Anomaly detection in Internet of Things‑based healthcare using an AUC-optimized proximal SVM with clustering-guided differential evolution for hyperparameter tuning
The Internet of Things (IoT) makes it possible to monitor patients continuously through wearable, networked medical devices. Yet, the healthcare systems built with the use of IoT are extremely susceptible to cyberattacks, including denial-of-service, spoofing, and unauthorized access that generate anomalous and incredibly unbalanced network traffic. There are two significant flaws associated with many deep learning (DL) and machine learning (ML) models of IoT security, including low performance in the presence of a very high-class imbalance and hyperparameter sensitivity. This work proposes an anomaly detection framework based on the imbalanced maximizing area under the curve proximal support vector machine (ImAUC-PSVM) model and the differential evolution (DE) algorithm for effective hyperparameter tuning. The ImAUC-PSVM directly optimizes the AUC metric, which makes it robust to imbalanced traffic without the need for data resampling or cost-sensitive schemes. The DE algorithm is further enhanced by the use of a new mutation strategy that works with k-means clustering to select strong solution groups and guide the search. The proposed model is tested on the NSL-KDD (Network Security Laboratory-Knowledge Discovery in Databases) and MAWI (Measurement and Analysis on the Widely Integrated Distributed Environment Internet) datasets. The experiment findings report an average F-measure of 89.948 and 91.665, respectively. The proposed system produces F-measure values of 89.95% and 91.67% on NSL-KDD and MAWI datasets, which exceed baseline model results while requiring less computational power. The research data proves that the developed model provides efficient anomaly detection for IoT healthcare systems, which enables practical system deployment in actual healthcare environments.