arXiv:2608.00118cs.CRcs.LG2026-08

为医疗物联网设计轻量级深度学习防护系统,实现在边缘设备上低延迟检测攻击。

Deep Learning for Cyber Threat Detection and Mitigation in Healthcare-IoT

  • 构建三组真实场景数据集,涵盖多种医疗物联网攻击类型。
  • 提出TCN与残差TCN模型,支持在树莓派4上实时检测DDoS攻击。
  • 模型量化后部署至TFLite,实现低功耗、低延迟的边缘安全防护。

医疗物联网(H-IoT)中的可穿戴设备面临严重的网络安全威胁,资源受限系统一旦失守将直接危及患者安全。生理数据与网络流量是主要攻击目标。现有深度学习防护机制多采用复杂大模型,且数据集质量缺乏评估。本文通过在Cooja与ns-3中生成三个真实数据集:UL-ECE-MQTT-DDoS-H-IoT2025与UL-ECE-UDP-DDoS-H-IoT2025用于检测分布式拒绝服务(DDoS)攻击,以及包含生理与网络特征的多类攻击数据集UL-ECE-MultiAttack-H-IoT2025,涵盖选择性转发(SF)、中间人(MITM)与DDoS攻击。基于此,设计了时间卷积网络(TCN)与残差TCN(Res-TCN)模型,结合监测频率与动态阈值策略实现攻击检测与缓解。模型经量化转换为TensorFlow Lite(TFLite),成功部署于Raspberry Pi 4,在边缘端实现低延迟与低功耗运行,验证了其在H-IoT环境中的实用性。

原文摘要 · Abstract (English)

Cybersecurity is a fundamental requirement for protecting wearable devices used in healthcare Internet of Things (H-IoT) systems. Security failures in these resource-constrained systems directly compromise patient safety. Physiological data and network traffic are frequent targets of cyberattacks in H-IoT environments. To address these risks, deep learning-based cybersecurity mechanisms for H-IoT often involve complex architectures with large parameter counts. Existing datasets are also rarely assessed for quality, limiting their applicability. However, this research addresses these challenges by developing multiple realistic datasets and proposing lightweight deep learning models, namely the Temporal Convolutional Network (TCN) and Residual TCN (Res-TCN), for H-IoT. It includes two binary classification datasets for Distributed Denial of Service (DDoS) attacks and a multiclass dataset representing Selective Forwarding (SF), Man-in-the-Middle (MITM), and DDoS attacks. The datasets UL-ECE-MQTT-DDoS-H-IoT2025 and UL-ECE-UDP-DDoS-H-IoT2025 are generated in Cooja and ns-3 to capture transmission behaviours and protocol variations. The third dataset, UL-ECE-MultiAttack-H-IoT2025, integrates physiological and network features to represent multiple cyber threats in H-IoT. Building on this, the TCN model is designed to detect and mitigate DDoS attacks over the MQTT and UDP-based datasets. It incorporates a monitoring frequency-based detection mechanism and a dynamic threshold-based mitigation strategy. To enable edge deployment, the model is quantised and converted into TensorFlow Lite (TFLite) for real-time DDoS detection on Raspberry Pi 4, achieving low latency and power-efficient operation in H-IoT. This thesis establishes a deep learning-based cybersecurity defence mechanism encompassing realistic dataset generation, lightweight model design, and edge deployment for securing H-IoT systems.

医疗物联网深度学习边缘计算安全防护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。