AI-Driven Healthcare Cyber Threat Intelligence Using Explainable Machine Learning and Federated Learning
DOI:
https://doi.org/10.64149/Keywords:
Federated Learning; Explainable AI; SHAP; Internet of Medical Things; Intrusion Detection; Cyber Threat Intelligence; Healthcare Security; Non-IID Data.Abstract
The Internet of Medical Things (IoMT) has greatly expanded the attack surface for clinical infrastructure however, privacy regulation and institutional data-governance obstacles make centralized collection of network telemetry across hospitals difficult. We propose an Artificial Intelligence-based Healthcare Cyber Threat Intelligence (CTI) framework that combines federated learning (FL) and explainable machine learning to intrusions detection of Internet-of-Medical-Things (IoMT) traffic based on the principle in where raw data is never pooled. We investigate (i) a leakage-aware preprocessing audit that removes 24 identifier, near-constant and duplicate columns ahead of any model training; using the IoMT-TrafficData corpus (3,243,188 flow records; benign + eight attack families) we simulate a ten-hospital federation through Dirichlet label-skew partitioning and natural service-based partitioning; (iii) two federated learning algorithms combining global SHAP attributions + per-client normalised SHAP-divergence analysis with attention-weight interpretation via a compact Tabular Attention Network (TAN; 11,657 parameters); trained under FedAvg & FedProx regimes with focal loss to address severe class imbalance.
The Federated Model attains macro-F1=0.935 (FedProx) from an isolated local-only training macros_F1=0.524 (Dirichlet α=0.1), without ever sharing raw records and approaching the centralized upper bound 0.979. As-behaved for tabular flow data, gradient-boosted trees are still the accuracy ceiling (LightGBM macro-F1 0.999) and we candidly report this and frame the contribution of our proposed model as privacy-preserving, explainable, distributed detection rather than record-low raw-accuracy. To enable reproducible and trustworthy CTI research, from our findings, we additionally expose genuine adverse results -- weak detection of the rare slowread type (F1 0.63) under Dirichlet-induced client starvation, and statistical null correlation between learned attention weights & SHAP importance.



