REVIEW 3 major objections 6 minor 1 cited by
A Review on the Security Vulnerabilities of the IoMT against Malware Attacks and DDoS
T0 review · 3 major / 6 minor · reviewed 2026-08-10 · deepseek-v4-flash
Pith's one-line read This literature review argues that inadequate encryption, weak authentication, and irregular firmware updates are the primary causes of IoMT security risk, with malware and DDoS as the dominant attack forms.
desk verdict A readable but unverifiable rehash of IoMT security surveys, whose quantitative success-rate claims don't survive contact with the reported method. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the Internet of Medical Things (IoMT), the network of connected medical devices and healthcare IT systems. The argument about its security is carried by a systematic literature review: a defined search across three major scholarly databases, inclusion and exclusion criteria (peer-reviewed, 2019–2024, English, focused on IoMT security), quality screening, and categorical extraction of publication type, venue, year, technology, and vulnerability. This machinery turns individual papers into comparative claims by rating mitigation approaches on success rate, complexity, and scalability, and it is what allows the review to assert that blockchain-based solutions achieve the highest reported success rate (90%), machine learning approaches reach 82–88% for detection tasks, and edge computing best fits resource-constrained devices.
What would settle it
A reader could go to the cited studies and verify each headline number: if the sources do not contain the 90% blockchain success rate, the 82–88% machine-learning range, or the over-70% vulnerability figure, the review's quantitative synthesis is unsupported. A complementary test would be a real-world audit of hospital IoMT fleets to see whether exploited vulnerabilities trace to weak encryption, weak authentication, and firmware lag as the review claims.
Extended reading notes
Core claim
On its own terms, the review's central discovery is that the IoMT vulnerability landscape is dominated by three recurring weaknesses—encryption, authentication, and firmware hygiene—and that the same three defenses keep recurring as solutions. Drawing on 586 peer-reviewed studies collected from three major scholarly databases, it reports that malware and DDoS attacks account for most observed threats, that over 70% of IoMT devices in current use are vulnerable to known malware, and that evaluated mitigations show success rates of about 82–88% for machine learning, 90% for blockchain, and 70–85% for cryptographic methods. The paper presents this as a synthesis of existing evidence rather than a new measurement, so the numbers are claims about what the literature already demonstrates.
Load-bearing premise
The review assumes that the summary statistics it reports—over 70% of IoMT devices vulnerable to known malware, a 90% success rate for blockchain, and 82–88% for machine learning—are accurately drawn from the cited studies, even though it provides no per-study data table, confidence interval, or meta-analytic check.
Editorial extensions
If this is right
- If weak encryption, weak authentication, and irregular firmware updates are the dominant root causes, then targeted investment in those three areas should reduce the majority of IoMT exploitation.
- Machine learning-based detection is effective against malware and DDoS but demands computational resources and large datasets, so its deployment depends on lighter models or off-device processing.
- Blockchain offers tamper-proof data storage and access control, but its high reported success rate comes with computational overhead, making efficiency the key open problem.
- Edge computing localizes threat detection and reduces latency, making it the most scalable option for resource-constrained medical devices.
- Standardized security protocols across IoMT ecosystems are a necessary condition for turning any of these mitigations into dependable practice.
Reading between the lines
- Beyond the paper, the three root-cause categories—encryption, authentication, and firmware—could be turned into a minimal audit checklist for hospital IoMT procurement, and a field study could test whether those categories predict observed breaches.
- The reported success rates are composite numbers without per-study breakdowns or confidence intervals, so treating them as point estimates is premature; a meta-analysis of the cited detection studies would be the natural check.
- The recurring resource-constraint constraint suggests the durable solutions will be those that shift heavy computation off the device, such as edge-based anomaly detection, rather than on-device cryptography alone.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper claims to be a systematic literature review of IoMT security vulnerabilities related to malware and DDoS attacks, based on 586 papers retrieved from ACM Digital Library, IEEE Xplore, and Elsevier (2019–2024). It concludes that inadequate encryption, weak authentication, and irregular firmware updates are the main causes of IoMT risk, and it identifies machine learning, blockchain, and edge computing as promising mitigations. The paper also reports quantitative mitigation success rates (blockchain 90%, machine learning 82–88%, cryptography 70–85%) and states that over 70% of IoMT devices currently in use are vulnerable to known malware attacks.
