You configured Endpoint Protection IPS exceptions for specific IPS signatures but when these signatures are revoked from the defintions, the exceptions are removed automatically.
This is by design. When new IPS defintions arrive on the SEPM the list of IPS exceptions is queried and when a referrenced IPS signature is removed, the related exceptions are automatically removed, too.
All Endpoint Protection releases with manually added IPS exceptions.
You need to monitor the IPS signatures for changes as the Updated IPS policy with the amended exceptions might be disrtibuted before the new content is deliverd to the clients.