Skip to main content

System-Wide Ransomware Attack Detection via Perturbation-Resilient Representation Learning

By
Fengkai Yuan; Lingbo Zhao; Zhilu Wang; Wenhao Wang; Dan Meng; Rui Hou

Ransomware has evolved into system-level attacks that distribute malicious actions across seemingly normal processes, rendering process-level detection ineffective. However, system-wide detection aggregates concurrent applications, whose interactions may obscure ransomware behavior or make benign activity appear malicious. The key challenge is to distinguish inherent benign-malicious traits from application-dependent perturbations. We present CoLPR, a contrastive self-supervised framework that addresses this challenge by learning perturbation-resilient representations. Its Inborn augmentation strategy executes realistic application combinations and constructs positive pairs with the same co-participants under diverse perturbations. By encouraging representation consistency within these pairs, contrastive learning preserves benign-malicious invariance while suppressing perturbation-specific features. Unlike conventional supervised and time-series representation-learning approaches, CoLPR remains effective under substantial multi-application interference, outperforming baselines by 5%–10%. Across three deployment environments, it achieves 100% recall, 98.7% accuracy, and an average detection delay of 5.31 seconds, within the 60-second short-term backup window, with acceptable runtime overhead. It also detects unseen ransomware families under multi-application perturbations.

Read on IEEE Xplore