Ablasi Kelompok Fitur Multi-View pada Random Forest untuk Deteksi Intrusi IIoT

Authors

  • Januar Al Amien UNIVERSITAS MUHAMMADIYAH RIAU
  • Bayu Anugrah Putra Universitas Muhammadiyah Riau
  • Fauzan Azim Universitas Muhammadiyah Riau
  • Reny Medikawati Taufiq Universitas Muhammadiyah Riau
  • Syahril Syahril Universitas Muhammadiyah Riau

DOI:

https://doi.org/10.37859/jf.v16i2.12438
Keywords: feature ablation, random forest, industrial internet of things, intrusion detection, multi-view features

Abstract

Internet of Things (IIoT) systems generate heterogeneous multisource telemetry data, including network traffic, host resource usage, and security logs. Intrusion detection studies commonly combine all available feature sources based on the assumption that incorporating more sources (multi-view) will always improve detection performance. This study examines this assumption using the X-IIoTID dataset through two experiments. First, feature selection based on Random Forest Gini importance was evaluated using five feature sizes (K = 10, 20, 30, 45, and 61), with cross-algorithm robustness assessed using Decision Tree, Logistic Regression, and K-Nearest Neighbors. Second, a systematic ablation study was conducted on seven combinations of three feature groups: Network (N), Host (H), and Log (L), with Timestamp excluded from the Network group to ensure consistent feature treatment. Using 299,999 samples, comprising 239,999 training and 60,000 test samples across 19 attack classes and a normal class, the results show that multiclass performance increased with the number of features, achieving an F1-macro of 0.876 at K = 10 and 0.912 at K = 61. The ablation study showed that the Full MultiView (N+H+L) achieved the best performance (F1-macro = 0.912), followed by N+H (0.905) and N+L (0.879). The Log group alone yielded low performance (0.098) but provided additional value when combined with Network features. These findings demonstrate that the effectiveness of multi-view intrusion detection depends on feature-source combinations rather than merely the number of sources, highlighting the importance of feature-group ablation in designing IIoT intrusion detection systems.

Downloads

Download data is not yet available.

References

Learning dalam Penanganan Pandemi COVID-19: Systematic Literatur Review,” J. FASILKOM, vol. 13, no. 02, pp. 318–325, Aug. 2023, doi: 10.37859/jf.v13i02.5651.

M. Al-Hawawreh, E. Sitnikova, and N. Aboutorab, “X-IIoTID: A Connectivity-Agnostic and Device-Agnostic Intrusion Data Set for Industrial Internet of Things,” IEEE Internet Things J., vol. 9, no. 5, pp. 3962–3977, 2022, doi: 10.1109/JIOT.2021.3102056.

A. Alnajim, S. Habib, M. Islam, S. Thwin, and F. Alotaibi, “A Comprehensive Survey of Cybersecurity Threats, Attacks, and Effective Countermeasures in Industrial Internet of Things,” Technologies, vol. 11, no. 6, p. 161, Nov. 2023, doi: 10.3390/technologies11060161.

S. Soni, Afdhil Hafid, and Didik Sudyana, “ANALISIS KESADARAN MAHASISWA UMRI TERKAIT PENGGUNAAN TEKNOLOGI & MEDIA SOSIAL TERHADAP BAHAYA CYBERCRIME,” J. FASILKOM, vol. 9, no. 3, pp. 28–34, Nov. 2019, doi: 10.37859/jf.v9i3.1664.

B. Alotaibi, “A Survey on Industrial Internet of Things Security: Requirements, Attacks, AI-Based Solutions, and Edge Computing Opportunities,” Sensors, vol. 23, no. 17, p. 7470, Aug. 2023, doi: 10.3390/s23177470.

J. Yu, G. Wang, N. Shi, R. Saxena, and B. Lee, “A Multi-View-Based Federated Learning Approach for Intrusion Detection,” Electronics, vol. 14, no. 21, p. 4166, Oct. 2025, doi: 10.3390/electronics14214166.

S. Lee, D. Roh, J. Yu, D. Moon, J. Lee, and J.-H. Bae, “Deep Feature Fusion via Transfer Learning for Multi-Class Network Intrusion Detection,” Appl. Sci., vol. 15, no. 9, 2025, doi: 10.3390/app15094851.

