Patient-Specific Spatio-Temporal False Data Injection Attack Detection for IoMT Using a Graph-GRU Digital Twin and Kalman Innovation Features

Alkhammash, Eman H. and Ghaleb, Fuad A. and Saeed, Faisal and Qasem, Sultan Noman (2026) Patient-Specific Spatio-Temporal False Data Injection Attack Detection for IoMT Using a Graph-GRU Digital Twin and Kalman Innovation Features. Bioengineering, 13 (8). p. 920. ISSN 2306-5354

[thumbnail of bioengineering-13-00920.pdf]
Preview
Text
bioengineering-13-00920.pdf - Published Version
Available under License Creative Commons Attribution.

Download (3MB)

Abstract

The Internet of Medical Things (IoMT) is a promising technology for enabling smart and efficient healthcare systems through continuous physiological monitoring, early anomaly detection, and proactive patient management. However, IoMT sensors are vulnerable to False Data Injection Attacks (FDIAs), in which adversaries can manipulate sensor measurements to compromise diagnostic accuracy, mislead clinical decision-making, and threaten patient safety. Existing detection approaches often rely on population-level statistical models that may not fully capture individual physiological variations or residual-based thresholds designed for relatively simple attack scenarios, limiting their ability to exploit the spatio-temporal dependencies of multi-sensor physiological streams and detect stealthy or adversarial FDIAs. This paper proposes a patient-specific FDIA detection framework based on a Graph Convolutional Network–Gated Recurrent Unit (GCN–GRU) digital twin that learns an individual patient’s normal physiological behaviour from clean baseline telemetry. The trained digital twin is integrated into a Kalman filter as the state prediction model, and the resulting standardised innovation residuals are used as detection features. To characterise stealthy attack behaviours, four complementary window-based feature groups are extracted from the innovation sequence: innovation statistics, sensor correlation drift, temporal smoothness, and uncertainty mismatch. A CNN-1D classifier is then trained to learn discriminative temporal attack patterns from these features for accurate detection. A structured attack taxonomy comprising five stealthy and adversarial FDIA scenarios is developed, where attacks are injected as smooth gradual or abrupt coordinated modifications to sensor measurements while remaining within plausible physiological ranges. Experiments conducted on the WUSTL-EHMS-2020 benchmark dataset demonstrate that the proposed framework achieves an F1-score of 94.3%, outperforming Isolation Forest and PCA Reconstruction by 34 percentage points. Furthermore, the proposed framework reduces the false alarm rate to 3.6%, compared with 35.1% and 9.2% achieved by Isolation Forest and PCA Reconstruction, respectively. These results demonstrate the effectiveness of the proposed framework for reliable detection of stealthy FDIAs in IoMT-based healthcare systems.

Item Type: Article
Identification Number: 10.3390/bioengineering13080920
Dates:
Date
Event
12 August 2026
Accepted
14 August 2026
Published Online
Uncontrolled Keywords: internet of medical things, IoMT, false data injection attacks, FDIA, digital twin, graph convolutional network, gated recurrent unit, GCN–GRU, Kalman filter, anomaly detection, patient-specific monitoring, edge intelligence
Subjects: CAH11 - computing > CAH11-01 - computing > CAH11-01-01 - computer science
Divisions: Architecture, Built Environment, Computing and Engineering > Computer Science
Depositing User: Gemma Tonks
Date Deposited: 25 Aug 2026 09:45
Last Modified: 25 Aug 2026 09:45
URI: https://www.open-access.bcu.ac.uk/id/eprint/17184

Actions (login required)

View Item View Item

Research

In this section...