A lightweight interpretable feature selection-based ensemble learning approach for internet of medical things attack detection
The rapid growth of the Internet of Medical Things (IoMT) and the proliferation of associated devices have significantly improved healthcare services and enabled more intelligent medical monitoring and communication. However, this increasing connectivity has also expanded the attack surface of healthcare networks, making IoMT environments more vulnerable to cyber threats. Traditional IoMT attack detection approaches often rely on high-dimensional data and computationally intensive models, limiting their suitability for real-time and resource-constrained medical settings. To address this issue, this study proposes an efficient and effective explainable ensemble-learning approach for multi-class IoMT attack detection. The proposed approach consists of six stages: data preprocessing, ensemble model selection, hyper-parameter tuning, feature selection, model training and evaluation, and model explainability. In the model selection stage, Random Forest (RF), extreme gradient boosting (XGB), light gradient boosting (LGB), and histogram gradient boosting (HGB) are adopted as strong baseline candidates for model selection. These four classifiers were compared, with RF emerging as the best-performing model when fine-tuned via a random search algorithm. The feature selection stage involved four different methods: Genetic Algorithm (GA), Fisher’s score, impurity reduction, and Chi-square, with impurity reduction yielding the most informative approach for IoMT traffic feature selection. Extensive experiments were conducted on the recent CIC-IoMT-2024 benchmark dataset, which includes training and testing sets collected from 40 devices and covers 18 attack types as well as an extensive selection of benign traffic. The results showed that the fine-tuned RF model with only the top 10 selected features achieved the best overall trade-off between effectiveness and efficiency, reaching 99.72% accuracy with a 92.64% macro F1-score. The explainability analysis further confirmed that the final model relies on meaningful traffic descriptors. These findings demonstrate that the proposed approach provides a lightweight, accurate, and interpretable solution for real-time IoMT attack detection.
Authors
- Bandar Almaslukh (ORCID: https://orcid.org/0000-0002-9149-6384)
Institutions
- Prince Sattam Bin Abdulaziz University (SA)
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-08-25
- DOI
- https://doi.org/10.1038/s41598-026-64929-3
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00
Funders
- Prince Sattam bin Abdulaziz University