The rapid proliferation of Internet of Medical Things (IoMT) devices in healthcare environments has created critical cybersecurity vulnerabilities that demand both accurate and interpretable intrusion detection solutions. Existing deep learning-based intrusion detection systems (IDS) achieve high detection accuracy but lack inherent explainability, limiting their clinical adoption under regulatory frameworks such as GDPR and FDA guidelines. This paper presents MedDefender-MHAN, an explainable multi-head attention network specifically designed for healthcare IoT threat detection. The proposed framework introduces a novel dual-stream architecture that combines convolutional neural networks for local spatial feature extraction with transformer-based encoders for long-range temporal dependency modeling. Unlike existing approaches that apply explainability as a post-hoc process, MedDefender-MHAN embeds interpretability directly into the multi-head attention mechanism, enabling real-time gradient-weighted explanation generation without external XAI pipelines. Evaluated on CICIDS2017 and TONIoT benchmark datasets, MedDefender-MHAN achieves detection accuracies of 99. 47% and 98. 92% respectively, with sub-3ms inference latency and a throughput of 435 samples per second. Explainability evaluation demonstrates 94. 6% alignment with expert-annotated attack signatures and 91. 9% temporal accuracy, outperforming post-hoc methods such as SHAP and Integrated Gradients. These results confirm that MedDefender-MHAN provides a clinically viable, regulatory-compliant security solution for real-world healthcare IoT infrastructure. The proposed framework addresses the dual imperatives of methodological transparency and clinical impact, directly responding to the growing need for trustworthy AI-driven security solutions in regulated healthcare IoMT environments.
Ali Alqazzaz (Fri,) studied this question.