TY - GEN
T1 - Ransomware Detection with ML and Deep Learning
T2 - 2026 International Conference on Advances in Artificial Intelligence and Machine Learning, AAIML 2026
AU - Tritilanunt, Suratose
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - Ransomware remains a major threat that requires early and reliable detection. This paper offers an evidence-based survey and a drift-aware taxonomy that help practitioners choose between classic machine learning (ML) and deep learning (DL) across static, dynamic, and graph-based feature regimes. We outline when lightweight tree-based ML provides strong accuracy and low latency, and when sequence or graph DL adds value on long, high-quality traces despite higher compute cost. We high-light common pitfalls-especially random splits and insufficient temporal testing-that inflate performance under concept drift, and recommend time-aware evaluation with temporal splits and challenge subsets. We summarize the space into a feature-method matching table and a deployment-oriented decision flow, and we recommend hybrid pipelines where fast static or aggregated dynamic ML acts as a filter and heavier DL as a confirmer. Practical routines for continual learning and lightweight drift monitoring (e.g., feature-frequency or trace-coverage shifts) are also provided. Finally, we call for a dynamic, drift-aware benchmark analogous to EMBER2024 and emphasize minimum reporting standards: FPR@TPR at fixed operating points (0.1%, 1%), end-to-end latency (p50/p95), and clear sandbox/EDR configuration.
AB - Ransomware remains a major threat that requires early and reliable detection. This paper offers an evidence-based survey and a drift-aware taxonomy that help practitioners choose between classic machine learning (ML) and deep learning (DL) across static, dynamic, and graph-based feature regimes. We outline when lightweight tree-based ML provides strong accuracy and low latency, and when sequence or graph DL adds value on long, high-quality traces despite higher compute cost. We high-light common pitfalls-especially random splits and insufficient temporal testing-that inflate performance under concept drift, and recommend time-aware evaluation with temporal splits and challenge subsets. We summarize the space into a feature-method matching table and a deployment-oriented decision flow, and we recommend hybrid pipelines where fast static or aggregated dynamic ML acts as a filter and heavier DL as a confirmer. Practical routines for continual learning and lightweight drift monitoring (e.g., feature-frequency or trace-coverage shifts) are also provided. Finally, we call for a dynamic, drift-aware benchmark analogous to EMBER2024 and emphasize minimum reporting standards: FPR@TPR at fixed operating points (0.1%, 1%), end-to-end latency (p50/p95), and clear sandbox/EDR configuration.
KW - Deep learning
KW - Machine learning
KW - Ransomware detection
UR - https://www.scopus.com/pages/publications/105040590243
U2 - 10.1109/AAIML67890.2026.11498152
DO - 10.1109/AAIML67890.2026.11498152
M3 - Conference contribution
AN - SCOPUS:105040590243
T3 - 2026 International Conference on Advances in Artificial Intelligence and Machine Learning, AAIML 2026
SP - 181
EP - 186
BT - 2026 International Conference on Advances in Artificial Intelligence and Machine Learning, AAIML 2026
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 20 March 2026 through 22 March 2026
ER -