🔒
Global Academic Platform
Serving Researchers Since 2012

A Novel Framework for Ransomware Detection Com- bining Traditional Machine Learning with CNN2D

DOI : 10.5281/zenodo.23032759
Download Full-Text PDF Cite this Publication

Text Only Version

A Novel Framework for Ransomware Detection Com- bining Traditional Machine Learning with CNN2D

R. Tharun Kumar, S. Ranga Lokesh Reddy, T. Varshith Goud

1 CSE(AI&ML), CMR Institute of Technology, Hyderabad, Telangana, India

2 CSE(AI&ML), CMR Institute of Technology, Hyderabad, Telangana, India

3 CSE(AI&ML), CMR Institute of Technology, Hyderabad, Telangana, India

Abstract – Ransomware attacks continue to cause significant financial and operational damage by en- crypting user data and demanding payment for re- covery, making early and accurate detection a criti- cal cybersecurity challenge. The time-honored signa- ture-based detection systems are not usually effec- tive in detecting the new and emerging ransomware variants and require behavior-oriented and data- centric detection systems. This study presents a hy- brid classification framework that utilizes Hardware Performance Counters and Input/Output event da- tasets to detect ransomware activity. The suggested technique uses a Two-Dimensional Convolutional Neural Network to refine fea-ture representation, and a Random Forest classifier to do the final pre- diction. The train and test datasets were split into 80:20, and a variety of machine learning algorithms were compared. The experimental findings showed that the proposed hybrid CNN2D and Random For- est model was able to classify data with a high accu- racy of 99% which was higher than the traditional machine learning and deep learning models that were applied under the same conditions. These find- ings indicate that combining convolution-based fea- ture optimization with ensemble classification pro- vides an effective and computationally efficient solu- tion for ransomware detection using system perfor- mance metrics.

Key Words: – Ransomware Detection; Hardware Performance Counters; Input/Output Event Analy- sis; Convolutional Neural Networks(CNN2D); Ran- dom Forest Classification; Behavior-Based Malware Detection

  1. INTRODUCTION

    Ransomware has become one of the most serious cy- bersecurity threats in recent years, affecting individuals, organizations, and even critical infrastructure. It is a form of malicious software that encrypts valuable files and requires payment of ransom to decrypt the files. With the increasing dependence on digital systems and data, ran-somware attacks have grown both in frequen- cy and complexity. Attackers continuously develop new variants that are harder to detect and prevent, making traditional security mechanisms less effective. Signa- ture-based detection methods depend on recognizing known malware patterns, but they often struggle to de- tect new or modified ransomware variants, particularly zero-day attacks. This has brought about a great demand of more intel-ligent and adaptive methods of detection that can handle the changing threats.

    To overcome these limitations, researchers have started focusing on behavior-based detection approaches. In- stead of relying on known signatures, these methods an- alyze how a program behaves within a system. In par- ticular, Hardware Performance Counters (HPCs) and Input/Output (I/O) events have gained attention as use- ful indicators of system activity. HPCs provide low- level information about processor operations, while I/O events capture data related to disk access and file oper- ations. During a ransomware attack, these metrics show noticeable changes due to encryption processes and ab- normal execution patterns. By studying these variations, it becomes possible to identify suspicious activities at an early stage and reduce potential damage.

    A number of machine learning methods have been used to detect ransomware with such system-level data. Sup- port Vector Machines, Decision Trees, and Random Forest algorithms have performed well in the classifica- tion of ran-somware and benign activities. These mod- els have the ability to learn patterns out of the data and provide forecasts on the basis of the trained knowledge. However, many of these approaches depend heavily on manually selected features, which may not always

    capture complex relationships within the data. Feature engineering can be time-consuming and may limit the overall performance of the model if important patterns are overlooked during the selection process.

    Deep learning techniques have been brought in recent years to overcome these challenges. These models can automatically extract valuable features out of raw data, minimizing the manual intervention. Particularly, Convo-lutional Neural Networks (CNNs) have been useful in deriving mean-ingful patterns out of structured data representations. Nonetheless, deep learning models on their own might be computationally intensive and might require large volumes of data to train effectively. This renders them less fitting in real-time setting. lim- ited computation systems or systems. resources. As well as, deep learning models. may sometimes overfit if the dataset is not suf adequately big or varied.

