About the programme 

Healthcare is becoming more connected, personalised, and data-driven than ever before. Connected medical devices, from implantables and wearables to hospital networks and drug delivery systems, are transforming how patients are monitored and treated. 

However, this transformative connectivity also brings a risk of cybersecurity vulnerabilities. 

IN-CYPHER (³Ô¹ÏºÚÁÏ/NTU CYber Protection for HEalthcaRe) is a joint research programme between ³Ô¹ÏºÚÁÏ Global Singapore and Nanyang Technological University (NTU) funded by Singapore's National Research Foundation. We develop the deep technologies needed to secure medical devices and healthcare systems now and in the future. 

The challenge 

Medical devices are unlike most other connected technology. 

They are safety critical. They have long lives and are often in use for one to two decades. And they operate within a strict regulatory framework designed to ensure they are fit for purpose and safe. This creates a unique security challenge. 

Devices already in the field may carry legacy software that cannot easily be updated. New devices must be designed with security built in from the start. As personalised medicine grows – drawing on data from wearables, genomics and physiological monitoring – the potential cyber risk (number of potential points where a cyberattack could happen) grows with it. New approaches to securing the devices of today and tomorrow are essential. 

Our research

IN-CYPHER is structured around four thematic pillars that loosely span hardware, software, data and clinical. A key feature of our programme is that of scientific diversity relevant to the medical device space: we have researchers in the areas of biosensor design, electronic circuit design, software engineering, machine learning, artificial intelligence (AI), and clinical applications. 

Our hardware teams are involved not only in building laboratory systems for the analysis and testing of existing medical devices, but also in designing silicon-level innovations to protect future devices based on novel physically unclonable functions, unique security signatures created directly in their hardware, so they cannot be cloned or replicated.

Our circuits and systems team investigates security across the full lifecycle of medical devices from analysing and testing existing systems to developing the next generation of secure biomedical hardware. We design secure circuits and low-power hardware that embed security directly into medical devices. We also build realistic testing environments to evaluate how those devices perform under real-world conditions. 

Our software teams work on building computational models that are useful in cybersecurity analysis; for example, we harness customised physiological simulators that can be used in assessing cyber-physiological risk associated with medical devices, or for anomaly detection. The teams also work on penetration testing, and analysis of software libraries specific to medical devices. 

Our AI team works on automating the processes of static and dynamic testing, and also on measuring and improving the quality of generative modelling for healthcare, with a particular focus on preserving privacy. 

Our clinical and biosensors teams work on the next generation of healthcare technologies: what we want to measure that would improve healthcare outcomes in specific clinical domains, what data it would generate, and how security might be incorporated from first principles. 

Together these activities span medical devices currently in use, those entering the market today, and those that we can anticipate in the near future.  

Our research themes

Protecting Connected and Implantable Medical Devices

Connected medical technologies are transforming healthcare by enabling continuous monitoring, personalised treatment, and remote clinical care beyond traditional hospital settings.  

Wearable sensors, implantable devices, and intelligent monitoring systems (such as cardiac monitors and insulin pumps) continuously acquire, process, and communicate physiological information, improving patient care and quality of life. As these technologies become increasingly connected, protecting both the devices and the sensitive medical data they generate is essential. Cyberattacks, device impersonation, and data tampering can compromise patient privacy and the safe operation of life-critical medical systems, making security a fundamental design consideration for future biomedical technologies. 

Our research 

The IN-CYPHER Circuits and Systems Team [Meet the Team: placeholder/link to circuits and systems section of Meet the Team page] develops secure hardware technologies that underpin trustworthy connected and implantable medical devices. Our research focuses on embedding security directly into biomedical circuits and sensing platforms through hardware security primitives, including Physical Unclonable Functions (PUFs) and hardware roots of trust. These technologies provide unique device identities for secure authentication, cryptographic key generation, and protection against tampering while meeting the stringent power, area, and reliability requirements of wearable and implantable devices. 

A key outcome of this research is the development of built-in security features that use the unique characteristics of each device's silicon to create a secure identity, helping protect wearable and implantable medical devices without significantly reducing their limited battery life. We have successfully designed, fabricated, and tested our first silicon chip, validating multiple PUF architectures, including the Quantum Tunnelling Physical Unclonable Function (QT-PUF) [1] and its variant, demonstrating the feasibility of lightweight hardware roots of trust for future connected medical technologies.  

Beyond device authentication, we investigate how security can be integrated throughout the biomedical sensing pipeline by incorporating hardware security mechanisms into sensor interfaces and mixed-signal circuits, enabling trusted data provenance and secure communication between medical devices and healthcare infrastructure. 

Towards secure-by-design healthcare systems 

Building on these foundations, our research is expanding towards secure-by-design biomedical systems where trust is embedded throughout the technology stack, from sensing devices and integrated circuits to secure edge intelligence and emerging bioelectronic platforms. Alongside advances in integrated circuits, biomedical instrumentation, AI hardware, and hardware security, we are exploring AI-assisted design automation to accelerate the development and verification of trustworthy healthcare technologies. Our long-term vision is to enable future healthcare systems that are inherently secure, resilient, and trustworthy by design. 

