Research team aims to enhance security of medical devices

A team of Virginia Commonwealth University researchers has received support from the National Science Foundation for a project that aims to increase the security of internet-connected medical devices.

Aug 22, 2022

3 min

Tamer Nadeem, Ph.D.Irfan Ahmed, Ph.D.

Tamer Nadeem, Ph.D., the principal investigator of the VCU-based MedKnights project, explained that the project’s focus is on the Internet of Medical Things (IoMT). Nadeem and co-PI Irfan Ahmed, Ph.D., both associate professors in the VCU College of Engineering Department of Computer Science, recently received $600,000 from the NSF’s Office of Advanced Cyberinfrastructure to put together a framework to improve IoMT security.


IoMT devices are used in a range of diagnostic, monitoring and therapeutic applications. IoMT includes patient monitors, ventilators, MRI machines — even “smart beds.” Ahmed cited the internet-connected insulin pump is a good example of an IoMT device. Internet connectivity allows for both monitoring and adjusting the dosage remotely — functions that require a high degree of security for patient privacy as well as safety.


All IoMT devices are potentially vulnerable to ransomware, denial of service and other malicious hacker attacks. Nadeem points out that IoMT devices have a higher security requirement than traditional IoT devices such as smart doorbells and smart thermostats in homes.


“The most important thing in the medical domain is privacy,” Nadeem said. “For IoT devices in your home, you wouldn’t care that much about privacy, but for medical devices, it is an essential thing. You wouldn’t want anyone to know what your health conditions are, or what problems you might have had.”


The work of the MedKnights group is important, as the IoMT domain is expanding; there is growth in terms of types of devices, number of patients using them and number of IoMT vendors. Nadeem added that the COVID pandemic and accompanying quarantine and stay-home orders increased the focus of medical-technology providers on the possibilities of IoMT.


“Talking to some of the medical-device providers, I’ve learned that they are considering a line of products where they can remotely monitor patients on those devices, and they also can configure those devices remotely,” Nadeem said.


Security is a large concern for the new generation of devices, because the current IoMT devices have been hit hard by hackers, he said. Security is an issue that extends from the individual patient to the institution.


“Statistics show there are a lot of ransom attacks being done on the health sectors during the pandemic,” Nadeem said. “That motivated us.”


The MedKnights team’s preparation for taking on the dragon of malicious IoMT attacks includes building a “test bed,” an isolated hardware/software assembly that Nadeem says will mimic the internet-enabled hospital setting.


“In the hospital environment, there’s set of rooms. Each room has a lot of medical devices; they could be wired, or they could be wireless devices,” he said. “But there is no way that we can do what we want to do in a hospital.”


The test bed will incorporate IoMT datasets based on typical device behavior, traffic and known malicious attacks. Nadeem explained that MedKnights will explore vulnerabilities of various IoMT hardware and software by subjecting the elements of the IoMT test bed to a range of attacks.


“We will try to see in real time how efficient our technologies to monitor or detect these attacks, then try to intervene if we notice any change in the activities on the network,” he said. “Now, if the attacks manage to get into the device, we would like to also to start to see whether we can monitor these devices and observe abnormality or any misbehavior.”


Nadeem said the next step is to isolate the source of fishy activity in the test bed network and begin to reverse-engineer the malware. He explained the group will work on understanding the question by looking for the “hole” that created the vulnerability.


Ahmed said the MedKnights will bring undergraduates into the project through DURI, the Dean’s Undergraduate Research Initiative at the VCU College of Engineering. High school students will have an opportunity to join the team through a similar program known as the Dean’s Early Research Initiative, or DERI. DURI and DERI are just two ways of getting younger scientists and engineers involved in actual research.


“For the last couple of years, I’ve been contacted by local high schools to host a couple of their students during the summer,” Nadeem added. “The students were really excited about it. We came up with some nice ideas about how to extend that work to their classrooms. As we continue this project, we will reach out to the schools, because we would love having a couple of their students involved.”

Connect with:
Tamer Nadeem, Ph.D.

Tamer Nadeem, Ph.D.

Professor

Wireless networks, edge/cloud systems, generative AI, cybersecurity, trustworthy AI, AI-enabled health, cyber-physical systems, and cobots.

Cybersecurity and PrivacyWireless NetworksEdge/Cloud ComputingGenerative AITrustworthy AI
Irfan Ahmed, Ph.D.

Irfan Ahmed, Ph.D.

Engineering Foundation Professor

Dr. Ahmed's research interests are broadly in cybersecurity, currently focusing on digital forensics, malware, and cyber-physical systems.

Digital ForensicsMalwareCyber-physical Systems SecuritySystem SecurityCybersecurity Education
Powered by

You might also like...

