A privacy preserving and trustworthy hybrid deep learning model for zero-day DDoS detection in healthcare industry 5.0
Abstract
Healthcare Industry 5.0 represents a human-centric, intelligent, and resilient healthcare ecosystem by integrating advanced technologies like Software-Defined Networking (SDN), Internet of Things (IoT), and 6G communication with personalized medical services. While this convergence enhances patient care through continuous monitoring, it also increases vulnerability to sophisticated cyberthreats, particularly Zero-Day Distributed Denial of Service (DDoS) attacks. Although Deep Learning (DL) models have demonstrated high accuracy in intrusions detection, but they often lack in interoperability and explainability, making it difficult for security analysts to trust and interpret the output. Moreover, the centralized training raises privacy concern and risks exposing sensitive medical data. To address these challenges, this study proposes a privacy preserving and explainable hybrid deep learning model for Zero-Day DDoS attack detection in Healthcare Industry 5.0 environments. The model integrates Variational Autoencoders (VAE) to recognize spatial key features and Long Short-Term Memory (LSTM) networks to capturing long temporal dependencies in attack patterns. Federated Learning ensures privacy by training locally and aggregated global parameters at the server. SHapley Additive exPlanations (SHAP) enhances transparency and explainability by highlighting key contributing features during the decision-making process. Simulation results reveal the efficacy of the proposed hybrid model on CICDDoS2019 and IoT-healthcare security datasets in terms of standard performance metrics.