A Survey on Security Threats and Mitigation Mechanisms for Smart Hospitals in the 6G Era
Abstract
1. Introduction
2. Architecture of Smart Hospitals in the 6G Edge Network
2.1. Intelligent Sensing Layer
2.2. Intelligent Edge Layer
2.3. Intelligent Control Layer
2.4. Intelligent Application Layer
2.5. Illustrative Practical Deployment Scenarios
2.5.1. Scenario A: Immersive Telesurgery and Remote Support
2.5.2. Scenario B: Real-Time Patient Digital Twins (DTs)
3. Threat Landscape Overview
3.1. Threats to Smart Hospitals in 6G Edge Networks
3.1.1. AI Threats
3.1.2. Network Threats
Computer Network Threats
IoMT Network Threats
3.1.3. Device Threats
Medical Devices Threats
Personal Devices Threats
3.1.4. Human-Centric Threats
4. Mitigation Mechanisms
4.1. Security Mechanisms
4.1.1. Authentication Mechanisms
4.1.2. Access Control
4.1.3. Anomaly Detection (AD)
4.1.4. Security Information and Event Management (SIEM)
4.1.5. Security Orchestration, Automation, and Response (SOAR)
4.1.6. Incident Response Systems (IRSs)
4.2. Privacy-Preserving Technologies
4.2.1. Federated Learning (FL)
4.2.2. Split-FL (SFL)
4.2.3. Compressive (Or Compressed) Sensing (CS)
4.2.4. Differential Privacy (DP)
4.2.5. Homomorphic Encryption (HE)
4.2.6. Secure Multi-Party Computation (SMPC)
4.3. AI Model Hardening for Security Mechanisms and Privacy-Preserving Technologies
4.4. Comparative Analysis and Critical Synthesis
5. Conclusions and Future Research Roadmap
5.1. Conclusions and Critical Insights
5.2. Future Research Roadmap and Open Questions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Shafik, W. Smart Health Revolution: Exploring Artificial Intelligence of Internet of Medical Things. In Healthcare Industry Assessment: Analyzing Risks, Security, and Reliability; Kumar, P., Singh, P., Diwakar, M., Garg, D., Eds.; Springer Nature: Cham, Switzerland, 2024; pp. 201–229. [Google Scholar] [CrossRef]
- Mathkor, D.M.; Mathkor, N.; Bassfar, Z.; Bantun, F.; Slama, P.; Ahmad, F.; Haque, S. Multirole of the internet of medical things (IoMT) in biomedical systems for managing smart healthcare systems: An overview of current and future innovative trends. J. Infect. Public Health 2024, 17, 559–572. [Google Scholar] [CrossRef] [PubMed]
- Kumar, A.; Dhanagopal, R.; Albreem, M.A.; Le, D.-N. A comprehensive study on the role of advanced technologies in 5G based smart hospital. Alex. Eng. J. 2021, 60, 5527–5536. [Google Scholar] [CrossRef]
- Kumar, A.; Masud, M.; Alsharif, M.H.; Gaur, N.; Nanthaamornphong, A. Integrating 6G technology in smart hospitals: Challenges and opportunities for enhanced healthcare services. Front. Med. 2025, 12, 1534551. [Google Scholar] [CrossRef] [PubMed]
- Kaldoudi, E. Smart hospital: The future of healthcare. Comput. Struct. Biotechnol. J. 2024, 24, 87–88. [Google Scholar] [CrossRef] [PubMed]
- Kwon, H.; An, S.; Lee, H.-Y.; Cha, W.C.; Kim, S.; Cho, M.; Kong, H.-J. Review of Smart Hospital Services in Real Healthcare Environments. Healthc. Inform. Res. 2022, 28, 3–15. [Google Scholar] [CrossRef] [PubMed]
- European Network and Information Security Agency. Smart Hospitals: Security and Resilience for Smart Health Service and Infrastructures; Publications Office: Luxembourg, 2016. Available online: https://data.europa.eu/doi/10.2824/28801 (accessed on 2 July 2025).
- Rajaei, O.; Khayami, S.R.; Rezaei, M.S. Smart hospital definition: Academic and industrial perspective. Int. J. Med. Inform. 2024, 182, 105304. [Google Scholar] [CrossRef] [PubMed]
- Stoynov, V.; Poulkov, V.; Valkova-Jarvis, Z.; Iliev, G.; Koleva, P. Ultra-Dense Networks: Taxonomy and Key Performance Indicators. Symmetry 2023, 15, 2. [Google Scholar] [CrossRef]
- Kamel, M.; Hamouda, W.; Youssef, A. Ultra-Dense Networks: A Survey. IEEE Commun. Surv. Tutor. 2016, 18, 2522–2545. [Google Scholar] [CrossRef]
- Konhäuser, W. Digitalization in Buildings and Smart Cities on the Way to 6G. Wirel. Pers. Commun. 2021, 121, 1289–1302. [Google Scholar] [CrossRef]
- Saad, W.; Bennis, M.; Chen, M. A Vision of 6G Wireless Systems: Applications, Trends, Technologies, and Open Research Problems. IEEE Netw. 2020, 34, 134–142. [Google Scholar] [CrossRef]
- Mantas, G.; Saghezchi, F.; Rodriguez, J.; Sucasas, V. Security and Privacy for 6G Massive IoT; Wiley: Hoboken, NJ, USA, 2025. [Google Scholar] [CrossRef]
- Arastouei, N.; Khan, A. 6G Technology in Intelligent Healthcare: Smart Health and Its Security and Privacy Perspectives. IEEE Wirel. Commun. 2025, 32, 116–121. [Google Scholar] [CrossRef]