    Based on these challenges, there is a necessity to have. a moderate way of approach to the combination of the advantages of both machine learning and deep. learning techniques. A hybrid was used in this project. ransom- ware detection model is proposed that improves a Two- Dimensional Convolutional. Neural Network (CNN2D) with a Random For est classifier. The ex is performed using CNN2D model. learn and optimize characteristics of the data, as the Random Forest algorithm performs. the final classification. This combination helps enhance the detection accuracy and retain reasonable computa- tional efficiency. The model is trained and tested using publicly available datasets that include HPC and I/O event data. Overall, the proposed approach aims to pro- vide an effective, reliable, and scalable solution for de- tecting ransomware attacks in modern computing envi- ronments.

  2. RELATED WORK

    Al-Rimy et al. (2023) worked on ransomware detec- tion using CNN, mainly focusing on automatic feature extraction. Their model performed well in identifying new variants, but it required a large dataset and higher computational power. In this work, instead of depend- ing fully on deep learning, CNN2D is used only for fea- ture optimization, and Random Forest is applied for classification to reduce complexity [1].

    Hussain et al. (2023) used deep neural networks to cap- ture complex behavioral patterns. Although the accu- racy was good, the model training took more time and resources. To overcome this, the current approach avoids deep standalone models and adopts a simpler hy- brid structure [2].

    Kumar and Singh (2023) used traditional machine learning algorithms like SVM and Random Forest. Their approach worked well, but it relied heavily on

    manually selected features. In comparison, the proposed system reduces this effort by automatically extracting features using CNN2D [3].

    Patel et al. (2023) combined multiple classifiers in a hy- brid model, which improved accuracy but also increased system complexity. The present work keeps the model simple by using only CNN2D and Random Forest [4].

    Zhang et al. (2023) used ensemble learning for behav- ior-based detection. While effective, it required a large dataset. The current work focuses more on structured HPC and I/O data, which reduces the dependency on large-scale data [5].

    Gupta and Kaur (2024) proposed a hybrid deep learning model that improved detection but required high com- putational power. The proposed system tries to balance this by limiting deep learning usage [6].

    Azugo et al. (2024) used a Random Forest model on the UGRansome dataset and reported fairly good results. However, their approach seems to depend a lot on the dataset used, and it may not perform the same way with different data. In this work, feature optimization using CNN2D is introduced to make the model more adapta- ble across datasets [7].

    Lee et al. (2024) worked on detecting zero-day ransom- ware using deep learning. Their method was effective, but it required significant computational resources. The approach used here tries to reduce this burden while still maintaining reliable detection performance [8].

    Sharma et al. (2024) combined CNN and LSTM models to capture multiple aspects of ransomware behavior. While this improved accuracy, it also made the system more complex. The current work avoids this complexity by using a simpler structure [9].

    Wang et al. (2024) focused on behavioral analysis along with deep learning techniques. Although their model performed well, it required continuous monitoring of system activity, which increased overhead. In contrast, this work uses structured datasets, making the process more efficient [10].

    Kim et al. (2025) concentrated on encryption behavior for detecting ransomware. This method works well in certain cases, but it may not cover all types of attacks. The proposed system uses broader system-level features to handle a wider range of scenarios [11].

    Zhang et al. (2025) also explored a combination of CNN and Random Forest. However, in this work, CNN2D is specifically applied to better handle structured data and improve feature representation [12].

    Patel and Mehta (2025) proposed a deep learning model with feature optimization, which showed good results

    but required high computational resources. The current approach reduces this requirement by using Random Forest for classification [13].

    Singh et al. (2025) used ensemble learning to handle evolving ransomware threats. While their method im- proved adaptability, it also added complexity to the

    system. The proposed model keeps things simpler while still maintaining good performance [14].

    Chen et al. (2025) presented a hybrid model combining machine learning and deep learning. Although their ap- proach performed well, it depended on large datasets. In comparison, this work focuses on efficiency by using structured data and a balanced hybrid model [15].

