Federated Continual Learning for Encrypted Traffic Classification at the Network Edge Under Asynchronous Concept Drift
Concept drift can degrade encrypted-traffic classifiers deployed at the network edge as applications, protocols, and usage patterns evolve. This paper formulates federated continual learning under asynchronous real- and virtual drift and proposes DriftGuard, a framework combining a two-level per-node detector, selective adapter-based adaptation with Fisher importance masking and class-balanced replay, and drift-aware server aggregation. Level 1 detects distributional changes in learned representations, while Level 2 monitors supervised prediction errors to provide evidence consistent with decision-relevant drift before selective adaptation is activated. We further derive a convergence bound under stated assumptions that explicitly incorporates environmental variation, detection delay, and false alarms. DriftGuard is evaluated in a controlled simulation using reproducible synthetic traffic-like features under sudden, gradual, virtual-only, and recurring drift. Across five independent runs, results are reported with standard deviations, 95% confidence intervals, and paired statistical comparisons. DriftGuard maintains competitive classification accuracy while limiting forgetting of stable classes, with its clearest advantage observed under gradual asynchronous drift. Results also show that immediate adaptation using ground-truth drift states does not necessarily improve performance under the evaluated adaptation policy. The findings provide controlled methodological validation rather than evidence of production-scale deployment performance.