cs.CROct 1, 2026

A Hybrid Approach to Malware Detection: Integrating Few-Shot Model-Agnostic Meta-Learning with Autoencoders

Authors: Emmanuela Andam, Yasir Abbas Zaidi, Abdelali Hadir, Emmanuel Grant, Naima Kaabouch

Organizations: Artificial Intelligence Research (AIR) Center, University of North Dakota, Grand Forks, ND, USA · School of Electrical Engineering and Computer Science, University of North Dakota, Grand Forks, ND, USA · National School of Commerce and Management, Hassan II University, Casablanca, Morocco

Abstract

Ransomware has emerged as a major cybersecurity threat, with incidents increasing in frequency and impact across critical sectors. These attacks are typically launched through phishing emails, malicious downloads, or exploitation of software vulnerabilities to gain system access. Once inside, the malware encrypts files and demands a ransom, often in cryptocurrency, for the decryption key. Conventional detection methods often struggle with novel or scarce samples, leaving systems vulnerable. To address these challenges, this paper proposes a hybrid deep learning framework that combines an Autoencoder Feature Extractor (AFE) with a Model Agnostic Meta Learning (MAML) classifier for few shot malware detection. The AFE generates compact latent features that reduce noise and dimensionality, while the MAML classifier rapidly adapts to new threats using limited labeled data. Experiments conducted on the Ransomware Dataset 2024 demonstrate the effectiveness of the framework in binary classification tasks. Across one to fifty shot settings, the proposed model consistently achieves high accuracy, F1 score, and Matthews Correlation Coefficient values, maintaining reliable classification even under extreme scarcity. These results highlight the model's robustness and effectiveness in adapting to limited data scenarios, demonstrating the potential of combining feature extraction with meta learning to enhance resilience against malware, particularly in sectors such as healthcare, manufacturing, and public infrastructure, where cyberattacks can cause significant operational and financial disruption.

Figures & tables

Explore similar work

CardsList
  1. A Hybrid Framework For Crypto-Ransomware Detection In Enterprise Shared Storage

    Jun 29, 2026Gervais Hatungimana, Abdun Naser Mahmood, Mohammad Jabed Morshed ChowdhuryMalware

  2. A Multi-task Mixture of Experts Framework for Malware Classification, Packing Detection, and Family Attribution

    Jun 29, 2026Jithin S., Roshin Sleeba C., Anvin Mariya P. B. +4MalwareExperts

  3. ThreatVisionAI: A Hybrid CNN-ViT Framework for Image-Based Malware Classification

    Jul 4, 2026Allyson Taylor, Prashanth BusiReddyGariMalwareImage Classification