Retrofit: Continual Learning with Controlled Forgetting for Binary Security Detection and Analysis
summary
In short
This episode discusses the 'RETROFIT' paper, a continual learning method designed for security analysis like malware detection and binary summarization. It solves the problem of catastrophic forgetting—where models lose knowledge of old threats when learning new ones. RETROFIT achieves this without storing historical data, using low-rank updates and confidence-guided arbitration to maintain performance while achieving substantial gains over existing methods.
Key concepts
- Catastrophic Forgetting
- This is the major issue where a model, when trained on new data (like modern malware), forgets its ability to recognize older threats. This is a huge problem in security because old malware remains active and must be detected.
- Continual Learning
- This allows a machine learning model to continuously absorb new information over time without losing the knowledge it previously acquired from past learning sessions. It enables adaptation to new threats while retaining old knowledge.
- Low-Rank Updates
- This mechanism ensures that when the model learns something new, only a small, focused set of weights change. This prevents large-scale changes and limits interference between different tasks or types of data.
- Confidence-Guided Arbitration
- This is a decision process where the system trusts the old model's knowledge if it is confident in its prediction. It defers to the new model only when the old model is unsure, acting like a senior engineer deferring to a new hire.
Terminology used across episodes
This episode discusses
- Retrofit: Continual Learning with Controlled Forgetting for Binary Security Detection and Analysis · Paper Radio
- Editing Models with Task Arithmetic
- Binary Code Summarization: Benchmarking ChatGPT/GPT-4 and Other Large Language Models
- Code Llama: Open Foundation Models for Code
The paper
Retrofit: Continual Learning with Controlled Forgetting for Binary Security Detection and Analysis · Read on arXiv
Yiling He, Junchi Lei, Hongyu She, Shuo Shao, Xinran Zheng, Yiping Liu, Zhan Qin, Lorenzo Cavallaro
University College London · Zhejiang University · Alibaba Group
Binary security has increasingly relied on deep learning to reason about malware behavior and program semantics. However, the performance often degrades as threat landscapes evolve and code representations shift. While continual learning (CL) offers a natural solution through sequential updates, most existing approaches rely on data replay or unconstrained updates, limiting their applicability and effectiveness in data-sensitive security environments. We propose RETROFIT, which regulates knowledge retention and adaptation with controlled forgetting at each update, without requiring historical data. Our key idea is to consolidate previously trained and newly fine-tuned models, serving as teachers of legacy and emergent knowledge, through retrospective-free parameter merging. Forgetting control is achieved by 1) constraining parameter changes to low-rank and sparse subspaces for approximate orthogonality, and 2) employing a confidence-guided arbitration mechanism to dynamically aggregate knowledge from both teachers. Our evaluation on two representative applications demonstrates that RETROFIT consistently mitigates forgetting while maintaining adaptability. In malware detection under temporal drift, it substantially improves the retention score, from 20.2% to 38.6% over CL baselines, and exceeds the oracle upper bound on new data. In binary summarization across decompilation levels, where analyzing stripped binaries is especially challenging, RETROFIT achieves over 2x the BLEU score of transfer learning used in prior work and surpasses all baselines in cross-representation generalization.
Transcript
Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.
Tom: Next we'll be talking about the paper "Retrofit: Continual Learning with Controlled Forgetting for Binary Security Detection and Analysis".
Jane: The paper was written by Yiling He, Junchi Lei, Hongyu She, Shuo Shao, Xinran Zheng et al. from University College London and Zhejiang University and Alibaba Group.
Tom: Stay tuned as we take you through the paper and discuss its implications.
Title: Tom: Welcome back to the show, everybody. Today we're diving into a paper that's got a mouthful of a title — "RETROFIT: Continual Learning with Controlled Forgetting for Binary Security Detection and Analysis."
Jane: And honestly, Tom, that title packs a lot in. Let's unpack it for our listeners. Binary security means we're looking at malware detection and analyzing compiled programs — the actual machine code, not source code. And continual learning is when a model has to keep learning from new data over time without forgetting what it already knew.
Tom: Right, and the "controlled forgetting" part is the twist. Normally, forgetting is the enemy. But this paper says, what if we deliberately control how much we forget, and when? That's a really interesting framing.