- Gao, X.; He, P.; Zhou, Y.; Qin, X. Artificial Intelligence Applications in Smart Healthcare: A Survey. Futur. Internet 2024, 16, 308. [Google Scholar] [CrossRef]
- Wang, Y.; Liu, L.; Wang, C. Trends in using deep learning algorithms in biomedical prediction systems. Front. Neurosci. 2023, 17, 1256351. [Google Scholar] [CrossRef] [PubMed]
- Yelne, S.; Chaudhary, M.; Dod, K.; Sayyad, A.; Sharma, R. Harnessing the Power of AI: A Comprehensive Review of Its Impact and Challenges in Nursing Science and Healthcare. Cureus 2023, 15, e49252. [Google Scholar] [CrossRef] [PubMed]
- Porambage, P.; Gur, G.; Osorio, D.P.M.; Liyanage, M.; Gurtov, A.; Ylianttila, M. The Roadmap to 6G Security and Privacy. IEEE Open J. Commun. Soc. 2021, 2, 1094–1122. [Google Scholar] [CrossRef]
- Batista, E.; López-Aguilar, P.; Solanas, A. Smart Health in the 6G Era: Bringing Security to Future Smart Health Services. IEEE Commun. Mag. 2024, 62, 74–80. [Google Scholar] [CrossRef]
- Imoize, A.L.; Adedeji, O.; Tandiya, N.; Shetty, S. 6G Enabled Smart Infrastructure for Sustainable Society: Opportunities, Challenges, and Research Roadmap. Sensors 2021, 21, 1709. [Google Scholar] [CrossRef] [PubMed]
- Siriwardhana, Y.; Porambage, P.; Liyanage, M.; Ylianttila, M. AI and 6G Security: Opportunities and Challenges. In 2021 Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit); IEEE: Porto, Portugal, 2021; pp. 616–621. [Google Scholar] [CrossRef]
- Rancea, A.; Anghel, I.; Cioara, T. Edge Computing in Healthcare: Innovations, Opportunities, and Challenges. Future Internet 2024, 16, 329. [Google Scholar] [CrossRef]
- Alnaim, A.K.; Alwakeel, A.M. Machine-Learning-Based IoT–Edge Computing Healthcare Solutions. Electronics 2023, 12, 1027. [Google Scholar] [CrossRef]
- Rahimi, A.K.; Pienaar, O.; Ghadimi, M.; Canfell, O.J.; Pole, J.D.; Shrapnel, S.; van der Vegt, A.H.; Sullivan, C. Implementing AI in Hospitals to Achieve a Learning Health System: Systematic Review of Current Enablers and Barriers. J. Med. Internet Res. 2024, 26, e49655. [Google Scholar] [CrossRef] [PubMed]
- Varnosfaderani, S.M.; Forouzanfar, M. The Role of AI in Hospitals and Clinics: Transforming Healthcare in the 21st Century. Bioengineering 2024, 11, 337. [Google Scholar] [CrossRef] [PubMed]
- Ismail, L.; Buyya, R. Artificial Intelligence Applications and Self-Learning 6G Networks for Smart Cities Digital Ecosystems: Taxonomy, Challenges, and Future Directions. Sensors 2022, 22, 5750. [Google Scholar] [CrossRef] [PubMed]
- Kuchuk, H.; Malokhvii, E. Integration of IoT with cloud, fog, and edge computing: A review. Adv. Inf. Syst. 2024, 8, 65–78. [Google Scholar] [CrossRef]
- Dang, L.M.; Piran, J.; Han, D.; Min, K.; Moon, H. A Survey on Internet of Things and Cloud Computing for Healthcare. Electronics 2019, 8, 768. [Google Scholar] [CrossRef]
- Uttekar, A.; Pillai, S.; Chirputkar, A.; Iyengar, V. Future of Medicine. In Virtual Reality and Augmented Reality with 6G Communication; John Wiley & Sons, Ltd.: Montreal, QC, Canada, 2025; pp. 373–403. [Google Scholar] [CrossRef]
- Aithal, A. Exploratory Analysis on Computer-Assisted Smart Spine Surgery using AR/VR Technology through Remote Telesurgery via 5G/6G. Poornaprajna Int. J. Basic Appl. Sci. (PIJBAS) 2026, 29, 29–64. [Google Scholar] [CrossRef]
- Haque, M.E.; Tariq, F.; Khandaker, M.R.A.; Hossain, M.S.; Imran, M.A.; Wong, K.-K. A Comprehensive Survey of 5G URLLC and Challenges in the 6G Era. arXiv 2025, arXiv:2508.20205. [Google Scholar] [CrossRef]
- Jameil, A.K.; Al-Raweshidy, H. A digital twin framework for real-time healthcare monitoring: Leveraging AI and secure systems for enhanced patient outcomes. Discov. Internet Things 2025, 5, 37. [Google Scholar] [CrossRef]
- Vallée, A. Digital twin for healthcare systems. Front. Digit. Health 2023, 5, 1253050. [Google Scholar] [CrossRef] [PubMed]
- Sun, T.; He, X.; Li, Z. Digital twin in healthcare: Recent updates and challenges. Digit. Health 2023, 9, 20552076221149651. [Google Scholar] [CrossRef] [PubMed]
- Argaw, S.T.; Troncoso-Pastoriza, J.R.; Lacey, D.; Florin, M.-V.; Calcavecchia, F.; Anderson, D.; Burleson, W.; Vogel, J.-M.; O’leary, C.; Eshaya-Chauvin, B.; et al. Cybersecurity of Hospitals: Discussing the challenges and working towards mitigating the risks. BMC Med. Inform. Decis. Mak. 2020, 20, 146. [Google Scholar] [CrossRef] [PubMed]
