arXiv:2603.00363cs.LGcs.AI2026-03被引 3

解决物联网入侵检测系统在新攻击下的记忆丢失问题

Quantifying Catastrophic Forgetting in IoT Intrusion Detection Systems

  • 将入侵检测视为领域持续学习问题,设计通用框架集成多种方法
  • 5种方法中基于回放的策略表现最佳,SI方法实现近乎零遗忘且训练高效
  • 适用于资源受限的动态物联网环境,对长期安全防御有重要意义

基于RPL的物联网网络中攻击模式的分布漂移对大规模互联系统的可靠性与安全性构成重大威胁。基于静态数据集训练的入侵检测系统(IDS)难以泛化至未知威胁,且在新增攻击更新时易发生灾难性遗忘。因此,确保IDS的持续适应能力对维持物联网网络安全至关重要。本文将入侵检测建模为领域持续学习问题,提出一种方法无关的IDS框架,可整合多种持续学习策略。我们在包含48个领域的综合性多攻击数据集上,系统性地评估了五种代表性方法在多种领域顺序下的表现。结果表明,持续学习能有效缓解灾难性遗忘,在可塑性、稳定性与效率间取得平衡,这对资源受限的物联网环境尤为关键。其中,基于回放的方法整体表现最优,而突触智能(SI)在保持近零遗忘的同时具备高训练效率,展现出在动态物联网网络中稳定可持续部署的强大潜力。

原文摘要 · Abstract (English)

Distribution shifts in attack patterns within RPL-based IoT networks pose a critical threat to the reliability and security of large-scale connected systems. Intrusion Detection Systems (IDS) trained on static datasets often fail to generalize to unseen threats and suffer from catastrophic forgetting when updated with new attacks. Ensuring continual adaptability of IDS is therefore essential for maintaining robust IoT network defence. In this focused study, we formulate intrusion detection as a domain continual learning problem and propose a method-agnostic IDS framework that can integrate diverse continual learning strategies. We systematically benchmark five representative approaches across multiple domain-ordering sequences using a comprehensive multi-attack dataset comprising 48 domains. Results show that continual learning mitigates catastrophic forgetting while maintaining a balance between plasticity, stability, and efficiency, a crucial aspect for resource-constrained IoT environments. Among the methods, Replay-based approaches achieve the best overall performance, while Synaptic Intelligence (SI) delivers near-zero forgetting with high training efficiency, demonstrating strong potential for stable and sustainable IDS deployment in dynamic IoT networks.

入侵检测持续学习物联网安全灾难性遗忘

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。