    Table 1: Comparison of Existing Ransomware Detection Techniques

    Title

    Problem Statement

    Solution

    Method

    Limitations

    Deep Learning-Based Detection of Ransom- ware using CNN Mod- els (2023)

    Difficulty in detecting unknown ransomware variants

    Used CNN for auto- mated feature extrac- tion

    Deep Learn- ing (CNN)

    Requires large dataset and high computation

    Intelligent Ransom- ware Detection using Deep Neural Networks (2023)

    Inefficiency of tradi- tional detection meth- ods

    Applied deep neural networks for detection

    Deep Learn- ing (DNN)

    High training time

    ML Approaches for Ransomware Detection using System Activity Data (2023)

    Failure of signature- based systems

    Used ML models for classification

    SVM, RF, DT

    Depends on feature se- lection

    Ransomware Detection using Hybrid ML Mod- els (2023)

    Low accuracy of single models

    Combined multiple ML models

    Hybrid ML

    Increased model com- plexity

    Behavior-Based Ran- somware Detection us- ing Ensemble Learning (2023)

    Difficulty in early de- tection

    Used ensemble learn- ing for better predic- tion

    Ensemble Learning

    Requires large training data

    Hybrid Deep Learning Framework for Ran- somware Detection (2024)

    High false positives in detection

    Combined DL models for accuracy

    Hybrid DL

    Computationally ex- pensive

    RF-Based Ransom- ware Detection using UGRansome Dataset (2024)

    Inefficient classifica- tion methods

    Used Random Forest classifier

    Random For- est

    Limited generalization

    DL Approach for Zero- Day Ransomware De- tection (2024)

    Detecting zero-day at- tacks

    Applied deep learning techniques

    Deep Learn- ing

    Requires high re- sources

    Detection using CNN and LSTM Hybrid Model (2024)

    Capturing sequential patterns

    Combined CNN and LSTM

    Hybrid DL

    Complex architecture

    Advanced Detection using Behavioral Anal- ysis (2024)

    Evasion techniques by ransomware

    Used behavior + DL models

    DL + Behav- ioral

    High monitoring cost

    ML-Based Detection using Encryption Be- havior (2025)

    Difficulty in detecting encrypted ransomware

    Analyzed encryption patterns

    Machine Learning

    Limited dataset scope

    Hybrid CNN + RF for Zero-Day Detection (2025)

    Low accuracy in zero- day detection

    Combined CNN and RF

    Hybrid (CNN

    + RF)

    Needs optimization

    DL-Based Classifica- tion using Feature Op- timization (2025)

    Poor feature represen- tation

    Used optimized DL models

    Deep Learn- ing

    High computation

    Ensemble Learning for Evolving Ransomware (2025)

    Rapid evolution of ran- somware

    Used ensemble meth- ods

    Ensemble Learning

    Complex tuning

    Hybrid ML-DL Frame- work for Detection (2025)

    Inefficiency of standalone models

    Combined ML and DL

    Hybrid Model

    Requires large dataset

  3. METHODOLOGY

    1. Dataset Description

      Figure 1: Architecture

      The two datasets were acquired on publicly available re-

      The experimental assessment was carried out. with publicly available Hardware Performance. Input/Output (IO) Events and Counters (HPC) datasets. Such data sets include low-level system performance measure- ments taken during the implementation of harmless pro- grams and ransomware samples.

      The HPC dataset contains the processor level perfor- mance measures, whereas the IO Events dataset is a da- taset of disk activity behavior in running the program.

      positories and combined to form a single dataset to be analyzed. Each record in the combined dataset consisted of multiple HPC and IO-related features, with the final column representing the class label, where:

      • 0 indicated a benign program

      • 1 indicated a ransomware program

        The merged dataset was stored in CSV format and used as input for all machine learning and deep learning ex- periments.

    2. Data Preprocessing

      Before training, the dataset was examined for missing or inconsistent values. Feature normalization was ap- plied to ensure uniform scaling across all performance metrics. Since HPC and IO metrics vary in magnitude, normalization prevented bias toward features with larger numerical ranges.

      The dataset was divided into training and testing subsets using an 80:20 split. Eighty percent of the data were used for training the models, while the remaining twenty percent were reserved for performance evalua- tion Stratified splitting was applied to preserve the orig- inal class distribution.

