{"id":"99c24181-94a3-41fc-b02a-dbc87b6df697","arxiv_id":"2501.11250","paper_version":1,"verdict":"REJECT","confidence":"MODERATE","novelty_score":3.0,"correctness_risk":"high","formal_verification":"none","parameter_count":0,"one_line_summary":"A survey classifying healthcare IoT devices and cataloging their cybersecurity threats and mitigation strategies, without presenting new empirical evidence.","lead":"This paper surveys cybersecurity threats facing internet-connected medical devices and lists mitigation strategies such as encryption, authentication, and network segmentation. It is a review with a proposed device classification, not a new measurement or demonstrated solution, so its value is organizational rather than evidential.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The paper's central empirical claim—that healthcare IoT attacks are frequent and increasing—rests on industry statistics that are either unreferenced or attached to unrelated bibliography entries; the factual foundation cannot be verified from the manuscript alone.","rationale":"I read the paper as a survey whose central contribution is a reliable synthesis of the frequency, nature, and mitigation of cyber attacks on healthcare IoT devices. For that contribution to hold, the cited statistics and references must actually support the claims. The reader's weakest-assumption analysis identifies exactly this evidential vulnerability, and my independent review confirms it: the key statistics in Sections III and IV are attributed to named reports that do not appear in the bibliography, and several bibliography entries are topically unrelated to the sentences they are attached to. The result is that the paper's empirical premise is unverifiable from the manuscript, which is a fatal flaw for a survey claiming to provide a 'comprehensive literature survey.' I am not alleging misconduct; citation errors and unverifiable secondary statistics can arise from careless compilation. But the effect is the same: the central claim lacks a demonstrated factual basis. I agree with the reader's REJECT verdict and recommend no change. A focused citation-verification table, as described in the concrete test, would settle whether the concern lands by showing whether the headline numbers are traceable to real sources.","tokens_in":7044,"tokens_out":2844,"duration_ms":29479,"concrete_test":"Build a citation-verification table mapping every quantitative claim in Sections III and IV to a specific retrievable primary source (URL, DOI, or reference number). In particular, locate the exact '45% increase' in Check Point Research's 2025 reporting, the '35% DDoS increase' and 'over 50% insecure IoT' figures in the 2024 Elastic Global Threat Report, and the '83% outdated operating systems' figure in the cited Symantec study. If any headline statistic cannot be traced to the named source, or if the sentence's supporting reference is topically unrelated, the empirical foundation of the central claim fails.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The survey's central claim is quantitative: healthcare IoT attacks are frequent and increasing, with specific figures such as a 45% increase in attacks on healthcare organizations, over 50% of attacks involving insecure IoT devices, a 35% increase in DDoS attacks, 47% of healthcare organizations reporting DDoS attacks, a 28% increase in MitM attacks, 15% of incidents attributed to MitM, a 60% year-over-year increase in IoT malware, and 83% of healthcare IoT devices running outdated operating systems. These statistics are the load-bearing evidence for the paper's stated purpose of highlighting the nature and frequency of cyber attacks. However, in Section III the 45% figure is attributed only to 'Check Point Research (2025)' with no reference entry, and in Section IV the Elastic/Cybersecurity Ventures, HIMSS, Check Point Research (2022), Ponemon, Palo Alto Unit 42, and Symantec sources are named but none appears in the reference list. The bibliography contains only 21 entries, and several are topically unrelated to the sentences they support: [10] and [17] concern arsenic uptake in grasses, [16] concerns alternative-medicine journal editing, [18] concerns mobile health in South Sudan, and [19] concerns lipohypertrophy and continuous glucose monitoring. A reader therefore cannot verify a single headline statistic from the cited literature, and the quantitative backbone of the survey is unsupported. This is not a disagreement with the field's consensus; it is a broken evidence trail for the paper's own factual assertions. The proposed device classification and solution catalog are generic and unvalidated, but the empirical frequency claim is what motivates the entire survey, so the unverifiable statistics are the most load-bearing weakness.