Open Access
ARTICLE
ET-BERT with Adapter Fusion: Operating-Regime Analysis of Modular Continual Adaptation for Encrypted Traffic Classification
1 Department of Computer Science and Engineering, Seoul National University of Science and Technology, Seoul, Republic of Korea
2 Research Center of Electrical and Information Technology, Seoul, Republic of Korea
3 Korea Institute of Science and Technology Information (KISTI), Republic of Korea
* Corresponding Author: Kiwook Sohn. Email:
# A preliminary version of this work was presented at MobiSec 2025. This article substantially extends the conference version with additional experiments and analyses
(This article belongs to the Special Issue: Advanced Security and Privacy for Future Mobile Internet and Convergence Applications: A Computer Modeling Approach)
Computer Modeling in Engineering & Sciences 2026, 148(1), 52 https://doi.org/10.32604/cmes.2026.084041
Received 15 April 2026; Accepted 15 June 2026; Issue published 27 July 2026
Abstract
Future mobile Internet and convergence applications increasingly rely on encrypted protocols, making security monitoring difficult because payload inspection is unavailable while traffic classes and threats evolve continuously. Encrypted traffic classification models must therefore adapt to newly emerging traffic classes without repeatedly overwriting or fully retraining large Transformer backbones. This study presents and extends an ET-BERT Adapter Fusion framework for AI/ML-driven encrypted-traffic security monitoring in future mobile Internet and convergence applications. The framework keeps the ET-BERT backbone frozen, trains a Base Adapter on USTC-TFC2016 classes 0–9, trains an Incremental Adapter for class 10, and composes them through Adapter Fusion. Across three seeds, Adapter Fusion in the core USTC-TFC2016 10 + 1 setting reached 0.9947 Macro-F1, close to Full Fine-Tuning (0.9978) and Consolidated Adapter training on classes 0–10 (0.9967), while preserving a modular update structure. A controlled Fusion Boundary study over 2–11 fused adapters showed a limited decrease in Macro-F1 from 0.9947 to 0.9681 rather than an abrupt collapse. Consolidated Adapter capacity experiments showed strong USTC-TFC2016 performance up to 20 classes and a clearer scale-dependent decline on CSTNET-TLS 1.3 from 0.9238 Macro-F1 at 10 classes to 0.7944 at 120 classes. Latency measurements further show that Adapter Fusion has higher inference overhead than Full Fine-Tuning and single-adapter alternatives. The conclusion is therefore not that Adapter Fusion is universally faster or more accurate, but that it offers a modular continual-adaptation regime for AI/ML-driven security in future mobile Internet and convergence applications, with benefits and limitations that depend on adapter count, data availability, and deployment constraints.Keywords
Cite This Article
Copyright © 2026 The Author(s). Published by Tech Science Press.This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.


Submit a Paper
Propose a Special lssue
View Full Text
Download PDF
Downloads
Citation Tools