AI-Driven Intrusion Detection in Healthcare Systems: A Systematic Review of Techniques, Evaluation Practices, and Real-World Deployment Challenges

Authors

  • Belinda Ndlovu National University of Science and Technology image/svg+xml

DOI:

https://doi.org/10.63158/IJAIS.v3i1.58

Keywords:

Artificial Intelligence, Intrusion Detection Systems, Healthcare Cybersecurity, Deployment Readines, Systematic Literature Review

Abstract

Cyberattacks threaten healthcare data security and clinical continuity. Although artificial intelligence (AI) promises improved intrusion detection, high accuracy rarely translates into clinical deployment. This systematic review examines evaluation practices and deployment conditions in healthcare intrusion detection research. Following PRISMA 2020, searches across ScienceDirect, Scopus, PubMed, MDPI and SpringerLink covered studies published between 2020 and 2024. Eleven studies met the inclusion criteria. Findings were triangulated against subsequent large-scale reviews to assess consistency across broader evidence. Classical machine learning dominated, with limited adoption of hybrid, federated or transformer-based approaches. Reported accuracy averaged 98.66%, predominantly using benchmark or synthetic datasets under controlled conditions. False positive rates, alert volumes, inference latency and robustness to distribution shift were rarely reported. No included study demonstrated sustained operation in a live clinical network. The review introduces the Healthcare IDS Deployment Readiness Assessment (HIDRA), comprising five dimensions and five ordinal readiness levels, alongside a minimum reporting set and six testable propositions. No study exceeded readiness level 2 of 5. HIDRA offers authors, reviewers and procurement teams a reusable instrument for assessing deployment readiness and identifying gaps between experimental performance and clinical feasibility.

References

[1] H. and F. J. Anthony Minnaar, “Cyberattacks and the Cybercrime Threat of Ransomware to Hospitals and Healthcare Services During the COVID-19 Pandemic,” Acta Criminol. Afr. J. Criminol. Vict., vol. 34, no. 3, p. 3, 2021, doi: 10.10520/ejc-crim.

[2] S. Ghafur, S. Kristensen, K. Honeyford, G. Martin, A. Darzi, and P. Aylin, “A retrospective impact analysis of the WannaCry cyberattack on the NHS,” npj Digit. Med., vol. 2, no. 1, pp. 1–7, 2019, doi: 10.1038/s41746-019-0161-6.

[3] M. Tabassum, S. Mahmood, A. Bukhari, B. Alshemaimri, A. Daud, and F. Khalique, “Anomaly-based threat detection in smart health using machine learning,” BMC Med. Inform. Decis. Mak., vol. 24, no. 1, 2024, doi: 10.1186/s12911-024-02760-4.

[4] M. Akshay Kumaar, D. Samiayya, P. M. D. R. Vincent, K. Srinivasan, C. Y. Chang, and H. Ganesh, “A Hybrid Framework for Intrusion Detection in Healthcare Systems Using Deep Learning,” Front. Public Health, vol. 9, no. January, pp. 1–18, 2022, doi: 10.3389/fpubh.2021.824898.

[5] A. Si-Ahmed, M. A. Al-Garadi, and N. Boustia, “Survey of Machine Learning based intrusion detection methods for Internet of Medical Things,” Appl. Soft Comput., vol. 140, pp. 0–2, 2023, doi: 10.1016/j.asoc.2023.110227.

[6] A. A. Hady, A. Ghubaish, T. Salman, D. Unal, and R. Jain, “Intrusion Detection System for Healthcare Systems Using Medical and Network Data: A Comparison Study,” IEEE Access, vol. 8, pp. 106576–106584, 2020, doi: 10.1109/ACCESS.2020.3000421.

[7] M. Khaldi, N. Mahammed, M. A. Lahmar, and F. D. Daouadji, “An Intrusion Detection System for Healthcare Applications using Machine Learning,” CEUR Workshop Proc., vol. 3694, pp. 94–101, 2024.

[8] S. B. Weber, S. Stein, M. Pilgermann, and T. Schrader, “Attack Detection for Medical Cyber-Physical Systems—A Systematic Literature Review,” IEEE Access, vol. 11, no. April, pp. 41796–41815, 2023, doi: 10.1109/ACCESS.2023.3270225.

[9] K. Arshad et al., “Deep Reinforcement Learning for Anomaly Detection: A Systematic Review,” IEEE Access, vol. 10, no. October, pp. 124017–124035, 2022, doi: 10.1109/ACCESS.2022.3224023.