Significance. If the quantitative synthesis were properly supported, this review would offer a useful map of mitigation effectiveness for healthcare cybersecurity researchers and practitioners. The paper usefully organizes common vulnerability themes, describes the IoMT architecture, and provides a table of representative papers and their mitigation approaches. However, the claimed systematic methodology and the headline quantitative results are not backed by the reported evidence, so the contribution cannot currently be assessed as a reliable synthesis.
major comments (3)
- [Section 3.4, Figure 5] The success-rate analysis (blockchain 90%, machine learning 82–88%, cryptography 70–85%) is the paper's main quantitative result, but no per-study extraction table, no definition of 'success rate,' no confidence intervals, and no aggregation method are provided. The cited works include surveys and protocol papers; it is not shown that these sources report success rates in this form. Without a data table linking each figure to a primary study, the central synthesis is unsupported.
- [Section 2, especially §2.3] The method section describes a systematic process with 586 initial papers, inclusion/exclusion criteria, and a quality assessment, but the manuscript reports no screening counts, no PRISMA-style flow diagram, no list of excluded studies, and no quality-assessment outcomes. Table 1 lists only ten papers, yet the text cites 35 references; the reader cannot determine how the final set was reached. Thus the 'systematic review' claim is not demonstrated.
- [Section 3.2] The assertion that 'over 70% of IoMT devices currently in use are vulnerable to known malware attacks' is attributed to [32], but no primary measurement, definition of vulnerability, or source data is given. This statistic is load-bearing for the paper's motivation and should be traceable to a specific study or presented as the authors' estimate with appropriate justification.
minor comments (6)
- [Section 4] The reference to 'Figure 5 and 5' should be 'Figures 5 and 6.'
- [Section 2.4] The statement 'as demonstrated in Figure 2' likely refers to Figure 3 or Figure 4; the figure cross-reference is incorrect.
- [Section 2.2] The sentence 'Studies either addressing IoMT security vulnerability nor published outside the designated date range...' is grammatically incomplete and should be revised for clarity.
- [Throughout] Capitalization of 'IOMT' is inconsistent; please use 'IoMT' consistently.
- [Figure 4 caption] The 'Alt:' text appears inside the figure caption; this appears to be a formatting artifact and should be moved or removed.
- [References] Reference [34] is published in a venue described as 'Distributed Learning and Broad Applications in Scientific Research,' which may not meet the stated peer-review inclusion criterion; this should be verified.
Circularity Check
No significant circularity: the paper is a literature review whose conclusions are summaries of external cited studies; the authors' self-citations are contextual and not load-bearing.
full rationale
This paper is a systematic literature review, not a derivation-based study. It contains no equations, no fitted parameters, and no quantity that is defined in terms of the result it is said to predict. Its central claims—that inadequate encryption, weak authentication, and irregular firmware updates are key vulnerability causes, and that machine learning, blockchain, and edge computing are promising mitigations—are presented as syntheses of the cited literature (e.g., [16], [17], [18], [25], [27], [30], [31]). Quantitative statements such as 'over 70% of IoMT devices currently in use are vulnerable' and the success-rate ranges in Section 3.4 are attributed to external references ([32]; [16], [25], [31]; [27], [30]; [17], [24], [28]). Whether those numbers accurately reflect the cited sources is a correctness or reporting-quality concern, not a circularity concern, because the numbers are not generated by the present paper's own methods. The authors do cite their own prior work ([8], [20], [22]), but these citations support background statements about seizure-detection architecture, botnet-based DDoS, and the CIA triad, respectively; none of these self-citations is load-bearing for the paper's main conclusions. No step in the paper reduces to its own inputs by construction, and no fitted input is renamed as a prediction. Therefore the appropriate circularity score is 0.
Assumptions & free parameters
assumptions (2)
- domain assumption The cited primary studies accurately report IoMT vulnerabilities and mitigation effectiveness.
- domain assumption The search and screening process produced a representative set of IoMT security literature.
Cite this review
Pith. "Pith review of A Review on the Security Vulnerabilities of the IoMT against Malware Attacks and DDoS." pith.science (2026). https://pith.science/paper/NO6XNZGB
@misc{pith2026250107703,
author = {Pith},
title = {Pith review of: A Review on the Security Vulnerabilities of the IoMT against Malware Attacks and DDoS},
year = {2026},
howpublished = {\url{https://pith.science/paper/NO6XNZGB}},
note = {Machine review of arXiv:2501.07703}
}
read the original abstract
The Internet of Medical Things (IoMT) has transformed the healthcare industry by connecting medical devices in monitoring treatment outcomes of patients. This increased connectivity has resulted to significant security vulnerabilities in the case of malware and Distributed Denial of Service (DDoS) attacks. This literature review examines the vulnerabilities of IoMT devices, focusing on critical threats and exploring mitigation strategies. We conducted a comprehensive search across leading databases such as ACM Digital Library, IEEE Xplore, and Elsevier to analyze peer-reviewed studies published within the last five years (from 2019 to 2024). The review shows that inadequate encryption protocols, weak authentication methods, and irregular firmware updates are the main causes of risks associated with IoMT devices. We have identified emerging solutions like machine learning algorithms, blockchain technology, and edge computing as promising approaches to enhance IoMT security. This review emphasizes the pressing need to develop lightweight security measures and standardized protocols to protect patient data and ensure the integrity of healthcare services.
