Consumer Healthcare Devices (CHD) in Healthcare 4.0 (HC 4.0) increasingly generate continuous physiological data that are transformed into 3-dimensional holographic visualizations for remote monitoring, diagnosis, and clinical decision support. However, existing IoMT and blockchain (BC)-based healthcare systems protect data storage and access but do not verify the integrity, freshness, or provenance of holographic patient representations, leaving such visualizations vulnerable to spoofing, replay, and slice-level tampering. This paper proposes a Blockchain-Assisted Holographic Counterpart (BAHC) framework that cryptographically binds wearable devices to holographic updates using PUF-derived Holographic Authentication Tokens (HAT), enforces slice-level integrity through a Merkle-Hologram-Commitment Tree (Merkle-HC Tree), and anchors updates on a permissioned Proof-of-Authority (PoA) BC. Privacy-preserving access control and verification are achieved using Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and Zero-Knowledge Proofs (ZKPs). The framework is evaluated on a controlled experimental testbed emulating 500 concurrent patient streams using independent public physiological datasets and public MRI volumes for synthetic hologram generation, measuring end-to-end latency, anomaly detection performance, rendering efficiency, and blockchain throughput under up to 100 validators. Experimental results show a 68.6% reduction in holographic rendering latency, a 34% reduction in diagnostic latency, a relative 27% improvement in anomaly detection performance, and sustained throughput close to 500 transactions per second, demonstrating that BAHC provides a scalable and trustworthy foundation for secure holographic monitoring in HC 4.0 systems.
Consumer assistant (CA) systems, including smart speakers, wearable devices, and home automation platforms, increasingly rely on biometric authentication mechanisms such as voice recognition and behavioral profiling. The irreversible nature of biometric data introduces persistent security risks, particularly under multi-stage cyber attacks. Existing cyber risk assessment (CRA) approaches are predominantly centralized and fail to capture vulnerability dependencies, attack propagation, and decentralized trust validation. This paper presents a blockchain (BC)-conditioned attack graph framework for quantitative CRA in CA environments. The proposed model integrates dependency-aware attack propagation (AP ), probabilistic state representation, and BC-based transition validation, where onchain verification directly influences attack feasibility and risk computation (RC). Unlike conventional approaches that use BC only for logging, the proposed framework incorporates BC directly into exploitability and impact modeling. A reproducible dataset derived from Common Vulnerabilities and Exposures (CVE) and National Vulnerability Database (NVD) vulnerability (vul) records (2020–2024) is mapped to CA components. Experimental results demonstrate reductions of 17.8% in attack surface (AS), 32.6% in attack success probability (ASP), and 31.2% in system-level cyber risk. The BC layer introduces an average transaction latency of 100 ms, making it suitable for periodic risk assessment.
The integration of Internet of Medical Devices (IoMD) in healthcare 4.0 enables real-time patient monitoring but introduces severe cybersecurity risks across sensor, network, and application layers. Traditional security models fail to address multi-layer threats such as device tampering, Man-in-the-Middle (MITM), Denial-of-Service (DoS), Eavesdropping, and insider attacks in a unified manner. This work proposes a blockchain (BC)-based IoMD security framework leveraging AES-256 encryption for confidentiality, SHA-256 hashing for integrity, and Practical Byzantine Fault Tolerance (PBFT) consensus for decentralized trust. The framework incorporates cryptographic firmware verification, BC-based device fingerprinting, payload hashing, and smart contract-based access control. The experiments demonstrate that the proposed system improves security effectiveness by up to 96
The proliferation of federated learning has revolutionized decentralized machine learning, but its distributed nature introduces a critical vulnerability, such as privacy leakage and model poisoning attacks. While contemporary literature offers various countermeasures, the fundamental challenge remains: achieving robust mitigation of adversarial influence without compromising global model utility or incurring prohibitive computational overhead. In this article, a robust and adaptive aggregation framework is engineered to neutralize sophisticated poisoning vectors within highly heterogeneous, non-independent, and identically distributed environments. This approach improves the inherent trade-off between security and performance by integrating a trust-based mechanism with rigorous privacy safeguards. This framework enables collaborative model construction while shielding the global objective. Formal theoretical proofs measure the efficacy of the proposed methodology, and empirical evaluations validate it. Furthermore, a security analysis across multiple poisoning attacks ensures the framework’s resilience. Furthermore, it demonstrates a superior balance of robustness, privacy preservation, and operational efficiency compared to existing baselines. The experimental results present that the proposed works perform the best compared to the state-of-the-art methods.
