arXiv Machine Learning

A Hybrid Framework For Crypto-Ransomware Detection In Enterprise Shared Storage

arXiv:2606. 30586v1 Announce Type: cross Abstract: Most corporate workplace environments enforce policies and technical controls that limit the storage of sensitive data on client endpoints.

arXiv AI
Sep 7

Cost-Aware Hierarchical Multi-Agent Ransomware Detection and Family Attribution

The paper introduces a Cost-Aware Hierarchical Multi-Agent System (HMAS) for ransomware detection and family attribution that adaptively selects analysis modalities to balance accuracy and computational cost. Static analysis is used first, with dynamic and memory modalities added only when confidence is low or specialist agents disagree, guided by a cost model. Experiments show HMAS achieves high accuracy (96.57% binary detection, 0.90 macro‑F1 attribution) while reducing analysis cost by 43.97% and latency, with 56.05% of cases resolved using static evidence alone.

By Mubashar Iqbal, Asifullah Khan
arXiv Machine Learning
Sep 24

Enhancing Multiclass Malware Classification in Resource-Constrained Environments

The paper presents a lightweight machine‑learning approach for multi‑class malware detection on resource‑constrained devices. Using a LightGBM classifier with SMOTE oversampling, SOM‑US undersampling, and Genetic‑Algorithm feature selection, the authors achieve 89.1 % accuracy on four malware families and 76 % on 16 individual malware types. A second Random‑Forest model further improves family classification to 91.2 % and individual classification to 78.7 %.

By Abdul Khalek Alve, Alif Rahman, Saadman Zaman, Sazzad Hossen Himel, Muhammad Iqbal Hossain
arXiv Machine Learning
Sep 21

Identifying Security Platform Product Abuse with Machine Learning

arXiv:2609.21303v1 Announce Type: cross Abstract: Product abuse is an individually rare, but growing, problem across the SaaS industry. Highly sophisticated threat actors can misuse security platform...

By Shaefer Drew, Michael Brautbar, Paul Knight, Edward Raff, Lana Peric-McDermott, Simran Sarin, Nickolas Machado, Hanna Albright, Vitaly Zaytsev
arXiv Machine Learning
Sep 18

Delphi Scanner: efficient and interpretable static malware detection via API sequence modeling

Delphi Scanner is a static malware detection system for Windows PE files that balances efficiency and interpretability. It employs a convolutional neural network to model Windows API sequences and a rule‑based interpretation layer to map APIs to high‑level malicious capabilities. Tested on over 190,000 PE files, it achieves 95.35% accuracy with a 1.53 MB model, and demonstrates robustness against out‑of‑distribution samples and adversarial manipulations.

By Bijied Brahimi, Vincent Cohadon, Gabriel Glazman, Rayan Al Mohaize, Omran Berjawi, Rida Khatoun