Organizations: Artificial Intelligence Research (AIR) Center, University of North Dakota, Grand Forks, ND, USA · School of Electrical Engineering and Computer Science, University of North Dakota, Grand Forks, ND, USA · National School of Commerce and Management, Hassan II University, Casablanca, Morocco
Ransomware has emerged as a major cybersecurity threat, with incidents increasing in frequency and impact across critical sectors. These attacks are typically launched through phishing emails, malicious downloads, or exploitation of software vulnerabilities to gain system access. Once inside, the malware encrypts files and demands a ransom, often in cryptocurrency, for the decryption key. Conventional detection methods often struggle with novel or scarce samples, leaving systems vulnerable. To address these challenges, this paper proposes a hybrid deep learning framework that combines an Autoencoder Feature Extractor (AFE) with a Model Agnostic Meta Learning (MAML) classifier for few shot malware detection. The AFE generates compact latent features that reduce noise and dimensionality, while the MAML classifier rapidly adapts to new threats using limited labeled data. Experiments conducted on the Ransomware Dataset 2024 demonstrate the effectiveness of the framework in binary classification tasks. Across one to fifty shot settings, the proposed model consistently achieves high accuracy, F1 score, and Matthews Correlation Coefficient values, maintaining reliable classification even under extreme scarcity. These results highlight the model's robustness and effectiveness in adapting to limited data scenarios, demonstrating the potential of combining feature extraction with meta learning to enhance resilience against malware, particularly in sectors such as healthcare, manufacturing, and public infrastructure, where cyberattacks can cause significant operational and financial disruption.
Figures & tables
Fig. 1: Reported Cyber Threats to Critical Infrastructure by Type and Sector, based on data from the FBI’s 2024 Internet Crime Report
Fig. 2: Few-shot sampling workflow showing dataset partitioning into support (K = 5 per class) and query (N = 2000 per class) sets for MAML training.
Fig. 3: Pipeline for few-shot malware detection. The process begins with stratified sampling to create support and query sets, followed by an autoencoder for feature extraction, and finally a classifier for malware detection.
Parameter
Value
Description
N (N-way)
2
Number of distinct classes per task (e.g., malware vs. benign)
K (K-shot)
5
Number of labeled samples per class in the support set
Q
10,000
Number of samples per class in the query set
TABLE I: Core Few-Shot Learning Parameters
Layer Name
Layer Type
Input Dim.
Output Dim.
Activation
Encoder Layer 1
nn.Linear
72
256
ReLU
Encoder Layer 2
nn.Linear
256
128
ReLU
Encoder Layer 3
nn.Linear
128
64
ReLU
Latent Space (Vector)
-
64
64
-
Classifier Layer 1
nn.Linear
64
128
ReLU
Classifier Layer 2
nn.Linear
128
64
ReLU
TABLE II: Architecture of the Autoencoder and the MAML Classifier
Fig. 4: Model-Agnostic Meta-Learning training process, showing (a) the inner-loop task adaptation where model parameters are updated based on a task’s loss, and (b) the outer-loop meta-optimization where the original parameters are updated to improve future adaptation.
Jun 29, 2026·Jithin S., Roshin Sleeba C., Anvin Mariya P. B. +4MalwareExperts
Department of Computer Applications, Cochin University of Science and Technology, India · Department of Electrical, Computer and Biomedical Engineering, University of Pavia, Italy