- Ali, M.; Naeem, F.; Tariq, M.; Kaddoum, G. Federated Learning for Privacy Preservation in Smart Healthcare Systems: A Comprehensive Survey. IEEE J. Biomed. Health Inform. 2023, 27, 778–789. [Google Scholar] [CrossRef] [PubMed]
- Pelekoudas-Oikonomou, F.; Zachos, G.; Papaioannou, M.; de Ree, M.; Ribeiro, J.C.; Mantas, G.; Rodriguez, J. Blockchain-Based Security Mechanisms for IoMT Edge Networks in IoMT-Based Healthcare Monitoring Systems. Sensors 2022, 22, 2449. [Google Scholar] [CrossRef] [PubMed]
- Kirubavathi, G.; Anne, W.R.; Sridevi, U.K. A recent review of ransomware attacks on healthcare industries. Int. J. Syst. Assur. Eng. Manag. 2024, 15, 5078–5096. [Google Scholar] [CrossRef]
- Mao, B.; Liu, J.; Wu, Y.; Kato, N. Security and Privacy on 6G Network Edge: A Survey. IEEE Commun. Surv. Tutor. 2023, 25, 1095–1127. [Google Scholar] [CrossRef]
- Kalapaaking, A.P.; Stephanie, V.; Khalil, I.; Atiquzzaman, M.; Yi, X.; Almashor, M. SMPC-Based Federated Learning for 6G-Enabled Internet of Medical Things. IEEE Netw. 2022, 36, 182–189. [Google Scholar] [CrossRef]
- Son, B.D.; Hoa, N.T.; Van Chien, T.; Khalid, W.; Ferrag, M.A.; Choi, W.; Debbah, M. Adversarial Attacks and Defenses in 6G Network-Assisted IoT Systems. IEEE Internet Things J. 2024, 11, 19168–19187. [Google Scholar] [CrossRef]
- Bai, L.; Hu, H.; Ye, Q.; Li, H.; Wang, L.; Xu, J. Membership Inference Attacks and Defenses in Federated Learning: A Survey. ACM Comput. Surv. 2024, 57, 89. [Google Scholar] [CrossRef]
- Je, D.; Jung, J.; Choi, S. Toward 6G Security: Technology Trends, Threats, and Solutions. IEEE Commun. Stand. Mag. 2021, 5, 64–71. [Google Scholar] [CrossRef]
- Dong, J.; Chen, J.; Xie, X.; Lai, J.; Chen, H. Survey on Adversarial Attack and Defense for Medical Image Analysis: Methods and Challenges. arXiv 2024, arXiv:2303.14133v2. [Google Scholar]
- Apostolidis, K.D.; Papakostas, G.A. A Survey on Adversarial Deep Learning Robustness in Medical Image Analysis. Electronics 2021, 10, 2132. [Google Scholar] [CrossRef]
- Rauniyar, A.; Hagos, D.H.; Jha, D.; Håkegård, J.E.; Bagci, U.; Rawat, D.B.; Vlassov, V. Federated Learning for Medical Applications: A Taxonomy, Current Trends, Challenges, and Future Research Directions. IEEE Internet Things J. 2024, 11, 7374–7398. [Google Scholar] [CrossRef]
- Oseni, A.; Vamplew, P.; Foale, C.; Naseriparsa, M. Adversarial Robustness in Federated Learning for Safety-Critical Healthcare IoT Systems. TechRxiv 2025. [Google Scholar] [CrossRef] [PubMed]
- Benabderrahmane, F.; Kerkouche, E.; Bouchemal, N. Risk-Aware Privacy-Preserving Federated Learning for Remote Patient Monitoring: A Multi-Layer Adaptive Security Framework. Appl. Sci. 2025, 16, 29. [Google Scholar] [CrossRef]
- Vu, T.-H.; Jagatheesaperumal, S.K.; Nguyen, M.-D.; Van Huynh, N.; Kim, S.; Pham, Q.-V. Applications of Generative AI (GAI) for Mobile and Wireless Networking: A Survey. IEEE Internet Things J. 2025, 12, 1266–1290. [Google Scholar] [CrossRef]
- Alqahtani, A.; Bhatia, M. Digital-Twin-Empowered Cybersecurity Framework for Healthcare Vulnerability Assessment. IEEE Internet Things J. 2026, 13, 23471–23479. [Google Scholar] [CrossRef]
- Chaudhary, S.; Kakkar, R.; Jadav, N.K.; Nair, A.; Gupta, R.; Tanwar, S.; Agrawal, S.; Alshehri, M.D.; Sharma, R.; Sharma, G.; et al. A Taxonomy on Smart Healthcare Technologies: Security Framework, Case Study, and Future Directions. J. Sens. 2022, 2022, 1863838. [Google Scholar] [CrossRef]
- Papaioannou, M.; Karageorgou, M.; Mantas, G.; Sucasas, V.; Essop, I.; Rodriguez, J.; Lymberopoulos, D. A Survey on Security Threats and Countermeasures in Internet of Medical Things (IoMT). Trans. Emerg. Telecommun. Technol. 2022, 33, e4049. [Google Scholar] [CrossRef]
- Rahim, J.; Ibn Rahim, M.I.; Afroz, A.; Akinola, O. Cybersecurity Threats in Healthcare IT: Challenges, Risks, and Mitigation Strategies. J. Artif. Intell. Gen. Sci. (JAIGS) 2024, 6, 438–462. [Google Scholar] [CrossRef]
- He, Y.; Maglaras, L.; Aliyu, A.; Luo, C. Healthcare Security Incident Response Strategy—A Proactive Incident Response (IR) Procedure. Secur. Commun. Netw. 2022, 2022, 2775249. [Google Scholar] [CrossRef]
- ENISA. Checking-Up on Health: Ransomware Accounts for 54% of Cybersecurity Threats. Available online: https://www.enisa.europa.eu/news/checking-up-on-health-ransomware-accounts-for-54-of-cybersecurity-threats (accessed on 19 August 2025).