[10] A. B. Nassif, M. A. Talib, Q. Nasir, and F. M. Dakalbab, “Machine Learning for Anomaly Detection: A Systematic Review,” IEEE Access, vol. 9, pp. 78658–78700, 2021, doi: 10.1109/ACCESS.2021.3083060.

[11] S. Badi, “Mitigating Security Risks in Healthcare Applications through AI and Machine Mitigating Security Risks in Healthcare Applications through AI and Machine Learning,” no. August, 2024, doi: 10.13140/RG.2.2.32500.36485.

[12] S. Arefin, “Strengthening Healthcare Data Security with Ai-Powered Threat Detection,” no. October, 2024, doi: 10.18535/ijsrm/v12i10.ec02.

[13] M. J. Page et al., “The PRISMA 2020 statement: An updated guideline for reporting systematic reviews,” BMJ, vol. 372, 2021, doi: 10.1136/bmj.n71.

[14] D. Moher, A. Liberati, J. Tetzlaff, and D. G. Altman, “Preferred reporting items for systematic reviews and meta-analyses: the PRISMA statement,” J. Clin. Epidemiol., vol. 62, no. 10, pp. 1006–1012, 2009, doi: 10.1016/j.jclinepi.2009.06.005.

[15] S. M. Wa Umba, A. M. Abu-Mahfouz, and D. Ramotsoela, “Artificial Intelligence-Driven Intrusion Detection in Software-Defined Wireless Sensor Networks: Towards Secure IoT-Enabled Healthcare Systems,” Int. J. Environ. Res. Public Health, vol. 19, no. 9, 2022, doi: 10.3390/ijerph19095367.

[16] A. Sundas, S. Badotra, S. Bharany, A. Almogren, E. M. Tag-ElDin, and A. U. Rehman, “HealthGuard: An Intelligent Healthcare System Security Framework Based on Machine Learning,” Sustainability, vol. 14, no. 19, 2022, doi: 10.3390/su141911934.

[17] T. Alsolami, B. Alsharif, and M. Ilyas, “Enhancing Cybersecurity in Healthcare: Evaluating Ensemble Learning Models for Intrusion Detection in the Internet of Medical Things,” Sensors, vol. 24, no. 18, 2024, doi: 10.3390/s24185937.

[18] P. K. Yeng, L. O. Nweke, A. Z. Woldaregay, B. Yang, and E. A. Snekkenes, “Data-Driven and Artificial Intelligence (AI) Approach for Modelling and Analyzing Healthcare Security Practice: A Systematic Review,” Adv. Intell. Syst. Comput., vol. 1250 AISC, no. March, pp. 1–18, 2021, doi: 10.1007/978-3-030-55180-3_1.

[19] J. Lansky et al., “Deep Learning-Based Intrusion Detection Systems: A Systematic Review,” IEEE Access, vol. 9, pp. 101574–101599, 2021, doi: 10.1109/ACCESS.2021.3097247.

[20] O. Adohinzin and Y. Harrath, “A Systematic Review of Intrusion Detection Systems for Internet of Medical Things: Performance, Efficiency, Explainability, and Generalization,” Digit. Threats Res. Pract., 2026, doi: 10.1145/3816026.

[21] T. B. Ogunseyi, G. Thiyagarajan, H. He, V. Bist, and Z. Du, “Performance Analysis of Explainable Deep Learning-Based Intrusion Detection Systems for IoT Networks: A Systematic Review,” Sensors, vol. 26, no. 2, p. 363, 2026, doi: 10.3390/s26020363.

[22] R. Kalakoti, S. Nomm, and H. Bahsi, “Explainable Transformer-Based Intrusion Detection in Internet of Medical Things (IoMT) Networks,” in 2024 Int. Conf. Mach. Learn. Appl. (ICMLA), IEEE, 2024, pp. 1164–1169.

[23] S. Dadkhah, E. C. P. Neto, R. Ferreira, R. C. Molokwu, S. Sadeghi, and A. A. Ghorbani, “CICIoMT2024: A benchmark dataset for multi-protocol security assessment in IoMT,” Internet Things, vol. 28, p. 101351, 2024, doi: 10.1016/j.iot.2024.101351.

[24] G. Krishnamoorthy and S. M. K. Sistla, “Exploring Machine Learning Intrusion Detection: Addressing Security and Privacy Challenges in IoT—A Comprehensive Review,” J. Knowl. Learn. Sci. Technol., vol. 2, no. 2, pp. 114–125, 2023, doi: 10.60087/jklst.vol2.n2.p125.

