The study concluded that hybrid machine learning significantly improves hospital intrusion detection performance compared to traditional systems and should be integrated into larger healthcare datasets for broader scalability across different environments.
Abstract
This research presents a hybrid machine learning-based intrusion detection system for real-time hospital network security. Most hospital security systems still rely on outdated signature-based detection, even though hospital networks are more connected compared to ever and that connectivity carries heavy risks. Cyber threats like DDoS attacks, brute-force attacks, and data theft have become more advanced. but hospitals still make use of techniques that are just unable to keep up with real-time evolving threats or zero-day vulnerabilities. The CIC-IDS2017 dataset was used to carry out research, which comprises more than 216,000 network flow records. The research used a quantitative experimental approach. Random Forest was used as a baseline for comparison, while XGBoost was implemented for supervised multiclass classification and Isolation Forest for anomaly detection. The system was further refined through feature engineering, PCA dimensionality reduction, and calibrated decision thresholds. After carrying out the necessary tests from the datasets needed for the research, results showed that the new hybrid system achieved aggregate F1-score improvement from 0.788 in the existing system to 0.903, while reducing mean detection latency for exfiltration attacks from 48 seconds to under 15 seconds, of which is a great improvement. The developed system also provided real-time monitoring, SHAP explainability, alert management, and downloadable incident reporting through a FastAPI-powered dashboard. The study concluded that hybrid machine learning significantly improves hospital intrusion detection performance compared to traditional systems. Future work should integrate federated learning and larger healthcare datasets for broader scalability across different environments
The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.
Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al.· Information and Software Tec...· 394 citations· ⚡54
This state-of-practice investigation was performed using a literature review followed by a multiple-case study approach and presents how inconsistency between managerial strategies and execution can lead to failure by means of a behavioral framework.
Carmine Giardino, Xiaofeng Wang, P. Abrahamsson· International Conference on...· 175 citations· ⚡19
This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.
Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al.· Empirical Software Engineeri...· 127 citations· ⚡15
It is found that roles of MVPs in startups were not fully aware by entrepreneurs, and entrepreneurs should consider a systematic approach to fully explore the value of MVP, as a multiple facet product (MFP).
Anh Nguyen-Duc, P. Abrahamsson· International Conference on...· 93 citations· ⚡9
It is found that what perceived as biggest challenges by software startups do vary across different life cycle stages, even though its significance decreases when the learning focuses of the startups move from problem to solution and their products mature.
Xiaofeng Wang, Henry Edison, Sohaib Shahid Bajwa et al.· International Conference on...· 62 citations· ⚡6
A comprehensive overview of how enhanced sampling methods are reshaping the field, with a particular focus on the data-driven construction of collective variables, is provided.
Kai Zhu, Enrico Trizio, Jintu Zhang et al.· Chemical Reviews· 58 citations
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduOct 7, 2026
Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.
Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.
MIT News · Artificial Intelligence· news.mit.eduOct 6, 2026