Optimized Hybrid Approach for Anomaly Detection of DDoS and Network Attacks in IoMT Systems using Autoencoders and TabNet
Kirubavathi G, Shreya Sivakumar, Sivakumar Manickam · 2024
The growing complexity of Distributed Denial of Service (DDoS) assaults presents substantial issues for protecting Internet of Medical Things (IoMT) systems, which, despite changing healthcare, are still vulnerable due to limited computational resources and different communication protocols. Traditional anomaly detection systems frequently struggle with scalability and precision in dynamic settings. This study presents a hybrid system that combines AutoEncoder and TabNet models trained on the CICIoMT 2024 dataset, which contains a variety of protocols and attack scenarios. AutoEncoder finds anomalies using reconstruction errors, whereas TabNet uses attention methods for tabular data. Normalization and handling of missing values were among the data preprocessing steps. AutoEncoder was highly precise in recognizing benign traffic, but suffered with occasional attacks. TabNet fared well in several attack classes, with a weighted F1-score of 1.00 in MQTT-DoS-Publish Flood scenarios, but struggled with imbalanced datasets such as TCP IP-DDoS-UDP2. The hybrid architecture provides a scalable solution by combining AutoEncoder's precision and TabNet's increased recall, paving the path for real-time IoMT anomaly detection.