Skip to main navigation Skip to search Skip to main content

Patient-Specific Spatio-Temporal False Data Injection Attack Detection for IoMT Using a Graph-GRU Digital Twin and Kalman Innovation Features

  • Eman H. Alkhammash (Corresponding / Lead Author)
  • , Fuad A. Ghaleb (Corresponding / Lead Author)
  • , Faisal Saeed
  • , Sultan Noman Qasem* (Corresponding / Lead Author)
  • *Corresponding author for this work
  • Taif University
  • Imam Mohammad Ibn Saud Islamic University

Research output: Contribution to journalArticlepeer-review

Abstract

The Internet of Medical Things (IoMT) is a promising technology for enabling smart and efficient healthcare systems through continuous physiological monitoring, early anomaly detection, and proactive patient management. However, IoMT sensors are vulnerable to False Data Injection Attacks (FDIAs), in which adversaries can manipulate sensor measurements to compromise diagnostic accuracy, mislead clinical decision-making, and threaten patient safety. Existing detection approaches often rely on population-level statistical models that may not fully capture individual physiological variations or residual-based thresholds designed for relatively simple attack scenarios, limiting their ability to exploit the spatio-temporal dependencies of multi-sensor physiological streams and detect stealthy or adversarial FDIAs. This paper proposes a patient-specific FDIA detection framework based on a Graph Convolutional Network–Gated Recurrent Unit (GCN–GRU) digital twin that learns an individual patient’s normal physiological behaviour from clean baseline telemetry. The trained digital twin is integrated into a Kalman filter as the state prediction model, and the resulting standardised innovation residuals are used as detection features. To characterise stealthy attack behaviours, four complementary window-based feature groups are extracted from the innovation sequence: innovation statistics, sensor correlation drift, temporal smoothness, and uncertainty mismatch. A CNN-1D classifier is then trained to learn discriminative temporal attack patterns from these features for accurate detection. A structured attack taxonomy comprising five stealthy and adversarial FDIA scenarios is developed, where attacks are injected as smooth gradual or abrupt coordinated modifications to sensor measurements while remaining within plausible physiological ranges. Experiments conducted on the WUSTL-EHMS-2020 benchmark dataset demonstrate that the proposed framework achieves an F1-score of 94.3%, outperforming Isolation Forest and PCA Reconstruction by 34 percentage points. Furthermore, the proposed framework reduces the false alarm rate to 3.6%, compared with 35.1% and 9.2% achieved by Isolation Forest and PCA Reconstruction, respectively. These results demonstrate the effectiveness of the proposed framework for reliable detection of stealthy FDIAs in IoMT-based healthcare systems.
Original languageEnglish
Article number920
Number of pages32
JournalBioengineering
Volume13
Issue number8
DOIs
Publication statusPublished (VoR) - 14 Aug 2026

Funding

This work was supported and funded by the Deanship of Scientific Research at Imam Mohammad Ibn Saud Islamic University (IMSIU) (grant number IMSIU-DDRSP2601).

Keywords

  • internet of medical things
  • IoMT
  • false data injection attacks
  • FDIA
  • digital twin
  • graph convolutional network
  • gated recurrent unit
  • Kalman filter
  • GCN–GRU
  • anomaly detection
  • patient-specific monitoring
  • edge intelligence

Fingerprint

Dive into the research topics of 'Patient-Specific Spatio-Temporal False Data Injection Attack Detection for IoMT Using a Graph-GRU Digital Twin and Kalman Innovation Features'. Together they form a unique fingerprint.

Cite this