Logo image
Adapter-Based Few-Shot Continual Learning for Malicious Packet Recognition
Preprint   Open access

Adapter-Based Few-Shot Continual Learning for Malicious Packet Recognition

Kyle Stein, Guillermo Francia, III Eman El-Sheikh and Arash Mahyari
08/24/2026

Metrics

1 Record Views

Abstract

malware malware classification packet recognition Computer Science Cybersecurity Machine Learning
The continual evolution of malware variants necessitates detection systems that can adapt to new threats without retraining from scratch. However, continually updating models on new data often leads to catastrophic forgetting, where previously learned knowledge is overwritten. While continual learning has been increasingly explored for malware detection, the specific setting of Few-Shot Class-Incremental Learning (FSCIL), where new malware classes must be learned from only a small number of labeled examples, remains comparatively underexplored. Therefore, this work investigates the FSCIL setting for malware classification. To address the stability-plasticity dilemma, we propose a hybrid framework that leverages a Self-Supervised Learning (SSL) backbone initialized through domain-specific pre-training on malware packets. Our method incorporates Low-Rank Adaptation (LoRA) to efficiently adapt the model during the base session while freezing the core backbone to preserve previously learned representations, alongside a prototype-based classification head for incremental sessions to establish robust decision boundaries from limited samples. Extensive experiments across several datasets demonstrate that our approach consistently outperforms prior malware FSCIL baselines and achieves state-of-the-art performance.
url
Adapter-Based Few-Shot Continual Learning for Malicious Packet RecognitionView
Preprint link to article Open CC BY V4.0

Details

Logo image