Organizations: Artificial Intelligence Research (AIR) Center, University of North Dakota, Grand Forks, ND, USA · School of Electrical Engineering and Computer Science, University of North Dakota, Grand Forks, ND, USA · National School of Commerce and Management, Hassan II University, Casablanca, Morocco
Ransomware has emerged as a major cybersecurity threat, with incidents increasing in frequency and impact across critical sectors. These attacks are typically launched through phishing emails, malicious downloads, or exploitation of software vulnerabilities to gain system access. Once inside, the malware encrypts files and demands a ransom, often in cryptocurrency, for the decryption key. Conventional detection methods often struggle with novel or scarce samples, leaving systems vulnerable. To address these challenges, this paper proposes a hybrid deep learning framework that combines an Autoencoder Feature Extractor (AFE) with a Model Agnostic Meta Learning (MAML) classifier for few shot malware detection. The AFE generates compact latent features that reduce noise and dimensionality, while the MAML classifier rapidly adapts to new threats using limited labeled data. Experiments conducted on the Ransomware Dataset 2024 demonstrate the effectiveness of the framework in binary classification tasks. Across one to fifty shot settings, the proposed model consistently achieves high accuracy, F1 score, and Matthews Correlation Coefficient values, maintaining reliable classification even under extreme scarcity. These results highlight the model's robustness and effectiveness in adapting to limited data scenarios, demonstrating the potential of combining feature extraction with meta learning to enhance resilience against malware, particularly in sectors such as healthcare, manufacturing, and public infrastructure, where cyberattacks can cause significant operational and financial disruption.
Figures & tables
Fig. 1: Reported Cyber Threats to Critical Infrastructure by Type and Sector, based on data from the FBI’s 2024 Internet Crime Report
Fig. 2: Few-shot sampling workflow showing dataset partitioning into support (K = 5 per class) and query (N = 2000 per class) sets for MAML training.
Fig. 3: Pipeline for few-shot malware detection. The process begins with stratified sampling to create support and query sets, followed by an autoencoder for feature extraction, and finally a classifier for malware detection.
Parameter
Value
Description
N (N-way)
2
Number of distinct classes per task (e.g., malware vs. benign)
K (K-shot)
5
Number of labeled samples per class in the support set
Q
10,000
Number of samples per class in the query set
TABLE I: Core Few-Shot Learning Parameters
Layer Name
Layer Type
Input Dim.
Output Dim.
Activation
Encoder Layer 1
nn.Linear
72
256
ReLU
Encoder Layer 2
nn.Linear
256
128
ReLU
Encoder Layer 3
nn.Linear
128
64
ReLU
Latent Space (Vector)
-
64
64
-
Classifier Layer 1
nn.Linear
64
128
ReLU
Classifier Layer 2
nn.Linear
128
64
ReLU
TABLE II: Architecture of the Autoencoder and the MAML Classifier
Fig. 4: Model-Agnostic Meta-Learning training process, showing (a) the inner-loop task adaptation where model parameters are updated based on a task’s loss, and (b) the outer-loop meta-optimization where the original parameters are updated to improve future adaptation.
Most corporate workplace environments enforce policies and technical controls that limit the storage of sensitive data on client endpoints. Consequently, ransomware operators have evolved variants that expand their attack surface from local systems to network drives and shared storage resources. As traditional endpoint detection mechanisms focus primarily on local system behaviour, a compromised client can impact remote file servers, such as by encrypting shared data, without directly triggering behavioural changes on the servers themselves. In this paper, we propose a hybrid detection framework for detecting crypto-ransomware intrusion within integrated file server and client environments. The framework is based on a new technique referred to as Region of Interest (RoI) to analyse network traffic and extract Indicators of Compromise (IoCs). The IoC repository serves as an additional ruleset to enhance existing security tools such as EDRs and IDSs, while RoI-derived features are used to train an ML model to detect highly evasive variants. This study incorporates a broader set of ransomwares families and carefully selected benign behaviors based on domain expertise, ensuring coverage of common user actions that could interfere with ransomware detection. Beyond IoCs, which operate in a signature-based manner, our machine learning module achieves a detection precision of 99.64%, with a 0% false negative rate (FNR) and a minimal false positive rate (FPR). Furthermore, the proposed method enables early detection, identifying ransomware intrusions before significant damage occurs, achieving an accuracy of 99.44%.
Gervais Hatungimana, Abdun Naser Mahmood, Mohammad Jabed Morshed Chowdhury
Department of Computer Science and Information Technology, La Trobe University, Melbourne, VIC, Australia
Malware classification remains a challenging problem due to its inherent heterogeneity, the presence of packed binaries, and the diverse distribution of malware families. Traditional single-model detection mechanisms often fail to generalize across such diverse data, leading to degraded performance, particularly on obfuscated and rare malware samples. In this work, we propose a unified multi-task malware analysis framework based on Mixture of Experts (MoE) architectures. The proposed system evaluates performance across two different input representations, i.e., high-dimensional EMBER feature sets and raw 1D byte arrays extracted from Portable Executable files. It simultaneously performs three critical tasks: malware family classification, packed versus unpacked detection, and malware versus benign identification. By decomposing the problem into specialized expert networks and employing adaptive gating mechanisms, the model enables effective task-specific learning while maintaining overall scalability. We investigate multiple architectural variants, including Homogeneous MoE, Heterogeneous MoE, and Multi-Gate MoE (MMoE). Performance is evaluated in both standard and adversarial settings using original and mutated samples. The obtained results demonstrate that the Multi-Gate MoE model achieves the best performance, reaching a combined detection rate of 0.9744 with only 2.56% failure rate. Moreover, this configuration exhibits improved robustness under mutation-induced distribution shifts. Our findings highlight the effectiveness of expert specialization and task-specific routing in handling complex malware distributions, making the proposed framework a promising direction for scalable and resilient malware detection systems.
Jithin S., Roshin Sleeba C., Anvin Mariya P. B. +4
Department of Computer Applications, Cochin University of Science and Technology, India · Department of Electrical, Computer and Biomedical Engineering, University of Pavia, Italy
Traditional malware detection methods struggle to generalize to obfuscated or previously unseen threats. This paper introduces ThreatVisionAI, a hybrid malware family classification framework that integrates a raw-image CNN, a wavelet-based CNN, and a Vision Transformer (ViT) to capture complementary spatial, frequency-domain, and global relational features in malware images. The wavelet-based CNN captures multi-scale frequency information that helps distinguish closely related families, while the ViT branch models long-range dependencies across the image. Evaluated on the Malimg dataset, ThreatVisionAI achieves 98.01% accuracy and a weighted F1 score of 0.9742, with wavelet-domain features providing measurable gains on minority and visually similar families. These results confirm that frequency-aware and transformer-based representations improve image-based malware family classification.
Allyson Taylor, Prashanth BusiReddyGari
Department of Mathematics & Computer Science University of North Carolina Pembroke