Trustworthy AI-Powered Intrusion Detection for the Internet of Medical Things (IoMT): A Review
Jahidul Islam, Dristi Datta, Fowzia AkhterThe Internet of Medical Things (IoMT) is transforming healthcare through continuous patient monitoring, telemedicine, cloud–edge services, and Healthcare 5.0. However, the rapid growth of interconnected medical devices has expanded the healthcare cyberattack surface, making intelligent intrusion detection essential for protecting sensitive medical data and ensuring resilient clinical operations. Existing reviews examine specific aspects of AI-powered intrusion detection but rarely provide a deployment-oriented synthesis linking technical performance with operational and clinical requirements. This review critically examines Artificial Intelligence (AI)-powered Intrusion Detection Systems (IDSs) for IoMT across six analytical dimensions: detection performance, explainability, privacy preservation, computational efficiency, benchmarking practices, and cross-dataset generalization. This structured narrative review adopted the PRISMA 2020 framework to ensure transparent record identification, screening, and reporting, with evidence synthesized qualitatively rather than through quantitative meta-analysis. A total of 5127 records published between 2021 and 2026 were screened, resulting in 24 primary studies supported by 115 complementary studies. The findings show that machine learning, deep learning, hybrid AI, Explainable Artificial Intelligence (XAI), Federated Learning (FL), blockchain-assisted security, and edge intelligence have significantly advanced IoMT intrusion detection. However, despite benchmark accuracies often exceeding 95%, deployment remains constrained by dataset dependency, weak cross-dataset generalization, computational overhead, limited explainability, fragmented benchmarking, and insufficient operational validation. This review identifies deployment readiness, rather than predictive accuracy alone, as the principal challenge for next-generation healthcare cybersecurity and provides a practical framework for developing trustworthy, interoperable, privacy-preserving, and deployment-ready IoMT cybersecurity architectures supported by standardized evaluation protocols.