CeeDet: A Class-Incremental Learning Method with Early-Exit Mechanism for Malicious Traffic Detection in IIoT
摘要
The Industrial Internet of Things is increasingly threatened by continuously evolving cyberattacks, where new attack types emerge and older patterns persist. Existing detection methods often fail to adapt to this non-stationary data due to catastrophic forgetting and computational inefficiency. This paper introduces CeeDet, a class-incremental learning method designed for adaptive malicious traffic detection in IIoT networks. CeeDet integrates a hierarchical Mamba-based temporal feature extractor with an early-exit inference mechanism, allowing for dynamic adjustment of the inference path to achieve significant time savings. A Knowledge Distillation along Temporal dimension with soft-DTW strategy facilitates knowledge retention across evolving attacks without replaying previous data. Evaluations on the CIC-IIoT-2025 and NF-ToN-IoT-v2 benchmarks show that CeeDet achieves up to 87% average accuracy and forgets less than 12% of previously learned knowledge. Moreover, the early-exit mechanism provides an average 27.2% inference time reduction within the imbalanced dataset, demonstrating the method’s performance in continuously evolving IIoT scenarios.