Malware Traffic Classification via Expandable Class Incremental Learning With Architecture Search

Xixi Zhang, Yu Wang, Tomoaki Otsuki Ohtsuki, Guan Gui, Chau Yuen, Marco Di Renzo, Hikmet Sari · IEEE Transactions on Information Forensics and Security · 2025

Malware traffic classification (MTC) is a crucial step in network intrusion detection, which is significant for network security and management. With the continuous evolution of malware traffic, traditional MTC methods are difficult to adapt efficiently to new traffic categories, and manually designed neural network structures suffer from performance bottlenecks and low design efficiency. Hence, we propose an enhanced MTC method based on expandable class incremental learning (CIL) with architecture search. The architecture search can automatically design the optimal neural network structure tailored to different network traffic characteristics, avoiding the limitations of manually designing network structures and improving classification performance. Meanwhile, expandable CIL allows the MTC model to gradually learn new traffic categories without forgetting previous knowledge, avoiding the computational overhead and efficiency loss caused by frequent retraining of the model. The experimental results demonstrate that the proposed CIL-MTC approach surpasses advanced incremental learning methods on both the Edge-IIoTset and ISCX VPN-nonVPN datasets, achieving superior classification performance while maintaining lower average trainable parameters and training costs. Especially, it achieves an average incremental accuracy of 98.55% and 99.09% on the Edge-IIoTset dataset with incremental tasks of 5 and 2, respectively.

Read the paper · More papers on PaperTik