Few Shot Learning For Ransomware Detection Using Siamese Neural Network

Authors

  • Usman Ahmad Bello Sokoto State University image/svg+xml
  • Abubakar Bello Tambuwal
  • Anas Tukur Balarabe

DOI:

https://doi.org/10.33003/fjs-2026-1012-5348

Keywords:

Deep Learning (DL), Few Short Learning (FSL), Machine Learning (ML), Ransomware Detection (RD)

Abstract

Ransomware poses a threat to the availability, confidentiality and integrity of an individual's, organization, or a company’s sensitive data. The attack involves locking digital data and holding its hostage until the attacker receives ransom. Due to the rapid spread of devices and interconnectedness, the increasing prevalence of ransomware attacks is concerning. Several research have been proposed, tested, evaluated and published to improve the methodology and implementation of ransomware detection methods, from behavioral, dynamic to static-based detection. Much research has been focusing on machine learning and deep learning to enhance detection accuracy. However, deep learning, with its advantage over traditional techniques, is hindered by its dependence on large number of datasets, often referred to as "data hunger". An emerging approach called few-shot learning (FSL) method is being used in various domains especially in cyber security due to its effectiveness in cases with limited data. This study investigates the usefulness of FSL in ransomware detection and explores the performance of this model with less data, utilizing its strengths to create a robust, unified model to accurately detect and classify ransomware and good wares. Utilizing the ransomware access pattern (Ransap) dataset converted into grayscale images, the proposed techniques improved the classification performance. Specifically, accuracy increased from 97.69% to 98.33%, precision from 95.71% to 97.52%, and the F1-score from 97.31% to 98.33%. In addition, the model achieved a recall of 99.16% and an AUC of 99.03%, compared with the benchmark values of 100% for both recall and AUC. 

Author Biographies

  • Abubakar Bello Tambuwal

    Senior Lecturer

  • Anas Tukur Balarabe

    Senior Lecturer

References

Ale, L., Li, L., Kar, D., Zhang, N., Palikhe, A., & Christi, C. (2020). Few-Shot Learning to Classify Android Malwares. 1001–1007. https://doi.org/10.1109/ICSIP49896.2020.9339429

Arabo, A., Dijoux, R., Poulain, T., & Chevalier, G. (2020). ScienceDirect ScienceDirect ScienceDirect Detecting Ransomware Using Process Behavior Analysis Detecting Ransomware Using Process Behavior Analysis. Procedia Computer Science, 168(2019), 289–296. https://doi.org/10.1016/j.procs.2020.02.249

Cheng, G., Guo, C., & Tang, Y. (2019). dptCry : an approach to decrypting ransomware WannaCry based on API hooking. CCF Transactions on Networking, 0123456789. https://doi.org/10.1007/s42045-019-00024-8

Davidian, M., Kiperberg, M., & Vanetik, N. (2024). Early Ransomware Detection with Deep Learning Models.

Duan, R., Li, D., Tong, Q., Yang, T., Liu, X., & Liu, X. (2021). A Survey of Few-Shot Learning : An Effective Method for Intrusion Detection. 2021. https://doi.org/10.1155/2021/4259629

Dauda, M. K., Ahmad, I., & Alassafi, M. O. (2024). ENHANCING RANSOMWARE DETECTION USING SIAMESE NETWORK. April. https://doi.org/10.59018/022438

Hampton, N., Baig, Z., & Zeadally, S. (2018). Journal of Information Security and Applications Ransomware behavioural analysis on windows platforms. 40, 44–51. https://doi.org/10.1016/j.jisa.2018.02.008

Hwang, J., Kim, J., Lee, S., & Kim, K. (2020). Two ‑ Stage Ransomware Detection Using Dynamic Analysis and Machine Learning Techniques. Wireless Personal Communications, 112(4), 2597–2609. https://doi.org/10.1007/s11277-020-07166-9

Khan, F., Ncube, C., Ramasamy, L. K., Kadry, S., & Nam, Y. (2020). A Digital DNA Sequencing Engine for Ransomware Detection Using Machine Learning. IEEE Access, 8, 119710–119719. https://doi.org/10.1109/ACCESS.2020.3003785

Mercaldo, F. (2021). A framework for supporting ransomware detection and prevention based on hybrid analysis. Journal of Computer Virology and Hacking Techniques, 17(3), 221–227. https://doi.org/10.1007/s11416-021-00388-w

Parkar, P. (2021). A Survey on Cyber Security IDS using ML Methods. ICICCS.

