BusyBox is widely reused in Linux-based Internet-of-Things (IoT) firmware, but stripped symbols, heterogeneous instruction sets, uncertain component versions, and selective patch backports make N-day vulnerability localization difficult. We propose EvoPatch-IoT, an evolution-aware retrieval framework whose novelty lies not in another standalone encoder, but in coupling target-local geometric localization, architecture-normalized anonymous multi-view evidence, and a version-causal historical prototype memory for reference-guided retrieval. We also release an original benchmark constructed by collecting official BusyBox releases and compiling each selected version separately for AArch64, ARM, MIPS, MIPSEL, and x86_64 in both stripped and unstripped forms. It contains 57 compiled versions and 555 binaries, together with 155,845 high-confidence stripped-to-unstripped anchors; the dataset is available in the public record. On the original symmetric 57-version benchmark (1020 directed architecture pairs), EvoPatch-IoT obtains 34.56% Hit@1 and 56.24% Hit@10. Relative to the actual strongest baseline, the in-house geometry-only ShapeStat control, these are gains of 8.00% and 5.50%, rather than gains over a weaker literature-inspired control. A stricter historical-only evaluation on 15 chronologically held-out recent versions gives 28.76% Hit@1 and 49.93% Hit@10 versus 26.55% and 47.83% for geometry alone; paired tests over 300 architecture pairs yield p < 1.6 × 10−16, with version-block 95% confidence intervals excluding zero. Direct ablations show that geometry and historical prototypes provide most of the gain, while fusion mainly improves first-rank precision and MRR. A single-CVE patch-state study is retained as supporting, not general, evidence.