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This manuscript is a survey-style paper on cybersecurity threats to Internet of Things (IoT) devices in healthcare. It proposes a six-class, threat-oriented taxonomy of healthcare IoT devices (wearables, implantables, smart devices, ambient devices, operational tools, and research-and-development equipment), catalogs attack types per class, presents a set of industry statistics intended to show that attacks on healthcare IoT are frequent and increasing, and reviews mitigation strategies spanning device security, authentication, network segmentation, blockchain, regulatory frameworks, user training, and AI-assisted detection. The central empirical claim is that attacks are frequent and rising, supported by figures such as a 45% yearly increase in attacks on healthcare organizations, more than 50% of attacks involving insecure IoT devices, a 35% increase in DDoS attacks, a 60% year-over-year increase in IoT malware, and 83% of healthcare IoT devices running outdated operating systems. The paper concludes with future research directions centered on AI-driven detection, lightweight cryptography, and quantum-resilient protocols.","tokens_in":7303,"tokens_out":10495,"duration_ms":80967,"significance":"The topic is timely and important, and the paper has two useful organizing contributions: the threat-oriented device taxonomy in §II (Figs. 2-8) is a reasonable framework for discussing healthcare IoT risk, and §V catalogs a broad, mainstream set of mitigation measures including MFA, micro-segmentation, FOTA updates, and SOAR/XDR platforms. Beyond that, the manuscript offers no machine-checked results, no reproducible artifacts, no original data, and no falsifiable predictions of its own; as a survey, its entire value lies in the accuracy and verifiability of its cited evidence. On that basis the paper fails: the headline statistics in §III and §IV are not traceable to any bibliography entry, and a substantial fraction of the 21 references do not support the sentences they are attached to. The paper cannot serve as a reliable synthesis of the literature in its current form.","major_comments":[{"comment":"The central quantitative claim of the paper—that attacks on healthcare IoT devices are frequent and increasing—is not supported by the reference list. The 45% increase in attacks on healthcare organizations is attributed in this paragraph to 'Check Point Research (2025)', but no such entry exists in the 21-item bibliography, and the manuscript's submission date of 20 January 2025 makes the cited source unverifiable. Since this is the only quantitative evidence offered for the paper's core assertion in §III, the claim cannot be checked from the manuscript as submitted.","section":"§III, unnumbered paragraph after §III.C"},{"comment":"None of the seven headline statistics in §IV is traceable to a bibliography entry: the '2024 Elastic Global Threat Report' (attributed to Cybersecurity Ventures), the HIMSS figure that 47% of healthcare organizations experienced a DDoS attack, the Check Point Research (2022) figure of a 28% increase in man-in-the-middle attacks, the Ponemon Institute (2023) estimate of 15%, the Palo Alto Networks Unit 42 figure of a 60% year-over-year increase in IoT malware, the Symantec figure of 83% of devices on outdated operating systems, and the claim that insecure IoT devices contributed to over 50% of attacks. In addition, the Elastic Global Threat Report is attributed to the wrong organization. The quantitative backbone of the survey is therefore unverifiable and cannot support the conclusion that threats are rising.","section":"§IV"},{"comment":"Numerous bibliography entries are topically unrelated to the claims they are cited to support. [10] and [17], both on arsenic uptake in grasses, support statements about smart medical equipment in §II.C and §III.C; [16], on alternative-medicine journal editing, supports the recommendation for security assessments of implantable devices in §III.B; [18], on mobile health in South Sudan, and [19], on lipohypertrophy and continuous glucose monitoring, support claims about healthcare information systems and hospital operations in §III.C; [9], on developmental neurobiology, supports the description of implantable devices in §II.B; and [12], on job stress, supports the list of asset-tracking and hygiene-monitoring systems in §II.E. Because the citations do not match their contexts, a reader cannot verify any of these statements from the listed sources; this is a systemic evidence-integrity problem, not a local error. Note also that [10] and [17] are duplicate entries.","section":"Reference list entries [9], [10], [12], [16], [17], [18], [19]"},{"comment":"The paper repeatedly describes itself as a comprehensive survey (Abstract; 'comprehensive review' in §I; 'comprehensive literature survey' in §VII), but with only 21 references—several of them duplicates or off-topic—and with no stated search strategy, inclusion criteria, databases used, or temporal coverage, the comprehensiveness claim is unjustified. For a survey whose stated purpose is to highlight the nature and frequency of attacks, the absence of a verifiable evidence base is a load-bearing deficiency, not a stylistic issue.","section":"Abstract, §I, and §VII"}],"minor_comments":[{"comment":"The phrase 'spine cord simulators' should read 'spinal cord stimulators'.","section":"§II.B"},{"comment":"'HV AC' should read 'HVAC'.","section":"§II.D and Fig. 6"},{"comment":"The caption 'IoT Breseach and development tools' appears to contain a typographical error; 'Breseach' is likely intended to be 'research'.","section":"Fig. 8 caption"},{"comment":"The phrase 'The 2024 Elastic Global Threat Report report' contains a duplicated word, and the Fig. 9 caption ('A sample statistics...') contains a number-agreement error.","section":"§IV"},{"comment":"'Security motoring' should read 'security monitoring', and the abbreviation PTP-SOAR is never defined in the text.","section":"Fig. 14 caption"},{"comment":"'Mitigating these threats require implementing' should be 'Mitigating these threats requires implementing' for subject-verb agreement.","section":"§III.A"},{"comment":"Several figures appear to reproduce commercial vendor diagrams (e.g., Rishabh, Arm TrustZone, Cisco Duo, Hyperledger Fabric, IoT Core) without source attribution or permission statements; the provenance of these figures should be clarified.","section":"Figures 7–15"}],"recommendation":"reject","confidential_remarks":"The reject verdict is, in my assessment, well grounded and I concur with the reader. The distinguishing feature of this manuscript is not a disagreement with consensus but a broken evidence chain: every quantitative claim central to the paper's purpose is either unnamed or attached to a reference that does not exist or does not say what is claimed. I would add one observation for the editor: the acknowledgment credits S. Bay of Johnson Controls for 'the data, technical reports, and case studies,' and several unattributed statistics and vendor-derived figures in §III–§V appear to have industry provenance; the editor may wish to have the authors clarify the provenance and permissions for these materials. This manuscript might be salvageable as a different paper, but only with a complete re-sourcing of its claims, which goes beyond the scope of a revision."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Hi,\n\nShort version: this is a survey with a sensible outline and one genuinely useful piece of organization—the threat-oriented classification of healthcare IoT devices into wearables, implantables, smart medical equipment, ambient devices, operations tools, and R&D. That grouping gives the narrative a clean spine, and some of the figures (device examples, authentication flow) could work in an undergraduate lecture. The catalog of threats and mitigations is accurate, though generic; nothing here is new to the literature, and the authors don't claim otherwise.\n\nThe problem is the evidence trail. The paper's motivation is quantitative: a 45% attack increase, over 50% of attacks via insecure IoT, a 35% DDoS jump, 47% of hospitals attacked, 83% of devices on outdated OS—these numbers are the backbone of the \"frequent and increasing\" thesis. But in Section III, the 45% figure is attributed only to \"Check Point Research (2025)\" with no reference entry, and the paper was submitted in January 2025, which makes that citation suspect. Section IV names Elastic/Cybersecurity Ventures, HIMSS, Check Point Research (2022), Ponemon, Palo Alto Unit 42, and Symantec, but none appears in the reference list. Meanwhile, several actual references don't match their context: [10] and [17] are duplicate arsenic-uptake papers in grasses, [16] is about alternative-medicine journals, [18] about mHealth in South Sudan, [19] about lipohypertrophy and continuous glucose monitoring. You cannot verify a single headline statistic from the listed sources. For a survey whose stated purpose is comprehensive synthesis, that is not a minor formatting issue; it breaks the factual foundation.\n\nThe proposed classification is unvalidated, but that's less damning: it's an organizational contribution, not an empirical claim. The real problem is that a reader cannot trust the paper's central assertion. This reads more like careless cut-and-paste citation management than fraud, but the practical effect is the same—the paper cannot currently be used as a reference.