نحو حلول متقدمة قائمة على الذكاء الاصطناعي لتأمين إنترنت الأشياء الطبية في أنظمة المعلومات الصحية الذكية
Towards advanced AI-based solutions for securing IoMT in smart health information systems

شارك:
المجلة: Scientific Reports، المجلد: 16، العدد: 1
DOI: https://doi.org/10.1038/s41598-025-31850-0
PMID: https://pubmed.ncbi.nlm.nih.gov/41501256
تاريخ النشر: 2026-01-07
المؤلف: Xuyuan Liu
الموضوع الرئيسي: أمن الشبكات وكشف التسلل

نظرة عامة

إن إنترنت الأشياء الطبية (IoMT) يشمل شبكة من الأجهزة الطبية والتطبيقات المتصلة التي تعتبر ضرورية للرعاية الصحية الحديثة. ومع ذلك، فإن هذا الترابط يطرح مخاطر كبيرة على الأمن السيبراني، بما في ذلك خروقات البيانات والهجمات الخبيثة التي تعرض سلامة المرضى للخطر. لمعالجة هذه التحديات، يقدم هذا البحث نموذج BiGRU/RBWK، الذي يدمج وحدات التكرار الموجهة ثنائية الاتجاه (BiGRU) مع خوارزمية تحسين الصقر الأسود المنقح (RBWK). يعزز RBWK نموذج BiGRU من خلال تحسين المعلمات الفائقة، مما يؤدي إلى تحسين سرعة التقارب ودقة التصنيف. يستخدم النموذج خط أنابيب معالجة مسبقة قوي يستخدم الإزالة التكرارية للميزات (RFE) جنبًا إلى جنب مع آلات الدعم الناقل (SVM) للتخفيف من الإفراط في التكيف وتقليل المتطلبات الحاسوبية.

تظهر النتائج التجريبية من مجموعتين بيانات عامتين، WUSTL-EHMS-2020 وECU-IoHT، أن نموذج BiGRU/RBWK يحقق مقاييس أداء متفوقة، بما في ذلك معدلات دقة تبلغ 95.6% و93.8%، على التوالي، بالإضافة إلى تحسين الدقة والاسترجاع وقيمة F1-score وAUC-ROC مقارنة بالطرق الحالية مثل Random Forest وLSTM وCNN والنماذج الهجينة. تشير النتائج إلى أن نموذج BiGRU/RBWK لا يظهر فقط قدرات كشف عالية مع معدلات إيجابية خاطئة منخفضة (درجات AUC-ROC تبلغ 0.974 و0.958) ولكنه يقدم أيضًا تحسينًا في القابلية للتفسير والعمومية، مما يجعله مناسبًا للتطبيقات في الوقت الحقيقي في بيئات IoMT ذات الموارد المحدودة. ستستكشف الأبحاث المستقبلية دمج التعلم الفيدرالي والذكاء الاصطناعي القابل للتفسير لتعزيز حماية الخصوصية وشفافية النموذج، مما يضمن القابلية للتوسع والتكيف عبر إعدادات IoMT المتنوعة.

مقدمة

تسلط مقدمة الورقة الضوء على التأثير التحويلي لإنترنت الأشياء (IoT) على مختلف القطاعات، مع التركيز بشكل خاص على الرعاية الصحية، حيث تطور إلى إنترنت الأشياء الطبية (IoMT). تعزز هذه التكنولوجيا الكفاءة التشغيلية في البيئات الطبية، مما يسهل دمج الأجهزة الطبية والتطبيقات مع تكنولوجيا المعلومات. يعد IoMT محوريًا في تحسين رعاية المرضى، وتحسين العمليات السريرية، وتعزيز النتائج المالية من خلال تمكين التواصل السلس وتبادل البيانات بين الأجهزة الطبية المتصلة.

