{"id":"19a11d83-8ffb-435c-9d80-0dfc76509164","arxiv_id":"2501.07703","paper_version":1,"verdict":"REJECT","confidence":"HIGH","novelty_score":0.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A literature review identifies weak encryption, weak authentication, and irregular firmware updates as the main IoMT security risks, and suggests machine learning, blockchain, and edge computing as mitigations.","lead":"This paper reviews published research on how internet-connected medical devices can be attacked by malware and DDoS floods. It is a survey that lists known weaknesses and defenses, not a new experiment.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Load-bearing concern: the review's quantitative claims (90% blockchain, 82–88% ML, >70% vulnerable) are presented as if drawn from cited studies, but no extraction table or per-study evidence is provided; if these figures are not in the sources, the central synthesis is unsupported.","rationale":"The reader's weakest_assumption identifies the quantitative summary figures as unsupported. I agree that this is the central load-bearing issue. The paper's abstract and conclusion claim that ML, blockchain, and edge computing are promising, but the only quantified evidence in Section 3.4 are success rates presented without any derivation. The method section (Section 2) describes a systematic review workflow, yet it never reports how many of the 586 papers survived screening, what quality scores were assigned, or how the success rates in Figures 5 and 6 were computed. Table 1 lists only ten papers, and several of the cited sources for the 90% figure are surveys or protocol descriptions, not empirical demonstrations. This makes the numbers internally unverifiable. A concrete external check—reading the cited papers and searching for the exact figures—would settle whether the numbers were extracted or inaccurately attributed. If they are not in the sources, the primary evidence for the review's positive conclusions evaporates, leaving only general statements that do not require a systematic review. The reader's REJECT verdict is appropriate; my analysis does not change that verdict.","tokens_in":9140,"tokens_out":4791,"duration_ms":43655,"concrete_test":"Obtain the full texts of [16] (Papaioannou et al.), [25] (Wazid & Gope), [27] (Bhutia et al.), [30] (Da Costa et al.), [31] (Chatterjee et al.), and [32] (Elhoseny et al.). Search each for the figures '90%', '82%', '88%', '70%' and for any statement about success rate or percentage of vulnerable devices. Record whether each number appears, and in what context (e.g., an experimental result, a cited statistic, or an author's assertion). If the figures do not appear in the cited sources, or appear only as uncited secondary claims, the review's quantitative synthesis is unsupported.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's central claim is that ML, blockchain, and edge computing are promising mitigations for IoMT malware/DDoS risks. The evidence offered for 'promising' is the success-rate analysis in Section 3.4: blockchain 90%, ML 82–88%, cryptography 70–85%, plus the Section 3.2 statement that over 70% of IoMT devices are vulnerable. These figures are asserted without a per-study data table, confidence intervals, or any meta-analytic combination. The cited sources include survey papers (e.g., [16] Papaioannou et al., [30] Da Costa et al.) and protocol papers (e.g., [25] Wazid & Gope, [31] Chatterjee et al.) that do not appear to report such success rates in that form. A survey cannot 'demonstrate' a 90% success rate for a class of solutions unless it aggregates primary studies; no aggregation method is described. If the numbers are not actually in the cited papers, the review's only concrete quantitative support for its headline conclusion is missing. This is load-bearing because the qualitative statements alone (weak encryption, weak auth, irregular updates) are common knowledge and not the paper's contribution; the claimed value of the review is the synthesis of mitigation effectiveness.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper claims to be a systematic literature review of IoMT security vulnerabilities related to malware and DDoS attacks, based on 586 papers retrieved from ACM Digital Library, IEEE Xplore, and Elsevier (2019–2024). It concludes that inadequate encryption, weak authentication, and irregular firmware updates are the main causes of IoMT risk, and it identifies machine learning, blockchain, and edge computing as promising mitigations. The paper also reports quantitative mitigation success rates (blockchain 90%, machine learning 82–88%, cryptography 70–85%) and states that over 70% of IoMT devices currently in use are vulnerable to known malware attacks.","tokens_in":9364,"tokens_out":3259,"duration_ms":31917,"significance":"If the quantitative synthesis were properly supported, this review would offer a useful map of mitigation effectiveness for healthcare cybersecurity researchers and practitioners. The paper usefully organizes common vulnerability themes, describes the IoMT architecture, and provides a table of representative papers and their mitigation approaches. However, the claimed systematic methodology and the headline quantitative results are not backed by the reported evidence, so the contribution cannot currently be assessed as a reliable synthesis.","major_comments":[{"comment":"The success-rate analysis (blockchain 90%, machine learning 82–88%, cryptography 70–85%) is the paper's main quantitative result, but no per-study