Jane: It is. And I love that the authors are from University College London, Zhejiang University, and Alibaba Group. So you've got academic rigor mixed with industry practicality right from the start.
Tom: Exactly. And the problem they're tackling is super real. Think about malware detection — new threats appear every year. If you train a model on two thousand fourteen malware, it's going to struggle with two thousand eighteen malware. But if you keep updating it, it might forget the old stuff, which is still out there causing problems.
Jane: And that's the classic dilemma. You want your model to adapt to new threats, but you don't want it to lose the ability to spot the old ones. The paper calls this catastrophic forgetting, and it's a huge issue in security because old malware doesn't just disappear.
Tom: So they're proposing RETROFIT as a solution. And the key constraint here is that in security, you often can't just store all the old data and replay it. Malware samples are sensitive, there are sharing restrictions, privacy rules. So you need a way to keep learning without keeping the data.
Jane: That's the "retrospective-free" part. No looking back at old data. The previous model itself becomes the memory. That's a clever trick — instead of storing data, you store knowledge in the weights of the model.
Tom: And that's what we're going to dig into. How do you actually pull that off without the model collapsing or forgetting everything? Stick around, because the method they came up with is pretty elegant.
Summary: Tom: So Jane, we've set the stage. Let's talk about what RETROFIT actually does. The paper's core idea is that you treat the old model and the newly fine-tuned model as two teachers, and you merge their knowledge.
Jane: Right. And the way they control forgetting is through two mechanisms. First, they constrain the parameter updates to be low-rank and sparse. That means when the model learns something new, it only changes a small, focused set of weights, not everything at once.
Tom: And the second mechanism?
Jane: Confidence-guided arbitration. So when the old model is confident about a prediction, the system says, "trust the old knowledge, don't overwrite it." But when the old model is unsure, it lets the new model take the lead. It's like having a senior engineer and a new hire — you defer to the senior when they know what they're doing, but you let the new hire handle unfamiliar territory.
Tom: That's a great analogy. And the results are pretty striking. In malware detection, they tested on data spanning five years. The naive approach of just fine-tuning on new data — they call it CFT — had a retention score of about zero point six six six. RETROFIT pushed that up to zero point nine two three.
Jane: That's a massive improvement. And here's the kicker — RETROFIT actually beat the oracle model on new data. The oracle is the model trained on all data at once, which is supposed to be the upper bound. But RETROFIT outperformed it on the two thousand eighteen test set.
Tom: Wait, how does that work? How can a continual learning model beat a model that sees everything?
Jane: The paper suggests that full retraining isn't always optimal. When you train on everything, the model can overfit to the bulk of the data and miss the nuances of the newest threats. RETROFIT's controlled forgetting actually acts as a form of regularization, keeping the model sharp on recent data while retaining the essentials of the past.
Tom: And in the binary analysis task — summarizing stripped binaries, which are super hard to understand — RETROFIT more than doubled the BLEU score compared to the transfer learning approach used in prior work. We're talking fifteen point zero five versus seven point two zero.
Jane: Stripped binaries are the worst-case scenario for security analysts. All the variable names and symbols are removed, so you're staring at raw assembly and pseudocode. Being able to summarize those accurately is a huge deal for incident response.
Tom: So the method works on two very different tasks. That's a strong signal that the approach is general, not just tuned for one problem.
Jane: Exactly. And the fact that they're using LLM-based models for the binary analysis part — that's where the field is heading. We're going to talk about what this means for real-world deployment next.
Improvements: Tom: Alright, so we've covered what RETROFIT does and the headline results. But let's bring in Lu and Meng, because I want to hear their take on the practical side. Lu, you're the researcher — what excites you most here?
Lu: Thanks, Tom. What excites me is the theoretical grounding. The paper proves that by keeping updates low-rank and using frozen random projections, the updates for different tasks become nearly orthogonal in high-dimensional space. That's a formal guarantee that interference between tasks is bounded. It's not just a heuristic that happens to work — there's math behind why it works.
Meng: But Lu, as an engineer, I want to know — does that theoretical elegance translate to something I can actually run? What's the computational cost?
