Mobile Ransomware Detection Leveraging Swarm Intelligence and Machine Learning: A KELM-Based Approach

preprint OA: closed CC-BY-4.0
📄 Open PDF Full text JSON View at publisher

Abstract

Abstract Mobile dependence amplifies privacy risks associated with advanced malware threats such as ransomware, Trojan horses, botnet and spyware. Ransomware, in particular, encrypts those portable devices, demanding payment for access, presenting a critical challenge for user privacy, economic stability, and corporate trust. This paper proposes an effective strategy leveraging machine learning and swarm intelligence. Our strategy incorporates the Kernel Extreme Learning Machine (KELM) for efficient data processing and a Sand Cat Swarm Optimization (SCSO) algorithm for optimal parameter selection. The paper also highlights the most important features for accurate detection and shows the potential risks associated with these threats, such as unauthorized access to personal information , changes to phone and network data, and gaining deep control over the device. While the KELM algorithm is used to classify the mobile applications (apps) as either ransomware or non-ransomware, the SCSO functionality looks for the best features and ideal values for the KELM hyperparameters. To evaluate the effectiveness of the proposed system, we used a dataset comprising 1000 real-world samples collected from diverse platforms including Koodous, Virus Total, HelDroid, and RansomProper security projects, as well as benign applications obtained from the official Google Play Store. The experiments were then divided into two parts: the evaluation of the SCSO swarm size and the inquiries into the hybridization of the logarithmic operator. To identify ransomware, the optimal SCSO version with the KELM is utilized, and its efficacy is contrasted with other traditional machine learning methods. When compared to other algorithms, the suggested (SCSO-KELM) performs better in terms of several evaluation metrics, including promising convergence characteristics. The proposed method outperforms others in various metrics.
Full text 13,271 characters · extracted from preprint-html · click to expand
Mobile Ransomware Detection Leveraging Swarm Intelligence and Machine Learning: A KELM-Based Approach | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Mobile Ransomware Detection Leveraging Swarm Intelligence and Machine Learning: A KELM-Based Approach Ruba Abu Khurma, Moutaz Alazab, Yaning Xiao, Keshav Sood, Shui Yu, and 3 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-5302086/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Mobile dependence amplifies privacy risks associated with advanced malware threats such as ransomware, Trojan horses, botnet and spyware. Ransomware, in particular, encrypts those portable devices, demanding payment for access, presenting a critical challenge for user privacy, economic stability, and corporate trust. This paper proposes an effective strategy leveraging machine learning and swarm intelligence. Our strategy incorporates the Kernel Extreme Learning Machine (KELM) for efficient data processing and a Sand Cat Swarm Optimization (SCSO) algorithm for optimal parameter selection. The paper also highlights the most important features for accurate detection and shows the potential risks associated with these threats, such as unauthorized access to personal information , changes to phone and network data, and gaining deep control over the device. While the KELM algorithm is used to classify the mobile applications (apps) as either ransomware or non-ransomware, the SCSO functionality looks for the best features and ideal values for the KELM hyperparameters. To evaluate the effectiveness of the proposed system, we used a dataset comprising 1000 real-world samples collected from diverse platforms including Koodous, Virus Total, HelDroid, and RansomProper security projects, as well as benign applications obtained from the official Google Play Store. The experiments were then divided into two parts: the evaluation of the SCSO swarm size and the inquiries into the hybridization of the logarithmic operator. To identify ransomware, the optimal SCSO version with the KELM is utilized, and its efficacy is contrasted with other traditional machine learning methods. When compared to other algorithms, the suggested (SCSO-KELM) performs better in terms of several evaluation metrics, including promising convergence characteristics. The proposed method outperforms others in various metrics. Mobile Malware Ransomware Detection Machine Learning Swarm Intelligence Kernel Extreme Learning Machine (KELM) Sand Cat Swarm Optimization (SCSO) Feature Selection Hybrid Algorithms Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-5302086","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":370026754,"identity":"2530857c-a026-49fa-a224-13216415cd62","order_by":0,"name":"Ruba Abu Khurma","email":"","orcid":"","institution":"Al-Huson University College, Al-Balqa Applied University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Ruba","middleName":"Abu","lastName":"Khurma","suffix":""},{"id":370026755,"identity":"5198967c-fcb0-4a54-8f69-d6c592eda5cd","order_by":1,"name":"Moutaz Alazab","email":"","orcid":"","institution":"Al-Balqa Applied University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Moutaz","middleName":"","lastName":"Alazab","suffix":""},{"id":370026756,"identity":"f5757b14-1b60-4962-b2e3-988d4ff98372","order_by":2,"name":"Yaning Xiao","email":"","orcid":"","institution":"Southern University of Science and Technology","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Yaning","middleName":"","lastName":"Xiao","suffix":""},{"id":370026757,"identity":"4ea8c6c7-d1c2-4c07-8cee-52ae8996d3ca","order_by":3,"name":"Keshav