DOI: 10.3390/bioengineering13080920 ISSN: 2306-5354

Patient-Specific Spatio-Temporal False Data Injection Attack Detection for IoMT Using a Graph-GRU Digital Twin and Kalman Innovation Features

Eman H. Alkhammash, Fuad A. Ghaleb, Faisal Saeed, Sultan Noman Qasem

The Internet of Medical Things (IoMT) is a promising technology for enabling smart and efficient healthcare systems through continuous physiological monitoring, early anomaly detection, and proactive patient management. However, IoMT sensors are vulnerable to False Data Injection Attacks (FDIAs), in which adversaries can manipulate sensor measurements to compromise diagnostic accuracy, mislead clinical decision-making, and threaten patient safety. Existing detection approaches often rely on population-level statistical models that may not fully capture individual physiological variations or residual-based thresholds designed for relatively simple attack scenarios, limiting their ability to exploit the spatio-temporal dependencies of multi-sensor physiological streams and detect stealthy or adversarial FDIAs. This paper proposes a patient-specific FDIA detection framework based on a Graph Convolutional Network–Gated Recurrent Unit (GCN–GRU) digital twin that learns an individual patient’s normal physiological behaviour from clean baseline telemetry. The trained digital twin is integrated into a Kalman filter as the state prediction model, and the resulting standardised innovation residuals are used as detection features. To characterise stealthy attack behaviours, four complementary window-based feature groups are extracted from the innovation sequence: innovation statistics, sensor correlation drift, temporal smoothness, and uncertainty mismatch. A CNN-1D classifier is then trained to learn discriminative temporal attack patterns from these features for accurate detection. A structured attack taxonomy comprising five stealthy and adversarial FDIA scenarios is developed, where attacks are injected as smooth gradual or abrupt coordinated modifications to sensor measurements while remaining within plausible physiological ranges. Experiments conducted on the WUSTL-EHMS-2020 benchmark dataset demonstrate that the proposed framework achieves an F1-score of 94.3%, outperforming Isolation Forest and PCA Reconstruction by 34 percentage points. Furthermore, the proposed framework reduces the false alarm rate to 3.6%, compared with 35.1% and 9.2% achieved by Isolation Forest and PCA Reconstruction, respectively. These results demonstrate the effectiveness of the proposed framework for reliable detection of stealthy FDIAs in IoMT-based healthcare systems.

More from our Archive