    3. Baseline Machine Learning Models

      To evaluate classification performance, several tradi- tional machine learning algorithms were implemented, including:

      • Support Vector Machine (SVM)

      • K-Nearest Neighbors (KNN)

      • Decision Tree

      • Random Forest

      • XGBoost

        Each model was trained on the 80% training dataset and evaluated on the 20% test dataset. Performance metrics such as accuracy and confusion matrix were computed for comparative analysis.

    4. Deep Learning Models

      In addition to traditional machine learning models, two deep learning architectures were evaluated:

      • Deep Neural Network (DNN)

      • Long Short-Term Memory (LSTM)

        These models were trained using the same training da- taset to ensure fair comparison. The performance of these models was evaluated using identical testing con- ditions.

    5. Proposed Extension Using CNN2D

      As an extension to the existing approaches, a Two- Dimensional Convolutional Neural Network (CNN2D) was implemented to enhance feature optimization.

      Although the dataset was structured in tabular form, the feature vectors were reshaped into two-dimensional ma- trices to enable convolutional processing. The CNN2D architecture consisted of:

      • Convolutional layers for feature extraction

      • Activation layers for non-linear transformation

      • Pooling layers for dimensionality reduction

      • Fully connected layers for classification

        The CNN2D model was trained on the 80% training da- taset and evaluated on the 20% testing dataset. This ap- proach allowed the model to automatically learn opti- mized feature representations from HPC and IO metrics.

    6. Evaluation Metrics

      Model performance was assessed using classification accuracy and confusion matrix analysis. The confusion matrix provided detailed insights into:

      • True Positives (Correct ransomware detection)

      • True Negatives (Correct benign detection)

      • False Positives

      • False Negatives

        All algorithms were evaluated under identical experi- mental conditions to ensure consistency in comparison.

    7. Algorithm Input:

      Hardware Performance Counter (HPC) dataset and In- put/Output (IO) event dataset containing processor us- age and disk activity metrics.

      Output:

      Classification label indicating whether the program be- havior is Benign (0) or Ransomware (1).

      Figure 2: Flowchart

      Step 1: Load the HPC and IO event datasets containing system performance metrics collected during program execution.

      Step 2: Merge the HPC and IO datasets into a unified dataset and store it in structured CSV format.

      Step 3: Perform data preprocessing by checking for missing or inconsistent values in the dataset.

      Step 4: Apply feature normalization to ensure uniform scaling of processor and disk activity metrics.

      Step 5: Divide the dataset into training and testing subsets using an 80:20 split, where 80% of the data is used for model training and 20% for testing.

      Step 6: Reshape the one-dimensional feature vectors into two-dimensional matrices to enable convolutional processing in the CNN2D architecture.

      Step 7: Train the CNN2D model to perform feature ex- traction by applying convolution layers, activation func- tions, and pooling layers to learn optimized feature rep- resentations.

      Step 8: Extract the learned feature vectors from the final layer of the CNN2D model.

      Step 9: Train a Random Forest classifier using the ex- tracted feature vectors obtained from the CNN2D model.

      Step 10: Apply the trained Random Forest classifier to the testing dataset for classification.

      Step 11: Evaluate the model performance using metrics such as accuracy, precision, recall, F1-score, and confusion matrix.

      Step 12: Output the predicted label indicating whether the input sample represents benign activity or ransom- ware behavior.

      End Algorithm

    8. Logic

      The proposed ransomware detection framework iden- tifies malicious activity by analyzing processor and disk usage behavior. Ransomware typically performs rapid file encryption, which leads to abnormal CPU uti- lization and high disk read/write operations.

      The system first collects Hardware Performance Counter (HPC) metrics and Input/Output (IO) event data that represent system performance during program execution. Then the preprocessing of the dataset is done by eliminating inconsistencies and normalizing the da- taset to provide uniform feature scaling. The processed data is splitted into training and testing data in the ratio of 80:20. The feature vectors are then reshaped into 2D matrices and fed into a CNN2D model that automati- cally learns to discover significant features processor and disk activity patterns of features. The CNN2D ar- chitecture obtains the extracted and optimized feature representations that reflect the differences in behavior among benign applications and ransomware.

      These obtained features are then fed into a Random For- est classifier which does the final classification. Ran- dom Forest is ensemble in nature hence enhances the reliability of predictions because it involves several de- cision trees.

