Adapter-Based Few-Shot Continual Learning for Malicious Packet Recognition

📅 2026-08-24
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
为解决恶意软件变种持续更新导致的灾难性遗忘问题,本文提出一种基于自监督学习和低秩适应的混合框架,以少量样本实现高效模型更新。
📝 Abstract
The continual evolution of malware variants necessitates detection systems that can adapt to new threats without retraining from scratch. However, continually updating models on new data often leads to catastrophic forgetting, where previously learned knowledge is overwritten. While continual learning has been increasingly explored for malware detection, the specific setting of Few-Shot Class-Incremental Learning (FSCIL), where new malware classes must be learned from only a small number of labeled examples, remains comparatively underexplored. Therefore, this work investigates the FSCIL setting for malware classification. To address the stability-plasticity dilemma, we propose a hybrid framework that leverages a Self-Supervised Learning (SSL) backbone initialized through domain-specific pre-training on malware packets. Our method incorporates Low-Rank Adaptation (LoRA) to efficiently adapt the model during the base session while freezing the core backbone to preserve previously learned representations, alongside a prototype-based classification head for incremental sessions to establish robust decision boundaries from limited samples. Extensive experiments across several datasets demonstrate that our approach consistently outperforms prior malware FSCIL baselines and achieves state-of-the-art performance.
Problem

Research questions and friction points this paper is trying to address.

Few-Shot Class-Incremental Learning
malware classification
catastrophic forgetting
Innovation

Methods, ideas, or system contributions that make the work stand out.

Few-Shot Class-Incremental Learning
Low-Rank Adaptation
Self-Supervised Learning
Kyle Stein
Kyle Stein
Ph.D. Candidate, University of West Florida
Deep LearningComputer VisionCybersecurity
Guillermo Francia III
Guillermo Francia III
Center for Cybersecurity--University of West Florida
Information SecurityIndustrial Control SystemsSCADA SecurityVehicular Control Systems SecurityMachine Learning
E
Eman El-Sheikh
Center for Cybersecurity, University of West Florida, Pensacola, FL, USA
A
Andrew Arash Mahyari
Department of Intelligent Systems and Robotics, University of West Florida, Pensacola, FL, USA; Florida Institute For Human and Machine Cognition (IHMC), Pensacola, FL, USA