Jurnal FASILKOM (teknologi inFormASi dan ILmu KOMputer)
Vol. 16 No. 2 (2026): Jurnal FASILKOM (teknologi inFormASi dan ILmu KOMputer)

Ablasi Kelompok Fitur Multi-View pada Random Forest untuk Deteksi Intrusi IIoT

Amien, Januar Al (Unknown)
Anugrah Putra, Bayu (Unknown)
Azim, Fauzan (Unknown)
Medikawati Taufiq, Reny (Unknown)
Syahril, Syahril (Unknown)



Article Info

Publish Date
30 Aug 2026

Abstract

Internet of Things (IIoT) systems generate heterogeneous multisource telemetry data, including network traffic, host resource usage, and security logs. Intrusion detection studies commonly combine all available feature sources based on the assumption that incorporating more sources (multi-view) will always improve detection performance. This study examines this assumption using the X-IIoTID dataset through two experiments. First, feature selection based on Random Forest Gini importance was evaluated using five feature sizes (K = 10, 20, 30, 45, and 61), with cross-algorithm robustness assessed using Decision Tree, Logistic Regression, and K-Nearest Neighbors. Second, a systematic ablation study was conducted on seven combinations of three feature groups: Network (N), Host (H), and Log (L), with Timestamp excluded from the Network group to ensure consistent feature treatment. Using 299,999 samples, comprising 239,999 training and 60,000 test samples across 19 attack classes and a normal class, the results show that multiclass performance increased with the number of features, achieving an F1-macro of 0.876 at K = 10 and 0.912 at K = 61. The ablation study showed that the Full MultiView (N+H+L) achieved the best performance (F1-macro = 0.912), followed by N+H (0.905) and N+L (0.879). The Log group alone yielded low performance (0.098) but provided additional value when combined with Network features. These findings demonstrate that the effectiveness of multi-view intrusion detection depends on feature-source combinations rather than merely the number of sources, highlighting the importance of feature-group ablation in designing IIoT intrusion detection systems.

Copyrights © 2026






Journal Info

Abbrev

JIK

Publisher

Subject

Computer Science & IT Decision Sciences, Operations Research & Management

Description

Jurnal FASILKOM (teknologi inFormASi dan ILmu KOMputer) is expected to be a media of scientific study of research result, a thought and a study criticial analysis to a System engineering research, Informatics Engineering, Information Technology, Computer Engineering, Informatics Management, and ...