Unsupervised LearningAnomaly DetectionAnomaly Detection

Isolation Forest

Primary task · Anomaly Detection

Isolation Forest is an unsupervised learning method in the anomaly detection family. This page summarizes its mechanism, practical uses, important trade-offs, and a browser-based concept explorer.

← Directory
Visual intuition

From data to learned behaviour

An ensemble combines several imperfect learners so that their errors partly cancel or later learners repair earlier mistakes. Bagging mainly reduces variance, boosting builds learners sequentially, and stacking learns how to combine heterogeneous base predictions.

Infographic
1Data2Base learners3Diverse errors4Combine5Final predictionTraining transforms evidence into a reusable model state
Conceptual simulation

Watch the learning mechanism form

The structure below is synchronized with the same training state used by the prediction simulation.

Mechanism view
Training control centre

Control both simulations together

Reset regenerates the synthetic data and model state. Train animates to completion. Pause freezes the animation. Train Step advances one learning stage.

Step 0 / 12
Model simulation

Inspect the learned prediction / representation

Synthetic data are generated locally in your browser.

Model description

Understand Isolation Forest after watching it learn

This section connects the animation to the actual statistical or computational idea behind the model.

Deep description

Isolation Forest Isolation Forest is an unsupervised learning method in the anomaly detection family. This page summarizes its mechanism, practical uses, important trade-offs, and a browser-based concept explorer.

What is learned. During training, the algorithm builds or adjusts the parameters and internal representation used by Isolation Forest. The core learning mechanism is: Isolates anomalies by randomly selecting a feature and a split value; anomalies require far fewer recursive splits to be isolated in tree leaves.

How training becomes inference. Create base learner(s) → train on resampled data or residual/error signal → collect predictions → aggregate or fit meta-learner → repeat until ensemble budget/early-stopping criterion is reached. Once training stops, the fitted state is reused on unseen inputs rather than being reconstructed from scratch. The resulting output is: An anomaly/outlier score and, after thresholding, an inlier/outlier decision.

Why practitioners use it. Linear time complexity O(n), highly effective on high-dimensional data, does not assume normal distribution. Typical fits include Credit card transaction fraud, IT server telemetry anomaly detection, industrial equipment failure warning.

What to verify before trusting it. Axis-aligned splits can produce artifact anomaly scores in corner spaces (mitigated by Extended Isolation Forest). The visual simulation is intentionally simplified, so real use should still validate preprocessing, data independence, hyperparameters, uncertainty and task-appropriate metrics.

Internal statethe parameters and internal representation used by Isolation Forest
Typical outputAn anomaly/outlier score and, after thresholding, an inlier/outlier decision.
Good fitCredit card transaction fraud, IT server telemetry anomaly detection, industrial equipment failure warning.
Main cautionAxis-aligned splits can produce artifact anomaly scores in corner spaces (mitigated by Extended Isolation Forest).
1Training data→
2Learning objective→
3Internal model state→
4Prediction / representation→
5Evaluation
Intuition

What the model is trying to learn

An ensemble combines several imperfect learners so that their errors partly cancel or later learners repair earlier mistakes. Bagging mainly reduces variance, boosting builds learners sequentially, and stacking learns how to combine heterogeneous base predictions.

Mathematical lens

Core logic

The final prediction is a function of multiple base predictions: an average/vote for bagging, a weighted additive expansion for boosting, or a learned meta-model for stacking. Diversity and error correlation are therefore as important as individual learner strength.

Training sequence

How learning progresses

Create base learner(s) → train on resampled data or residual/error signal → collect predictions → aggregate or fit meta-learner → repeat until ensemble budget/early-stopping criterion is reached.

Original mechanism

Taxonomy description

Isolates anomalies by randomly selecting a feature and a split value; anomalies require far fewer recursive splits to be isolated in tree leaves.

Evaluation guide

How to evaluate this model responsibly

ValidationChoose validation that matches the independence assumptions of the data.
MetricsUse task-specific primary and complementary metrics.
HPOEstablish a baseline first, then search the parameters that materially change capacity.
Post-processingValidate any downstream transformation on held-out data.
Hyperparameters

Key parameters

n_estimatorsTypical: 100

Number of isolation trees.

contaminationTypical: auto

Expected anomaly fraction / threshold rule.

max_samplesTypical: auto

Samples used per tree.

max_featuresTypical: 1.0

Features sampled per tree.

Use & trade-offs

Where it fits

Typical applications

Credit card transaction fraud, IT server telemetry anomaly detection, industrial equipment failure warning.

Strengths

Linear time complexity O(n), highly effective on high-dimensional data, does not assume normal distribution.

Limitations

Axis-aligned splits can produce artifact anomaly scores in corner spaces (mitigated by Extended Isolation Forest).

Code example

Minimal Python implementation

# Purpose: demonstrate Isolation Forest with a small, inspectable example.
# Follow the comments and printed stages to connect each operation with its result.
# Minimal anomaly-detection starter for Isolation Forest
# Import the library or helper used in this example.
import numpy as np
# Import the library or helper used in this example.
from sklearn.ensemble import IsolationForest

# Print this intermediate result so you can verify the workflow step by step.
print("STEP 1 · Prepare the miniature example")
# Create the numerical values used in the calculation.
X = np.array([[0,0],[0.1,0.2],[-0.1,0.1],[8,8]])
# Print this intermediate result so you can verify the workflow step by step.
print("STEP 2 · Fit / train the model")
# Store this intermediate value with a descriptive name for the next step.
labels = IsolationForest(contamination=0.25, random_state=42).fit_predict(X)
# Print this intermediate result so you can verify the workflow step by step.
print("STEP 3 · Inspect predictions / metrics")
# Print this intermediate result so you can verify the workflow step by step.
print(labels.tolist())
Expected / representative output
STEP 1 · Prepare the miniature example
STEP 2 · Fit / train the model
STEP 3 · Inspect predictions / metrics
[1, 1, 1, -1]