Abstract:
With the deep integration of cloud-edge-end collaborative computing and IoT, the massive heterogeneous terminals in dynamic heterogeneous networks have become the core protection objects of cybersecurity systems. The multivariate time-series data generated by these intelligent terminals during continuous operation, including industrial control sensor logs and network traffic features, carry complete semantic information about terminal behavior. Accurate classification of such time-series data is a critical foundation for terminal threat detection. However, the data distribution imbalance caused by terminal heterogeneity poses three key challenges to existing time-series classification models. First, constrained by fixed-resolution processing paradigms, models struggle to capture multi-granularity threaten features across different time scales. Second, existing methods forcibly map all resolution features into a unified high-dimensional space, ignoring intrinsic differences in feature dimension distribution across time resolutions, introducing noise, feature redundancy, and limiting deployment feasibility on resource-constrained edge terminals. Third, performing joint classification with multiple resolutions at inference incurs significant time and memory overhead from the feature extraction and fusion of each resolution branch, further exacerbating the inherent tension between lightweight deployment and high-accuracy detection. To address the alignment between time resolutions and feature dimensions, we propose an adaptive multi-resolution representation learning (AdaMRL) model for dynamic heterogeneous networks, achieving bidirectional alignment and decoupling of time resolutions and feature dimensions. The core contributions of this work are as follows. First, a multi-resolution Matryoshka feature architecture is constructed, equipping each time resolution with an independent Matryoshka representation learning layer to adaptively select an appropriate dimensional subspace for representation learning. Second, a multi-resolution joint loss supervision mechanism is proposed, which applies synchronized constraints to representations at each resolution during training to enhance cross-resolution feature robustness and accelerate model convergence. Third, an adaptive dimension selection and ensemble strategy is designed, dynamically matching the optimal feature dimensionality to each resolution at inference, with collaborative decision-making via soft-voting. Extensive experiments on 10 UEA multivariate time-series benchmark datasets and the industrial IoT edge security dataset Edge-IIoTset demonstrate that AdaMRL achieves state-of-the-art classification performance. Compared with baseline models, the proposed method improves average classification accuracy by 0.78% and reduces redundant feature parameter computation by 27.3% under optimal adaptive configuration, striking an effective balance between detection accuracy and computational efficiency, and providing robust support for real-time security protection of edge heterogeneous terminals.