References 

[1] Y. Ma, V. Mohan, C. H. Chang and E. M. Drakakis, "QT-PUF: Quantum Tunneling Leakage Based PUF for Implantable IoMT Devices," 2026 IEEE International Symposium on Circuits and Systems (ISCAS), Shanghai, China, 2026, pp. 748-752, doi: 10.1109/ISCAS66217.2026.11562250. [Preprint: ] 

Securing Connected Wearables and Healthcare Systems

In a modern hospital, thousands of medical devices are connected to the same network. From imaging machines and infusion pumps to patient monitoring systems and electronic health records, each connection is a potential point of vulnerability. 

As healthcare systems become more interconnected, understanding how those networks can be compromised and building the tools to defend them becomes increasingly critical. 

Threat modelling is the systematic process of identifying the motivations behind security incidents, the nature of potential compromise, and the exposure surface of devices and data. It is the foundation of any effective security strategy. 

As personalised medicine expands the range of connected devices in clinical use, maintaining up-to-date threat models becomes more important and more complex. 

Our work 

We have built the Chicomoztac Cyber Range to address this challenge. It is a realistic simulation of a hospital network, replicating four clinical departments with the medical data formats and communication protocols used in real healthcare environments. This platform allows us to safely study realistic security scenarios and generate labelled datasets for training and evaluating detection systems. 

Our autonomous security testing agent, Autopatch, has demonstrated its effectiveness on real commercial medical devices. It can identify critical vulnerabilities including unauthenticated access to medical imaging servers and exposed patient records. In a real hospital setting, findings like these could mean the difference between a patient's records staying private and falling into the wrong hands. 

These findings have been fed into a responsible disclosure pipeline in partnership with SingHealth. 

We are working toward a shared national cybersecurity testing infrastructure for Singapore, with regulatory alignment to Singapore's Cybersecurity Labelling Scheme for Medical Devices. Engagement with the Cyber Security Agency, Health Sciences Authority, and Synapxe is also underway.  

Algorithms for Security, Privacy and Provenance

Connected medical devices collect highly sensitive information. This data tells us about a patient's health, behaviour and biology. It informs treatment decisions, but could cause serious harm in the wrong hands. Protecting that data and ensuring it is accurate, private, and trustworthy is as important as protecting the devices that generate it. 

Healthcare systems increasingly rely on AI to analyse patient data and support clinical decisions, which brings new questions about how that AI behaves, how it can be audited, and how its outputs can be trusted. 

Our work 

Our research on privacy-preserving data generation has uncovered systematic problems with the evaluation of existing privacy protection methods. We have developed new approaches that improve both the quality of synthetic patient data and the rigour with which privacy protections are measured. We are translating this work into trusted research environments and engaging with Singapore's Infocomm Media Development Authority and Personal Data Protection Commission on governance frameworks. 

On the security side, our Binary Library Analysis and Detection Engine (BLADE) and Predictive and Reactive Intelligence for Security Management (PRISM) tools work together to automatically scan medical device software for weaknesses and vulnerabilities. Together, they have uncovered previously unknown security flaws in widely used medical imaging software, which could otherwise have put patient data at risk. 

We are also studying how multiple AI systems communicate and make decisions when working together. As AI takes on a greater role in healthcare, it is essential that we can trust these systems to behave reliably and safely, and that we have the tools to verify that they do. 

Clinical Innovation and Translation

The ultimate measure of IN-CYPHER's research is its impact on patients. 

Connected medical devices are not just engineering challenges. They are clinical tools that directly affect people's health, safety, and quality of life. Securing them requires collaboration between technologists, clinicians, and patients. 

Diabetes management is one of the most compelling examples of how connected devices are transforming healthcare. Continuous glucose monitors and closed-loop insulin delivery systems automatically adjust insulin doses based on real-time glucose readings. These devices offer patients greater freedom and more precise control over their condition. However, they can also introduce new security risks. 

Our work 

We have built an in-house test rig for continuous glucose monitors, which we use to study cybersecurity vulnerabilities in closed-loop insulin delivery systems. This work brings together cybersecurity researchers, clinicians and bioengineers, reflecting the complexity of securing devices that sit at the intersection of software, hardware and human biology and requires interdisciplinary collaboration. 

We have submitted formal comments to the British Standards Institution on continuous glucose monitor cybersecurity standardisation. We are also co-organising a joint workshop with Singapore's Cyber Security Agency, Health Sciences Authority, National University Hospital, and SingHealth to develop a national framework for medical device cybersecurity assessment. 

Separately, we are developing a point-of-care diagnostic platform capable of simultaneously detecting multiple diabetes biomarkers, enabling clinicians to distinguish between different types of diabetes quickly and accurately at the bedside. 

We also have well-established clinical collaborations with the National University Hospital, A*STAR and Respire Diagnostics, with ethics approval secured and patient-validated research underway.