Sood","email":"","orcid":"","institution":"Deakin University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Keshav","middleName":"","lastName":"Sood","suffix":""},{"id":370026758,"identity":"75968808-fa7c-4b99-8b9c-ab03f3f31e18","order_by":4,"name":"Shui Yu","email":"","orcid":"","institution":"The University of Technology Sydney","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Shui","middleName":"","lastName":"Yu","suffix":""},{"id":370026759,"identity":"355b03f9-d76b-48fc-93a2-dfc5a34c782d","order_by":5,"name":"Tony Jan","email":"","orcid":"","institution":"Torrens University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Tony","middleName":"","lastName":"Jan","suffix":""},{"id":370026760,"identity":"e81a01f1-43b8-4da0-af03-0dc140600a35","order_by":6,"name":"Mohd Asif Shah","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAwklEQVRIiWNgGAWjYDACCRBhICcHog48IEGLsTFYSwLxWhiMExtAFFFa+KWbH378UWCQPj/s8EOgLXZyug0EtEjOOWYszWNgkLvxdpoBUEuysdkBAloMbiQYSDMY/MndODsBpOVA4jbCWtI///xhYJBuODv9A7FacswkgA5LkJfOIdIWyRk5ZdZALYYbpHMKDiQYEOEXfon0zTd//DGQl5+dvvnDhwo7OYJaEC4EqzQgVjkIyDeQonoUjIJRMApGFAAA/FhDpQIRtLUAAAAASUVORK5CYII=","orcid":"","institution":"Bakhtar University","correspondingAuthor":true,"submittingAuthor":false,"prefix":"","firstName":"Mohd","middleName":"Asif","lastName":"Shah","suffix":""},{"id":370026761,"identity":"1abd06f6-9639-438b-9c38-f2157a753aeb","order_by":7,"name":"Saurav Mallik","email":"","orcid":"","institution":"Harvard T H Chan School of Public Health","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Saurav","middleName":"","lastName":"Mallik","suffix":""}],"badges":[],"createdAt":"2024-10-21 07:38:12","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-5302086/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-5302086/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":68048390,"identity":"2e0951d1-4df9-4f29-8dd8-bb7fac11c8ae","added_by":"auto","created_at":"2024-11-01 19:16:33","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":671614,"visible":true,"origin":"","legend":"","description":"","filename":"HYBRIDRANSOMWAREAPPROACH.pdf","url":"https://assets-eu.researchsquare.com/files/rs-5302086/v1_covered_9ebbe84f-e68f-4b76-842f-022db0fadb07.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Mobile Ransomware Detection Leveraging Swarm Intelligence and Machine Learning: A KELM-Based Approach","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Mobile Malware, Ransomware Detection, Machine Learning, Swarm Intelligence, Kernel Extreme Learning Machine (KELM), Sand Cat Swarm Optimization (SCSO), Feature Selection, Hybrid Algorithms","lastPublishedDoi":"10.21203/rs.3.rs-5302086/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-5302086/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"Mobile dependence amplifies privacy risks associated with advanced malware threats such as ransomware, Trojan horses, botnet and spyware. Ransomware, in particular, encrypts those portable devices, demanding payment for access, presenting a critical challenge for user privacy, economic stability, and corporate trust. This paper proposes an effective strategy leveraging machine learning and swarm intelligence. Our strategy incorporates the Kernel Extreme Learning Machine (KELM) for efficient data processing and a Sand Cat Swarm Optimization (SCSO) algorithm for optimal parameter selection. The paper also highlights the most important features for accurate detection and shows the potential risks associated with these threats, such as unauthorized access to personal information , changes to phone and network data, and gaining deep control over the device. While the KELM algorithm is used to classify the mobile applications (apps) as either ransomware or non-ransomware, the SCSO functionality looks for the best features and ideal values for the KELM hyperparameters. To evaluate the effectiveness of the proposed system, we used a dataset comprising 1000 real-world samples collected from diverse platforms including Koodous, Virus Total, HelDroid, and RansomProper security projects, as well as benign applications obtained from the official Google Play Store. The experiments were then divided into two parts: the evaluation of the SCSO swarm size and the inquiries into the hybridization of the logarithmic operator. To identify ransomware, the optimal SCSO version with the KELM is utilized, and its efficacy is contrasted with other traditional machine learning methods. When compared to other algorithms, the suggested (SCSO-KELM) performs better in terms of several evaluation metrics, including promising convergence characteristics. The proposed method outperforms others in various metrics.","manuscriptTitle":"Mobile Ransomware Detection Leveraging Swarm Intelligence and Machine Learning: A KELM-Based Approach","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2024-10-28 09:32:48","doi":"10.21203/rs.3.rs-5302086/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"df2d0d2d-19e0-4fca-9fa3-ad017a05cb34","owner":[],"postedDate":"October 28th, 2024","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2024-11-01T19:08:25+00:00","versionOfRecord":[],"versionCreatedAt":"2024-10-28 09:32:48","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-5302086","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-5302086","identity":"rs-5302086","version":["v1"]},"buildId":"WrCJVZZCHTDjtuVLN7oU0","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2024) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00
unpaywall
last seen: 2026-05-22T02:00:06.705733+00:00
License: CC-BY-4.0