- Karunarathne, S.M.; Saxena, N.; Khan, M.K. Security and Privacy in IoT Smart Healthcare. IEEE Internet Comput. 2021, 25, 37–48. [Google Scholar] [CrossRef]
- Udugahapattuwa, P.; de Alwis, C.; Zeydan, E.; Wijewardhana, U.; Liyanage, M. Quantum-Resistant Security for Blockchain-Enabled 6G Networks: A Comprehensive Review. IEEE Open J. Commun. Soc. 2026, 7, 3253–3287. [Google Scholar] [CrossRef]
- Rajak, S.; Summaq, A.; Kumar, M.P.; Ghosh, A.; Elumalai, K.; Chinnadurai, S. Revolutionizing Healthcare with 6G: A Deep Dive Into Smart, Connected Systems. IEEE Access 2024, 12, 194150–194170. [Google Scholar] [CrossRef]
- Zhou, J.; Hai, T.; Jawawi, D.N.A.; Wang, D.; Lakshmanna, K.; Maddikunta, P.K.R.; Iwendi, M. A lightweight energy consumption ensemble-based botnet detection model for IoT/6G networks. Sustain. Energy Technol. Assess. 2023, 60, 103454. [Google Scholar] [CrossRef]
- Amirthabai, S.C.; Malhotra, U.; Rajeswari, S.T.; Natesan, S.T. Healthcare security in cloud-based wireless sensor networks: Botnet attack detection via autoencoder-aided goal-based artificial intelligent agent. Concurr. Comput. Pract. Exp. 2024, 36, e8152. [Google Scholar] [CrossRef]
- Ullah, S.; Li, J.; Chen, J.; Ali, I.; Khan, S.; Ahad, A.; Ullah, F.; Leung, V.C.M. A Survey on Emerging Trends and Applications of 5G and 6G to Healthcare Environments. ACM Comput. Surv. 2024, 57, 85. [Google Scholar] [CrossRef]
- Maguluri, D.S.; Velagala, L.P.; Hossain, G. Securing Healthcare 5.0: Exploring BYOD Cyber Risks, Misuse Cases, and Best Practices. In Proceedings of the 2024 12th International Symposium on Digital Forensics and Security (ISDFS), San Antonio, TX, USA, 29–30 April 2024; pp. 1–6. [Google Scholar] [CrossRef]
- Deb, S.; Lupu, E.; Drakakis, E.; Bharath, A.; Leung, Z.; Ma, G.; Chattopadhyay, A. Securing the Internet of Medical Things (IoMT): Real-World Attack Taxonomy and Practical Security Measures. arXiv 2025, arXiv:2507.19609. [Google Scholar] [CrossRef]
- Shah, S.W.; Kanhere, S.S. Recent Trends in User Authentication—A Survey. IEEE Access 2019, 7, 112505–112519. [Google Scholar] [CrossRef]
- Le, T.-V.; Lu, C.-F.; Hsu, C.-L.; Do, T.K.; Chou, Y.-F.; Wei, W.-C. A Novel Three-Factor Authentication Protocol for Multiple Service Providers in 6G-Aided Intelligent Healthcare Systems. IEEE Access 2022, 10, 28975–28990. [Google Scholar] [CrossRef]
- Jebri, S.; Ben Amor, A.; Abid, M.; Bouallegue, A. Data Security and Anonymous Mutual Authentication in 6G/IoT Healthcare System: Emergency Case. In Proceedings of the 2023 International Wireless Communications and Mobile Computing (IWCMC), Marrakesh, Morocco, 19–23 June 2023; pp. 1082–1087. [Google Scholar] [CrossRef]
- Parmar, V.; Sanghvi, H.A.; Patel, R.H.; Pandya, A.S. A Comprehensive Study on Passwordless Authentication. In Proceedings of the 2022 International Conference on Sustainable Computing and Data Communication Systems (ICSCDS), Erode, India, 7–9 April 2022; pp. 1266–1275. [Google Scholar] [CrossRef]
- Al Kabir, M.A.; Elmedany, W. An Overview of the Present and Future of User Authentication. In Proceedings of the 2022 4th IEEE Middle East and North Africa COMMunications Conference (MENACOMM), Erode, India, 7–9 April 2022; pp. 10–17. [Google Scholar] [CrossRef]
- Kazmi, S.H.A.; Hassan, R.; Qamar, F.; Nisar, K.; Ibrahim, A.A.A. Security Concepts in Emerging 6G Communication: Threats, Countermeasures, Authentication Techniques and Research Directions. Symmetry 2023, 15, 1147. [Google Scholar] [CrossRef]
- Sireesha, K.; Amaravathi, P. ROR model based formal security analysis and informal security analysis. Dogo Rangsang Res. J. 2021, 8, 569–574. [Google Scholar]
- Liu, W.; Wang, X.; Peng, W.; Xing, Q. Center-Less Single Sign-On with Privacy-Preserving Remote Biometric-Based ID-MAKA Scheme for Mobile Cloud Computing Services. IEEE Access 2019, 7, 137770–137783. [Google Scholar] [CrossRef]
- Armando, A.; Basin, D.; Boichut, Y.; Chevalier, Y.; Compagna, L.; Cuellar, J.; Drielsma, P.H.; Heám, P.C.; Kouchnarenko, O.; Mantovani, J.; et al. The AVISPA tool for the automated validation of internet security protocols and applications. In Proceedings of the International Conference on Computer Aided Verification, Scotland, UK, 6–10 July 2005; Etessami, K., Rajamani, S.K., Eds.; Springer: Berlin/Heidelberg, Germany, 2005; pp. 281–285. [Google Scholar] [CrossRef]
- Hsu, C.-L.; Le, T.-V.; Hsieh, M.-C.; Tsai, K.-Y.; Lu, C.-F.; Lin, T.-W. Three-Factor UCSSO Scheme with Fast Authentication and Privacy Protection for Telecare Medicine Information Systems. IEEE Access 2020, 8, 196553–196566. [Google Scholar] [CrossRef]
- Hsu, C.-L.; Le, T.-V.; Lu, C.-F.; Lin, T.-W.; Chuang, T.-H. A Privacy-Preserved E2E Authenticated Key Exchange Protocol for Multi-Server Architecture in Edge Computing Networks. IEEE Access 2020, 8, 40791–40808. [Google Scholar] [CrossRef]
- Mahmood, K.; Obaidat, M.S.; Shamshad, S.; Alenazi, M.J.F.; Kumar, G.; Anisi, M.H.; Conti, M. Cost-Effective Authenticated Solution (CAS) for 6G-Enabled Artificial Intelligence of Medical Things (AIoMT). IEEE Internet Things J. 2024, 11, 23977–23984. [Google Scholar] [CrossRef]
- Wazid, M.; Das, A.K.; Kumar, N.; Vasilakos, A.V. Design of secure key management and user authentication scheme for fog computing services. Future Gener. Comput. Syst. 2019, 91, 475–492. [Google Scholar] [CrossRef]