تشير الورقة إلى زيادة كبيرة في استخدام الأجهزة القابلة للارتداء التي تراقب العلامات الحيوية مثل معدل ضربات القلب وضغط الدم ومستويات الجلوكوز في الدم، مما يساهم في جمع بيانات صحية دقيقة ومستمر. بالإضافة إلى ذلك، يدعم IoMT الطب عن بُعد، مما يسمح لمقدمي الرعاية الصحية بتشخيص وعلاج المرضى عن بُعد، وهو ما يعد مفيدًا بشكل خاص للسكان المحرومين أو النائيين. يبرز هذا التحول من نماذج الرعاية الصحية التقليدية التفاعلية إلى نهج مبتكرة واستباقية الإمكانيات التي يمتلكها IoMT لتحسين نتائج المرضى وتقليل إعادة دخول المستشفيات.

النتائج

في هذا القسم، يقدم المؤلفون تحليلًا مقارنًا لأداء الأمان لنموذج BiGRU/RBWK المقترح مقابل نماذج متقدمة مختلفة لرصد التهديدات السيبرانية في بيئات إنترنت الأشياء الطبية (IoMT). توضح النتائج، التي تم تصويرها من خلال الرسوم البيانية الشريطية، الفعالية المتفوقة لنموذج BiGRU/RBWK في معالجة كل من مجموعات البيانات غير المتوازنة والمعقدة. تم اختيار النماذج المقارنة، بما في ذلك Random Forest وLSTM وCNN وAutoencoders وCNN-LSTM، بناءً على ملاءمتها وأدائها المثبت في مهام كشف التسلل. تم اختيار Random Forest لصلابته وقابليته للتفسير، بينما يقوم LSTM بنمذجة الطبيعة التسلسلية لحركة مرور الشبكة بشكل فعال. تم تضمين CNN لقدرتها على استخراج الميزات من البيانات الهيكلية، وتم استخدام Autoencoders للكشف عن الشذوذ غير المراقب. تم أيضًا اختبار نموذج CNN-LSTM الهجين للاستفادة من كل من تعلم الميزات المكانية والزمانية.

تشير النتائج إلى أن نموذج BiGRU/RBWK يتفوق على المعايير المحددة، محققًا معدلات دقة ملحوظة، مما يثبت فعاليته في سياق تحليل حركة مرور IoMT. يبرز هذا التقييم الشامل ضد مجموعة من نماذج التعلم الآلي التقليدية والمتقدمة إمكانيات إطار BiGRU/RBWK كحل متطور لرصد التهديدات السيبرانية في بيئات IoMT.

المناقشة

تسلط قسم المناقشة في الورقة الضوء على الحاجة الملحة لتعزيز تدابير الأمان في إنترنت الأشياء الطبية (IoMT) بسبب الزيادة المتزايدة في اعتماد الأجهزة الطبية المتصلة والتهديدات السيبرانية المرتبطة بها. يقدم المؤلفون نموذجًا هجينًا جديدًا، BiGRU/RBWK، الذي يدمج وحدات التكرار الموجهة ثنائية الاتجاه (BiGRU) مع خوارزمية تحسين الصقر الأسود المنقح (RBWK). يهدف هذا النموذج إلى تحسين كشف التسلل في أنظمة IoMT من خلال التقاط الاعتماديات طويلة الأجل في بيانات حركة مرور الشبكة بشكل فعال، مما يعزز التعرف على الأنماط العادية والخبيثة. أظهر النموذج المقترح دقة تصنيف مثيرة للإعجاب بلغت 95.6% و93.8% على مجموعتين بيانات متاحة للجمهور، متفوقًا على الطرق الحالية مثل Random Forest وLSTM.

تناقش الورقة أيضًا التحديات الكبيرة في أمان IoMT، بما في ذلك نقص آليات مصادقة البيانات التي تعرض المنظمات الصحية لمخاطر مثل التلاعب بالبيانات والوصول غير المصرح به. يؤكد المؤلفون على أهمية وجود خط أنابيب معالجة مسبقة قوي، والذي يتضمن تقنيات مثل تقدير الاحتمالات القصوى والإزالة التكرارية للميزات، للتخفيف من مشكلات مثل الإفراط في التكيف وعدم توازن الفئات. من خلال ضمان دقة تصنيف عالية ومعدلات إيجابية خاطئة منخفضة، يسعى نموذج BiGRU/RBWK ليس فقط لحماية المعلومات الصحية الحساسة ولكن أيضًا لاستعادة ثقة أصحاب المصلحة في أنظمة IoMT، مما يسهل في النهاية اعتماد حلول الصحة الرقمية على نطاق أوسع.