extraction table, no definition of 'success rate,' no confidence intervals, and no aggregation method are provided. The cited works include surveys and protocol papers; it is not shown that these sources report success rates in this form. Without a data table linking each figure to a primary study, the central synthesis is unsupported.","section":"Section 3.4, Figure 5"},{"comment":"The method section describes a systematic process with 586 initial papers, inclusion/exclusion criteria, and a quality assessment, but the manuscript reports no screening counts, no PRISMA-style flow diagram, no list of excluded studies, and no quality-assessment outcomes. Table 1 lists only ten papers, yet the text cites 35 references; the reader cannot determine how the final set was reached. Thus the 'systematic review' claim is not demonstrated.","section":"Section 2, especially §2.3"},{"comment":"The assertion that 'over 70% of IoMT devices currently in use are vulnerable to known malware attacks' is attributed to [32], but no primary measurement, definition of vulnerability, or source data is given. This statistic is load-bearing for the paper's motivation and should be traceable to a specific study or presented as the authors' estimate with appropriate justification.","section":"Section 3.2"}],"minor_comments":[{"comment":"The reference to 'Figure 5 and 5' should be 'Figures 5 and 6.'","section":"Section 4"},{"comment":"The statement 'as demonstrated in Figure 2' likely refers to Figure 3 or Figure 4; the figure cross-reference is incorrect.","section":"Section 2.4"},{"comment":"The sentence 'Studies either addressing IoMT security vulnerability nor published outside the designated date range...' is grammatically incomplete and should be revised for clarity.","section":"Section 2.2"},{"comment":"Capitalization of 'IOMT' is inconsistent; please use 'IoMT' consistently.","section":"Throughout"},{"comment":"The 'Alt:' text appears inside the figure caption; this appears to be a formatting artifact and should be moved or removed.","section":"Figure 4 caption"},{"comment":"Reference [34] is published in a venue described as 'Distributed Learning and Broad Applications in Scientific Research,' which may not meet the stated peer-review inclusion criterion; this should be verified.","section":"References"}],"recommendation":"reject","confidential_remarks":"The paper's central quantitative claims are not verifiable from the reported evidence, and the method section does not provide the core artifacts of a systematic review (screening counts, quality assessment results, extraction tables). Because the missing evidence is load-bearing for the paper's contribution, I recommend rejection. A substantially revised version that provides a complete extraction table and screening log could be reconsidered, but the current manuscript does not establish the reliability of its synthesis."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: this is a conventional literature review that restates what the IoMT security community already knows, and its central quantitative claims—blockchain 90% success, ML 82–88%, and over 70% of IoMT devices vulnerable—are not supported by the method as reported. There is no new synthesis beyond the standard list of weaknesses (weak encryption, weak authentication, irregular firmware) and the standard mitigation trio (ML, blockchain, edge).\n\nCredit where due: the architecture overview is clear, and the thematic organization is readable. If you need a short briefing for a non-expert, the first three sections are serviceable. The table mapping papers to mitigation approaches is a reasonable starting point, and the paper is honest about being a review rather than claiming new results.\n\nThe main problem is that the paper calls itself a systematic review but withholds the reporting that makes systematic reviews auditable. It screens 586 papers but never says how many made it into the synthesis. No flow diagram with exclusion counts, no quality assessment results, no extraction table. The success-rate figures appear as aggregate percentages with no per-study rows or confidence intervals. Since the cited sources include survey papers and protocol papers, not meta-analyses, those exact numbers likely don't exist in that form in the sources. This is load-bearing because the paper's conclusion that ML/blockchain/edge are 'promising' rests on those numbers. Also, the 2017 case described as a DDoS attack that halted ventilators is actually the WannaCry ransomware incident; that factual slip undercuts trust in the review's details.\n\nMinor but telling: citation-year inconsistencies (Adil is 2019 in the body, 2023 in the references) and some figure references are sloppy. These are easy fixes.