Check out some other posts from VCU College of Engineering

VCU College of Engineering Dean Azim Eskandarian, D.Sc., named Fellow of The Society of Automotive Engineers International featured image

2 min

VCU College of Engineering Dean Azim Eskandarian, D.Sc., named Fellow of The Society of Automotive Engineers International

Recently named a Fellow of the Society of Automotive Engineers (SAE) International, Azim Eskandarian, D.Sc., the Alice T. and William H. Goodwin Jr. Dean of the Virginia Commonwealth University (VCU) College of Engineering, received one of the organization’s highest honors. The designation recognizes individuals who have made extraordinary and sustained impacts on the mobility industry through technical excellence, leadership, innovation and dedicated service to the profession and to SAE International. “SAE Fellows – whose leadership and technical contributions strengthen our organization embody the highest level of professional achievement,” said Carla Bailo, 2026 SAE International president and chair of the board of directors. “Election to SAE Fellow reflects an individual’s lasting influence on mobility engineering and reinforces the standards of excellence that guide SAE’s strategic direction.” Selected through a comprehensive review process led by the SAE International Fellows Committee and approved by the SAE International Board of Directors, SAE Fellows exemplify the organization’s mission to advance mobility knowledge and solutions for the benefit of humanity. “It is a great honor to receive this distinction from an organization that is so essential to the advancement of the automotive industry,” said Eskandarian. “I hope to continue collaborating with engineers, researchers and other professionals who share a vision for the great work we can do to improve the safety and efficiency of transportation.” Numerous scientific and technical contributions to automotive safety, academic programs, workforce development in crashworthiness, collision avoidance, advanced driver assistance systems, intelligent vehicles, and autonomous driving have stemmed from the more than 40 years of work Eskandarian has pioneered. His research on intelligent and autonomous vehicles includes the development of novel methods for driver safety systems. As an academic leader, Eskandarian’s enduring commitment to education, mentorship and service led him to start impactful academic programs at several universities. This includes robotics and autonomous systems programs and new master’s concentrations at the VCU College of Engineering, a graduate academic program in intelligent transportation systems and an undergraduate concentration in transportation engineering at George Washington University, and an automotive engineering concentration at Virginia Tech. Eskandarian is also a Fellow of two other technical societies, the American Society of Mechanical Engineers (ASME) and the Institute of Electrical and Electronics Engineers (IEEE).

VCU College of Engineering receives $600,000 for AI-driven cybersecurity research featured image

2 min

VCU College of Engineering receives $600,000 for AI-driven cybersecurity research

To advance AI-enabled cybersecurity research, the National Science Foundation (NSF) presented Kemal Akkaya, Ph.D., professor and chair of the Department of Computer Science, with a $600,000 grant through the organization’s Cybersecurity Innovation for Cyberinfrastructure program. Akkaya’s three-year project will explore how large language models (LLMs) can automate packet labeling for intrusion detection systems. “From transportation and healthcare to finance, improving the accuracy of machine learning algorithms used to defend the networks that underpin these sectors’ cyberinfrastructure is critical for protecting them from cyberattacks. Strengthening these defenses helps ensure the reliability and security of the essential services people rely on every day,” said Akkaya. Intrusion detection systems monitor network traffic to identify suspicious or malicious activity. These systems rely on machine learning models trained on large volumes of accurately labeled data. Producing those datasets, however, is time intensive and often requires expert cybersecurity knowledge. As digital systems increasingly power transportation, health care, finance and communication, the volume and sophistication of cyber attacks continue to grow. At the same time, artificial intelligence is reshaping how both attackers and defenders operate. Improving how quickly and accurately security systems can be trained is critical to protecting the infrastructure that supports daily life. Akkaya’s project will investigate how generative AI can help address this challenge. The team will fine tune open-source large language models using network data, threat signatures and expert annotations. Model accuracy will be strengthened through retrieval-augmented refinement, ensemble modeling and human-in-the-loop verification. Labeled datasets will be released in stages to support the development and evaluation of cybersecurity models. Using data from AmLight, an international research and education network operated by Florida International University (FIU), the project includes collaboration with researchers from FIU. The award strengthens VCU’s growing leadership in AI-enabled cybersecurity research and provides hands-on research training for graduate students. Resulting datasets from this work will support machine learning education for undergraduate students.

Director Gennady Miloshevsky, Ph.D., shares his vision for the nuclear program at the VCU College of Engineering featured image

5 min

Director Gennady Miloshevsky, Ph.D., shares his vision for the nuclear program at the VCU College of Engineering