- Zhang, Q.; Xue, X.; Yang, J. Blockchain-Enabled Trustworthy Healthcare Data Sharing Mechanism for Reliable 6G-IoT Networks. IEEE Internet Things J. 2025, 13, 7738–7748. [Google Scholar] [CrossRef]
- Devaraj, P.; Basha, S.A.C.; Santhosh, N.N.P.; Panda, N. A Post-Quantum Secure Architecture for 6G-Enabled Smart Hospitals: A Multi-Layered Cryptographic Framework. Future Internet 2026, 18, 165. [Google Scholar] [CrossRef]
- Son, S.; Kwon, D.; Lee, S.; Kwon, H.; Park, Y. A Zero-Trust Authentication Scheme with Access Control for 6G-Enabled IoT Environments. IEEE Access 2024, 12, 154066–154079. [Google Scholar] [CrossRef]
- Yang, Y.; Zheng, X.; Guo, W.; Liu, X.; Chang, V. Privacy-preserving smart IoT-based healthcare big data storage and self-adaptive access control system. Inf. Sci. 2019, 479, 567–592. [Google Scholar] [CrossRef]
- Chen, X.; Feng, W.; Ge, N.; Zhang, Y. Zero Trust Architecture for 6G Security. IEEE Netw. 2024, 38, 224–232. [Google Scholar] [CrossRef]
- Rose, S.; Borchert, O.; Mitchell, S.; Connelly, S. Zero Trust Architecture; NIST Special Publication 800-207; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2020. [CrossRef]
- Huber, B.; Kandah, F. Zero Trust+: A Trusted-based Zero Trust architecture for IoT at Scale. In Proceedings of the 2024 IEEE International Conference on Consumer Electronics (ICCE), Las Vegas, NV, USA, 5–8 January 2024; pp. 1–6. [Google Scholar] [CrossRef]
- Yao, W.; Zhao, H.; Shi, H. Privacy-Preserving Collaborative Intrusion Detection in Edge of Internet of Things: A Robust and Efficient Deep Generative Learning Approach. IEEE Internet Things J. 2024, 11, 15704–15722. [Google Scholar] [CrossRef]
- Mothukuri, V.; Khare, P.; Parizi, R.M.; Pouriyeh, S.; Dehghantanha, A.; Srivastava, G. Federated-Learning-Based Anomaly Detection for IoT Security Attacks. IEEE Internet Things J. 2022, 9, 2545–2554. [Google Scholar] [CrossRef]
- Gupta, D.; Kayode, O.; Bhatt, S.; Gupta, M.; Tosun, A.S. Hierarchical Federated Learning based Anomaly Detection using Digital Twins for Smart Healthcare. In Proceedings of the 2021 IEEE 7th International Conference on Collaboration and Internet Computing (CIC), Atlanta, GA, USA, 13–15 December 2021; pp. 16–25. [Google Scholar] [CrossRef]
- Tabassum, M.; Mahmood, S.; Bukhari, A.; Alshemaimri, B.; Daud, A.; Khalique, F. Anomaly-based threat detection in smart health using machine learning. BMC Med. Inform. Decis. Mak. 2024, 24, 347. [Google Scholar] [CrossRef] [PubMed]
- Saeed, M.M.; Saeed, R.A.; Abdelhaq, M.; Alsaqour, R.; Hasan, M.K.; Mokhtar, R.A. Anomaly Detection in 6G Networks Using Machine Learning Methods. Electronics 2023, 12, 3300. [Google Scholar] [CrossRef]
- Wu, X.; Yang, Y.; Bilal, M.; Qi, L.; Xu, X. 6G-Enabled Anomaly Detection for Metaverse Healthcare Analytics in Internet of Things. IEEE J. Biomed. Health Inform. 2024, 28, 6308–6317. [Google Scholar] [CrossRef]
- Zachos, G.; Mantas, G.; Porfyrakis, K.; de Bastos, J.M.C.S.; Rodriguez, J. Anomaly-Based Intrusion Detection for IoMT Networks: Design, Implementation, Dataset Generation, and ML Algorithms Evaluation. IEEE Access 2025, 13, 41994–42028. [Google Scholar] [CrossRef]
- Zachos, G.; Mantas, G.; Porfyrakis, K.; Rodriguez, J. Implementing Anomaly-Based Intrusion Detection for Resource-Constrained Devices in IoMT Networks. Sensors 2025, 25, 1216. [Google Scholar] [CrossRef] [PubMed]
- Zachos, G.; Essop, I.; Mantas, G.; Porfyrakis, K.; Ribeiro, J.C.; Rodriguez, J. An Anomaly-Based Intrusion Detection System for Internet of Medical Things Networks. Electronics 2021, 10, 2562. [Google Scholar] [CrossRef]
- Wahed, M.A.; Alzboon, M.S.; Alqaraleh, M.; Halasa, A.; Al-Batah, M.; Bader, A.F. Comprehensive Assessment of Cybersecurity Measures: Evaluating Incident Response, AI Integration, and Emerging Threats. In Proceedings of the 2024 7th International Conference on Internet Applications, Protocols, and Services (NETAPPS), St. Louis, MO, USA, 6–7 November 2024; pp. 1–8. [Google Scholar] [CrossRef]
- González-Granadillo, G.; González-Zarzosa, S.; Diaz, R. Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures. Sensors 2021, 21, 4759. [Google Scholar] [CrossRef] [PubMed]
- Ghoraishi, M.; Siddiqui, M.S.; Compastié, M.; Mhiri, S.; Ntanos, C.; Kontoulis, M.; Lopez, D.R.; Lioy, A.; Markakis, E.; Baskaran, S.B.M. iTrust6G: Zero-Trust Security for 6G Networks. In Proceedings of the 2024 IEEE Future Networks World Forum (FNWF), Dubai, United Arab Emirates, 15–17 October 2024; pp. 411–416. [Google Scholar] [CrossRef]
- Kinyua, J.; Awuah, L. AI/ML in Security Orchestration, Automation and Response: Future Research Directions. Intell. Autom. Soft Comput. 2021, 28, 527–545. [Google Scholar] [CrossRef]
- Lee, M.; Jang-Jaccard, J.; Kwak, J. Novel Architecture of Security Orchestration, Automation and Response in Internet of Blended Environment. Comput. Mater. Contin. 2022, 73, 199–223. [Google Scholar] [CrossRef]
- Islam, C.; Babar, M.A.; Nepal, S. A Multi-Vocal Review of Security Orchestration. ACM Comput. Surv. 2019, 52, 37. [Google Scholar] [CrossRef]
- Ahmadi-Assalemi, G.; Al-Khateeb, H.; Epiphaniou, G.; Maple, C. Cyber Resilience and Incident Response in Smart Cities: A Systematic Literature Review. Smart Cities 2020, 3, 894–927. [Google Scholar] [CrossRef]
- Rahman, A.; Hossain, S.; Muhammad, G.; Kundu, D.; Debnath, T.; Rahman, M.; Khan, S.I.; Tiwari, P.; Band, S.S. Federated learning-based AI approaches in smart healthcare: Concepts, taxonomies, challenges and open issues. Clust. Comput. 2023, 26, 2271–2311. [Google Scholar] [CrossRef] [PubMed]
