1
Return

Graph Neural Networks for IoMT Intrusion Detection: Modeling Architectures, Learning Paradigms, and Deployment Challenges

delete2026-06-16
delete0
PRE
AI
H
Hanli Chen
F
Faizan Qamar
G
Gaoyang Guo
M
Muhammad Habib ur Rehman
S
Siti Norul Huda Sheikh Abdullah
DOI:10.1109/jiot.2026.3704452delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Internet of Medical Things (IoMT) connects medical sensors, devices, gateways, and cloud services for remote patient monitoring and timely care. However, its widespread application expands the attack surface. Many threat detection methods, including machine learning (ML) and traditional deep learning (DL), treat traffic as independent records, ignoring the correlation and evolution characteristics of network attacks. Graph neural network (GNN) methods have attracted significant attention for IoMT attack detection due to their unique advantages in handling graph structures. This article reviews GNN methods for IoMT threat detection and provides a comprehensive overview of key IoMT architecture components. It introduces threat classification across perception, network, service, and application layers. Technically, it covers aggregation-based, attention-based, and spatio–temporal hybrid models. It explores advanced paradigms like self-supervised learning (SSL), federated learning (FL), and knowledge distillation. This article summarizes GNN applications for IoMT and discusses key limitations, including data imbalance, heterogeneous and dynamic data challenges, and deployment bottlenecks on constrained devices. It also highlights robustness to adversarial manipulation, clinical workflow interpretability amidst false positives, and medical service availability. Finally, it discusses future research directions, including lightweight and scalable GNN methods, dynamic heterogeneous graph modeling, privacy-preserving federated architectures, few-shot learning, explainable-AI (XAI)-based interpretable GNN methods, and GNN methods robust to adversarial attacks.
Keywords:
Cyber security
deep learning (DL)
graph neural networks (GNNs)
Internet of Medical Things (IoMT)
intrusion detection
threat detection

Journal

IEEE Internet of Things Journal cover
IEEE Internet of Things Journal
IF:
8.9
Papers:
1.4W
Citations:
7.8W

Organization

U
University of Bedfordshire
Scholars:
827
Papers: 844
Citations: 0
U
universiti kebangsaan malaysia
Scholars:
3.4K
Papers: 1.4K
Citations: 1
Cited Papers

Cited Papers

Citing Papers

Citing Papers