\n\nThis paper could serve as a pointer for someone looking for a short primer, but it does not meet the transparency bar for a systematic review and adds nothing new. I would not use it as a source for quantitative claims. If it lands on my desk, I'd desk-reject it, though a major revision that adds a PRISMA-style flow, a per-study extraction table, and either verifiable sources for the success-rate numbers or removal of those claims could make it a passable survey. As-is, it doesn't deserve referee time.","headline":"A readable but unverifiable rehash of IoMT security surveys, whose quantitative success-rate claims don't survive contact with the reported method.","tokens_in":9839,"tokens_out":2911,"would_cite":false,"duration_ms":30952,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":false},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This literature review argues that inadequate encryption, weak authentication, and irregular firmware updates are the primary causes of IoMT security risk, with malware and DDoS as the dominant attack forms.","keywords":["IoMT","medical device security","malware","DDoS attacks","encryption","authentication","firmware updates","machine learning"],"falsifier":"A reader could go to the cited studies and verify each headline number: if the sources do not contain the 90% blockchain success rate, the 82–88% machine-learning range, or the over-70% vulnerability figure, the review's quantitative synthesis is unsupported. A complementary test would be a real-world audit of hospital IoMT fleets to see whether exploited vulnerabilities trace to weak encryption, weak authentication, and firmware lag as the review claims.","tokens_in":8937,"feed_emoji":"🩺","tokens_out":9053,"duration_ms":75136,"temperature":0.7,"pith_summary":"The paper is a systematic review of five years of peer-reviewed research on security vulnerabilities in the Internet of Medical Things (IoMT), the network of connected devices used to monitor and treat patients. It sets out to establish that the main causes of IoMT risk are inadequate encryption protocols, weak authentication mechanisms, and irregular firmware updates, and that malware and distributed denial-of-service (DDoS) attacks are the most significant threats exploiting these weaknesses. It further claims that machine learning, blockchain, and edge computing are the most promising mitigation directions, while noting that computational overhead and scalability limit all three. If the review's synthesis is right, then security efforts in healthcare should concentrate on lightweight cryptography, stronger authentication, and dependable update processes before investing in more complex defenses.","feed_headline":"Weak encryption and firmware lapses drive most medical IoT risk","feed_subtitle":"Attackers keep exploiting the same three gaps in connected medical devices: encryption, authentication, and patching","key_machinery":"The central object is the Internet of Medical Things (IoMT), the network of connected medical devices and healthcare IT systems. The argument about its security is carried by a systematic literature review: a defined search across three major scholarly databases, inclusion and exclusion criteria (peer-reviewed, 2019–2024, English, focused on IoMT security), quality screening, and categorical extraction of publication type, venue, year, technology, and vulnerability. This machinery turns individual papers into comparative claims by rating mitigation approaches on success rate, complexity, and scalability, and it is what allows the review to assert that blockchain-based solutions achieve the highest reported success rate (90%), machine learning approaches reach 82–88% for detection tasks, and edge computing best fits resource-constrained devices.","core_discovery":"On its own terms, the review's central discovery is that the IoMT vulnerability landscape is dominated by three recurring weaknesses—encryption, authentication, and firmware hygiene—and that the same three defenses keep recurring as solutions. Drawing on 586 peer-reviewed studies collected from three major scholarly databases, it reports that malware and DDoS attacks account for most observed threats, that over 70% of IoMT devices in current use are vulnerable to known malware, and that evaluated mitigations show success rates of about 82–88% for machine learning, 90% for blockchain, and 70–85% for cryptographic methods. The paper presents this as a synthesis of existing evidence rather than a new measurement, so the numbers are claims about what the literature already demonstrates.","pith_inferences":["Beyond the paper, the three root-cause categories—encryption, authentication, and firmware—could be turned into a minimal audit checklist for hospital IoMT procurement, and a field study could test whether those categories predict observed breaches.","The reported success rates are composite numbers without per-study breakdowns or confidence intervals, so treating them as point estimates is premature; a meta-analysis of the cited detection studies would be the natural check.","The recurring resource-constraint constraint suggests the durable solutions will be those that shift heavy computation off the device, such as edge-based anomaly detection, rather than on-device cryptography alone."],"forward_implications":["If weak encryption, weak authentication, and irregular firmware updates are the dominant root causes, then targeted investment in those three areas should reduce the majority of IoMT exploitation.","Machine learning-based detection is effective against malware and DDoS but demands computational resources and large datasets, so its deployment depends on lighter models or off-device processing.","Blockchain offers tamper-proof data storage and access control, but its high reported success rate comes with computational overhead, making efficiency the key open problem.","Edge computing localizes threat detection and reduces latency, making it the most scalable option for resource-constrained medical devices.","Standardized security protocols across IoMT ecosystems are a necessary condition for turning any of these mitigations into dependable practice."],"supporting_citations":[{"why":"Survey establishing that malware infections and DDoS attacks are the main threats exploiting IoMT vulnerabilities.","marker":"[16]"},{"why":"Shows