Security alerts for medical devices Personal proposal by Per-Arne Andersen H4 · Spring 2027 https://thesis.uya.no/proposals/beyond-the-security-alert/ Compare a readable security classifier with a random forest using medical-device network traffic. TECHNICAL - Train a depth-5 decision tree and a 100-tree random forest. - Build an alert view showing the predicted class and the tree rule used. DATA (access-required) CICIoMT2024: WiFi/MQTT attack CSVs Use the publisher’s train/test split. Keep benign, DoS and reconnaissance traffic; remove labels and identifying fields from inputs. CICIoMT2024: https://www.unb.ca/cic/datasets/iomt-dataset-2024.html METHOD Fit preprocessing on training data only; report test macro-F1, false positives and timing. Keep a fixed set of classifier outputs when comparing plain and explained alerts with 6 IT responders on 12 disjoint cases; score interpretation and escalation reasons. OUTPUT Reproducible classifier comparison and alert viewer. BACHELOR Task: Implement a reproducible decision-tree classifier and an alert replay screen. Data: CICIoMT2024: WiFi/MQTT attack CSVs (access-required) Use the publisher’s train/test split. Keep benign, DoS and reconnaissance traffic; remove labels and identifying fields from inputs. Requires: Provider download form requires registration and currently reports a server error. Confirm access before selecting; recruit IT responders for the user study. Method: After securing CICIoMT2024 access, retain the publisher split; report benign/DoS recall and false alarms, then check basic responder tasks. Plan 4 participant sessions. Output: A documented classifier demo with bounded performance and usability results. Use relevant literature to justify the established approach; a new research contribution is not the aim of this proposal. MASTER Separate classifier performance from responder usefulness. Audit the published split for leakage, compare tree/forest baselines, then test fixed-tree explanations under differing service impacts. A higher F1 alone is not the thesis contribution. Intended contribution: A reproducible evaluation connecting alert evidence to escalation decisions and its limits. STARTING PAPERS Buçinca et al. (2021) — To Trust or to Think: https://arxiv.org/abs/2102.09692 Derive a competing explanation based on verification effort and overreliance. Vessey & Galletta (1991) — Cognitive Fit: https://pubsonline.informs.org/doi/10.1287/isre.2.1.63 Test whether a representation helps one kind of task more than another. Search Scopus or Web of Science and ACM Digital Library using the topic query, then follow citations to the thesis start date. Record searches and compare methods, data, findings and limitations in literature-matrix.csv. Use that review to confirm or revise the gap and choose a current comparator. The linked papers are starting points. START HERE Tools: Python, pandas, scikit-learn, Streamlit 1. Open the CICIoMT2024 source link and obtain WiFi/MQTT attack CSVs and their published split. 2. Inventory labels, identifiers, duplicates and class counts separately in training and test data. 3. Fit a training-only preprocessing pipeline and benchmark one classifier before building the alert view. Literature search: medical device security alert explanation analyst decisions Study controls: - Before collecting participant data, agree consent, storage and withdrawal handling with the supervisor. Use participant codes, not names, in study files. - Cap training at 20,000 rows/class with seed 1. Group validation by capture before sampling; audit cross-split duplicates and exclude file/label identifiers. If capture identity is unavailable, restrict conclusions to the publisher split. - Explain predictions from the same fixed tree in both interface conditions; do not compare tree explanations with unexplained forest predictions. Measure feature-to-prediction latency, not live detection latency. - For the master’s study, use the research task above to define the factors and comparisons in this pilot plan. Preregister one primary outcome and feasible scope after the literature review; do not add every possible model or interface variant. REQUIRES Provider download form requires registration and currently reports a server error. Confirm access before selecting; recruit 6 IT responders for the user study. -------------------- NON-TECHNICAL - Turn published attack categories into paper incident reports. - Interview IT responders about which evidence they need before escalating. DATA (mixed) 12 incident cards based on CICIoMT2024 Create 4 benign, 4 DoS and 4 reconnaissance cards, each with an explicitly fictional service impact. Recruit 6 IT responders. CICIoMT2024: https://www.unb.ca/cic/datasets/iomt-dataset-2024.html METHOD 45-minute scenario interviews; code evidence used, escalation reasons and uncertainty. Compare decisions across the 3 incident types. OUTPUT Incident-report template and coded decision criteria. BACHELOR Task: Find what an IT responder needs before escalating an incident. Data: 12 incident cards based on CICIoMT2024 (mixed) Create 4 benign, 4 DoS and 4 reconnaissance cards, each with an explicitly fictional service impact. Requires: Recruit responders; the service context must be created. Method: Use the fictional incident cards in 4 responder interviews; organise evidence and escalation steps. Output: An incident checklist and clear escalation requirements. Use relevant literature to justify the established approach; a new research contribution is not the aim of this proposal. MASTER Explain why security evidence sufficient for one role is insufficient for another. Contrast technical and service-impact reasoning, using identical incidents to examine role interpretations and verification costs. Intended contribution: An evidence-to-escalation model with role-specific boundary conditions. STARTING PAPERS Orlikowski & Gash (1994) — Technological Frames: https://dl.acm.org/doi/10.1145/196734.196745 Compare how roles interpret the purpose, operation and use of the same system. Vasconcelos et al. (2023) — Explanations Can Reduce Overreliance: https://arxiv.org/abs/2212.06823 Compare verification cost with trust as explanations of observed decisions. Search Scopus or Web of Science and ACM Digital Library using the topic query, then follow citations to the thesis start date. Record searches and compare methods, data, findings and limitations in literature-matrix.csv. Use that review to confirm or revise the gap and choose a current comparator. The linked papers are starting points. START HERE Tools: LibreOffice Writer/Calc, audio recorder with consent; no programming required. 1. Prepare a pilot with 2 examples from: 12 incident cards based on CICIoMT2024. Write the task questions and a reference answer sheet. 2. Write a recruitment message, information sheet and consent form for the participants named above. Agree privacy handling with the supervisor before contact. 3. Pilot one session after approval; revise unclear questions, freeze the task sets and coding categories, then recruit the planned sample. Literature search: medical device security alert explanation analyst decisions qualitative scenario study Study controls: - Before collecting participant data, agree consent, storage and withdrawal handling with the supervisor. Use participant codes, not names, in study files. - Pilot separately, then freeze the questions and coding plan. Check objective answer keys independently; keep an audit trail of coding, including disagreements. - For comparisons, counterbalance order and case assignment; do not show a person both versions of one case. Report participant-level findings, not repeated tasks as independent people. REQUIRES Recruit responders; the service context must be created. Bachelor: apply established methods and evaluate a practical solution or study. Master: position a research question in current scientific literature, investigate a mechanism or unresolved problem, and explain the contribution. Final scope is agreed with me. Study sizes are proposed; participant recruitment and planned materials are not already arranged.