      Finally, the model is evaluated using performance met- rics such as accuracy, precision, recall, and F1-score to measure the effectiveness of ransomware detection.

    9. Equations

      • Feature Normalization (Min-Max Scaling):

      • 2D Convolution Operation (CNN2D):

      • ReLU Activation Function:

      • Max Pooling Operation:

      • Random Forest Prediction:

      • Accuracy Metric:

      • Precision:

      • Recall:

      • F1-Score:

  4. RESULT ANALYSIS

    The experimental evaluation was conducted using the integrated HPC and IO events dataset consisting of 6000 samples, equally distributed between benign and ran- somware classes. The dataset was divided using an 80:20 split, where 4800 samples were used for training and 1200 samples were used for testing.

    Multiple machine learning and deep learning models were trained and evaluated under identical experimental conditions. The performance metrics were calculated using the test dataset. The evaluation metrics included accuracy, precision, recall, and F1-score.

    Table 2: Presents the classification accuracy obtained by different machine learning and deep learning models on the test dataset.

    MODEL

    ACCURACY

    SVM

    88

    KNN

    97

    Decision Tree

    93

    Random Forest

    98

    XGBoost

    98

    DNN

    88

    LSTM

    93

    CNN2D+ RF

    99

    As shown in Table 1, Random Forest and XGBoost achieved 98% accuracy, while the proposed CNN2D with RF model achieved 99% accuracy.

    To visually compare the performanceof the evalu- ated models, a bar chart representation is shown in Fig- ure 3.

    Figure 3: Model accuracy comparison on the test da- taset including CNN2D with RF.

    The Random Forest classifier achieved an accuracy of 98% on the test dataset. The confusion matrix obtained from the evaluation is shown in Table 3.

    Figure 4: Random Forest Confusion matrix

    Table 3: shows the confusion matrix obtained using the Random Forest classifier.

    Predicted Ransom- ware

    Predicted Benign

    Actual Ran- somware

    590

    10

    Actual Be- nign

    14

    586

    From the confusion matrix, the computed performance metrics were:

    • Precision: 97.68%

    • Recall: 98.33%

    • F1-score: 98.00%

      CNN2D with RF Performance Evaluation

      The proposed CNN2D with RF model achieved an accuracy of 99% on the test dataset. The confusion ma- trix obtained from the evaluation is presented in Table 4.

      Figure 5: CNN2D+RF Confusion matrix

      Table 4: presents the confusion matrix obtained using the proposed CNN2D with RF model.

      Predicted Ransom- ware

      Predicted Benign

      Actual Ran- somware

      596

      4

      Actual Be- nign

      8

      592

      Based on the confusion matrix, the calculated perfor- mance metrics were:

    • Precision: 98.68%

    • Recall: 99.33%

    • F1-score: 99.00%

    classification accuracy. This indicates that system-level features such as processor activity and disk usage pro- vide sufficient information to distinguish ransomware from normal applications.

    The improved performance is mainly due to the combi- nation of CNN2D and Random Forest. CNN2D auto- matically learns meaningful feature patterns, while Ran- dom Forest ensures accurate and stable classification with reduced overfitting. This method describes more of the data than models which use features engineered manually.

    However, the dataset may not fully represent real-world environments, and performance may vary for unseen ransomware variants. Therefore, further evaluation on larger and more diverse datasets is necessary before real-world deployment.

    1. CONCLUSION

      This study presents a hybrid ransomware detection framework using Hardware Performance Counters (HPC) and Input/Output (I/O) event data. The objective is to determine whether system-level metrics, processed using a Two-Dimensional Convolutional Neural Net- work and classified with a Random Forest model, can effectively distinguish ransomware from benign pro- grams. The results show that the proposed model out- performs traditional machine learning and standalone deep learning approaches. By combining feature extrac- tion with classification, the framework improves detec- tion accuracy while maintaining efficiency. The study demonstrates that processor and disk activity metrics are reliable indicators for ransomware detection and of- fer a practical solution for enhancing cybersecurity sys- tems.