\n\nIf the authors redo the citation work, source every statistic to a real, dated report, and add a systematic search methodology, a revised version could be a serviceable teaching survey. As submitted, I would not send this to a referee. Desk reject, with the door open for a properly sourced revision.\n\nRecommendation: don't engage. If you need a classroom intro to healthcare IoT security, steal the classification idea and replace every number with a verifiable source.","headline":"A readable but evidence-broken survey: the proposed IoT device taxonomy is a useful teaching scaffold, but the unverifiable statistics and unrelated citations sink its central claim.","tokens_in":7846,"tokens_out":3444,"would_cite":false,"duration_ms":32493,"reading_group":"no","serious_thinker":"no","would_accept_peer_review":false},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This review argues that cyber attacks on healthcare IoT devices are frequent and rising, and that layered defenses are the right response.","keywords":["Cybersecurity","IoT","Healthcare","Devices","Attacks","Vulnerabilities","Mitigation Strategies"],"falsifier":"Collect independent, time-stamped records of cyber attacks on healthcare IoT devices—from breach disclosure registries, device vulnerability databases, and hospital incident reports—and check whether year-over-year growth matches the cited rates; a flat or declining trend would contradict the paper's central assertion.","tokens_in":6840,"feed_emoji":"🛡️","tokens_out":10625,"duration_ms":87575,"temperature":0.7,"pith_summary":"The paper is a review of cybersecurity threats facing Internet of Things (IoT) devices in healthcare. Its central claim is that these devices are attacked frequently and increasingly, citing statistics such as a 45% year-over-year rise in attacks on healthcare organizations and involvement of insecure IoT devices in over 50% of attacks. The authors organize devices into a threat-oriented taxonomy—wearable, implantable, smart medical, ambient, operational, and research—and walk through the attack types that target each class. They argue that a multi-layered combination of device hardening, network segmentation, authentication, staff training, and regulatory compliance can substantially reduce the risk. A sympathetic reader would take the paper as a structured map of the problem space and a checklist of defenses, rather than a new experimental result.","feed_headline":"Hospital IoT devices face frequent, rising cyber attacks","feed_subtitle":"Review maps threats to wearables, implants, and hospital gear, with layered defenses to blunt them.","key_machinery":"The central object is the authors' proposed threat-oriented classification of healthcare IoT devices into six classes: wearable, implantable, smart medical, ambient, operational, and research devices. This taxonomy carries the argument by mapping each class to its typical attack vectors—data interception, device hijacking, denial of service, ransomware, and so on—and then to corresponding mitigations, turning the review into a structured risk catalogue. The paper also leans on a set of industry statistics as evidence of attack frequency, and on established security frameworks as the skeleton for its recommendations.","core_discovery":"On its own terms, the paper establishes a risk landscape: it asserts that the connectivity and data richness that make healthcare IoT valuable also make it a frequent target, and it supports that assertion with industry statistics, including a 45% increase in attacks on healthcare organizations, a 35% rise in denial-of-service attacks, over 50% of attacks involving insecure IoT devices, and 83% of healthcare IoT devices running outdated operating systems. The review then claims that no single measure can address this, and that layered defenses spanning device-level security, network controls, authentication, user awareness, and compliance with healthcare privacy and security regulations are the way to mitigate the risk. The paper also offers a threat-oriented device classification as a tool for reasoning about which attacks apply where.","pith_inferences":["The paper's taxonomy could be extended to home-use medical IoT devices, which sit outside hospital perimeters but feed data into clinical workflows, making them a plausible entry point the review does not cover.","If the quoted attack rates are accurate, attackers' incentives will increasingly target wearable and implantable devices, because they carry high-value continuous health data and often use weak or default authentication.","The layered-defense recommendations could be tested empirically by comparing