REACT: Residual-Adaptive Contextual Tuning for Fast Model Adaptation in Threat Detection
Jiayun Zhang, Junshen Xu, Bugra Can, Yi Fan
Abstract
Web and mobile systems show constant distribution shifts due to the evolvement of services, users, and threats, severely degrading the performance of threat detection models trained on prior distributions. Fast model adaptation with minimal new data is essential for maintaining reliable security measures. A key challenge in this context is the lack of ground truth, which undermines the ability of existing solutions to align classes across shifted distributions. Moreover, the limited new data often fails to represent the underlying distribution, providing sparse and potentially noisy information for adaptation. In this paper, we propose REACT, a novel framework that adapts the model using a few unlabeled data and contextual insights. We leverage the inherent data imbalance in threat detection and meta-train weights on diverse unlabeled subsets to generalize common patterns across distributions, eliminating the reliance on labels for alignment. REACT decomposes a neural network into two complementary components: meta weights as a shared foundation of general knowledge, and residual adaptive weights as adjustments for specific shifts. To compensate for the limited availability of new data, REACT trains a hypernetwork to predict adaptive weights based on data and contextual information, enabling knowledge sharing across distributions. The meta weights and the hypernetwork are updated alternately, maximizing both generalization and adaptability. Extensive experiments across multiple datasets and models demonstrate that REACT improves AUROC by 14.85% over models without adaptation, outperforming the state-of-the-art.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c0e639bf-86b6-4ae9-87df-626fad370ba8Builds on25
- Adaptive Conformal Inference Under Distribution ShiftIsaac Gibbs, Emmanuel J. CandèsNeurIPS 2021 · 665 citations
- TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and TimeFeargus Pendlebury, Fabio Pierazzi, Roberto Jordaney, Johannes Kinder et al.USENIX Security 2019 · 441 citations
- Classification-Based Anomaly Detection for General DataLiron Bergman, Yedid HoshenICLR 2020 · 412 citations
- Transcend: Detecting Concept Drift in Malware Classification ModelsRoberto Jordaney, Kumar Sharad, Santanu Kumar Dash, Zhi Wang et al.USENIX Security 2017 · 325 citations
- Few-shot Network Anomaly Detection via Cross-network Meta-learningKaize Ding, Qinghai Zhou, Hanghang Tong, Huan LiuWWW 2021 · 157 citations
Related papers
- Learning from Limited Heterogeneous Training Data: Meta-Learning for Unsupervised Zero-Day Web Attack Detection across Web DomainsPeiyang Li, Ye Wang, Qi Li, Zhuotao Liu et al.CCS 2023 · 13 citations
- Fusion Is Not A Simple Ensemble! Towards The Evolving Views in Insider Threat DetectionChengyu Song, Lin Yang, Jianming Zheng, Jingjing Zhang et al.WWW 2026
- Test-time Adaptation in Non-stationary Environments via Adaptive Representation AlignmentZhen-Yu Zhang, Zhiyu Xie, Huaxiu Yao, Masashi SugiyamaNeurIPS 2024 · 12 citations
- METER: A Dynamic Concept Adaptation Framework for Online Anomaly DetectionJiaqi Zhu, Shaofeng Cai, Fang Deng, Beng Chin Ooi et al.VLDB 2024 · 18 citations
- Protecting Model Adaptation from Trojans in the Unlabeled DataLijun Sheng, Jian Liang, Ran He, Zilei Wang et al.AAAI 2025