Recently named the nuclear program director at the Virginia Commonwealth University (VCU) College of Engineering, Gennady Miloshevsky, Ph.D., associate professor in the Department of Mechanical & Nuclear Engineering, answers some questions about the direction of VCU Engineering’s nuclear program and what he hopes it can accomplish. What are your top priorities for the nuclear program at the VCU College of Engineering? I want to focus on student development, innovative research and our rankings in best program lists, but that is not everything. Strategy is important. We need to align ourselves with the country’s national energy needs. There are many new developments in the energy sector, like small modular reactors or fusion energy systems, and having the right faculty to engage with these advancements is important. Providing students with a well-rounded education and good opportunities for gaining experience benefits the College of Engineering’s public and private sector partners. Nuclear subject matter is complex, so higher education is very important for workforce development. We want to build partnerships, like the one we have with Dominion Energy, that support this goal. A priority for me is continuing to establish relationships with Commonwealth Fusion Systems, which seeks to build and operate the first commercial grid-scale fusion plant in Chesterfield County, Virginia. Our workforce partners will benefit from VCU’s well-trained nuclear engineering graduates joining the workforce. So, aligning our strategy with national energy needs, hiring the right faculty to support our programs and building industry partnerships that benefit our student’s education and career opportunities are important things for VCU Engineering’s nuclear program. Where would you like to see the College of Engineering’s nuclear program 10 years from now? I would like to see growth in the nuclear program. For example, some new graduate courses on topics like nuclear materials or fusion energy. In 2024, I developed a general course for fusion energy, so building out a curriculum that goes more in-depth would be good. When you look at small modular reactors and micro reactors, current energy policy does not allow private companies to build their own. However, as energy demands increase, policy could change to where you see these compact devices installed in places like data centers, for example. A more in-depth curriculum allows VCU Engineering students to step into industry roles that lead growth of the energy industry while also ensuring students are capable of adapting to the changing field and taking advantage of new developments. What sort of cross-disciplinary opportunities are there for the College of Engineering’s nuclear program? Nuclear engineering and nuclear science are very interdisciplinary fields. You have physics that covers the nuclear reaction and the radiation it generates, for example, then chemistry is needed when talking about nuclear fuel cycles and nuclear waste. You also need materials science because good materials capable of withstanding radiation and high temperatures are needed in nuclear fission and fusion energy systems. This science then connects to engineering, building the reactors, the energy distribution systems like a power grid. It is a small sample of the overall work, but you see how mechanical and electrical engineering are key to this part. All these disciplines come together to solve the same problem. One researcher might be figuring out how to confine plasma and make it stable, then another researcher is looking at how plasma can disrupt the containment wall and how to make materials to protect the wall. Within our department, we are making connections between mechanical-focused faculty working on high-temperature ceramics or additive manufacturing techniques and those of us researching nuclear energy systems in order to make joint proposals. We are also collaborating outside VCU. As an example, I am involved with an alliance founded by the Defense Threat Reduction Agency (DTRA) comprised of 17 universities, research labs and military centers. Coordinated through DTRA, we work together on many of the same problems.Through this partnership, my Ph.D. students do summer research rotations with national labs like Lawrence Livermore National Laboratory in California and The Pacific Northwest National Laboratory. We also bring cadets and midshipman into VCU from other institutions, like the DTRA Nuclear Science and Engineering Research Center, United States Military Academy West Point and the Virginia Military Institute, whose students have been part of research experience for undergraduates programs in the summer. How is artificial intelligence impacting the field of nuclear engineering? So, the United States is sponsoring the Genesis Mission, which seeks to transform science innovation through the power of AI. One area of the Genesis Mission is nuclear fission and fusion energy. I see this playing out with the Department of Energy encouraging national labs, universities and industry to work together on applying these AI advancements to solve the research problems of nuclear energy. It is a great opportunity for students, who we can involve in this work to give them real-world experience with topics they will see after graduation. Last semester I taught a course at VCU on the practical applications of AI on nuclear engineering problems. It is not something like ChatGPT or anything like that. What we did is take Google’s TensorFlow platform that is a library of AI models and machine neural networks. Using Python scripting students learn how to apply these AI resources to about 30 problems in mechanical and nuclear engineering. They create scripts, use data sets and run analytics. We have a nuclear reactor simulator and I have some ideas to create AI-based software we can pair with the simulator, then give the software a data set and let it control the operation of the simulator in a safe way. Tell us about your background. What brought you VCU and the Department of Mechanical and Nuclear Engineering? Actually, I am not a mechanical or a nuclear engineer. My background is in physics. I graduated from the Belarusian State University in 1990 and continued to a Ph.D. in physics from the Heat and Mass Transfer Institute of the National Academy of Sciences of Belarus working on topics related to fusion plasmas and nuclear weapon effects. In space, nuclear weapons produce shockwaves and radiation. I computationally model these effects in my research to determine how something like a nuclear warhead detonation in orbit will impact the materials a satellite is made of, for example. My research also crosses over into nuclear fusion, specifically thermodynamic and optical plasma properties, fusion plasma disruptions, melt motion and splashing from plasma facing components. Accelerating Next-Generation Extreme Ultraviolet (EUV) Lithography (ANGEL) is my most recent collaborative project, supported by the Department of Energy’s (DOE) Office of Science, Fusion Energy Sciences. It involves two national laboratories, three universities and a private-sector company focusing on advancement of future micro-electronic chips, EUV photon sources, mitigation of material degradation and plasma chemistry. Prior to joining the VCU College of Engineering I worked at Purdue University at a DOE-funded center investigating nuclear fusion and the effects of plasma on materials. Around 2019 I wanted to develop my own lab, so I came to VCU with startup funds from the Nuclear Regulatory Commission and DTRA. My first priority after joining the VCU College of Engineering was continuing my fusion research, the second was collaborating with an alliance of universities focused on work for DTRA and DOE.

View all posts