Comparative positioning of this study
| Model | Core idea | Strengths | Limitations |
|---|---|---|---|
| Unsupervised models (Autoencoders) | Learn “normal” behaviour and detect anomalies via reconstruction error | Do not require labelled data; effective for subtle anomalies | Limited handling of context-dependent or sophisticated threats; sensitivity–generalisation trade-off |
| Sequence models (LSTMs, CNN-LSTM hybrids) | Model temporal dependencies in event streams | Strong for sequential anomalies | Struggle with long-range dependencies; computationally heavy |
| Graph-based models (GNNs) | Capture relational and temporal patterns among entities | Detect anomalies in structured, multi-entity contexts | High complexity; interpretability challenges; energy costly |
| Transformer-based models | Self-attention to capture long-range dependencies | State-of-the-art for sequential log analysis | High computational/energy cost; limited real-time clinical adoption |
| Hybrid & Ensemble methods | Combine multiple learners (stacking, boosting, hybrid rules) | Improve accuracy and robustness; reduce bias/variance | Still energy-intensive; often domain-agnostic |
| Context-aware anomaly detection | Integrate contextual metadata (user role, department, access patterns) | Reduces false positives; enhances interpretability | Context often underutilised in healthcare |
| Energy-efficient anomaly detection | Lightweight ML; metrics beyond accuracy (e.g. carbon footprint) | Practical for constrained environments; aligns with sustainability | Limited adoption in healthcare anomaly detection |
| Meta-Classifier (Proposed) | Modular fusion of autoencoder scores, LightGBM outputs, rule-based indicators, contextual metadata | High recall; interpretable; energy-efficient; validated on realistic healthcare access logs | Synthetic data. Need adaptations to specific healthcare institutions or HER systems |
| Model | Core idea | Strengths | Limitations |
|---|---|---|---|
| Unsupervised models (Autoencoders) | Learn “normal” behaviour and detect anomalies via reconstruction error | Do not require labelled data; effective for subtle anomalies | Limited handling of context-dependent or sophisticated threats; sensitivity–generalisation trade-off |
| Sequence models (LSTMs, CNN-LSTM hybrids) | Model temporal dependencies in event streams | Strong for sequential anomalies | Struggle with long-range dependencies; computationally heavy |
| Graph-based models (GNNs) | Capture relational and temporal patterns among entities | Detect anomalies in structured, multi-entity contexts | High complexity; interpretability challenges; energy costly |
| Transformer-based models | Self-attention to capture long-range dependencies | State-of-the-art for sequential log analysis | High computational/energy cost; limited real-time clinical adoption |
| Hybrid & Ensemble methods | Combine multiple learners (stacking, boosting, hybrid rules) | Improve accuracy and robustness; reduce bias/variance | Still energy-intensive; often domain-agnostic |
| Context-aware anomaly detection | Integrate contextual metadata (user role, department, access patterns) | Reduces false positives; enhances interpretability | Context often underutilised in healthcare |
| Energy-efficient anomaly detection | Lightweight ML; metrics beyond accuracy (e.g. carbon footprint) | Practical for constrained environments; aligns with sustainability | Limited adoption in healthcare anomaly detection |
| Meta-Classifier (Proposed) | Modular fusion of autoencoder scores, LightGBM outputs, rule-based indicators, contextual metadata | High recall; interpretable; energy-efficient; validated on realistic healthcare access logs | Synthetic data. Need adaptations to specific healthcare institutions or HER systems |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.