Enhancing Ransomware Detection Accuracy Through Data-Driven Incremental Machine Learning Models for Predictive Analysis

Vyom Kulshreshtha, Deepak Motwani, Pankaj Sharma · 2025

The increasing use of obfuscation techniques by attackers has made the detection of novel ransomware variants more challenging for traditional detection systems. This study presents a data-driven machine learning approach to enhance ransomware detection accuracy using the CIC-MalMem2022 dataset. After comprehensive preprocessing, including noise reduction, feature engineering, label encoding, and normalization, three incremental learning models were implemented: Stochastic Gradient Descent (SGD) Classifier, Passive Aggressive Classifier (PAC), and Hoeffding Tree Classifier (HTC). Performance evaluation revealed that SGD achieved the highest accuracy, precision, recall, and F1score (all at 99.94%) with the lowest log loss (0.0021) and minimal computation time (0.03s), outperforming PAC and HTC in both predictive accuracy and efficiency. Model interpretability, assessed using LIME, highlighted key features influencing predictions, affirming the robustness of the SGD model. Compared to traditional models like XGBoost and Deep Neural Networks, which performed significantly lower, the incremental learning models, particularly SGD, demonstrated superior accuracy, speed, and interpretability, making them highly effective for real-time ransomware detection.

Read the paper · More papers on PaperTik