Hybrid machine learning framework for anomaly detection in industrial IoT environments

Indonesian Journal of Electrical Engineering and Computer Science

Hybrid machine learning framework for anomaly detection in industrial IoT environments

Abstract

The industrial internet of things (IIoT) has become a core component of Industry 4.0, enabling highly connected and data-driven industrial systems while simultaneously increasing exposure to cyber threats. Conventional intrusion detection systems (IDS), especially rule-based and signature-driven approaches, often struggle to cope with the dynamic, high-dimensional, and heterogeneous nature of IIoT traffic. This study proposes a hybrid anomaly detection framework that integrates autoencoder, isolation forest, and long short-term memory (LSTM) models using a weighted decision fusion strategy. Each component contributes complementary capabilities, including nonlinear feature learning, efficient outlier detection, and temporal pattern modeling. The framework is evaluated on the botnet of things (BoT-IoT) dataset and further validated using IoT-23. Experimental results show that the proposed hybrid approach achieves a precision of 0.999, recall of 0.970, and an F1-score of 0.985, while maintaining a false-negative rate below 0.001%. Although its area under the curve (AUC) is slightly lower than that of a standalone light gradient boosting machine (LightGBM) baseline, the hybrid framework consistently reduces missed detections, making it well suited for reliable real-time IIoT security monitoring.

Discover Our Library

Embark on a journey through our expansive collection of articles and let curiosity lead your path to innovation.

Explore Now
Library 3D Ilustration