incident rates across hospitals that have adopted most layers versus those that have not, a comparison the review does not perform.","The statistical foundation would be stronger if independent, peer-reviewed incident data, rather than vendor reports, were used to verify the rising-trend claim."],"forward_implications":["Healthcare organizations should treat IoT devices as a distinct attack surface and enforce device-level controls such as secure boot, signed firmware updates, and hardware-backed encryption.","Networks should segment IoT traffic from core clinical systems, with micro-segmentation and AI-driven intrusion detection to contain malware spread.","Compliance with healthcare privacy and security regulations becomes not just a legal requirement but a substantive part of the security posture.","Investment in AI-based and behavior-focused threat detection is justified because attack methods evolve faster than static signatures.","IoT manufacturers should adopt security-by-design so that secure boot, authentication, and patch mechanisms exist before devices reach hospitals."],"supporting_citations":[{"why":"supplies the observation that the properties making IoT valuable also render it vulnerable to cyber attacks.","marker":"[5]"},{"why":"provides an earlier classification of healthcare IoT devices that the authors build on.","marker":"[6]"},{"why":"offers a competing functional classification the authors critique for lacking a security view.","marker":"[7]"},{"why":"supplies the security standards the authors recommend for compliance and risk management.","marker":"[20]"},{"why":"supports the use of AI-driven security tools as both a near-term mitigation and a future research direction.","marker":"[21]"}],"fun_headline_variants":["Cyber attacks on healthcare IoT: frequent, rising, and layered defenses","Hospital IoT under attack: 45% rise, review maps defenses","Healthcare IoT: frequent attacks, layered solutions from review","Rising IoT attacks in healthcare demand layered defenses, says review","Review: frequent cyber attacks on hospital IoT need layered fixes"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The paper's central claim of frequent, rising attacks rests on industry statistics quoted in Section IV, yet the listed references do not themselves establish those figures, so the quantitative urgency is not verifiable from the paper's sources.","fun_headline_variants_meta":{"raw":{"variants":["Cyber attacks on healthcare IoT: frequent, rising, and layered defenses","Hospital IoT under attack: 45% rise, review maps defenses","Healthcare IoT: frequent attacks, layered solutions from review","Rising IoT attacks in healthcare demand layered defenses, says review","Review: frequent cyber attacks on hospital IoT need layered fixes"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000315,"raw_usage":{"total_tokens":1702,"prompt_tokens":781,"completion_tokens":921,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":397,"completion_tokens_details":{"reasoning_tokens":846}},"tokens_in":397,"tokens_out":921,"duration_ms":9547,"temperature":1.0,"reasoning_tokens":846,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T18:27:52.330326+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Collect independent, time-stamped records of cyber attacks on healthcare IoT devices—from breach disclosure registries, device vulnerability databases, and hospital incident reports—and check whether year-over-year growth matches the cited rates; a flat or declining trend would contradict the paper's central assertion.","supporting_citations":[{"cited_title":"Healthcare iot: Benefits, vulnerabilities and solutions,","cited_arxiv_id":null,"evidence_quote":"supplies the observation that the properties making IoT valuable also render it vulnerable to cyber attacks."},{"cited_title":"Iot-based applications in healthcare devices,","cited_arxiv_id":null,"evidence_quote":"provides an earlier classification of healthcare IoT devices that the authors build on."},{"cited_title":"An intelligent iot based healthcare system using fuzzy neural networks,","cited_arxiv_id":null,"evidence_quote":"offers a competing functional classification the authors critique for lacking a security view."},{"cited_title":"A review of security standards and frameworks for iot-based smart environments,","cited_arxiv_id":null,"evidence_quote":"supplies the security standards the authors recommend for compliance and risk management."},{"cited_title":"Analysis of IoT security challenges and its solutions using artificial intelligence,","cited_arxiv_id":null,"evidence_quote":"supports the use of AI-driven security tools as both a near-term mitigation and a future research direction."}],"review_version":1}