Qiang, Q., Cheng, M., Hu, Y., Zhou, Y., Sun, J., Ding, Y., Qi, Z., & Jiao, F. (n.d.). An Incremental Malware Classification Approach Based on Few-Shot Learning. ICC 2022 - IEEE International Conference on Communications, 2682–2687. https://doi.org/10.1109/ICC45855.2022.9838295

Raza, D. M., & Victor, D. B. (2021). Crime Using Random Forest. Proceedings of the International Conference on Artificial Intelligence and Smart Systems (ICAIS-2021), 7, 980–987.

Razaulla, S., Fachkha, C., Markarian, C., Gawanmeh, A., Member, S., Mansoor, W., & Member, S. (2023). The Age of Ransomware : A Survey on the Evolution , Taxonomy , and Research Directions. IEEE Access, 11(April), 40698–40723. https://doi.org/10.1109/ACCESS.2023.3268535

Sciences, N. (2023). Emerging Threats in Cybersecurity: A Review Article. 1–9.

Snell, J., Swersky, K., & Zemel, R. (2017). Prototypical Networks for Few-shot Learning. Nips.

Source, S. (2024). Annual share of organizations affected by ransomware attacks worldwide from 2018 to 2023. 1–4.

Sreelaja, N. K. (2021). Ant Colony Optimization based Light weight Binary Search for efficient signature matching to filter Ransomware. Applied Soft Computing, 111, 107635. https://doi.org/10.1016/j.asoc.2021.107635

Tran, T. K., Sato, H., & Kubo, M. (2019). Image-based Unknown Malware Classification with Few-Shot Learning Models.

Xin, C., Liu, Z., Zhao, K., Miao, L., Ma, Y., Zhu, X., Zhou, Q., Wang, S., Li, L., Yang, F., Xu, S., & Chen, H. (2024). An improved transformer network for skin cancer classification. Computers in Biology and Medicine, 149(June), 105939. https://doi.org/10.1016/j.compbiomed.2022.105939

Yang, A., Lu, C., Li, J., Huang, X., Ji, T., & Li, X. (2023). Application of meta-learning in cyberspace security : a survey. Digital Communications and Networks, 9(1), 67–78. https://doi.org/10.1016/j.dcan.2022.03.007

Yilmaz, Y., Cetin, O., Arief, B., & Hernandez-castro, J. (2021). Journal of Information Security and Applications Investigating the impact of ransomware splash screens. Journal of Information Security and Applications, 61(July), 102934. https://doi.org/10.1016/j.jisa.2021.102934

Zhang, H., & Zhang, S. (2024). Focaler-IoU: More Focused Intersection over Union Loss. 1–4.

Zhu, J., Jang-Jaccard, J., Singh, A., Welch, I., AL-Sahaf, H., & Camtepe, S. (2022). A few-shot meta-learning based siamese neural network using entropy features for ransomware classification. Computers and Security, 117. https://doi.org/10.1016/j.cose.2022.102691

FSL Model System Architecture

Downloads

Published

24-07-2026

How to Cite

Ahmad Bello, U., Bello Tambuwal, A., & Tukur Balarabe, A. (2026). Few Shot Learning For Ransomware Detection Using Siamese Neural Network. FUDMA JOURNAL OF SCIENCES, 10(12), 85-93. https://doi.org/10.33003/fjs-2026-1012-5348