This study presents an approach to lung disease detection that merges neural network methodologies by using patient lung sounds alongside demographic information (location, age, and Body Mass Index (BMI)), instrument specifications, and indicators of crackles and wheezes. The objective of this paper is to offer an efficient, low cost diagnostic method. Traditional auscultation-based diagnosis faces challenges from subjectivity and sound variability. The proposed Respiratory Disease Detection Model (RDDM) uses spectrogram images from lung sounds to capture nuanced patterns while integrating clinical data for contextual insights. This fusion-based model provides automated analysis, enhancing diagnostic precision and efficiency, and ensuring good generalization to new cases, paving the way for advancements in lung disease detection.
Consumer Electronics (CE) systems increasingly use Artificial Intelligence (AI), Machine Learning (ML), and Federated Learning (FL) for data-driven intelligence. This integration introduces risks such as privacy leakage during aggregation, poisoning of model updates, and integrity threats from unverified participants. Differentially private FL reduces leakage but often degrades accuracy by more than 10%, while Blockchain (BC)-based FL improves integrity at the cost of up to 12.9% overhead. To address these issues, a hybrid FL framework with BC auditing (BA) is proposed. The design combines Secure Aggregation (SA), Robust Global Update (RGU) rules, and lightweight BC consensus to defend against adaptive adversaries. Experimental results show an 8.3% accuracy gain under non-IID data, a 30.9% reduction in privacy leakage, and a poisoning-induced accuracy drop limited to 6.1% compared to 23.9% in standard FL. The framework maintains 97.8% BC integrity with only 3.2% overhead, demonstrating a balanced trade-off between accuracy, privacy, robustness, and integrity for real-world CE deployments.
Smart healthcare holds immense potential to revolutionize the healthcare industry, promoting patient-centric care, preventive medicine, and improved health outcomes. By harnessing the power of advanced technologies and data-driven solutions, healthcare providers can deliver more efficient, accessible, and personalized healthcare services, ultimately transforming the approach and experience of healthcare. Biomedical images have now become the new support for better diagnosis in the medical field. In the area of image security, perceptual hashing provides a powerful approach to enhancing the security of medical images by creating compact and unique representations of their visual content. This paper proposes a framework for smart healthcare where biomedical images are secured with perceptual hashing. In this framework, an authentication module is also deployed to verify the identity of smart users allowed to access the biomedical images over the edge or cloud layers. The performance analysis of the hashing module is evaluated using the structural similarity index measure (SSIM), peak signal-to-noise ratio (PSNR), bit error rate (BER), and Hausdorff distance. Additionally, the performance analysis of the authentication module is evaluated in terms of a system accuracy of 89
The implementation of keystroke biometric techniques for user authentication is becoming crucial in today’s digital landscape. Its primary strengths lie in the ability to offer security and accessibility when required. As a behavioral biometric, keystroke dynamics is gaining attention because it doesn’t require additional specialized hardware, making it ideal for securing most personal digital and mobile devices. It enables continuous and unobtrusive authentication, ensuring comprehensive session security, which is vital for data protection. Keystroke data can be easily gathered through standard keyboards or touchscreens, and this paper aims to summarize its applicability, challenges, and various approaches used to address issues in the field of keystroke dynamics-based user authentication. The paper also emphasizes new and evolving methods in user verification using keystroke dynamics, paving the way for promising future research opportunities.
In today’s world, people frequently use smartphones and computers, which have made it easier to perform online activities such as purchasing, banking, and communication. Additionally, this simplicity makes one more susceptible to cybercrime. Smishing, or SMS-based phishing, is used more frequently by attackers to acquire sensitive information, such as passwords and banking details. To overcome these types of problems, a smishing detection model is employed that can rapidly categorize SMS messages into ham and spam phishing messages. This approach employs real-world data and utilizes preprocessing techniques. In the proposed approach, the performance of five classifiers: random forest(RF), support vector classifier (SVC), XGBoost (XGB), logistic regression (LR), and adaboost (ABD). In which the SVC achieved the best performance with 99.19% training and 99.45% testing accuracy, a false positive rate (FPR) of 0.0010, and an inference time (IT) of 0.0063 per second. Additionally, data balance and adversarial training have been evaluated to improve the models’ robustness. The proposed work enables users to automatically distinguish between legitimate (ham) and fraudulent (smishing) SMS messages, enhancing personal security and trust in mobile communication.