      Figure 6: Performance graph between Deep learning and Machine learning algorithms

  5. DISCUSSION

This study explores whether ransomware can be ef- fectively detected using Hardware Performance Coun- ters (HPC) and Input/Output (I/O) event data through a hybrid learning approach. The results show that the pro- posed CNN2D and Random Forest model performs bet- ter than traditional machine learning methods and standalone deep learning models in terms of

  1. FUTURE WORK

      • Evaluate the proposed CNN2DRandom Forest framework using larger and more diverse ransom- ware families to analyze its robustness against evolving attack techniques.

      • Expand the dataset with additional real-world sam- ples collected from different hardware platforms and operating system environments to improve model generalization.

      • Incorporate additional behavioral features such as memory utilization patterns, network traffic indica- tors, and file entropy measurements for better de- tection capability.

      • Investigate the use of multi-modal system metrics to enhance detection of ransomware variants that at- tempt to evade monitoring by reducing disk activ- ity.

      • Explore adaptive and incremental learning tech- niques that allow the model to update dynamically as new ransomware behaviors emerge.

      • Optimize the proposed framework for real-time de- ployment and evaluate its performance under live system execution conditions.

      • Improve scalability and adaptability of the detection system to develop more reliable behavior-based ran- somware defense mechanisms.

  2. REFERENCES

  1. ‌A. Al-Rimy, M. Maarof, and S. Shaid, Deep Learning-Based Detec- tion of Ransomware using CNN Models, Computers & Security, vol. 120, pp. 102115, 2023.

  2. ‌A. Hussain, M. Alhussein, and K. Aurangzeb, Intelligent Ransomware Detection using Deep Neural Networks, IEEE Access, vol. 11, pp. 4567845690, 2023.

  3. ‌R. Kumar and A. Singh, Machine Learning Approaches for Ransom- ware Detection using System Activity Data, Journal of Cyber Security Technology, vol. 7, no. 2, pp. 89104, 2023.

  4. ‌D. Patel, S. Shah, and R. Mehta, Ransomware Detection using Hybrid Machine Learning Models, Procedia Computer Science, vol. 218, pp. 345352, 2023.

  5. ‌Y. Zhang, X. Liu, and H. Wang, Behavior-Based Ransomware Detec- tion using Ensemble Learning, Future Generation Computer Systems, vol. 137, pp. 210220, 2023.

  6. ‌S. Gupta and P. Kaur, Hybrid Deep Learning Framework for Ransom- ware Detection, Journal of Information Security and Applications, vol. 78, pp. 103115, 2024.

  7. ‌P. Azugo, H. Venter, and M. Wa Nkongolo, Random Forest-Based Ransomware Detection using UGRansome Dataset, arXiv preprint arXiv:2404.12855, 2024.

  8. ‌J. Lee, J. Kim, and K. Lee, Deep Learning Approach for Zero-Day Ransomware Detection, IEEE Transactions on Information Forensics and Security, vol. 19, pp. 11231135, 2024.

  9. ‌R. Sharma, P. Verma, and S. Gupta, Detection of Ransomware using CNN and LSTM Hybrid Model, Computers & Electrical Engineering, vol. 108, pp. 108120, 2024.

  10. ‌L. Wang, Y. Chen, and Z. Li, Advanced Ransomware Detection using Behavioral Analysis and Deep Learning, IEEE Access, vol. 12, pp. 5567855690, 2024.

  11. ‌H. Kim, J. Park, and S. Lee, Machine Learning-Based Ransomware Detection using Encryption Behavior Analysis, Sensors, vol. 25, no. 3, pp. 14561468, 2025.

  12. ‌Y. Zhang, X. Liu, and H. Wang, Hybrid CNN and Random Forest Model for Zero-Day Ransomware Detection, IEEE Transactions on Information Forensics and Security, vol. 20, pp. 210222, 2025.

  13. ‌D. Patel and R. Mehta, Deep Learning-Based Ransomware Classifi- cation using Feature Optimization Techniques, Expert Systems with Applications, vol. 235, pp. 119130, 2025.

  14. ‌A. Singh, R. Kumar, and P. Sharma Ensemble Learning Approach for Detecting Evolving Ransomware Threats, Journal of Network and Computer Applications, vol. 225, pp. 103115, 2025.

  15. ‌X. Chen, Y. Zhao, and L. Zhang, Intelligent Ransomware Detection using Hybrid ML-DL Framework, IEEE Access, vol. 13, pp. 33456 33470, 2025.