Comparative Performance of Machine-Learning Algorithms for Detecting Network Intrusions in Internet-of-Medical-Things Environments: A Systematic Technical Evidence Synthesis
DOI:
https://doi.org/10.66687/JMRISKeywords:
deep learning, machine learning, intrusion detection, Internet of Medical ThingsAbstract
Background: The Internet of Medical Things (IoMT) connects wearable sensors, bedside monitors, implantable devices, gateways, clinical systems and cloud infrastructure. Although connectivity supports continuous monitoring and more efficient healthcare delivery, it also introduces network attack surfaces capable of affecting confidentiality, integrity, availability and potentially patient safety. Machine-learning-based intrusion detection systems (IDSs) have therefore received increasing attention.
Objective: To compare machine-learning approaches available through 2021 for detecting network intrusions in IoMT environments and identify algorithmic and deployment characteristics most appropriate for healthcare networks.
Methods: A structured technical evidence synthesis was conducted using peer-reviewed studies published no later than 31 December 2021. References were restricted to Q1 journals in cybersecurity, networking, artificial intelligence, Internet of Things and biomedical informatics. IoMT-specific studies were prioritized and supplemented with high-quality IoT intrusion-detection research where algorithms, datasets or methodological principles were directly transferable. Classical machine learning, ensemble learning and deep-learning approaches were compared across discrimination, multiclass detection, computational demand, interpretability, class imbalance, validation methodology and deployment feasibility.
Results: Random Forest and related ensemble methods consistently demonstrated strong performance for structured network-flow data while retaining moderate computational and interpretive advantages. Deep belief networks and recurrent architectures demonstrated high detection performance for complex or sequential attack patterns. Hybrid CNN-LSTM models offered automatic feature learning and temporal modeling but required greater computational resources. A 2021 optimized deep recurrent approach reported 99.76% overall accuracy, while earlier IoMT studies demonstrated high detection performance using Random Forest, deep belief networks and ensemble architectures. However, direct ranking was inappropriate because studies used different datasets, attacks, feature sets and validation procedures. Dataset representativeness, class imbalance, false-alarm burden and computational location were at least as important as headline accuracy.
Conclusion: No single algorithm can be considered universally optimal for IoMT intrusion detection. For structured flow-level data, Random Forest and ensemble methods provide a strong accuracy-efficiency compromise. Deep and recurrent architectures are attractive when temporal or high-dimensional attack patterns justify additional computational cost. Practical IoMT IDSs should employ layered deployment, per-class evaluation, temporally independent validation and explicit measurement of latency, false alarms and resource consumption.
References
Hady AA, Ghubaish A, Salman T, Unal D, Jain R. Intrusion detection system for healthcare systems using medical and network data: a comparison study. IEEE Access. 2020;8:106576-106584. doi:10.1109/ACCESS.2020.3000421.
Thamilarasu G, Odesile A, Hoang A. An intrusion detection system for Internet of Medical Things. IEEE Access. 2020;8:181560-181576. doi:10.1109/ACCESS.2020.3026260.
Manimurugan S, Al-Mutairi S, Aborokbah MM, Chilamkurti N, Ganesan S, Patan R. Effective attack detection in Internet of Medical Things smart environment using a deep belief neural network. IEEE Access. 2020;8:77396-77404. doi:10.1109/ACCESS.2020.2986013.
Kumar P, Gupta GP, Tripathi R. An ensemble learning and fog-cloud architecture-driven cyber-attack detection framework for IoMT networks. Comput Commun. 2021;166:110-124.
Khan S, Akhunzada A. A hybrid DL-driven intelligent SDN-enabled malware detection framework for Internet of Medical Things (IoMT). Comput Commun. 2021;170:209-216. doi:10.1016/j.comcom.2021.01.013.
Saheed YK, Arowolo MO. Efficient cyber attack detection on the Internet of Medical Things-smart environment based on deep recurrent neural network and machine learning algorithms. IEEE Access. 2021;9:161546-161554. doi:10.1109/ACCESS.2021.3128837.
Hathaliya JJ, Tanwar S. An exhaustive survey on security and privacy issues in Healthcare 4.0. Comput Commun. 2020;153:311-335. doi:10.1016/j.comcom.2020.02.018.
Liaqat S, Akhunzada A, Shaikh FS, Giannetsos A, Jan MA. SDN orchestration to combat evolving cyber threats in Internet of Medical Things (IoMT). Comput Commun. 2020;160:697-705. doi:10.1016/j.comcom.2020.07.006.
Al-Garadi MA, Mohamed A, Al-Ali AK, Du X, Ali I, Guizani M. A survey of machine and deep learning methods for Internet of Things (IoT) security. IEEE Commun Surv Tutor. 2020;22(3):1646-1685.
Tahsien SM, Karimipour H, Spachos P. Machine learning based solutions for security of Internet of Things (IoT): a survey. J Netw Comput Appl. 2020;161:102630. doi:10.1016/j.jnca.2020.102630.
Zarpelão BB, Miani RS, Kawakani CT, de Alvarenga SC. A survey of intrusion detection in Internet of Things. J Netw Comput Appl. 2017;84:25-37.
Diro AA, Chilamkurti N. Distributed attack detection scheme using deep learning approach for Internet of Things. Future Gener Comput Syst. 2018;82:761-768.
Koroniotis N, Moustafa N, Sitnikova E, Turnbull B. Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset. Future Gener Comput Syst. 2019;100:779-796.
Lohiya R, Thakkar A. Application domains, evaluation data sets, and research challenges of IoT: a systematic review. IEEE Internet Things J. 2021;8(11):8774-8798. doi:10.1109/JIOT.2020.3048439.