用轻量数字孪生与联邦强化学习,实现医疗物联网的隐私保护防御。
Federated Temporal Attention Intelligence for Cyber-Resilient IoMT: Lightweight Digital Twins and PPO-Driven Honeypot Deception

- 基于GRU和时序注意力的流量威胁分类,结合数字孪生异常评分动态调控检测
- 在两个数据集上准确率达99.66%以上,比基线快81%收敛,对罕见攻击类别的F1达1.0
- 支持可解释性分析,适合医疗物联网安全防护场景
互联网医疗设备(IoMT)的快速普及带来了严峻的网络安全挑战,尤其在资源受限、低延迟和严格数据隐私要求的医疗环境中。本文提出轻量级数字孪生与联邦强化学习(LDT-FRL)框架,集成四种互补机制:基于GRU骨干的时序注意力编码器(TAE)用于流级威胁分类;轻量级LSTM数字孪生模型通过正常流量训练生成设备级异常分数,以学习的Sigmoid耦合门控TAE分类器;基于七维状态的联邦近端策略优化(PPO)代理,决策于允许、隔离、蜜罐重定向三动作;智能蜜罐层将可疑流量转化为可行动威胁情报。采用基于EMA平滑客户端验证损失作为逆权重的联邦平均策略,在非独立同分布客户端下稳定全局更新。在CICDDoS 2019和TON-IoT基准测试中,分别达到99.66%和99.95%的测试准确率,宏平均F1分别为0.9913和0.9995,收敛速度比DTFL-CD基线快81%,并在严重不平衡的MITM类别上实现完美F1=1.000。SHAP、LIME、Grad-CAM及反事实分析表明,TAE聚焦于语义有意义的流量特征,为每项防御决策提供可解释证据。
原文摘要 · Abstract (English)
The rapid proliferation of Internet of Medical Things (IoMT) devices introduces critical cybersecurity vulnerabilities in healthcare environments where resource-constrained medical devices operate under strict latency requirements and stringent data-privacy regulations. To address these challenges, this paper presents the Lightweight Digital Twin and Federated Reinforcement Learning (LDT-FRL) framework, a privacy-preserving defense architecture integrating four complementary mechanisms: a Temporal Attention Encoder (TAE) built on a GRU backbone with learned temporal self-attention for flow-level threat classification; lightweight LSTM-based Digital Twins trained on normal-class traffic to generate per-device anomaly scores that gate the TAE classifier through a learned sigmoid coupling; a Federated Proximal Policy Optimization (PPO) agent selecting among ALLOW, ISOLATE, and HONEYPOT_REDIRECT actions based on a seven-dimensional state; and an intelligent honeypot layer that converts redirected suspicious traffic into actionable threat intelligence. A federated aggregation strategy employing EMA-smoothed per-client validation losses as inverse-weighted FedAvg coefficients stabilizes global model updates under non-IID client distributions. Evaluated on CICDDoS 2019 and TON-IoT benchmarks, LDT-FRL achieves 99.66% and 99.95% test accuracy respectively, with macro-F1 scores of 0.9913 and 0.9995, converging 81% faster than the DTFL-CD baseline while attaining perfect F1=1.000 on the severely imbalanced MITM class. Explainability analysis via SHAP, LIME, Grad-CAM, and counterfactual methods confirms that the TAE focuses on semantically meaningful flow features, providing interpretable evidence for each defense decision.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。