- Ahmed, S.T.; Kumar, V.V.; Singh, K.K.; Singh, A.; Muthukumaran, V.; Gupta, D. 6G enabled federated learning for secure IoMT resource recommendation and propagation analysis. Comput. Electr. Eng. 2022, 102, 108210. [Google Scholar] [CrossRef]
- Abdulrahman, S.; Tout, H.; Ould-Slimane, H.; Mourad, A.; Talhi, C.; Guizani, M. A Survey on Federated Learning: The Journey From Centralized to Distributed On-Site Learning and Beyond. IEEE Internet Things J. 2021, 8, 5476–5497. [Google Scholar] [CrossRef]
- Ferrag, M.A.; Friha, O.; Kantarci, B.; Tihanyi, N.; Cordeiro, L.; Debbah, M.; Hamouda, D.; Al-Hawawreh, M.; Choo, K.-K.R. Edge Learning for 6G-Enabled Internet of Things: A Comprehensive Survey of Vulnerabilities, Datasets, and Defenses. IEEE Commun. Surv. Tutor. 2023, 25, 2654–2713. [Google Scholar] [CrossRef]
- Saraswat, D.; Bhattacharya, P.; Verma, A.; Prasad, V.K.; Tanwar, S.; Sharma, G.; Bokoro, P.N.; Sharma, R. Explainable AI for Healthcare 5.0: Opportunities and Challenges. IEEE Access 2022, 10, 84486–84517. [Google Scholar] [CrossRef]
- Blika, A.; Palmos, S.; Doukas, G.; Lamprou, V.; Pelekis, S.; Kontoulis, M.; Ntanos, C.; Askounis, D. Federated Learning for Enhanced Cybersecurity and Trustworthiness in 5G and 6G Networks: A Comprehensive Survey. IEEE Open J. Commun. Soc. 2025, 6, 3094–3130. [Google Scholar] [CrossRef]
- Chaddad, A.; Wu, Y.; Desrosiers, C. Federated Learning for Healthcare Applications. IEEE Internet Things J. 2024, 11, 7339–7358. [Google Scholar] [CrossRef]
- Nguyen, D.C.; Ding, M.; Pathirana, P.N.; Seneviratne, A.; Li, J.; Poor, H.V. Federated Learning for Internet of Things: A Comprehensive Survey. IEEE Commun. Surv. Tutor. 2021, 23, 1622–1658. [Google Scholar] [CrossRef]
- Nguyen, D.C.; Pham, Q.-V.; Pathirana, P.N.; Ding, M.; Seneviratne, A.; Lin, Z.; Dobre, O.; Hwang, W.-J. Federated Learning for Smart Healthcare: A Survey. ACM Comput. Surv. 2022, 55, 60. [Google Scholar] [CrossRef]
- Bashir, A.K.; Victor, N.; Bhattacharya, S.; Huynh-The, T.; Chengoden, R.; Yenduri, G.; Maddikunta, P.K.R.; Pham, Q.-V.; Gadekallu, T.R.; Liyanage, M. Federated Learning for the Healthcare Metaverse: Concepts, Applications, Challenges, and Future Directions. IEEE Internet Things J. 2023, 10, 21873–21891. [Google Scholar] [CrossRef]
- Thapa, C.; Arachchige, P.C.M.; Camtepe, S.; Sun, L. SplitFed: When Federated Learning Meets Split Learning. Proc. AAAI Conf. Artif. Intell. 2022, 36, 8485–8493. [Google Scholar] [CrossRef]
- Hafi, H.; Brik, B.; Frangoudis, P.A.; Ksentini, A.; Bagaa, M. Split Federated Learning for 6G Enabled-Networks: Requirements, Challenges, and Future Directions. IEEE Access 2024, 12, 9890–9930. [Google Scholar] [CrossRef]
- Djelouat, H.; Amira, A.; Bensaali, F. Compressive Sensing-Based IoT Applications: A Review. J. Sens. Actuator Netw. 2018, 7, 45. [Google Scholar] [CrossRef]
- Zhang, Y.; Huang, H.; Yang, L.-X.; Xiang, Y.; Li, M. Serious Challenges and Potential Solutions for the Industrial Internet of Things with Edge Intelligence. IEEE Netw. 2019, 33, 41–45. [Google Scholar] [CrossRef]
- Zhang, Y.; He, Q.; Xiang, Y.; Zhang, L.Y.; Liu, B.; Chen, J.; Xie, Y. Low-Cost and Confidentiality-Preserving Data Acquisition for Internet of Multimedia Things. IEEE Internet Things J. 2018, 5, 3442–3451. [Google Scholar] [CrossRef]
- Gao, Z.; Ke, M.; Mei, Y.; Qiao, L.; Chen, S.; Ng, D.W.K.; Poor, H.V. Compressive-Sensing-Based Grant-Free Massive Access for 6G Massive Communication. IEEE Internet Things J. 2024, 11, 7411–7435. [Google Scholar] [CrossRef]
- Lu, Y.; Zheng, X. 6G: A survey on technologies, scenarios, challenges, and the related issues. J. Ind. Inf. Integr. 2020, 19, 100158. [Google Scholar] [CrossRef]
- Nguyen, V.-L.; Lin, P.-C.; Cheng, B.-C.; Hwang, R.-H.; Lin, Y.-D. Security and Privacy for 6G: A Survey on Prospective Technologies and Challenges. IEEE Commun. Surv. Tutor. 2021, 23, 2384–2428. [Google Scholar] [CrossRef]
- Hassan, M.U.; Rehmani, M.H.; Chen, J. Differential Privacy Techniques for Cyber Physical Systems: A Survey. IEEE Commun. Surv. Tutor. 2020, 22, 746–789. [Google Scholar] [CrossRef]
- Munjal, K.; Bhatia, R. A systematic review of homomorphic encryption and its contributions in healthcare industry. Complex Intell. Syst. 2023, 9, 3759–3786. [Google Scholar] [CrossRef] [PubMed]
- Li, S.; Zhao, S.; Min, G.; Qi, L.; Liu, G. Lightweight Privacy-Preserving Scheme Using Homomorphic Encryption in Industrial Internet of Things. IEEE Internet Things J. 2022, 9, 14542–14550. [Google Scholar] [CrossRef]
- Alloghani, M.; Alani, M.M.; Al-Jumeily, D.; Baker, T.; Mustafina, J.; Hussain, A.; Aljaaf, A.J. A systematic review on the status and progress of homomorphic encryption technologies. J. Inf. Secur. Appl. 2019, 48, 102362. [Google Scholar] [CrossRef]
- Li, D.; Liao, X.; Xiang, T.; Wu, J.; Le, J. Privacy-preserving self-serviced medical diagnosis scheme based on secure multi-party computation. Comput. Secur. 2020, 90, 101701. [Google Scholar] [CrossRef]
- Knott, B.; Venkataraman, S.; Hannun, A.; Sengupta, S.; Ibrahim, M.; van der Maaten, L. CrypTen: Secure Multi-Party Computation Meets Machine Learning. In Advances in Neural Information Processing Systems; Curran Associates, Inc.: New York, NY, USA, 2021; pp. 4961–4973. Available online: https://proceedings.neurips.cc/paper/2021/hash/2754518221cfbc8d25c13a06a4cb8421-Abstract.html (accessed on 31 August 2025).
