Table 1

Comparative positioning of this study

ModelCore ideaStrengthsLimitations
Unsupervised models (Autoencoders)Learn “normal” behaviour and detect anomalies via reconstruction errorDo not require labelled data; effective for subtle anomaliesLimited handling of context-dependent or sophisticated threats; sensitivity–generalisation trade-off
Sequence models (LSTMs, CNN-LSTM hybrids)Model temporal dependencies in event streamsStrong for sequential anomaliesStruggle with long-range dependencies; computationally heavy
Graph-based models (GNNs)Capture relational and temporal patterns among entitiesDetect anomalies in structured, multi-entity contextsHigh complexity; interpretability challenges; energy costly
Transformer-based modelsSelf-attention to capture long-range dependenciesState-of-the-art for sequential log analysisHigh computational/energy cost; limited real-time clinical adoption
Hybrid & Ensemble methodsCombine multiple learners (stacking, boosting, hybrid rules)Improve accuracy and robustness; reduce bias/varianceStill energy-intensive; often domain-agnostic
Context-aware anomaly detectionIntegrate contextual metadata (user role, department, access patterns)Reduces false positives; enhances interpretabilityContext often underutilised in healthcare
Energy-efficient anomaly detectionLightweight ML; metrics beyond accuracy (e.g. carbon footprint)Practical for constrained environments; aligns with sustainabilityLimited adoption in healthcare anomaly detection
Meta-Classifier (Proposed)Modular fusion of autoencoder scores, LightGBM outputs, rule-based indicators, contextual metadataHigh recall; interpretable; energy-efficient; validated on realistic healthcare access logsSynthetic data. Need adaptations to specific healthcare institutions or HER systems
Source(s): Authors’ own work

or Create an Account

Close Modal
Close Modal