Ransomware Detection Utilizing Ensemble Based Interpretable Deep Learning Model

Tanjir Alam Chisty, Md. Mijanur Rahman · 2024

Ransomware, a form of malicious software, encrypts victim data and renders it inaccessible until a ransom is paid. Different ransomware variants employ various tactics to avoid detection during their attacks. Understanding the techniques used in ransomware development and deployment is crucial to counter these threats. This study presents a stacked ensemble-based machine learning (ML) approach for ransomware detection. The ensemble model consists of Naive Bayes (NB), Random Forest (RF), and K-Nearest Neibors (KNN) as base classifiers and Artificial Neural Network (ANN) as meta-classifiers. Additionally, Explainable AI (XAI) utilizing LIME and SHAP has been applied to gain insights into prediction outcomes and validate model correctness. The use of LIME and SHAP ensures the inter-pretability of the model, which is a crucial factor in real-world implications. The research employs a publicly available dataset and evaluates the model using multiple metrics. Experimental results reveal that the proposed model achieves an impressive accuracy of 98.57%. The model is benchmarked against existing ML techniques, demonstrating its superior performance.

Read the paper · More papers on PaperTik