arXiv:cs.LG(机器学习,全量分类)· Emmanuela Andam, Yasir Abbas Zaidi, Abdelali Hadir, Emmanuel Grant, Naima Kaabouch·· 18 小时前AI 评分29
混合深度学习方法用于恶意软件检测:Autoencoder 特征提取结合 MAML 少样本分类
A Hybrid Approach to Malware Detection: Integrating Few-Shot Model-Agnostic Meta-Learning with Autoencoders
AI 导读
该论文提出一种混合深度学习框架,将 Autoencoder 特征提取器(AFE)与 Model Agnostic Meta Learning(MAML)分类器结合,用于少样本恶意软件检测。在 Ransomware Dataset 2024 上,模型在 1 至 50 shot 设置下均保持高准确率、F1 分数和 Matthews 相关系数,极端样本稀缺时仍能可靠分类。
正文
Abstract:Ransomware has emerged as a major cybersecurity threat, with incidents increasing in frequency and impact across critical sectors. These attacks are typically launched through phishing emails, malicious downloads, or exploitation of software vulnerabilities to gain system access. Once inside, the malware encrypts files and demands a ransom, often in cryptocurrency, for the decryption key. Conventional detection methods often struggle with novel or scarce samples, leaving systems vulnerable. To address these challenges, this paper proposes a hybrid deep learning framework that combines an Autoencoder Feature Extractor (AFE) with a Model Agnostic Meta Learning (MAML) classifier for few shot malware detection. The AFE generates compact latent features that reduce noise and dimensionality, while the MAML classifier rapidly adapts to new threats using limited labeled data. Experiments conducted on the Ransomware Dataset 2024 demonstrate the effectiveness of the framework in binary classification tasks. Across one to fifty shot settings, the proposed model consistently achieves high accuracy, F1 score, and Matthews Correlation Coefficient values, maintaining reliable classification even under extreme scarcity. These results highlight the model's robustness and effectiveness in adapting to limited data scenarios, demonstrating the potential of combining feature extraction with meta learning to enhance resilience against malware, particularly in sectors such as healthcare, manufacturing, and public infrastructure, where cyberattacks can cause significant operational and financial disruption.
| Comments: | Accepted at 2025 Cyber Awareness and Research Symposium (CARS). This is the author's accepted manuscript |
| Subjects: | Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI); Machine Learning (cs.LG) |
| Cite as: | arXiv:2610.01949 [cs.CR] |
| (or arXiv:2610.01949v1 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2610.01949 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Emmanuela Andam [view email]
[v1]
Thu, 1 Oct 2026 16:11:35 UTC (2,016 KB)
来源:arXiv:cs.LG(机器学习,全量分类) · arxiv.org