Isolation Forest

class dtaianomaly.anomaly_detection.IsolationForest(window_size: str | int, stride: int = 1, **kwargs)[source]

Anomaly detector based on the Isolation Forest algorithm.

The isolation forest [Liu2008isolation] generates random binary trees to split the data. If an instance requires fewer splits to isolate it from the other data, it is nearer to the root of the tree, and consequently receives a higher anomaly score.

Notes

The isolation forest inherets from PyodAnomalyDetector.

Parameters:
  • window_size (int or str) – The window size to use for extracting sliding windows from the time series. This value will be passed to compute_window_size().

  • stride (int, default=1) – The stride, i.e., the step size for extracting sliding windows from the time series.

  • **kwargs – Arguments to be passed to the PyOD isolation forest.

window_size_

The effectively used window size for this anomaly detector

Type:

int

pyod_detector_

An Isolation Forest detector of PyOD

Type:

IForest

Examples

>>> from dtaianomaly.anomaly_detection import IsolationForest
>>> from dtaianomaly.data import demonstration_time_series
>>> x, y = demonstration_time_series()
>>> isolation_forest = IsolationForest(10).fit(x)
>>> isolation_forest.decision_function(x)
array([-0.02301142, -0.01266304, -0.00786237, ..., -0.04561172,
       -0.0420979 , -0.04414417])

References

[Liu2008isolation]

F. T. Liu, K. M. Ting and Z. -H. Zhou, “Isolation Forest,” 2008 Eighth IEEE International Conference on Data Mining, Pisa, Italy, 2008, pp. 413-422, doi: 10.1109/ICDM.2008.17.

decision_function(X: ndarray) ndarray

Compute decision scores.

Parameters:

X (array-like of shape (n_samples, n_attributes)) – Input time series.

Returns:

decision_scores – The decision scores of the anomaly detector. Higher indicates more anomalous.

Return type:

array-like of shape (n_samples)

Raises:
  • ValueError – If X is not a valid array.

  • NotFittedError – If this method is called before fitting the anomaly detector.

fit(X: ndarray, y: ndarray | None = None, **kwargs) BaseDetector

Fit this PyOD anomaly detector on the given data.

Parameters:
  • X (array-like of shape (n_samples, n_attributes)) – Input time series.

  • y (ignored) – Not used, present for API consistency by convention.

  • kwargs – Additional parameters to be passed to compute_window_size().

Returns:

self – Returns the instance itself

Return type:

PyODAnomalyDetector

Raises:

ValueError – If X is not a valid array.

predict_proba(X: ndarray) ndarray

Predict anomaly probabilities

Estimate the probability of a sample of X being anomalous, based on the anomaly scores obtained from decision_function by rescaling them to the range of [0, 1] via min-max scaling.

Parameters:

X (array-like of shape (n_samples, n_attributes)) – Input time series.

Returns:

anomaly_scores – 1D array with the same length as X, with values in the interval [0, 1], in which a higher value implies that the instance is more likely to be anomalous.

Return type:

array-like of shape (n_samples)

Raises:
  • ValueError – If scores is not a valid array.

  • ValueError – If the prediction scores from ‘decision_function’ are constant, but not in the interval [0, 1], because these values can not unambiguously be transformed to an anomaly probability.

save(path: str | Path) None

Save detector to disk as a pickle file with extension .dtai. If the given path consists of multiple subdirectories, then the not existing subdirectories are created.

Parameters:

path (str or Path) – Location where to store the detector.