Skip to content

Author

Akib Rahman

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Review Open access 2026

AI-Driven Risk Mitigation and Infrastructure Security Frameworks for Strengthening U.S. Healthcare and Critical Systems: A Conceptual Architecture, Compliance Mapping, and Governance Protocol

Healthcare cybersecurity in the United States has historically operated on a reactive model, addressing breaches and ransomware incidents only after clinical damage has occurred. This paper argues that the proliferation of Internet of Medical Things (IoMT) devices, combined with escalating ransomware activity now causally linked to increased in-hospital mortality, makes this reactive posture untenable. Drawing on the peer-reviewed literature, we propose a three-layer conceptual security architecture consisting of passive telemetry collection, unsupervised machine learning anomaly detection (deep autoencoders for network-flow analysis and Isolation Forest models for behavioral and access-log analysis), and an AI-augmented Security Orchestration, Automation, and Response (SOAR) layer enforcing graduated, reversible containment through a software-defined networking control plane. We map this architecture against the NIST Cybersecurity Framework 2.0, the CISA Cross-Sector Cybersecurity Performance Goals, and the HIPAA Security Rule's technical safeguards. Distinct from prior conceptual work in this space, this paper does not stop at naming the failure modes of AI-driven security; it specifies four concrete governance protocols designed to close them: a staged, statistically bounded retraining protocol to resist data poisoning; an ensemble-diversity and protocol-aware evasion defense; a time-bound Clinical Override Protocol that resolves the false-positive-versus-patient-safety tension left unresolved in prior proposals; and a stratified differential-impact auditing requirement to detect performance disparities across device classes and facility resource levels before they cause harm. We also specify a concrete, reproducible validation pathway using public IoT/IoMT intrusion benchmark datasets as the necessary next step toward empirical certification of this architecture. We conclude that artificial intelligence can materially strengthen healthcare's Detect and Respond capabilities, but only within a governance structure that operationalizes, rather than merely acknowledges, these failure modes as first-order design constraints.

Mantaka Rowshon, Sharmin Sultana, Akib Rahman · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.