Lu: That's the beautiful part. RETROFIT doesn't need a data buffer, the model size stays constant, and inference is identical to the base model. The extra cost is only during training, and it's actually cheaper than full fine-tuning because you're only training the low-rank matrices and the masks.
Meng: So it's actually more efficient than the naive baseline? That's rare. Most continual learning methods add overhead.
Jane: And that's why I think this could actually get adopted. Security teams are already stretched thin. If you tell them, "here's a method that reduces forgetting, improves new threat detection, and costs less to train," that's a compelling pitch.
Tom: But Meng, you're the skeptic. What's the catch?
Meng: The catch is that this was tested on two specific tasks — Android malware detection and binary summarization. The malware detection uses a simple MLP, and the binary analysis uses CodeT5. I'd want to see it work on more diverse architectures and threat types before I'm fully convinced.
Lu: That's fair. But the paper also shows it integrates with active learning frameworks like HCC, which is how real security systems actually update. They demonstrated that RETROFIT improves both retention and adaptation when combined with active learning, even with limited labeling budgets.
Jane: And that's the practical bridge. Active learning tells you which samples to label, and RETROFIT tells you how to use them without destroying prior knowledge. They're complementary.
Tom: So we've got theory, we've got practice, and we've got efficiency. What about the bigger picture? Lalam, you're our in-house model — what's the vision here?
Lalam: The vision is a shift in how we think about model updates in security. Instead of treating each update as a fresh start or a full retrain, we treat it as a careful negotiation between old and new knowledge. This could extend beyond malware detection to fraud detection, intrusion detection, even content moderation — anywhere data evolves and you can't keep everything.
Meng: And that's the cultural impact too. We're building systems that respect data minimization — they don't hoard sensitive data. That's a win for privacy and compliance.
Jane: And for security analysts, it means tools that stay reliable over time. That's the trust factor. If your detection tool keeps failing on old malware, you stop trusting it. RETROFIT helps maintain that trust.
Conclusion: Tom: Alright, we're wrapping up our discussion of "RETROFIT: Continual Learning with Controlled Forgetting for Binary Security Detection and Analysis." Let's pull it all together.
Jane: The core problem was that security models degrade over time — they forget old threats when learning new ones, and they struggle to generalize across different code representations. RETROFIT solves this without storing historical data, which is a huge constraint in security.
Tom: And the solution is elegant — low-rank updates to limit interference, plus confidence-guided arbitration to decide when to trust old knowledge versus new knowledge. It's like a smart negotiation between the past and the present.
Jane: The results speak for themselves. A thirty-eight point six percent improvement in retention over the naive baseline in malware detection, and more than double the BLEU score on stripped binary summarization compared to prior transfer learning. And it even beat the oracle on new data.
Lu: And the theoretical guarantees give me confidence that this isn't a fluke. The math says interference is bounded, and the experiments confirm it.
Meng: From an engineering standpoint, it's practical. No data buffer, constant model size, cheaper training. That's a rare combination.
Lalam: And the broader vision is systems that learn continuously while respecting data privacy and maintaining trust. That's the direction we need to go.
Tom: Well said, everyone. We're saying goodbye to RETROFIT and getting ready to discuss the next paper. Thanks for tuning in, and we'll see you next time.
Jane: Take care, everyone.
More episodes
- 2610.10768-Strategic Investment Decision Making for Value Creation in Energy Transition: A Reinforcement Learning Approach
- 2610.10858-RFChipAgent: Multi-Agentic AI Flow for Analog/RF Chip Design
- 2610.10613-Temporal transformer CAN encoder with federated lightweight heads for anomaly detection
- 2610.10616-When Routing Reveals Membership: Privacy Leakage from MoE Router Telemetry
- 2610.10655-Nullify: Null-Space Activation Steering for Training-Free LLM Unlearning
- 2610.11031-Language Modeling is Monotone Compression
- 2610.01253-Context-Aware Error Mitigation Orchestration for Hybrid Quantum Reinforcement Learning on NISQ Systems
- 2604.24201-CMGL: Confidence-guided Multi-omics Graph Learning for Cancer Subtype Classification
- 2609.34069-Towards Certificate-Driven Software Porting: A Self-Improving Agentic Harness for Scientific Program Optimization
- 2312.01221-Enabling Quantum Natural Language Processing for Hindi Language