- Zhao, C.; Zhao, S.; Zhao, M.; Chen, Z.; Gao, C.-Z.; Li, H.; Tan, Y.-A. Secure Multi-Party Computation: Theory, practice and applications. Inf. Sci. 2019, 476, 357–372. [Google Scholar] [CrossRef]
- Udechukwu, L.M.; Oladoyinbo, T.O.; Mayeke, N.R.; Adesokan-Imran, T.O.; Olasege, R.O. AI-Driven Adversarial Defense Framework with Generative Adversarial Network for Secure Healthcare IoT Ecosystems. Arch. Curr. Res. Int. 2025, 25, 148–165. [Google Scholar] [CrossRef]
- Zhang, C.; Yu, S.; Tian, Z.; Yu, J.J.Q. Generative Adversarial Networks: A Survey on Attack and Defense Perspective. ACM Comput. Surv. 2023, 56, 91. [Google Scholar] [CrossRef]
- Wang, H.; Zou, G.; Cao, K.; Cui, Y.; Wei, T.; Hu, S. An Elastic Federated Learning Collaboration Framework for Computing-Constrained IoT. IEEE Trans. Comput. Des. Integr. Circuits Syst. 2026, 45, 1197–1210. [Google Scholar] [CrossRef]
- Sultana, K.; Ahmed, K.; Gu, B.; Wang, H. Elastic Optimization for Stragglers in Edge Federated Learning. Big Data Min. Anal. 2023, 6, 404–420. [Google Scholar] [CrossRef]



| Threat | Target | Primary Attack Vector | Compromised Security Goal(s) | |||||
|---|---|---|---|---|---|---|---|---|
| AI | Network | Devices | Human-Centric | |||||
| Computer | IoMT | Medical | Personal | |||||
| Poisoning (Data injection, Data manipulation, Logic corruption) | ✓ | Malicious Data/Code Injection (Training Phase) | Integrity, Availability | |||||
| Membership (& Reverse) inference | ✓ | Statistical Query Analysis | Confidentiality | |||||
| Model inference (Model Extraction, Model Inversion) | ✓ | API Querying/Output Analysis | Confidentiality | |||||
| Evasion | ✓ | Adversarial Sample Generation (Inference Phase) | Integrity | |||||
| Brute Force | ✓ | Automated Credential Guessing | Confidentiality, Authenticity | |||||
| Routing | ✓ | Network Path Manipulation/Misdirection | Availability, Integrity | |||||
| SQL Injection | ✓ | Database Query Manipulation | Confidentiality, Integrity | |||||
| Byzantine | ✓ | ✓ | Malicious Node Coordination/False Data Injection | Integrity, Availability | ||||
| Shilling | ✓ | ✓ | Fake Profile/Malicious Rating Generation | Integrity | ||||
| Desynchronization | ✓ | ✓ | Timing/Synchronization Protocol Disruption | Availability, Integrity | ||||
| Node Injection | ✓ | ✓ | Unauthorized Device Addition to Network | Authenticity, Integrity | ||||
| Node Subversion | ✓ | ✓ | Device Compromise/Takeover | Confidentiality, Integrity, Availability | ||||
| Sybil | ✓ | ✓ | Forged Identity/Multiple Node Generation | Authenticity, Integrity | ||||
| XSS | ✓ | ✓ | Malicious Script Injection (Application Layer) | Confidentiality, Integrity | ||||
| Cookie Manipulation | ✓ | ✕ | Session Data Alteration | Authenticity, Confidentiality | ||||
| Malware (Ransomware, trojans, spyware, viruses) | ✓ | ✓ | ✕ | ✕ | Malicious Payload Execution | Confidentiality, Integrity, Availability | ||
| DoS (Wormhole, Blackhole, Collision, Congestion, Overwhelm, Amplification, HELLO flood, Jamming) | ✓ | ✓ | ✕ | ✕ | Volumetric Traffic Flooding/Signal Interference | Availability | ||
| Impersonation | ✓ | ✓ | ✕ | Identity Theft/Credential Reuse | Authenticity, Confidentiality | |||
| Masquerading | ✓ | ✓ | ✕ | Deceptive Identity Presentation | Authenticity, Integrity | |||
| Forgery (Spoofing (IP/DNS)) | ✓ | ✓ | ✕ | Network Protocol/Packet Falsification | Authenticity, Integrity | |||
| Eavesdropping (Sniffing, MitM (Replay), Traffic Analysis, Session Hijacking (Parallel Session)) | ✓ | ✓ | ✕ | ✕ | ✕ | Wireless Signal/Network Traffic Interception | Confidentiality | |
| DDoS | ✓ | ✕ | Distributed Traffic Overwhelm | Availability | ||||
| IoT-botnet | ✓ | ✕ | Coordinated Malware Execution via Compromised Nodes | Availability, Integrity | ||||
| Battery Drainage | ✓ | ✕ | Resource Exhaustion (Sleep Deprivation Attacks) | Availability | ||||
| Energy Drainage | ✓ | ✕ | Continuous Protocol Polling/Processing Overload | Availability | ||||
| Firmware Modification | ✓ | ✕ | Unauthorized Code Flashing/Overwriting | Integrity, Availability | ||||
| Tampering | ✓ | ✕ | Physical Hardware Manipulation | Integrity, Availability | ||||
| Device Cloning/Replication | ✕ | ✕ | ✓ | ✕ | Hardware or Cryptographic Key Duplication | Authenticity, Integrity | ||
| Key Logger | ✓ | Keystroke Interception (Software or Hardware) | Confidentiality | |||||
| Phishing | ✓ | Social Engineering/Psychological Manipulation | Confidentiality, Authenticity | |||||
| Digital Twin Manipulation | ✓ | ✕ | ✕ | ✕ | Real-Time Data Alteration/Synchronization Disruption | Integrity, Availability | ||
| Generative AI Exploitation | ✓ | ✕ | ✓ | Automated Vulnerability Probing/Synthetic Data Generation | Confidentiality, Integrity, Authenticity | |||
| Quantum-enabled cryptanalytic attacks | ✕ | ✓ | ✓ | ✓ | ✕ | ✕ | Cryptographic key | Confidentiality, Integrity, Authenticity |