القيود

تعترف الدراسة بعدة قيود لنموذج BiGRU/RBWK المقترح لرصد التهديدات السيبرانية في أنظمة إنترنت الأشياء الطبية (IoMT)، على الرغم من أدائه الواعد. تعتبر الاعتماد على مجموعات البيانات المعلّمة للتدريب مصدر قلق رئيسي، حيث غالبًا ما تكون نادرة في إعدادات الرعاية الصحية الواقعية بسبب قضايا الخصوصية وطبيعة الهجمات السيبرانية المتطورة. تعتمد فعالية النموذج على جودة وتمثيل بيانات التدريب؛ أي تحيزات أو نقص في هذه المجموعات قد تعيق قدراته على التعميم.

بالإضافة إلى ذلك، على الرغم من تنفيذ تقنيات المعالجة المسبقة مثل العينة العشوائية السفلية (RUS) والإزالة التكرارية للميزات (RFE) لمعالجة عدم توازن الفئات والتخفيف من مخاطر الإفراط في التكيف، لا يزال النموذج يواجه تحديات عند العمل مع مجموعات بيانات محدودة أو غير متوازنة بشكل كبير. قد تؤثر هذه القيود سلبًا على دقة الكشف، خاصة بالنسبة لفئات الهجوم الأقل. لمعالجة هذه القضايا، ستستكشف الأبحاث المستقبلية أساليب التعلم شبه المراقب والتعلم الذاتي لتقليل الاعتماد على البيانات المعلّمة، جنبًا إلى جنب مع تقنيات تعزيز البيانات المتقدمة لتحسين قوة النموذج وأدائه.

Journal: Scientific Reports, Volume: 16, Issue: 1
DOI: https://doi.org/10.1038/s41598-025-31850-0
PMID: https://pubmed.ncbi.nlm.nih.gov/41501256
Publication Date: 2026-01-07
Author(s): Xuyuan Liu
Primary Topic: Network Security and Intrusion Detection

Overview

The Internet of Medical Things (IoMT) encompasses a network of interconnected medical devices and applications crucial for modern healthcare. However, this interconnectedness poses significant cybersecurity risks, including data breaches and malicious attacks that jeopardize patient safety. To address these challenges, this paper introduces the BiGRU/RBWK model, which integrates Bidirectional Gated Recurrent Units (BiGRU) with a Refined Black-winged Kite (RBWK) optimization algorithm. The RBWK enhances the BiGRU model by optimizing hyperparameters, leading to improved convergence speed and classification accuracy. The model employs a robust preprocessing pipeline utilizing Recursive Feature Elimination (RFE) alongside Support Vector Machines (SVM) to mitigate overfitting and reduce computational demands.

Experimental results from two public datasets, WUSTL-EHMS-2020 and ECU-IoHT, demonstrate that the BiGRU/RBWK model achieves superior performance metrics, including accuracy rates of 95.6% and 93.8%, respectively, along with enhanced precision, recall, F1-score, and AUC-ROC values compared to existing methods such as Random Forest, LSTM, CNN, and hybrid models. The findings indicate that the BiGRU/RBWK model not only exhibits high detection capabilities with low false positive rates (AUC-ROC scores of 0.974 and 0.958) but also offers improved interpretability and generalizability, making it suitable for real-time applications in resource-constrained IoMT environments. Future research will explore the integration of federated learning and explainable AI to further enhance privacy protection and model transparency, ensuring scalability and adaptability across diverse IoMT settings.

Introduction

The introduction of the paper highlights the transformative impact of the Internet of Things (IoT) on various sectors, with a particular emphasis on healthcare, where it has evolved into the Internet of Medical Things (IoMT). This technology enhances operational efficiency in medical environments, facilitating the integration of medical devices and applications with information technology. The IoMT is pivotal in improving patient care, optimizing clinical processes, and enhancing financial outcomes by enabling seamless communication and data exchange among interconnected medical devices.

