Earticle

현재 위치 Home

IoMT 환경에서 네트워크·생체 Feature 기반 AI 침입탐지 체계 : 이중 XAI 분석과 통계 검증 중심으로
An AI-Based Intrusion Detection System Using Network and Biomedical Features in IoMT Environments: Focusing on Dual XAI Analysis and Statistical Validation

첫 페이지 보기
  • 발행기관
    한국EA학회 바로가기
  • 간행물
    정보화연구 KCI 등재 바로가기
  • 통권
    제23권 2호 (2026.06)바로가기
  • 페이지
    pp.189-199
  • 저자
    임동성
  • 언어
    한국어(KOR)
  • URL
    https://www.earticle.net/Article/A486903

※ 기관로그인 시 무료 이용이 가능합니다.

4,200원

원문정보

초록

영어
As the Internet of Medical Things environment continues to expand, cyber threats involving network packet manipulation and biomedical data falsification are increasingly emerging. Existing IoMT intrusion detection studies have primarily relied on network features, and even studies applying explainable AI techniques such as SHAP have faced methodological limitations in interpreting feature importance without statistical validation of the results. This study constructs a multiclass intrusion detection system applying XGBoost, Random Forest, and KNN models based on the WUSTL-EHMS-2020 dataset, and proposes a three-tier validation framework comprising Ablation Study, statistical distribution verification, and dual SHAP·LIME XAI analysis. Experimental results demonstrate that XGBoost achieves the highest performance with an F1- score of 0.9548. Ablation Study confirms that integrating biomedical features improves Spoofing detection F1 from 0.7962 to 0.8848, quantifying that the actual contributor to the 25% AUC improvement reported in prior research is biomedical feature synergy in the Spoofing class through multiclass analysis. Furthermore, although SHAP analysis identifies body temperature as a top contributing feature for Spoofing detection, inconsistencies with t-test results and LIME analysis suggest this reflects a confounding variable effect rather than actual discriminative power. The proposed three-tier validation framework serves as a methodological safeguard ensuring XAI reliability, and provides a practical foundation for building explainable and verifiable AIbased intrusion detection monitoring systems in IoMT environments.
한국어
의료 사물인터넷(IoMT)환경의 확산과 함께 네트워크 패킷 조작 및 생체 데이터 위·변조를 통한 사이버 위협이 증가하고 있다. 기존 IoMT 침입탐지 연구는 주로 네트워크 feature에 의존하였으며, 설명 가능한 AI 기법인 SHAP을 적용한 연구도 결과의 통계적 타당성 검증 없이 특징(feature) 중요도를 해석하는 방법론적 한계가 존재하였다. 본 연구는 WUSTL-EHMS-2020 데이터셋을 기반으로 XGBoost, Random Forest, KNN 모델을 적용한 멀티클래스 침입탐지 체계를 구축하고, Ablation Study, 통계적 분포 검증, SHAP·LIME XAI 분석으로 구성된 3중 검증 체계를 제안하였다. 실험 결과, XGBoost가 F1-score 0.9548로 최고 성능을 달성하였다. Ablation Study를 통해 생체 feature 통합 시 Spoofing 탐지 F1이 0.7962에서 0.8848로 향상됨을 확인하였으며, 이는 선행연구에서 보고된 AUC 25% 향상의 실질적 기여자가 Spoofing 클래스에서의 생체 feature 시너지임을 멀티클래스 분석으로 정량화한 것이다. 또한 SHAP 분석에서 Spoofing 탐지에 체온이 상위 기여 feature로 나타났으나, t-검정 및 LIME 분석과 의 불일치는 이것이 실제 판별력이 아닌 교란변수 효과임을 시사하였다. 본 연구에서 제안하는 3중 검증체계는 XAI 결과의 신뢰성을 보장하는 방법론적 안전망으로서 IoMT 환경에서 설명 가능하고 검증 가능한 AI 기반 침입탐지 모니터링 체계 구축을 위한 실용적 기반이 될 수 있다.

목차

요약
Abstract
1. 서론
2. 관련 연구
2.1. IoMT 보안 위협
2.2. IoMT 침입탐지체계 연구 동향
2.3. 선행연구의 한계 및 본 연구의 차별성
3. 데이터셋 및 전처리
3.1. WUSTL-EHMS-2020 데이터셋 개요
3.2. 전처리 파이프라인
3.3. 생체 Feature 공격 유형별 분포 분석
4. 연구 방법론
4.1. 연구 모델 개요
4.3. Ablation Study 실험 설계
4.4. XAI 적용
4.5. 3중 검증 체계 구조
4.6. 평가 지표
5. 실험 결과 및 분석
5.1. AI 모델 성능 결과
5.2. Ablation Study 결과 및 해석
5.3. SHAP 분석 결과 및 통계적 재검증
5.4. LIME 분석 결과
5.5. SHAP·LIME 일치성 분석
6. 결론
REFERENCES

저자

  • 임동성 [ DongSung Im | 오산대학교 컴퓨터소프트웨어과 ] Corresponding Author

참고문헌

자료제공 : 네이버학술정보

간행물 정보

발행기관

  • 발행기관명
    한국EA학회 [한국엔터프라이즈아키텍처학회]
  • 설립연도
    2002
  • 분야
    복합학>과학기술학
  • 소개
    한국EA학회는 전사적 관점의 아키텍처 개념 및 원칙을 국내 민간기업 및 정부기관에 적용 확산시키고, EA 및 관련 분야의 연구, 전문인력의 양성 및 정책적 건의 등을 통해 기업 및 정부기관의 경쟁력 및 생산성을 향상시키고, 우리나라 지식 기반 산업 등의 고도화를 도모하는 것을 목적으로 합니다.

간행물

  • 간행물명
    정보화연구 [정보화연구(구 정보기술아키텍처연구)]
  • 간기
    계간
  • pISSN
    1738-382X
  • 수록기간
    2004~2026
  • 등재여부
    KCI 등재
  • 십진분류
    KDC 325 DDC 658

이 권호 내 다른 논문 / 정보화연구 제23권 2호

    피인용수 : 0(자료제공 : 네이버학술정보)

    함께 이용한 논문 이 논문을 다운로드한 분들이 이용한 다른 논문입니다.

      페이지 저장