Federated Learning-Based Ransomware Detection via Indicators of Compromise

preprint OA: closed CC-BY-4.0
📄 Open PDF View at publisher

Abstract

Abstract Ransomware attacks have become increasingly prevalent and sophisticated, posing significant threats to data security and organizational operations worldwide. Leveraging a federated learning-based approach, this research presents a novel and significant advancement in ransomware detection by utilizing network and file system indicators of compromise while ensuring data privacy. The methodology involves the decentralized training of machine learning models across multiple clients, which enhances the model's robustness and adaptability to various ransomware attack scenarios. Extensive experiments and evaluations demonstrate the high accuracy, precision, recall, and F1-scores achieved by the proposed model, showcasing its effectiveness in real-world applications. The innovative combination of preprocessing, feature engineering, and sophisticated machine learning techniques within a federated learning framework results in a scalable and privacy-preserving solution capable of addressing the dynamic and evolving landscape of ransomware threats. This study contributes valuable insights into the development of effective ransomware detection systems, emphasizing the importance of collaborative and decentralized learning techniques in enhancing cybersecurity defenses.

My notes (saved in your browser only)

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2024) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00
unpaywall
last seen: 2026-05-23T02:00:01.238055+00:00
License: CC-BY-4.0