Hybrid machine learning framework for anomaly detection in industrial IoT environments
Indonesian Journal of Electrical Engineering and Computer Science
Abstract
The industrial internet of things (IIoT) has become a core component of Industry 4.0, enabling highly connected and data-driven industrial systems while simultaneously increasing exposure to cyber threats. Conventional intrusion detection systems (IDS), especially rule-based and signature-driven approaches, often struggle to cope with the dynamic, high-dimensional, and heterogeneous nature of IIoT traffic. This study proposes a hybrid anomaly detection framework that integrates autoencoder, isolation forest, and long short-term memory (LSTM) models using a weighted decision fusion strategy. Each component contributes complementary capabilities, including nonlinear feature learning, efficient outlier detection, and temporal pattern modeling. The framework is evaluated on the botnet of things (BoT-IoT) dataset and further validated using IoT-23. Experimental results show that the proposed hybrid approach achieves a precision of 0.999, recall of 0.970, and an F1-score of 0.985, while maintaining a false-negative rate below 0.001%. Although its area under the curve (AUC) is slightly lower than that of a standalone light gradient boosting machine (LightGBM) baseline, the hybrid framework consistently reduces missed detections, making it well suited for reliable real-time IIoT security monitoring.
Discover Our Library
Embark on a journey through our expansive collection of articles and let curiosity lead your path to innovation.





