Artificial Intelligence and Post-Quantum Cryptography for Healthcare Cybersecurity: A Critical Review of Techniques, Architectures, and Open Challenges
Bello Ijasini *
Department of Computer Science, Adamawa State University, Mubi, Nigeria.
Ibrahim Manga
Department of Computer Science, Adamawa State University, Mubi, Nigeria.
Bulus Bali
Department of Computer Science, Adamawa State University, Mubi, Nigeria.
Yawachi Aaron Yunusa
Department of Computer Science, Adamawa State University, Mubi, Nigeria.
*Author to whom correspondence should be addressed.
Abstract
Aims: This critical review examines how artificial intelligence (AI) and post-quantum cryptography (PQC) can be combined to strengthen cybersecurity in healthcare information systems, with an emphasis on the Internet of Medical Things (IoMT), clinical data platforms, zero-trust access control and cryptographic migration.
Study Design: The review uses a structured literature-search and evidence-mapping approach. It emphasises peer-reviewed sources in computer science, cybersecurity, healthcare informatics and cryptography, as well as authoritative standards.
Methodology: Evidence was organised into healthcare/IoMT cybersecurity, AI-enabled detection and response, PQC and migration, and integrated security architecture. NIST, FDA and IETF material was used to distinguish finalised standards from emerging work. Studies were compared by security function, deployment layer, resource overhead, interoperability, clinical risk and empirical validation.
Results: AI and PQC address different but complementary requirements. AI supports anomaly detection, behavioural analytics, alert prioritisation and migration assistance, but is exposed to evasion, poisoning, drift and explainability problems. NIST FIPS 203, FIPS 204 and FIPS 205 provide finalised standards for ML-KEM, ML-DSA and SLH-DSA. Major deployment barriers include constrained devices, larger keys and signatures, legacy dependencies, interoperability, implementation leakage, regulation and limited real-world validation. A five-layer reference architecture and a phased migration architecture are proposed.
Conclusion: Healthcare organisations should begin cryptographic discovery and risk-based PQC migration while strengthening AI security controls. Future work should prioritise hardware-aware PQC benchmarks, adversarially robust AI, clinically safe automated responses, cryptographic agility and multi-site validation.
Keywords: Artificial intelligence, post-quantum cryptography, healthcare cybersecurity, internet of medical things, zero trust, cryptographic agility, intrusion detection, ML-KEM, ML-DSA, adversarial machine learning