| Mechanism | Computational Cost | Communication Cost | Security Strength | Strengths | Weaknesses | 6G Edge Adaptability |
|---|---|---|---|---|---|---|
| Authentication | Low | Low | High | Fast, secure, prevents unauthorized access; lightweight variations exist for edge devices. | Traditional methods struggle with heterogeneous devices; blockchain-based authentication demands high consensus overhead. | High. Crucial for seamless multi-connectivity and distributed edge environments. |
| Access Control | Moderate | Moderate | High | Facilitates dynamic, cross-domain sharing; zero-trust eliminates lateral threat movement. | Traditional ZTA lacks rapid scalability; complex policy management in high-demand environments. | High. Software-defined and smart contract-based access fits the distributed 6G topology well. |
| AD | Low | Low | High | Highly effective at detecting zero-day and novel attacks; handles infinite data streams. | Requires constant model updating; vulnerable to adversarial ML attacks; high false-positive rates if unoptimized. | Very High. Can be embedded directly within the edge layer for real-time protection. |
| SIEM | High | High | Moderate | Centralizes event collection and correlation; provides compliance reporting and threat dashboards. | Constrained response intelligence; high reliance on manual intervention; struggles with legacy IoMT logs. | Moderate. Requires integration with decentralized AI to handle the massive data volume of 6G networks. |
| SOAR | High | High | Moderate | Automates the incident lifecycle; heavily reduces SOC workload; adapts to BTs. | Fully AI-powered systems are still in their infancy; lacks standardized evaluation metrics. | Moderate. High potential for 6G orchestration, but requires further maturity to handle edge-speed automated responses. |
| IRS | Moderate | Moderate | Moderate | Provides a structured framework (Preparation to Recovery); integrates CTI. | Highly reactive unless paired with predictive AI; difficult to execute within the ultra-low latency constraints of 6G. | Moderate. Needs significant tailoring to operate effectively at the latency and distributed nature of 6G. |
| Technology | Computational Cost | Communication Cost | Privacy Strength | Strengths | Weaknesses | 6G Edge Adaptability |
|---|---|---|---|---|---|---|
| FL | High | Moderate | High | Keeps raw data local; scalable. | Susceptible to data poisoning and free-rider attacks; struggles with heterogeneous datasets. | High. Decentralized nature aligns perfectly with edge computing nodes. |
| SFL | Low | Moderate | High | Reduces client overhead; exposes only cut-layer outputs. | Limited availability of diverse datasets; open questions on global scalability. | High. Effectively balances workloads between resource-constrained IoMT and edge servers. |
| CS | Low | Low | Moderate | Simultaneous acquisition and compression; extends device battery life. | Practical deployment, optimization, and system integration remain open research challenges. | High. A key enabler for privacy-preserving data transmission in distributed environments. |
| DP | Moderate | Low | High | Protects individual records while maintaining overall data utility. | Requires focused investigations for practical edge processing implementation. | Moderate. Needs optimization for real-time IoT. |
| HE | High | High | Very High | Computes directly on encrypted data; mitigates poisoning attacks. | Highly incompatible with low-latency IoMT workflows without edge offloading. | Moderate. Impractical for wearables and requires offloading to edge servers. |
| SMPC | High | High | Very High | Collaborative computation without revealing private inputs. | Complex implementation; introduces significant computational and communication overhead. | Moderate. Highly secure but requires trusted execution environment. |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Maraziotis, O.; Mantas, G.; Rodriguez, J.; Gil-Castiñeira, F. A Survey on Security Threats and Mitigation Mechanisms for Smart Hospitals in the 6G Era. Sensors 2026, 26, 4304. https://doi.org/10.3390/s26134304
Maraziotis O, Mantas G, Rodriguez J, Gil-Castiñeira F. A Survey on Security Threats and Mitigation Mechanisms for Smart Hospitals in the 6G Era. Sensors. 2026; 26(13):4304. https://doi.org/10.3390/s26134304
Chicago/Turabian StyleMaraziotis, Orestis, Georgios Mantas, Jonathan Rodriguez, and Felipe Gil-Castiñeira. 2026. "A Survey on Security Threats and Mitigation Mechanisms for Smart Hospitals in the 6G Era" Sensors 26, no. 13: 4304. https://doi.org/10.3390/s26134304
APA StyleMaraziotis, O., Mantas, G., Rodriguez, J., & Gil-Castiñeira, F. (2026). A Survey on Security Threats and Mitigation Mechanisms for Smart Hospitals in the 6G Era. Sensors, 26(13), 4304. https://doi.org/10.3390/s26134304