C. Xu, D. Li, Z. Liu, J. Yang, Q. Shen, and N. Tong, “Few-shot network intrusion detection method based on multi-domain fusion and cross-attention,” PLoS One, vol. 20, no. 7, p. e0327161, Jul. 2025, doi: 10.1371/journal.pone.0327161.

R. W. Anwer, M. Abrar, M. Ullah, A. Salam, and F. Ullah, “Advanced intrusion detection in the industrial Internet of Things using federated learning and LSTM models,” Ad Hoc Networks, vol. 178, p. 103991, Nov. 2025, doi: 10.1016/j.adhoc.2025.103991.

A. Termanini, H. Bourdoucen, D. Al-Abri, and A. Al Maashri, “Intrusion Detection Datasets for IIoT and ICS: A Taxonomic Review with a Decision-Aid Scoring Rubric,” Sensors, vol. 26, no. 13, p. 4099, Jun. 2026, doi: 10.3390/s26134099.

A. Y. Hussein, P. Falcarin, and A. T. Sadiq, “IoT Intrusion Detection Using Modified Random Forest Based on Double Feature Selection Methods,” 2022, pp. 61–78. doi: 10.1007/978-3-030-97255-4_5.

Y. Yin et al., “IGRF-RFE: a hybrid feature selection method for MLP-based network intrusion detection on UNSW-NB15 dataset,” J. Big Data, vol. 10, no. 1, p. 15, Feb. 2023, doi: 10.1186/s40537-023-00694-8.

O. Abu Alghanam, W. Almobaideen, M. Saadeh, and O. Adwan, “An improved PIO feature selection algorithm for IoT network intrusion detection system based on ensemble learning,” Expert Syst. Appl., vol. 213, p. 118745, Mar. 2023, doi: 10.1016/j.eswa.2022.118745.

L. Breiman, “Random Forests,” Mach. Learn., vol. 45, no. 1, pp. 5–32, Oct. 2001, doi: 10.1023/A:1010933404324.

V. Shanmugam, R. Razavi-Far, and E. Hallaji, “Addressing Class Imbalance in Intrusion Detection: A Comprehensive Evaluation of Machine Learning Approaches,” Electronics, vol. 14, no. 1, p. 69, Dec. 2024, doi: 10.3390/electronics14010069.

N. V. Chawla, K. W. Bowyer, L. O. Hall, and W. P. Kegelmeyer, “SMOTE: Synthetic Minority Over-sampling Technique,” J. Artif. Intell. Res., vol. 16, pp. 321–357, Jun. 2002, doi: 10.1613/jair.953.

L.-H. Li, R. Ahmad, R. Tanone, and A. K. Sharma, “STB: synthetic minority oversampling technique for tree-boosting models for imbalanced datasets of intrusion detection systems,” PeerJ Comput. Sci., vol. 9, p. e1580, Nov. 2023, doi: 10.7717/peerj-cs.1580.

S. A. Wahab, S. Sultana, N. Tariq, M. Mujahid, J. A. Khan, and A. Mylonas, “A Multi-Class Intrusion Detection System for DDoS Attacks in IoT Networks Using Deep Learning and Transformers,” Sensors, vol. 25, no. 15, p. 4845, Aug. 2025, doi: 10.3390/s25154845.

S. Kapoor and A. Narayanan, “Leakage and the reproducibility crisis in machine-learning-based science,” Patterns, vol. 4, no. 9, p. 100804, Sep. 2023, doi: 10.1016/j.patter.2023.100804.

F. Pedregosa et al., “Scikit-learn: Machine Learning in Python,” J. Mach. Learn. Res., vol. 12, pp. 2825–2830, 2011.

W. McKinney, “Data Structures for Statistical Computing in Python,” 2010, pp. 56–61. doi: 10.25080/Majora-92bf1922-00a.

C. R. Harris et al., “Array programming with NumPy,” Nature, vol. 585, no. 7825, pp. 357–362, Sep. 2020, doi: 10.1038/s41586-020-2649-2.

J. D. Hunter, “Matplotlib: A 2D Graphics Environment,” Comput. Sci. Eng., vol. 9, no. 3, pp. 90–95, 2007, doi: 10.1109/MCSE.2007.55.

Downloads

Published

2026-08-30