Published January 1, 2025 | Version v1
Conference paper Open

Adaptive Intrusion Detection for Evolving RPL IoT Attacks Using Incremental Learning

  • 1. Mem Univ, St John, NF, Canada
  • 2. Istanbul Tech Univ, Fac Comp & Informat Engn, Istanbul, Turkiye

Description

The routing protocol for low-power and lossy networks (RPL) has become the de facto routing standard for resource-constrained IoT systems, but its lightweight design exposes critical vulnerabilities to a wide range of routinglayer attacks such as hello flood, decreased rank, and version number manipulation. Traditional countermeasures, including protocol-level modifications and machine learning classifiers, can achieve high accuracy against known threats, yet they fail when confronted with novel or zero-day attacks unless fully retrained, an approach that is impractical for dynamic IoT environments. In this paper, we investigate incremental learning as a practical and adaptive strategy for intrusion detection in RPL-based networks. We systematically evaluate five model families, including ensemble models and deep learning models. Our analysis highlights that incremental learning not only restores detection performance on new attack classes but also mitigates catastrophic forgetting of previously learned threats, all while reducing training time compared to full retraining. By combining five diverse models with attack-specific analysis, forgetting behavior, and time efficiency, this study provides systematic evidence that incremental learning offers a scalable pathway to maintain resilient intrusion detection in evolving RPL-based IoT networks.

Files

bib-de19dfa8-723a-4a79-b265-9e2626e1cd40.txt

Files (202 Bytes)

Name Size Download all
md5:78bfd6c8a61b8773137f5cebb25dd360
202 Bytes Preview Download