Related Experiment Video
Updated: Jul 3, 2026

A Virtual Machine Platform for Non-Computer Professionals for Using Deep Learning to Classify Biological Sequences of Metagenomic Data
Published on: September 25, 2021
Enhancing ransomware defense: deep learning-based detection and family-wise classification of evolving threats
Amjad Hussain1, Ayesha Saadia2, Musaed Alhussein3
1Department of Cyber Security, Air University, Islamabad, Pakistan.
A new deep learning method, group normalization-based bidirectional long short-term memory (GN-BiLSTM), accurately detects and classifies ransomware variants. This approach enhances cybersecurity by identifying malware families and categories, crucial for preventing future attacks.
Area of Science:
- Cybersecurity
- Machine Learning
- Deep Learning
Background:
- Ransomware utilizes obfuscation techniques, making detection and classification challenging for traditional methods.
- Existing machine learning approaches struggle with advanced, obfuscated ransomware variants.
- Deep learning offers advanced capabilities for analyzing and classifying complex malware.
Purpose of the Study:
- To address the multi-class classification challenges in ransomware detection and family attribution.
- To propose and validate a novel deep learning model for enhanced ransomware identification.
- To improve the accuracy of detecting and classifying new ransomware variants.
Main Methods:
- Development of a novel group normalization-based bidirectional long short-term memory (GN-BiLSTM) model.
- Training and validation of the GN-BiLSTM model on the CIC-MalMem-2022 obfuscated malware dataset.
- Comparative analysis with five other deep learning models for performance evaluation.
Main Results:
- The GN-BiLSTM model achieved 99.99% accuracy in ransomware detection on the CIC-MalMem-2022 dataset.
- Category-wise classification accuracy reached 85.48%, and family identification accuracy was 74.65%.
- On a self-collected dataset, the model showed 99.20% detection, 97.44% category classification, and 96.23% family identification accuracy.
Conclusions:
- The proposed GN-BiLSTM approach demonstrates superior performance in detecting and classifying ransomware variants.
- This deep learning method is effective for identifying malware categories and families, even with obfuscation.
- The model shows significant potential for real-world implementation in advanced ransomware detection systems.
Related Concept Videos
Force Classification
Contact and non-contact forces are two of the most widely used categories of forces. As the name suggests, contact forces require physical contact between two objects to act upon each other. Examples of contact forces include frictional,...
Classification of Signals
A continuous-time signal holds a value at every instant in time, representing information seamlessly. In contrast, a discrete-time signal holds values only at specific moments, often denoted as x(n), where...
Classification of Systems-I
Homogeneity dictates that if an input x(t) is multiplied by a constant c, the output y(t) is multiplied by the same constant. Mathematically, this is expressed as:
Classification of Systems-II