Figures
Figures from the paper (3 more)
Forward citations
Cited by 1 Pith paper
-
Extreme Learning Machine Based System for DDoS Attacks Detections on IoMT Devices
An extreme learning machine classifier obtained roughly 95% accuracy detecting DDoS attacks in the CICIoMT2024 IoMT dataset, but the evaluation may leak test information during feature selection and the low-cost claim...
Reference graph
Works this paper leans on
-
[32]
M. Elhoseny, N. N. Thilakarathne, M. I. Alghamdi, R. K. Mahendran, A. A. Gardezi, H. Weerasinghe, and A. Welhenge, “Security and privacy issues in medical internet of things: overview, countermea- sures, challenges and future directions,”Sustainability, vol. 13, no. 21, p. 11645, 2021
work page 2021
-
[1]
A compre- hensive review of the state-of-the-art on security and privacy issues in healthcare,
A. L ´opez Mart´ınez, M. Gil P ´erez, and A. Ruiz-Mart´ınez, “A compre- hensive review of the state-of-the-art on security and privacy issues in healthcare,” ACM Computing Surveys , vol. 55, no. 12, pp. 1–38, 2023
work page 2023
-
[2]
Internet of things in smart and intelli- gent healthcare systems,
A. K. Nair and J. Sahoo, “Internet of things in smart and intelli- gent healthcare systems,” in Intelligent Internet of Things for Smart Healthcare Systems, pp. 1–19, CRC Press, 2023
work page 2023
-
[3]
Healthcare 4.0: An insight of architecture, security requirements, pillars and applications,
D. Bajaj, B. Bhushan, and D. Yadav, “Healthcare 4.0: An insight of architecture, security requirements, pillars and applications,” Biomed- ical data mining for information retrieval: Methodologies, techniques and applications, pp. 103–129, 2021
work page 2021
-
[4]
G. J. Joyia, R. M. Liaqat, A. Farooq, and S. Rehman, “Internet of medical things (iomt): Applications, benefits and future challenges in healthcare domain.,” J. Commun., vol. 12, no. 4, pp. 240–247, 2017
work page 2017
-
[5]
Recent advances in the internet-of-medical-things (iomt) systems security,
A. Ghubaish, T. Salman, M. Zolanvari, D. Unal, A. Al-Ali, and R. Jain, “Recent advances in the internet-of-medical-things (iomt) systems security,” IEEE Internet of Things Journal , vol. 8, no. 11, pp. 8707–8718, 2020
work page 2020
-
[6]
S. Rani, A. Kataria, S. Kumar, and P. Tiwari, “Federated learning for secure iomt-applications in smart healthcare systems: A comprehen- sive review,” Knowledge-based systems, vol. 274, p. 110658, 2023
work page 2023
-
[7]
Security and privacy management in internet of medical things (iomt): A synthesis,
R. Hireche, H. Mansouri, and A.-S. K. Pathan, “Security and privacy management in internet of medical things (iomt): A synthesis,” Jour- nal of cybersecurity and privacy , vol. 2, no. 3, pp. 640–661, 2022
work page 2022
Show all 35 references
-
[8]
Machine learning based iot adaptive architecture for epilepsy seizure detection: Anatomy and analysis,
Z. ElSayed, M. Ozer, N. Elsayed, and A. Abdelgawad, “Machine learning based iot adaptive architecture for epilepsy seizure detection: Anatomy and analysis,” arXiv preprint arXiv:2305.19347 , 2023
2023 arXiv
-
[9]
Lightweight encryption technique to enhance medical image security on internet of medical things applications,
