariate time series data with spatial and temporal dependencies. This model achieved an accuracy of 0.99 in binary class task, 0.82 in the 6-class task and 0.66 in the 19-class task, significantly outperforming the standalone models The attention mechanism enhanced the model's capacity to focus on the most informative time steps, particularly in sequences where anomalous behavior manifests intermittently or subtly. This capacity to dynamically prioritize relevant temporal features proved crucial in distinguishing between closely related attack types, such as DoS vs. DDoS or Spoofing vs. Benign traffic. Additionally, the inclusion of stacked layers in the hybrid models allowed for multi-level abstraction, enabling the model to learn both short-term patterns (through RNN layers) and long-term dependencies (through LSTM layers). Despite these promising results, the research identified several limitations. First, the reliance on a single dataset, albeit comprehensive, may limit generalizability. Second, deep models entail considerable computational overhead, rendering them less feasible for real-time or edge deployment without optimization. Lastly, class imbalance, even after downsampling, remains a challenge in training fair and unbiased models, especially when detecting underrepresented attack types. To overcome these limitations and further advance the field, several recommendations for future work are proposed. One major direction involves optimizing models for real-time deployment on edge devices using model compression techniques like weight sparsification, reduced-precision formats and teacher-student training frameworks. Another crucial area is explainability—employing tools like SHAP, LIME, or attention heatmaps can help visualize decision-making processes and provide insights into model behavior, thereby increasing trust in AI-powered intrusion detection systems. Moreover, expanding the dataset to include traffic from newer IoMT devices and communication protocols would enhance generalization and adaptability to real-world conditions. Feature engineering is another avenue for improvement. Re-extracting and enriching feature sets from raw pcap files could uncover new, more discriminative patterns—especially those that are currently indistinguishable using the existing features. This could also improve classification performance for subtle or overlapping attack types. Furthermore, adaptability to dynamic conditions in IoMT networks, which frequently experience changes in traffic volumes, device states, and operational contexts, is critical. Online learning, domain adaptation, and continual training approaches could help ensure models remain effective over time. Lastly, cross-dataset generalization and benchmarking are necessary to test the robustness and transferability of proposed models across different network environments. Evaluating the trained models on other benchmark datasets or real-world IoMT traffic can reveal the degree to which these systems can handle diverse operational scenarios and novel attack strategies. In conclusion, this thesis provides a thorough and structured comparison of various machine learning and deep learning methods for anomaly detection in IoMT networks using a large, realistic dataset. The findings underscore the potential of hybrid deep learning models with attention mechanisms to outperform traditional techniques in complex classification tasks. Nevertheless, realizing practical and generalizable solutions requires further efforts in dataset diversification, model explainability, optimization for edge devices, and adaptive learning strategies. As healthcare continues to evolve into a more connected and data-driven domain, robust and intelligent anomaly detection systems will play a crucial role in protecting patient data and ensuring the continuity and security of critical medical services.
Author
Dr. Ayşe Betül Büken
Institution
How to Cite
Ayşe Betül Büken (Master Thesis). Anomaly detect ionin internet of medical things using deep learning, 2025, Sakarya University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Sakarya University
- Computational investigation of battery materials using density functional theory(2023)
- Haci Ahmed b. Seyyid al-Bigavî and Tarjama al-Awārif al-maārif (sections of 22-43)(2024)
- Synthesis of carbazol substituted 3,4-dihydropyrimidine-2(1h)-thione deri̇vati̇ves(2024)
- Classification of recyclable wastes with deep learning models: A comparison on the effect of dataset size(2024)
- Hermeneutical analysis of sacrifice, sacred violence and scapegoat motifs in Turkish Mythology(2024)
- Novel thio-chalcone substituted metallophthalocyanines: synthesis, characterization and redox behaviour(2018)