Hiring in life sciences? Share your open positions with our professional community. Read more Close

Advertisement

TL-RL-FusionNet: Reinforcement Learning-Guided Residual MLP with Fused CNN Embeddings for Efficient and Adaptive Ransomware Detection.

Created on 13 Aug 2026

Authors

Jannatul Ferdous, Rafiqul Islam, Arash Mahboubi, Md Zahidul Islam

Published in

Sensors (Basel, Switzerland). Volume 26. Issue 15. Jul 27, 2026. Epub Jul 27, 2026.

Abstract

Ransomware detection remains challenging because modern variants exhibit diverse, elusive, and partly benign behaviors and can propagate rapidly across interconnected enterprises and sensor-enabled cyber-physical systems, causing cascading operational failures. These characteristics undermine signature-based and static-detection methods. Although machine learning has improved detection, many approaches still rely on fixed objectives that weight samples uniformly, limiting their adaptation to heterogeneity and overlaps between ransomware and benign activities. To address this challenge, we introduce TL-RL-FusionNet, a reinforcement learning (RL)-guided hybrid framework that combines dual transfer learning (TL) backbones, EfficientNetB0 and InceptionV3, with a lightweight residual multi-Layer perceptron (MLP) classifier. The framework converts sandbox reports into RGB grids, extracts features using frozen CNN backbone networks, and fuses embeddings for classification. Training is guided by a tabular Q-learning sample-weighting agent, formulated as a per-sample bandit over discrete weight actions. To prevent cross-fold information leakage, the Q-table is freshly initialized in each cross-validation fold and updated only using the fold-local training partition, whereas the held-out fold is used for the final evaluation. The framework was evaluated using two datasets. On our dataset, TL-RL-FusionNet achieved the best overall performance on Dataset 1, with 99.20% accuracy, 99.40% recall, and 99.84% AUC. On the public EldeRan benchmark, it achieved 90.36% accuracy using the full dynamic feature space and 92.08% using a Mutual Information-selected compact subset. Paired Wilcoxon tests across five folds were used to assess the RL contribution, while additional grid-order sensitivity analysis showed that the image-based representation remained robust under five random 10 × 10 feature-grid permutations. Interpretability analysis using t-distributed stochastic neighbor embedding (t-SNE) and gradient-weighted class activation mapping feature-grid mapping further showed that the model captured discriminative behavioral patterns. Overall, these results demonstrate that RL-guided sample reweighting improves adaptive ransomware detection while maintaining efficiency and interpretability. The dataset and supporting code are publicly available on GitHub.

PMID:
42590551
Bibliographic data and abstract were imported from PubMed on 13 Aug 2026.

Read full publication at:
Please sign in to see all details.

Advertisement

Stats

  • Community rating n/a 0 votes
  • Reviewers' rating n/a 0 votes
  • Your rating

1-terrible, 9-excellent. How would you rate this publication? Sign in in to submit your rating.

  • Recommendations n/a n/a positive of 0 vote(s)
  • Views 11
  • Comments 0

Recommended by

  • No recommendations yet.

Post a comment

You need to be signed in to post comments. You can sign in here.

Comments

There are no comments yet.

Advertisement