AI 中文总结
本研究提出IoMT-SecAlarmBench半合成基准,用于解决IoMT中完整性攻击检测缺乏反事实真实值的问题,评估现有检测器性能并揭示其存在的权衡问题,相关工具已公开。
AI 中文摘要
医疗物联网(IoMT)将临床生理数据与网络系统信息相结合,带来了一项挑战:如何判断异常读数是反映真实生理事件、设备故障,还是处于预期生理范围内的网络攻击。要解决这一问题需要反事实真实值,但现有数据集均未提供。我们提出IoMT-SecAlarmBench,这是一个半合成基准,采用结构化实验设计向真实的耦合心电图(ECG)+光电容积描记(PPG)记录中注入受控完整性攻击,该设计结合了四种攻击形态、四个严重程度级别、两种生理合理性条件以及重放攻击。每个注入窗口都保留其原因、攻击子类型以及未受攻击时会观测到的干净信号。我们使用与阈值无关的指标和匹配的误报预算,评估了来自五个方法家族的六种检测器。结果显示,没有任何方法能始终如一地检测到最具挑战性的情况:重放攻击和低振幅瞬态尖峰在所有检测器上的表现均接近随机水平。结果还揭示了检测攻击与将其与传感器故障区分之间存在权衡:在困难案例上表现最佳的检测器标记故障/伪影窗口的误报率是正常数据的5.3倍。三分类在真实生理事件上表现不佳,对双模态网络数据集的泄漏审计显示,之前报告的IoMT入侵检测性能部分是由识别信息驱动的。我们发布了基准、生成代码、预处理、评估工具和 datasheet。
英文摘要
The Internet of Medical Things (IoMT) combines clinical physiological data with cyber-system information, creating challenges in determining whether an abnormal reading reflects a genuine physiological event, a device fault, or a cyber-attack within the expected physiological range. Answering this requires counterfactual ground truth, which no existing dataset provides. We present IoMT-SecAlarmBench, a semi-synthetic benchmark that injects controlled integrity attacks into genuine coupled ECG+PPG recordings using a structured experimental design combining four attack morphologies, four severity levels, two physiological plausibility conditions, and replay attacks. Each injected window retains its cause, attack subtype, and the clean signal that would have been observed without the attack. We evaluate six detectors from five method families using threshold-independent measures and a matched false-alarm budget. Results show no method consistently detects the most difficult cases: replay attacks and low-amplitude transient spikes remain close to chance-level performance across detectors. Results also reveal a trade-off between detecting attacks and distinguishing them from sensor faults: the best-performing detector on hard cases flags fault/artifact windows at 5.3 times its false-alarm rate on normal data. Three-way classification performs poorly for genuine physiological events, and a leakage audit of a dual-modality network dataset indicates previously reported IoMT intrusion-detection performance is partly driven by identifying information. Benchmark, generation code, preprocessing, evaluation tools, and datasheet are released.
Comments10 pages, 2 figures, 5 tables. Submitted to IEEE International Conference on Big Data (BigData) 2026. Benchmark, generator, evaluation harness, and datasheet: https://github.com/techosystem/IoMT_SecAlarmBench