{"id":"W4416961692","doi":"10.1109/pst65910.2025.11268847","title":"Detecting Ransomware Before It Bites: A Hybrid Model Approach for Early Ransomware Detection","year":2025,"lang":"","type":"article","venue":"","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Ottawa; University of Fredericton","funders":"","keywords":"Ransomware; Obfuscation; Sandbox (software development); Executable; Malware; Encryption; Evasion (ethics); Static analysis","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001056967,0.001186087,0.001211473,0.002121748,0.0005508305,0.001692292,0.001666163,0.001301846,0.001465591],"category_scores_gemma":[0.002572859,0.0005272524,0.001076631,0.0007114818,0.0007079186,0.002288318,0.001197579,0.0014312,0.001006201],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0009667888,"about_ca_system_score_gemma":0.001135201,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.006910537,"about_ca_topic_score_gemma":0.008458234,"domain_scores_codex":[0.999201,0.0001719472,0.00004015557,0.0002289441,0.0002288987,0.000129059],"domain_scores_gemma":[0.9981794,0.0006392582,0.00033697,0.000244614,0.0004997726,0.00009990201],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0004830898,0.0008556399,0.02394271,0.0001385311,0.0003148226,0.0004518313,0.0004424886,0.6145173,0.01869831,0.01576188,0.003407983,0.3209854],"study_design_scores_gemma":[0.000001597392,0.00002964569,0.0004070915,0.000004441129,0.000008263743,0.00002950337,0.00001598547,0.9970227,0.0008269596,0.001473209,0.0001724125,0.000008168549],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.08612746,0.0003023047,0.9092177,0.000415069,0.00005879308,0.0001285795,0.0001319515,0.001448693,0.002169494],"genre_scores_gemma":[0.7983799,0.0003086432,0.1949673,0.0002604131,0.00007856303,0.0001871645,0.0003355602,0.0001439914,0.005338491],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.006910537,"threshold_uncertainty_score":0.0137406,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01895484400701467,"score_gpt":0.2747216601935627,"score_spread":0.2557668161865481,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}