M. K. Hasan, S. Islam, R. Sulaiman, S. Khan, A.-H. A. Hashim, S. Habib, M. Islam, S. Alyahya, M. M. Ahmed, S. Kamil, et al. , “Lightweight encryption technique to enhance medical image security on internet of medical things applications,” IEEE Access , vol. 9, pp. 47731–47742, 2021
2021
-
[10]
Container-based virtualization for blue- tooth low energy sensor devices in internet of things applications,
D. Tas ¸kin, C. Tas ¸kin,et al., “Container-based virtualization for blue- tooth low energy sensor devices in internet of things applications,” Tehniˇcki vjesnik, vol. 28, no. 1, pp. 13–19, 2021
2021
-
[11]
Security in iomt communications: A survey,
D. Koutras, G. Stergiopoulos, T. Dasaklis, P. Kotzanikolaou, D. Gly- nos, and C. Douligeris, “Security in iomt communications: A survey,” Sensors, vol. 20, no. 17, p. 4828, 2020
2020
-
[12]
Intelligence in the internet of medical things era: A systematic review of current and future trends,
F. Al-Turjman, M. H. Nawaz, and U. D. Ulusar, “Intelligence in the internet of medical things era: A systematic review of current and future trends,” Computer Communications , vol. 150, pp. 644–660, 2020
2020
-
[13]
A secure and efficient cloud-centric internet-of-medical-things-enabled smart healthcare system with pub- lic verifiability,
M. Kumar and S. Chand, “A secure and efficient cloud-centric internet-of-medical-things-enabled smart healthcare system with pub- lic verifiability,” IEEE Internet of Things Journal , vol. 7, no. 10, pp. 10650–10659, 2020
2020
-
[14]
Review of security and privacy for the internet of medical things (iomt),
G. Hatzivasilis, O. Soultatos, S. Ioannidis, C. Verikoukis, G. Demetriou, and C. Tsatsoulis, “Review of security and privacy for the internet of medical things (iomt),” in 2019 15th international conference on distributed computing in sensor systems (DCOSS) , pp. 457–464, IEEE, 2019
2019
-
[15]
Potential of internet of medical things (iomt) applications in building a smart healthcare sys- tem: A systematic review,
R. Dwivedi, D. Mehrotra, and S. Chandra, “Potential of internet of medical things (iomt) applications in building a smart healthcare sys- tem: A systematic review,” Journal of oral biology and craniofacial research, vol. 12, no. 2, pp. 302–318, 2022
2022
-
[16]
A survey on security threats and countermeasures in internet of medical things (iomt),
M. Papaioannou, M. Karageorgou, G. Mantas, V . Sucasas, I. Essop, J. Rodriguez, and D. Lymberopoulos, “A survey on security threats and countermeasures in internet of medical things (iomt),” Transac- tions on Emerging Telecommunications Technologies , vol. 33, no. 6, p. e4049, 2022
2022
-
[17]
Covid-19: Secure healthcare internet of things net- works, current trends and challenges with future research directions,
M. Adil, J. Ali, M. M. Jadoon, S. R. Alotaibi, N. Kumar, A. Farouk, and H. Song, “Covid-19: Secure healthcare internet of things net- works, current trends and challenges with future research directions,” ACM Transactions on Sensor Networks , vol. 19, no. 3, pp. 1–25, 2023
2023
-
[18]
The landscape of cyberse- curity vulnerabilities and challenges in healthcare: Security standards and paradigm shift recommendations,
K. Kioskli, T. Fotis, and H. Mouratidis, “The landscape of cyberse- curity vulnerabilities and challenges in healthcare: Security standards and paradigm shift recommendations,” in Proceedings of the 16th International Conference on Availability, Reliability and Security , pp. ...
