Per-Device Behavioral Anomaly Detection in IoMT Networks Using Autoencoders and EVT-Based Adaptive Thresholds

  • Evelin E. D. Limeira CESAR School
  • Rafael Roque CESAR School
  • Luciano Cabral CESAR School / IFPE
  • Fernando Aires CESAR School / UFRPE
  • Wellison R. M. Santos CESAR School / UFRPE
  • Milton Lima CESAR School

Resumo


Intrusion Detection Systems (IDSs) for the Internet of Medical Things (IoMT) must handle highly heterogeneous device traffic, which directly impacts anomaly detection and false-positive rates. This study evaluates per-device benign-only autoencoders combined with Extreme Value Theory (EVT)-based adaptive thresholds, localized reconstruction errors scoring, and SHAP-based feature attribution. Experiments are conducted on offline traffic traces from camera-class devices in the CICIoMT2024 dataset, considering behavioral, MQTT-based, and volumetric attack groups. Results indicate that per-device modeling is more effective at characterizing behavioral deviations than volumetric flooding attacks in this scenario. Furthermore, localized reconstruction-error scoring provides a more sensitive operating point than conventional global thresholding strategies.

Referências

Cavalcante, J., Barros, T. G. F., and de Souza, J. N. (2024). Autonomous network intrusion detection for resource-constrained devices of the internet of things. In Anais do XXIV Simposio Brasileiro de Seguranca da Informacao e de Sistemas Computacionais. SBC.

Dadkhah, S., Pinto Neto, E. C., Ferreira, R., Molokwu, R. C., Sadeghi, S., and Ghorbani, A. A. (2024). CICIoMT2024: A benchmark dataset for multi-protocol security assessment in IoMT. Internet of Things, 25:101080.

Damasceno, M. G. L., Souza, C. B. B., and Balieiro, A. M. (2025). Evaluating MLP and autoencoder models for zero-day attack detection in 6G networks. In Anais do XXV Simposio Brasileiro de Seguranca da Informacao e de Sistemas Computacionais. SBC.

Emelianova, N., Kamienski, C., and Prati, R. C. (2025). Optimizing IoT threat detection with kolmogorov-arnold networks (KANs). In Anais do XXV Simposio Brasileiro de Seguranca da Informacao e de Sistemas Computacionais. SBC.

Gorman, M., Ding, X., Maguire, L., and Coyle, D. (2023). Anomaly detection in batch manufacturing processes using localized reconstruction errors from 1-d convolutional autoencoders. IEEE Transactions on Semiconductor Manufacturing, 36(1):147–150.

Hernandez-Jaimes, M. L., Martinez-Cruz, A., Ramirez-Gutierrez, K. A., and Guevara-Martinez, E. (2024). Enhancing machine learning approach based on nilsimsa finger-printing for ransomware detection in IoMT. IEEE Access.

Kavkas, E. and Yildiz, K. (2025). Enhancing IoMT security with deep learning based approach for medical IoT threat detection. In Proceedings of the IEEE International Symposium on Digital Forensic and Security.

Khraisat, A., Gondal, I., Vamplew, P., and Kamruzzaman, J. (2019). Survey of intrusion detection systems: Techniques, datasets and challenges. Cybersecurity, 2(1):20.

Lundberg, S. M. and Lee, S.-I. (2017). A unified approach to interpreting model predictions. In Advances in Neural Information Processing Systems, volume 30.

Quincozes, C. B., Oliveira, H. C., Quincozes, S. E., Miani, R. S., and Quincozes, V. E. (2024). Uma arquitetura baseada em inteligencia artificial explicavel (XAI) para sistemas de deteccao de intrusoes em smart grids. In Anais do XXIV Simposio Brasileiro de Seguranca da Informacao e de Sistemas Computacionais. SBC.

Ramesh, K., Miller, N. C., and Faridi, A. (2024). Efficient machine learning frameworks for strengthening cybersecurity in internet of medical things (IoMT) ecosystems. arXiv preprint arXiv:2412.01375. Preprint; venue to be confirmed before camera-ready.

Sakurada, M. and Yairi, T. (2014). Anomaly detection using autoencoders with nonlinear dimensionality reduction. In Proceedings of the MLSDA 2014 2nd Workshop on Machine Learning for Sensory Data Analysis, MLSDA’14, page 4–11, New York, NY, USA. Association for Computing Machinery.

Siffer, A., Fouque, P.-A., Termier, A., and Largouet, C. (2017). Anomaly detection in streams with extreme value theory. In Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining.

Simioni, J. A., Viegas, E. K., Santin, A. O., and Horchulhack, P. (2024). Deteccao de intrusao atraves de redes neurais profundas com saidas antecipadas para inferencia rapida e confiavel. In Anais do XXIV Simposio Brasileiro de Seguranca da Informacao e de Sistemas Computacionais. SBC.

Sivanathan, A., Gharakheili, H. H., Loi, F., Radford, A., Wijenayake, C., Vishwanath, A., and Sivaraman, V. (2019). Classifying iot devices in smart environments using network traffic characteristics. IEEE Transactions on Mobile Computing, 18(8):1745–1759.

Sohail, F., Bhatti, M. A. M., Awais, M., and Iqtidar, A. (2024). Explainable boosting ensemble methods for intrusion detection in internet of medical things (IoMT) applications. IEEE Access. Venue confirmed as IEEE Access; DOI to be added in camera-ready.

Vieira, L. Q., Choren, R., and Sant’ana, R. (2025). Contrastive autoencoding with gaussian confidence regions for concept drift detection in IDS. In Anais do XXV Simposio Brasileiro de Seguranca da Informacao e de Sistemas Computacionais. SBC.

Yacoubi, M., Moussaoui, O., and Drocourt, C. (2026). AI for IoMT security: A comprehensive survey of intrusion detection and system architectures. Internet of Things, 36:101869.
Publicado
01/09/2026
LIMEIRA, Evelin E. D.; ROQUE, Rafael; CABRAL, Luciano; AIRES, Fernando; SANTOS, Wellison R. M.; LIMA, Milton. Per-Device Behavioral Anomaly Detection in IoMT Networks Using Autoencoders and EVT-Based Adaptive Thresholds. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 913-928. DOI: https://doi.org/10.5753/sbseg.2026.27109.