how outdated encryption and authentication in pandemic-era healthcare networks open the door to attacks.","marker":"[17]"},{"why":"Supports the claim that outdated firmware leaves unpatched vulnerabilities in medical devices.","marker":"[18]"},{"why":"Provides a blockchain-enabled security solution for IoMT e-health, the basis for the decentralized tamper-proof mitigation claim.","marker":"[25]"},{"why":"Machine-learning technique for detecting DDoS attacks on IoMT, one source of the reported detection success range.","marker":"[27]"},{"why":"Survey of machine-learning intrusion detection systems for IoT/IoMT, supporting the real-time anomaly-detection claim.","marker":"[30]"},{"why":"Blockchain-based management of sensitive medical data in IoMT networks, supporting decentralized data-integrity claims.","marker":"[31]"},{"why":"Source of the statistic that over 70% of IoMT devices are vulnerable to known malware attacks.","marker":"[32]"},{"why":"Edge-computing approach for threat detection in resource-constrained IoT networks, supporting the low-latency mitigation claim.","marker":"[34]"}],"fun_headline_variants":["Review: Weak encryption, auth, and patching drive most IoMT risk","Review: 70% of IoMT devices vulnerable to known malware","Review: ML, blockchain, edge computing promising for IoMT security","Malware and DDoS exploit IoMT's crypto, auth, and patch gaps"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The review assumes that the summary statistics it reports—over 70% of IoMT devices vulnerable to known malware, a 90% success rate for blockchain, and 82–88% for machine learning—are accurately drawn from the cited studies, even though it provides no per-study data table, confidence interval, or meta-analytic check.","fun_headline_variants_meta":{"raw":{"variants":["Review: Weak encryption, auth, and patching drive most IoMT risk","Review: 70% of IoMT devices vulnerable to known malware","Review: ML, blockchain, edge computing promising for IoMT security","Malware and DDoS exploit IoMT's crypto, auth, and patch gaps"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000664,"raw_usage":{"total_tokens":2990,"prompt_tokens":859,"completion_tokens":2131,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":475,"completion_tokens_details":{"reasoning_tokens":2051}},"tokens_in":475,"tokens_out":2131,"duration_ms":16322,"temperature":1.0,"reasoning_tokens":2051,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T20:36:13.296711+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A reader could go to the cited studies and verify each headline number: if the sources do not contain the 90% blockchain success rate, the 82–88% machine-learning range, or the over-70% vulnerability figure, the review's quantitative synthesis is unsupported. A complementary test would be a real-world audit of hospital IoMT fleets to see whether exploited vulnerabilities trace to weak encryption, weak authentication, and firmware lag as the review claims.","supporting_citations":[{"cited_title":"A survey on security threats and countermeasures in internet of medical things (iomt),","cited_arxiv_id":null,"evidence_quote":"Survey establishing that malware infections and DDoS attacks are the main threats exploiting IoMT vulnerabilities."},{"cited_title":"Covid-19: Secure healthcare internet of things net- works, current trends and challenges with future research directions,","cited_arxiv_id":null,"evidence_quote":"Shows how outdated encryption and authentication in pandemic-era healthcare networks open the door to attacks."},{"cited_title":"The landscape of cyberse- curity vulnerabilities and challenges in healthcare: Security standards and paradigm shift recommendations,","cited_arxiv_id":null,"evidence_quote":"Supports the claim that outdated firmware leaves unpatched vulnerabilities in medical devices."},{"cited_title":"Backm-eha: A novel blockchain-enabled security solution for iomt-based e-healthcare applications,","cited_arxiv_id":null,"evidence_quote":"Provides a blockchain-enabled security solution for IoMT e-health, the basis for the decentralized tamper-proof mitigation claim."},{"cited_title":"Ddos attacks detection in ‘internet of medical things’ using machine learning techniques,","cited_arxiv_id":null,"evidence_quote":"Machine-learning technique for detecting DDoS attacks on IoMT, one source of the reported detection success range."},{"cited_title":"Internet of things: A survey on machine learning- based intrusion detection approaches,","cited_arxiv_id":null,"evidence_quote":"Survey of machine-learning intrusion detection systems for IoT/IoMT, supporting the real-time anomaly-detection claim."},{"cited_title":"An approach towards the security management for sensitive medical data in the iomt ecosystem,","cited_arxiv_id":null,"evidence_quote":"Blockchain-based management of sensitive medical data in IoMT networks, supporting decentralized data-integrity claims."},{"cited_title":"Security and privacy issues in medical internet of things: overview, countermea- sures, challenges and future directions,","cited_arxiv_id":null,"evidence_quote":"Source of the statistic that over 70% of IoMT devices are vulnerable to known malware attacks."},{"cited_title":"Lever- aging artificial intelligence for enhanced threat detection, response, and anomaly identification in resource-constrained iot networks,","cited_arxiv_id":null,"evidence_quote":"Edge-computing approach for threat detection in resource-constrained IoT networks, supporting the low-latency mitigation claim."}],"review_version":1}