2021
-
[19]
Feature engineering based per- formance analysis of ml and dl algorithms for botnet attack detection in iomt,
S. Saif, N. Yasmin, and S. Biswas, “Feature engineering based per- formance analysis of ml and dl algorithms for botnet attack detection in iomt,” International Journal of System Assurance Engineering and Management, vol. 14, no. Suppl 1, pp. 512–522, 2023
2023
-
[20]
Iot botnet detection using an economic deep learning model,
N. Elsayed, Z. ElSayed, and M. Bayoumi, “Iot botnet detection using an economic deep learning model,” in 2023 IEEE World AI IoT Congress (AIIoT), pp. 0134–0142, IEEE, 2023
2023
-
[21]
Dos/ddos detec- tion for e-healthcare in internet of things,
I. ul Sami, M. B. Ahmad, M. Asif, and R. Ullah, “Dos/ddos detec- tion for e-healthcare in internet of things,” International Journal of Advanced Computer Science and Applications , vol. 9, no. 1, 2018
2018
-
[22]
A deep lstm based approach for intrusion detection iot devices network in smart home,
S. W. Azumah, N. Elsayed, V . Adewopo, Z. S. Zaghloul, and C. Li, “A deep lstm based approach for intrusion detection iot devices network in smart home,” in 2021 IEEE 7th World Forum on Internet of Things (WF-IoT), pp. 836–841, IEEE, 2021
2021
-
[23]
A statistical approach to secure health care services from ddos attacks during covid-19 pandemic,
Z. Zhou, A. Gaurav, B. Gupta, H. Hamdi, and N. Nedjah, “A statistical approach to secure health care services from ddos attacks during covid-19 pandemic,” Neural Computing and Applications , pp. 1–14, 2024
2024
-
[24]
Internet of medical things (iomt) security and privacy: A survey of recent advances and enabling technologies,
A. Saxena and S. Mittal, “Internet of medical things (iomt) security and privacy: A survey of recent advances and enabling technologies,” in Proceedings of the 2022 Fourteenth International Conference on Contemporary Computing, pp. 550–559, 2022
2022
-
[25]
Backm-eha: A novel blockchain-enabled security solution for iomt-based e-healthcare applications,
M. Wazid and P. Gope, “Backm-eha: A novel blockchain-enabled security solution for iomt-based e-healthcare applications,” ACM Transactions on Internet Technology, vol. 23, no. 3, pp. 1–28, 2023
2023
-
[26]
Risk assessment and classification of medical device software for the internet of medical things: Challenges arising from connected, intelligent medical devices,
I. Brass and A. Mkwashi, “Risk assessment and classification of medical device software for the internet of medical things: Challenges arising from connected, intelligent medical devices,” in Proceedings of the 12th International Conference on the Internet of Things , pp. 171–...
2022
-
[27]
Ddos attacks detection in ‘internet of medical things’ using machine learning techniques,
N. T. Bhutia, H. Verma, N. Chauhan, and L. K. Awasthi, “Ddos attacks detection in ‘internet of medical things’ using machine learning techniques,” in 2022 IEEE Conference on Interdisciplinary Approaches in Technology and Management for Social Innovation (IATMSI), pp. 1–6, IEEE, 2022
2022
-
[28]
Iot healthcare: Benefits, issues and challenges,
R. De Michele and M. Furini, “Iot healthcare: Benefits, issues and challenges,” in Proceedings of the 5th EAI international conference on smart objects and technologies for social good, pp. 160–164, 2019
2019
-
[29]
A systematic review of security and privacy issues in the internet of medical things; the role of machine learning approaches,
S. S. Hameed, W. H. Hassan, L. A. Latiff, and F. Ghabban, “A systematic review of security and privacy issues in the internet of medical things; the role of machine learning approaches,” PeerJ Computer Science, vol. 7, p. e414, 2021
2021
-
[30]
Internet of things: A survey on machine learning- based intrusion detection approaches,
K. A. Da Costa, J. P. Papa, C. O. Lisboa, R. Munoz, and V . H. C. de Albuquerque, “Internet of things: A survey on machine learning- based intrusion detection approaches,” Computer Networks, vol. 151, pp. 147–157, 2019
2019
-
[31]
An approach towards the security management for sensitive medical data in the iomt ecosystem,
P. Chatterjee, D. Das, S. Banerjee, U. Ghosh, A. B. Mpembele, and T. Rogers, “An approach towards the security management for sensitive medical data in the iomt ecosystem,” in Proceedings of the Twenty-fourth International Symposium on Theory, Algorithmic Foundations, and Prot...
2023
-
[33]
Cybersecurity in healthcare: a review of recent attacks and mitigation strategies,
E. A. Al-Qarni, “Cybersecurity in healthcare: a review of recent attacks and mitigation strategies,” International Journal of Advanced Computer Science and Applications , vol. 14, no. 5, 2023
2023
-
[34]
Lever- aging artificial intelligence for enhanced threat detection, response, and anomaly identification in resource-constrained iot networks,
L. Gudala, M. Shaik, S. Venkataramanan, and A. K. R. Sadhu, “Lever- aging artificial intelligence for enhanced threat detection, response, and anomaly identification in resource-constrained iot networks,” Distributed Learning and Broad Applications in Scientific Research , vol...
2019
-
[35]
Security vulnerabilities in existing security mechanisms for iomt and potential solutions for mitigating cyber-attacks,
M. Rahman and H. Jahankhani, “Security vulnerabilities in existing security mechanisms for iomt and potential solutions for mitigating cyber-attacks,” Information security technologies for controlling pan- demics, pp. 307–334, 2021
2021
Reviewed August 10, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.