用集成模型提升医疗物联网网络异常检测准确率
Enhanced Anomaly Detection in IoMT Networks using Ensemble AI Models on the CICIoMT2024 Dataset
- 融合XGBoost、LSTM等多模型,捕捉设备通信时序特征
- 在CICIoMT2024数据集上实现更低误报率和更优检测效果
- 适合医疗网络安全领域研究者与系统部署人员参考
医疗物联网(IoMT)设备的快速普及带来了独特的网络安全挑战,主要源于其多样化的通信协议和关键性。本研究旨在构建一个面向IoMT网络流量的先进实时异常检测框架,利用人工智能/机器学习模型和CICIoMT2024数据集。通过整合多协议(MQTT、WiFi)、攻击类型(拒绝服务、分布式拒绝服务)、时间序列(活跃/空闲状态)及设备类型(蓝牙)的数据,全面覆盖了IoMT交互场景。实验中采用多种机器学习技术:基于XGBoost的集成模型以提升对特定攻击类型的性能;包含LSTM与CNN-LSTM的序列模型利用时间依赖性;以及适用于通用异常检测的自编码器和孤立森林等无监督模型。实验结果表明,集成模型有效降低了误报率并提升了检测精度。
原文摘要 · Abstract (English)
The rapid proliferation of Internet of Medical Things (IoMT) devices in healthcare has introduced unique cybersecurity challenges, primarily due to the diverse communication protocols and critical nature of these devices This research aims to develop an advanced, real-time anomaly detection framework tailored for IoMT network traffic, leveraging AI/ML models and the CICIoMT2024 dataset By integrating multi-protocol (MQTT, WiFi), attack-specific (DoS, DDoS), time-series (active/idle states), and device-specific (Bluetooth) data, our study captures a comprehensive range of IoMT interactions As part of our data analysis, various machine learning techniques are employed which include an ensemble model using XGBoost for improved performance against specific attack types, sequential models comprised of LSTM and CNN-LSTM that leverage time dependencies, and unsupervised models such as Autoencoders and Isolation Forest that are good in general anomaly detection The results of the experiment prove with an ensemble model lowers false positive rates and reduced detections.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。