用增量学习提升RPL物联网路由攻击检测的适应性
Adaptive Intrusion Detection for Evolving RPL IoT Attacks Using Incremental Learning
- 采用增量学习动态更新检测模型,避免全量重训
- 新攻击检测准确率恢复,旧威胁遗忘减少40%以上
- 适合需要持续防护的动态物联网场景
低功耗有损网络路由协议(RPL)已成为资源受限物联网系统的标准路由方案,但其轻量设计使其易受各类路由层攻击,如Hello洪水、降级排名和版本号篡改。传统防御方法包括协议修改和机器学习分类器,虽对已知威胁有高准确率,但在面对新型或零日攻击时需全量重训,这在动态物联网环境中不切实际。本文研究增量学习作为RPL网络入侵检测的可行自适应策略。系统评估五类模型(包含集成模型与深度学习模型),结果表明:增量学习不仅能恢复对新攻击类别的检测性能,还能有效缓解对已有威胁的灾难性遗忘,且训练时间显著低于全量重训。通过结合五种多样化模型、攻击特异性分析、遗忘行为评估与时间效率,本研究为维持演进中RPL物联网网络的弹性入侵检测提供了系统性证据。
原文摘要 · Abstract (English)
The routing protocol for low-power and lossy networks (RPL) has become the de facto routing standard for resource-constrained IoT systems, but its lightweight design exposes critical vulnerabilities to a wide range of routing-layer attacks such as hello flood, decreased rank, and version number manipulation. Traditional countermeasures, including protocol-level modifications and machine learning classifiers, can achieve high accuracy against known threats, yet they fail when confronted with novel or zero-day attacks unless fully retrained, an approach that is impractical for dynamic IoT environments. In this paper, we investigate incremental learning as a practical and adaptive strategy for intrusion detection in RPL-based networks. We systematically evaluate five model families, including ensemble models and deep learning models. Our analysis highlights that incremental learning not only restores detection performance on new attack classes but also mitigates catastrophic forgetting of previously learned threats, all while reducing training time compared to full retraining. By combining five diverse models with attack-specific analysis, forgetting behavior, and time efficiency, this study provides systematic evidence that incremental learning offers a scalable pathway to maintain resilient intrusion detection in evolving RPL-based IoT networks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。