Continual Learning Trajectory as Memory for Replay-Free Consolidation in Malicious Code Analysis
Abstract
Malware classifiers must continually adapt as new threats emerge, but sequential updates can overwrite knowledge of earlier malware families, leading to catastrophic forgetting. Continual learning (CL) methods address this problem, but most treat past knowledge as something that must be explicitly stored or reconstructed. In malware analysis, these approaches are undesirable because of storage and computational costs, data-access policies, and security concerns. This leads to a fundamental question: \em Can the CL trajectory itself act as a form of memory? We study this question through the geometry of CL. Our experiments reveal a clear progression in linear connectivity—independently trained models are separated by high-loss regions; shared initialization introduces partial connectivity; and warm-start CL strengthens this connectivity further by combining common parameter ancestry with a continuous optimization trajectory. Based on this finding, we propose FreeMOCA, a replay-free CL method that recursively consolidates consecutive model states through linear parameter interpolation to reinforce favorable geometry across tasks. Unlike approaches that rely on replay, optimize nonlinear connectivity, or align and repair models before merging, FreeMOCA exploits connectivity already present in the learning trajectory and strengthens it through recursive consolidation.. We evaluate FreeMOCA in class-incremental learning setting on large-scale Windows and Android malware benchmarks against 10 CL baselines. FreeMOCA achieves average accuracies of 65.2% on EMBER-Class and 63.7% on AZ-Class, outperforming the strongest evaluated CL baselines by 2.1 and 8.8 percentage points, respectively, while reducing forgetting to 0.006 and 0.000. It requires only 15.98 MB of constant cross-task memory and averages 38.05 s of training time per task.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.