Few Shot Learning For Ransomware Detection Using Siamese Neural Network
DOI:
https://doi.org/10.33003/fjs-2026-1012-5348Keywords:
Deep Learning (DL), Few Short Learning (FSL), Machine Learning (ML), Ransomware Detection (RD)Abstract
Ransomware poses a threat to the availability, confidentiality and integrity of an individual's, organization, or a company’s sensitive data. The attack involves locking digital data and holding its hostage until the attacker receives ransom. Due to the rapid spread of devices and interconnectedness, the increasing prevalence of ransomware attacks is concerning. Several research have been proposed, tested, evaluated and published to improve the methodology and implementation of ransomware detection methods, from behavioral, dynamic to static-based detection. Much research has been focusing on machine learning and deep learning to enhance detection accuracy. However, deep learning, with its advantage over traditional techniques, is hindered by its dependence on large number of datasets, often referred to as "data hunger". An emerging approach called few-shot learning (FSL) method is being used in various domains especially in cyber security due to its effectiveness in cases with limited data. This study investigates the usefulness of FSL in ransomware detection and explores the performance of this model with less data, utilizing its strengths to create a robust, unified model to accurately detect and classify ransomware and good wares. Utilizing the ransomware access pattern (Ransap) dataset converted into grayscale images, the proposed techniques improved the classification performance. Specifically, accuracy increased from 97.69% to 98.33%, precision from 95.71% to 97.52%, and the F1-score from 97.31% to 98.33%. In addition, the model achieved a recall of 99.16% and an AUC of 99.03%, compared with the benchmark values of 100% for both recall and AUC.
References
Ale, L., Li, L., Kar, D., Zhang, N., Palikhe, A., & Christi, C. (2020). Few-Shot Learning to Classify Android Malwares. 1001–1007. https://doi.org/10.1109/ICSIP49896.2020.9339429
Arabo, A., Dijoux, R., Poulain, T., & Chevalier, G. (2020). ScienceDirect ScienceDirect ScienceDirect Detecting Ransomware Using Process Behavior Analysis Detecting Ransomware Using Process Behavior Analysis. Procedia Computer Science, 168(2019), 289–296. https://doi.org/10.1016/j.procs.2020.02.249
Cheng, G., Guo, C., & Tang, Y. (2019). dptCry : an approach to decrypting ransomware WannaCry based on API hooking. CCF Transactions on Networking, 0123456789. https://doi.org/10.1007/s42045-019-00024-8
Davidian, M., Kiperberg, M., & Vanetik, N. (2024). Early Ransomware Detection with Deep Learning Models.
Duan, R., Li, D., Tong, Q., Yang, T., Liu, X., & Liu, X. (2021). A Survey of Few-Shot Learning : An Effective Method for Intrusion Detection. 2021. https://doi.org/10.1155/2021/4259629
Dauda, M. K., Ahmad, I., & Alassafi, M. O. (2024). ENHANCING RANSOMWARE DETECTION USING SIAMESE NETWORK. April. https://doi.org/10.59018/022438
Hampton, N., Baig, Z., & Zeadally, S. (2018). Journal of Information Security and Applications Ransomware behavioural analysis on windows platforms. 40, 44–51. https://doi.org/10.1016/j.jisa.2018.02.008
Hwang, J., Kim, J., Lee, S., & Kim, K. (2020). Two ‑ Stage Ransomware Detection Using Dynamic Analysis and Machine Learning Techniques. Wireless Personal Communications, 112(4), 2597–2609. https://doi.org/10.1007/s11277-020-07166-9
Khan, F., Ncube, C., Ramasamy, L. K., Kadry, S., & Nam, Y. (2020). A Digital DNA Sequencing Engine for Ransomware Detection Using Machine Learning. IEEE Access, 8, 119710–119719. https://doi.org/10.1109/ACCESS.2020.3003785
Mercaldo, F. (2021). A framework for supporting ransomware detection and prevention based on hybrid analysis. Journal of Computer Virology and Hacking Techniques, 17(3), 221–227. https://doi.org/10.1007/s11416-021-00388-w
Parkar, P. (2021). A Survey on Cyber Security IDS using ML Methods. ICICCS.
Qiang, Q., Cheng, M., Hu, Y., Zhou, Y., Sun, J., Ding, Y., Qi, Z., & Jiao, F. (n.d.). An Incremental Malware Classification Approach Based on Few-Shot Learning. ICC 2022 - IEEE International Conference on Communications, 2682–2687. https://doi.org/10.1109/ICC45855.2022.9838295
Raza, D. M., & Victor, D. B. (2021). Crime Using Random Forest. Proceedings of the International Conference on Artificial Intelligence and Smart Systems (ICAIS-2021), 7, 980–987.
Razaulla, S., Fachkha, C., Markarian, C., Gawanmeh, A., Member, S., Mansoor, W., & Member, S. (2023). The Age of Ransomware : A Survey on the Evolution , Taxonomy , and Research Directions. IEEE Access, 11(April), 40698–40723. https://doi.org/10.1109/ACCESS.2023.3268535
Sciences, N. (2023). Emerging Threats in Cybersecurity: A Review Article. 1–9.
Snell, J., Swersky, K., & Zemel, R. (2017). Prototypical Networks for Few-shot Learning. Nips.
Source, S. (2024). Annual share of organizations affected by ransomware attacks worldwide from 2018 to 2023. 1–4.
Sreelaja, N. K. (2021). Ant Colony Optimization based Light weight Binary Search for efficient signature matching to filter Ransomware. Applied Soft Computing, 111, 107635. https://doi.org/10.1016/j.asoc.2021.107635
Tran, T. K., Sato, H., & Kubo, M. (2019). Image-based Unknown Malware Classification with Few-Shot Learning Models.
Xin, C., Liu, Z., Zhao, K., Miao, L., Ma, Y., Zhu, X., Zhou, Q., Wang, S., Li, L., Yang, F., Xu, S., & Chen, H. (2024). An improved transformer network for skin cancer classification. Computers in Biology and Medicine, 149(June), 105939. https://doi.org/10.1016/j.compbiomed.2022.105939
Yang, A., Lu, C., Li, J., Huang, X., Ji, T., & Li, X. (2023). Application of meta-learning in cyberspace security : a survey. Digital Communications and Networks, 9(1), 67–78. https://doi.org/10.1016/j.dcan.2022.03.007
Yilmaz, Y., Cetin, O., Arief, B., & Hernandez-castro, J. (2021). Journal of Information Security and Applications Investigating the impact of ransomware splash screens. Journal of Information Security and Applications, 61(July), 102934. https://doi.org/10.1016/j.jisa.2021.102934
Zhang, H., & Zhang, S. (2024). Focaler-IoU: More Focused Intersection over Union Loss. 1–4.
Zhu, J., Jang-Jaccard, J., Singh, A., Welch, I., AL-Sahaf, H., & Camtepe, S. (2022). A few-shot meta-learning based siamese neural network using entropy features for ransomware classification. Computers and Security, 117. https://doi.org/10.1016/j.cose.2022.102691
Downloads
Published
Issue
Section
Categories
License
Copyright (c) 2026 Usman Ahmad Bello, Abubakar Bello Tambuwal, Anas Tukur Balarabe

This work is licensed under a Creative Commons Attribution 4.0 International License.