The paper notes a significant increase in the use of wearable devices that monitor vital signs such as heart rate, blood pressure, and blood glucose levels, which contribute to continuous and accurate health data collection. Additionally, the IoMT supports telemedicine, allowing healthcare providers to diagnose and treat patients remotely, which is particularly beneficial for underserved or remote populations. This shift from traditional reactive healthcare models to innovative, proactive approaches underscores the potential of IoMT to improve patient outcomes and reduce hospital readmissions.

Results

In this section, the authors present a comparative analysis of the security performance of their proposed BiGRU/RBWK model against various advanced models for detecting cyberthreats in Internet of Medical Things (IoMT) environments. The results, illustrated through bar charts, demonstrate the superior effectiveness of the BiGRU/RBWK model in addressing both imbalanced and complex datasets. The selection of comparative models, including Random Forest, LSTM, CNN, Autoencoders, and CNN-LSTM, was based on their relevance and proven performance in intrusion detection tasks. Random Forest was chosen for its robustness and interpretability, while LSTM effectively models the sequential nature of network traffic. CNN was included for its capability in feature extraction from structured data, and Autoencoders were utilized for unsupervised anomaly detection. The hybrid CNN-LSTM model was also tested to leverage both spatial and temporal feature learning.

The results indicate that the BiGRU/RBWK model outperforms the selected benchmarks, achieving notable accuracy rates, thus validating its efficacy in the context of IoMT traffic analysis. This comprehensive benchmarking against a range of traditional and advanced machine learning paradigms underscores the potential of the BiGRU/RBWK framework as a state-of-the-art solution for cyber threat detection in IoMT environments.

Discussion

The discussion section of the paper highlights the pressing need for enhanced security measures in the Internet of Medical Things (IoMT) due to the increasing adoption of connected medical devices and the associated cyber threats. The authors present a novel hybrid model, BiGRU/RBWK, which integrates Bidirectional Gated Recurrent Units (BiGRU) with the Refined Black-winged Kite (RBWK) optimization algorithm. This model aims to improve intrusion detection in IoMT systems by effectively capturing long-term dependencies in network traffic data, thereby enhancing the identification of both normal and malicious patterns. The proposed model demonstrated impressive classification accuracies of 95.6% and 93.8% on two publicly available datasets, outperforming existing methods such as Random Forest and LSTM.

The paper also addresses significant challenges in IoMT security, including the lack of data authentication mechanisms that expose healthcare organizations to risks like data tampering and unauthorized access. The authors emphasize the importance of a robust preprocessing pipeline, which includes techniques like max likelihood imputation and recursive feature elimination, to mitigate issues such as overfitting and class imbalance. By ensuring high classification accuracy and low false positive rates, the BiGRU/RBWK model not only aims to protect sensitive health information but also seeks to restore stakeholder confidence in IoMT systems, ultimately facilitating the broader adoption of digital health solutions.

Limitations

The study acknowledges several limitations of the proposed BiGRU/RBWK model for detecting cyberthreats in Internet of Medical Things (IoMT) systems, despite its promising performance. A primary concern is the model’s reliance on labeled datasets for training, which are often scarce in real-world healthcare settings due to privacy issues and the evolving nature of cyberattacks. The effectiveness of the model is contingent upon the quality and representativeness of the training data; any biases or deficiencies in these datasets could hinder its generalization capabilities.

Additionally, while preprocessing techniques such as Random Under-Sampling (RUS) and Recursive Feature Elimination (RFE) have been implemented to address class imbalance and mitigate overfitting risks, the model still faces challenges when working with limited or highly imbalanced datasets. These limitations may adversely affect detection accuracy, particularly for minority attack classes. To address these issues, future research will explore semi-supervised and self-supervised learning approaches to reduce dependence on labeled data, alongside advanced data augmentation techniques to enhance model robustness and performance.

شارك: