HFL-RD: Heterogeneous Federated Learning-Empowered Ransomware Detection via APIs and Traffic Features

Kun Lan, Gaolei Li, Wenkai Huang, Jianhua Li · IEEE Transactions on Network and Service Management · 2025

Ransomware has evolved into a more organized attack threat with stronger anti detection and analysis capabilities, resulting in significant global losses. However, traditional methods separate the external and internal behaviors of ransomware infiltration into attack targets, making it difficult to discover the complex and covert evolution and iteration characteristics of advanced ransomware. The main contribution of this study lies in three aspects: a) The integration of Command-and-control (C&C) traffic behavior analysis and local API call operation analysis can effectively discern and capture the concealed characteristics of ransomware; b) The non-IID problem in aggregating ransomware features using federated learning can be resolved using dynamic regularization methods and penalty terms; c) By preprocessing the original data of ransomware traffic through one-dimensional convolution, the structural characteristics of network traffic in the process of attack operation can be retained to the greatest extent. Comprehensive experiments are conducted to validate the effectiveness of this model, specifically, the heterogeneous federated learning-empowered ransomware detection (HFL-RD) scheme outperformed existing methods, the experimental dataset gathered runnable ransomware from three public websites, including 300 ransomware samples from 30 families and 200 benign software samples from 7 categories. HFL-RD obtained a high accuracy over 95%. In terms of detecting unknown ransomware variants, it has demonstrated superior detection capabilities in terms of detection time and number of file corruption.

Read the paper · More papers on PaperTik