[25] I. Bala, I. A. Pindoo, M. M. Mijwil, M. Abotaleb, and W. Yundong, “Ensuring Security and Privacy in Healthcare Systems: A Review Exploring Challenges, Solutions, Future Trends, and the Practical Applications of Artificial Intelligence,” Jordan Med. J., vol. 58, no. 2, pp. 250–270, 2024, doi: 10.35516/jmj.v58i2.2527.

[26] B. Ndlovu and K. Maguraushe, “Balancing Ethics and Privacy in the Use of Artificial Intelligence in Institutions of Higher Learning: A Framework for Responsive AI Systems,” Indones. J. Inform. Educ., vol. 9, no. 1, p. 39, 2025, doi: 10.20961/ijie.v9i1.100723.

[27] T. Kapuya, W. Kubiku, M. Dube, and T. Mukudu, “Ethical AI Frameworks: Balancing Privacy, Consent and Responsible Use,” 2024, doi: 10.46254/EU07.20240168.

[28] M. Moyo and B. Ndlovu, “AI-Driven Intrusion Detection Systems: Algorithms, Key Applications, Efficacy,” in Lect. Notes Netw. Syst., Springer Nature Switzerland, 2026, pp. 40–53.

[29] M. A. Alsoufi et al., “Anomaly-based intrusion detection systems in iot using deep learning: A systematic literature review,” Appl. Sci., vol. 11, no. 18, 2021, doi: 10.3390/app11188383.

[30] A. Maramba and B. Ndlovu, “AI-Driven Threat and Incident Detection in Healthcare Cybersecurity: A Stacked Ensemble Model,” in 2025 4th Zimbabwe Conf. Inf. Commun. Technol., 2025, pp. 1–9, doi: 10.1109/ZCICT67553.2025.11602039.

[31] A. Dube, B. Mpande, F. Dzehonye, and T. Chazuza, “Zero Trust Architecture: Redefining Security,” in Lect. Notes Netw. Syst., Springer Nature Switzerland, 2026, pp. 26–39, doi: 10.1007/978-3-032-20533-9.

[32] U.S. Department of Health and Human Services, Office for Civil Rights, “Change Healthcare Cybersecurity Incident Frequently Asked Questions,” HHS.gov, 2025.

[33] A. Salehpour, M. A. Balafar, et al., “Intrusion detection system for IoMT in smart hospitals: a systematic literature review,” Internet Things Cyber-Phys. Syst., 2026, doi: 10.1016/j.iotcps.2026.01.006.

[34] Y. Wang et al., “A comprehensive survey on intrusion detection in internet of medical things: Datasets, federated learning, blockchain, and future research directions,” Meas. Sensors, 2025, doi: 10.1016/j.measen.2025.101896.

[35] U.S. Department of Health and Human Services, “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information: Notice of Proposed Rulemaking,” Fed. Regist., vol. 90, no. 4, pp. 898–1002, Jan. 2025.

[36] European Parliament and Council, “Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive),” Off. J. Eur. Union, L 333, pp. 80–152, 2022.

[37] European Parliament and Council, “Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act),” Off. J. Eur. Union, L series, 2024.

[38] B. Buyuktanir, S. Altinkaya, G. Karatas Baydogmus, et al., “Federated learning in intrusion detection: advancements, applications, and future directions,” Cluster Comput., vol. 28, p. 473, 2025, doi: 10.1007/s10586-025-05325-w.

[39] A. Berguiga, A. Harchay, and A. Massaoudi, “HIDS-IoMT: a deep learning-based intelligent intrusion detection system for the internet of medical things,” IEEE Access, 2025.

[40] H. Peng, C. Wu, and Y. Xiao, “FD-IDS: Federated learning with knowledge distillation for intrusion detection in non-IID IoT environments,” Sensors, vol. 25, no. 14, p. 4309, 2025, doi: 10.3390/s25144309.

[41] R. Kalakoti, S. Nomm, and H. Bahsi, “Federated learning of explainable AI (FedXAI) for deep learning-based intrusion detection in IoT networks,” Comput. Netw., p. 111479, 2025.

[42] J. Lu, A. Liu, F. Dong, F. Gu, J. Gama, and G. Zhang, “Learning under concept drift: A review,” IEEE Trans. Knowl. Data Eng., vol. 31, no. 12, pp. 2346–2363, 2018, doi: 10.1109/TKDE.2018.2876857.

Downloads

Published

2026-03-20

Issue

Section

Articles

How to Cite

AI-Driven Intrusion Detection in Healthcare Systems: A Systematic Review of Techniques, Evaluation Practices, and Real-World Deployment Challenges. (2026). International Journal of Artificial Intelligence and Science, 3(1), 1-38. https://doi.org/10.63158/IJAIS.v3i1.58