Abstract
Real-time anomaly detection is essential for promptly identifying unexpected patterns in high-velocity data streams across domains such as cybersecurity, industrial monitoring, and finance. This study presents a novel hybrid ensemble framework that integrates an Isolation Forest for rapid outlier scoring, an LSTM autoencoder for temporal–frequency sequence reconstruction, and an ADWIN-based drift detector for adaptive windowing. A Kafka- based ingestion pipeline simulates streaming conditions on benchmark datasets—including the Numenta Anomaly Benchmark (NAB) and KDD Cup 1999 network flows—enabling evaluation under varied anomaly rates and feature dimensionalities. Statistical, temporal, and frequency-domain features are extracted per time window and projected into a lower-dimensional subspace via incremental PCA. The ensemble fuses submodel scores using dynamically adaptive weights to maintain high precision and recall amidst concept drift. Experimental results demonstrate that the proposed approach achieves an average F₁-score of 93.0%—improving by approximately 7% and 6% over static Isolation Forest and LSTM baselines, respectively—while sustaining sub-second detection delays on both server (28.4 ms) and edge (112.1 ms) platforms. Resource profiling indicates efficient CPU utilization (<75%) and manageable memory footprints. These findings validate the framework’s effectiveness, adaptability, and deployability in real-time monitoring applications.