A significant challenge in cybersecurity is the lack of a large-scale network dataset that accurately records modern traffic patterns, a wide variety of modest incursions, and comprehensive network traffic data. Existing benchmark datasets such as KDDCup99, NSL-KDD, GureKDD, and UNSWNB-15 must be updated to reflect modern cyber attack signatures. To address this issue, a new labeled dataset, namely the TestCloudIDS dataset, is proposed, which contains fifteen variants of DDoS attacks in the cloud environment. In contrast to other datasets lacking realism and coverage of the latest attack strategies, it closely resembles the real world because of its careful construction. It integrates a wide range of attack situations, utilizing both conventional and current vectors, focusing on incorporating state-of-the-art techniques such as Raven Storm. In addition, we propose “SparkShield”, a technique for intrusion detection using Apache Spark within a big data environment. The effectiveness of “SparkShield” is evaluated through in-depth research using a variety of datasets and simulated attack scenarios. Three existing datasets are used to measure performance: UNSW-NB15, NSL-KDD, CICIDS2017, and the proposed TestCloudIDS dataset. The overall performance of the proposed approach achieved better threat classification and trained with recent attack patterns using the TestCloudIDS dataset.
The Federated Learning (FL)-based approaches are increasing rapidly for different areas, such as home automation, smart healthcare, smart cars, etc. In FL, multiple users participate collaboratively and distributively to construct a global model without sharing raw data. The FL- based system resolves several issues of central server-based machine learning approaches, such as data availability, maintaining user privacy, etc. Still, some issues exist, such as data poisoning attacks and re-identification attacks. This paper proposes a Data Poisoning Attack Defense (DPAD) Mechanism that detects and defends against the data poisoning attack efficiently and secures the aggregation process for the Federated Learning-based systems. The DPAD verifies each client's updates using an audit mechanism that decides whether a local update is considered for aggregation. The experimental results show the effectiveness of the attack and the power of the DPAD mechanism compared with the state-of-the-art methods.
Nowadays, with the exponential growth of digital connectivity and online services, phishing has emerged as one of the most familiar Cyber threats, targeting individuals and organizations alike. Phishing attacks aim to deceive users into revealing sensitive information such as usernames, passwords, and financial credentials by mimicking legitimate websites. To help mitigate these risks, there is an urgent need for intelligent systems capable of detecting and preventing phishing attacks in real-time. In this framework, various classification machine learning techniques are used, such as, Artificial neural network (ANN) achieved an accuracy of 98.90
The sharing of personal data in a distributed environment raises individual privacy concerns. However, analysis of these data may solve various real-life problems, including analysis of medical data, e-auction, secure voting, etc. Such analysis requires a system that ensures data privacy during and after computation. Secure Multi-Party Computation (MPC) is one of the popular cryptographic tools that allows a group of parties to compute a collaborative function without any personal interactions. MPC only produces the final result; it does not leak the input data or any partial results that may reveal personal information. The secret personal data of each participating party will be the input for this MPC function. In a collaborative environment, no one trusts another party but is interested in performing joint computation with their personal data. Some participating parties may be curious about others' input to gain an advantage. Ensuring the security and privacy of individual data in such an environment, the MPC has become an emerging area of interest. Based on the application, different variants of the MPC protocols exist. The efficiency of these protocols depends on communication and computation cost, which further depends on the number of participating parties. This study demonstrates the challenges involved in developing practically implementable MPCs. The present paper reviews some existing MPC protocols based on different parameters, like security, privacy, feasibility, efficiency, number of participating parties involved in computation, and their applications. Finally, some of the best-suited MPC protocols as per their application domain have been suggested.
Nowadays, the need for a robust data privacy framework in health monitoring system is driven because the health sector is a prime target for cyber-attacks due to the high value of sensitive data on the cloud server storage. This paper presents a robust data privacy framework designed for health monitoring systems, addressing the critical need for secure handling of sensitive patient information. The proposed framework integrates hybrid consensus mechanism, ring signature mechanism, and data authentication mechanism to ensure sustainable and secure blockchain infrastructure, robust framework, and accuracy and consistency of data. Moreover, Security-Performance Efficiency Metric show that the proposed robust data privacy framework is effective and efficient in compare to existing framework for improving transaction processing and blockchain administration.
