Jordi Doménech , Olga León , Muhammad Shuaib Siddiqui , Josep Pegueroles
{"title":"Evaluating and enhancing intrusion detection systems in IoMT: The importance of domain-specific datasets","authors":"Jordi Doménech , Olga León , Muhammad Shuaib Siddiqui , Josep Pegueroles","doi":"10.1016/j.iot.2025.101631","DOIUrl":null,"url":null,"abstract":"<div><div>The emergence of the Internet of Medical Things (IoMT) is revolutionizing healthcare delivery, but also introducing critical challenges to cybersecurity and patient safety. Intrusion Detection Systems (IDSs) enhanced by Machine Learning (ML) have emerged as a powerful solution to identify cyberattacks in these environments. However, existing studies often rely on general IoT datasets, potentially limiting their applicability in IoMT-specific scenarios. This study addresses these limitations by comparing the performance of ML models trained on a general IoT dataset (CICIoT2023) and an IoMT-specific dataset (CICIoMT2024) to demonstrate the importance of domain-specific data. Our findings reveal substantial drops of up to 66.87% in the F1-score when models trained on one dataset are tested on the other. Furthermore, the study critiques key dataset design choices in CICIoMT2024, and proposes baseline optimization techniques including uniform windowing, proper train-validation-test splits, adjustments in temporal dependencies for time series data, and improved dataset balancing. By applying these techniques, we observe significant improvements in IDS performance in comparison to other approaches, with scores of 0.9985 in model accuracy. The findings show the necessity of using IoMT-specific datasets and carefully designed preprocessing techniques to build robust IDSs tailored to the unique demands of medical IoT environments.</div></div>","PeriodicalId":29968,"journal":{"name":"Internet of Things","volume":"32 ","pages":"Article 101631"},"PeriodicalIF":6.0000,"publicationDate":"2025-05-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Internet of Things","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2542660525001453","RegionNum":3,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
The emergence of the Internet of Medical Things (IoMT) is revolutionizing healthcare delivery, but also introducing critical challenges to cybersecurity and patient safety. Intrusion Detection Systems (IDSs) enhanced by Machine Learning (ML) have emerged as a powerful solution to identify cyberattacks in these environments. However, existing studies often rely on general IoT datasets, potentially limiting their applicability in IoMT-specific scenarios. This study addresses these limitations by comparing the performance of ML models trained on a general IoT dataset (CICIoT2023) and an IoMT-specific dataset (CICIoMT2024) to demonstrate the importance of domain-specific data. Our findings reveal substantial drops of up to 66.87% in the F1-score when models trained on one dataset are tested on the other. Furthermore, the study critiques key dataset design choices in CICIoMT2024, and proposes baseline optimization techniques including uniform windowing, proper train-validation-test splits, adjustments in temporal dependencies for time series data, and improved dataset balancing. By applying these techniques, we observe significant improvements in IDS performance in comparison to other approaches, with scores of 0.9985 in model accuracy. The findings show the necessity of using IoMT-specific datasets and carefully designed preprocessing techniques to build robust IDSs tailored to the unique demands of medical IoT environments.
期刊介绍:
Internet of Things; Engineering Cyber Physical Human Systems is a comprehensive journal encouraging cross collaboration between researchers, engineers and practitioners in the field of IoT & Cyber Physical Human Systems. The journal offers a unique platform to exchange scientific information on the entire breadth of technology, science, and societal applications of the IoT.
The journal will place a high priority on timely publication, and provide a home for high quality.
Furthermore, IOT is interested in publishing topical Special Issues on any aspect of IOT.