With the technological revolution Healthcare - 4.0 strives to provide personalized quality of care at lowest reasonable cost. In this, the health data collected and processed by various Internet of Medical Things (IoMT) devices, communicated via open channel, stored at edge-cloud servers and shared among different stakeholders. It raises two primary concerns: efficiency and information leakage. The Attribute Based Access Control (ABAC) address these issues and widely accepted for data access management. It grants access to users based on the predefined policy. Healthcare information is highly sensitive and personal. The data owner wish to share it only with specific data users such as highly experienced cardiologist. But during a medical emergency, this information must be available to the caregiver, even though the caregiver may not be a cardiologist or have less experience. It requires an adaptive access control policy, based on the present health conditions of the data owner. The proposed adaptive access control framework bridge this gap by including some data attributes in the access policy construction. Another issue is, majority of data attributes are ranged value attributes. Such attribute can not be helpful in policy construction. It need to be converted as a sub-tree of all possible interval values. Each interval values now considered as simple attribute and participated in policy definition. It increases the number of attributes and creates performance bottleneck. To resolve it, this paper present an attribute exposition technique based on 0-encoding and 1-encoding. The present work also constructs a Garbled-circuit that anonymously compares the exposited attributes and strictly resists the attribute collusion.
Intrusion Detection Systems (IDS) are vital for safeguarding modern cloud infrastructures. However, traditional IDS models often suffer from limited generalization, poor interpretability, and susceptibility to adversarial attacks. This study proposes a novel hybrid IDS framework based on a Local Interpretable Model Explanation–Attentive Adversarial Meta-Ensemble (LIME-ME) architecture. The framework integrates signature-based detection with an ensemble of diverse classifiers—Random Forest, Logistic Regression, Support Vector Machine, Naive Bayes, and Multi-layer Perceptron—trained on a base dataset. Using LIME, the system generates local feature importance vectors concatenated with the base classifiers’ outputs to create rich, interpretable meta-features. Synthetic adversarial perturbations are introduced to enhance robustness, yielding an augmented meta-feature space. A meta-learner is trained on clean and adversarial meta-features to achieve superior detection performance and resilience against evasion. Experimental evaluations on benchmark datasets, including UNSW-NB15 and CIC-IDS2017, NSL-KDD, CICDDoS2019, TestCloudIDS, and TON_IoT demonstrate that the proposed approach significantly outperforms traditional IDS models regarding accuracy, precision, and robustness while offering transparent, explainable decision-making.
Access control in healthcare is essential for ensuring secure and privacy-preserving data management, yet traditional centralized approaches are vulnerable to security breaches and inefficiencies. Blockchain-based access control offers a decentralized and transparent alternative; however, existing solutions suffer from high execution time, excessive gas consumption, and limited scalability. To address these limitations, this work proposes a Tag-Based Access Control (TBAC) framework using blockchain, where a tag score is dynamically computed for entities based on predefined attributes, and access is granted accordingly. This method enhances granularity and flexibility in access control while maintaining the immutability and security of blockchain. Experimental results demonstrate that the proposed system reduces execution time by 20.9
The current healthcare infrastructure faces significant challenges, including security vulnerabilities, privacy breaches, data inconsistencies, and overly accessible health records. These issues highlight the urgent need for comprehensive reforms in information management and patient data protection. To address the current issues, the present work proposes RSHealth framework, an e-healthcare ring signature scheme. It is a promising solution for ensuring anti-tampering of transaction fie and identity anonymization of sender healthcare stakeholder during transmission from main healthcare community to a branch healthcare community, maintaining compliance with data privacy regulation. The RSHealth scheme includes five functions: TFSetup(), TFKeygen(), TFRing(), TFVerify(), and TFOpen(). These functions respectively initialize system parameters, generate keys, create ring signatures, verify authenticity, and reveal signer identities by authorized receiver healthcare stakeholders. Extensive experimentation is performed for aforementioned framework to judge the latency and throughput; varying sender healthcare stakeholder and sizes of transaction. The performance analysis shows that increasing sender healthcare stakeholder and transaction sizes leads to increased throughput and decreased latency.
Internet of Things (IoT) and Machine Learning (ML) techniques enlightened several areas and started a new era in industry. One challenging area is the Healthcare sector. The ML changed the direction and sped up the Healthcare sector and the Healthcare sector became Smart Healthcare (SH). The Medical Cyber-Physical System (MCPS) is effectively used in SH and it has several privacy and security issues. In such scenarios, Federated Learning (FL) has shown another direction to handle several challenges and opened an area for research. Additionally, blockchain (BC) technology has made the FL network secure. Inspired by several works in this paper Blockchain enabled FL- based MCPS is proposed that is capable of mitigating different adversarial attacks, Distributed Denial-of-Service, Sybil, etc. The performance of the FL is measured using accuracy, mean squared error (MSE), sensitivity, and specificity. After the final round achieved accuracy is 86%, MSE is 0.14, sensitivity is 89%, and sensitivity is 85%.
Durga Prasad Mohapatra合作论文数1