Ransomware Detection Using Light Gradient Boosting Machine Classifier
Keywords:
ransomware detection, LightGBM, multiclass classification, SMOTEENNAbstract
Ransomware continues to represent a critical cybersecurity threat across various sectors, leading to significant financial and operational disruptions. Traditional detection techniques, such as signaturebased and behavior-based approaches, often fall short in identifying advanced ransomware variants that utilize polymorphism, obfuscation, and zero-day exploits. To overcome these limitations, this study proposes a machine learning-based framework for multi-class ransomware detection using the Light Gradient Boosting Machine (LightGBM) classifier. The model was trained and evaluated on a labeled Android dataset comprising diverse ransomware families alongside benign applications. To address the issue of class imbalance, the Synthetic Minority Oversampling Technique with Edited Nearest Neighbors (SMOTEENN) was employed, followed by thorough feature preprocessing and hyperparameter optimization. The optimized LightGBM model achieved an accuracy of 90.78% and a weighted F1-score of 90.73%, outperforming baseline classifiers such as Decision Tree and Random Forest. This study offers both theoretical and practical contributions by presenting a lightweight yet highly accurate detection system suitable for real-world deployment, and by validating the effectiveness of SMOTEENN when combined with LightGBM for handling imbalanced, multiclass cybersecurity datasets.
Downloads
References
Ajayi, O., & Chigbu, D. I. (2025). Adversarial machine learning in cybersecurity: Challenges and countermeasures. Electronics, 14(3), 590.
Albin Ahmed, A., & Shaikh, K. (2023). Android ransomware detection using supervised machine learning techniques based on traffic analysis. Bulletin of Electrical Engineering and Informatics, 12(2), 1049–1056.
AlHashmi, A., Darem, A., & Abawajy, J. H. (2024). Ransomware early detection: A survey. Future Generation Computer Systems, 161, 103–122.
Ali, H., Pal, A., et al. (2024). Empowering ransomware detection with machine learning and ensemble methods: A comprehensive feature analysis. IEEE Access, 12, 194879–194892.
Aljabri, M., Altamimi, S. S., et al. (2024). Ransomware detection based on machine learning using memory features. Egyptian Informatics Journal, 25, Article 100445.
Alkasassbeh, M., & Abbadi, M. A. (2020). LightGBM algorithm for malware detection. International Journal of Intelligent Information and Database Systems, 16(2), 1–14.
Avhankar, P. B., & Khandare, S. S. (2025). A comprehensive survey on the taxonomy of malware detection techniques. Measurement: Sensors, 37, Article 101355.
Cen, M., Jiang, F., & Doss, R. (2024). ZeroRAN: Zero-day ransomware detection with feature engineering adaptation. In Proceedings of the 2024 International Conference on Computing, Networking and Communications (ICNC) (pp. 375–380).
Chen, J., Wang, C., Zhao, Z., et al. (2018). Uncovering the face of Android ransomware: Characterization and real-time detection. In Proceedings of IEEE INFOCOM 2018 (pp. 386–394).
Coveware. (2021, February 1). Ransomware payments decline as fewer companies pay. https://www.coveware.com/blog/2021/2/1/ransomware-payments-decline-as-fewer-companies-pay
Gao, C., Weng, G., Jia, L., & Du, J. (2022). Malware detection using LightGBM with a custom loss function. IEEE Access, 10, 84656–84669.
Hagerty, D., & Nygard, K. (2024). Ransomware trends and mitigation strategies. Journal of Cybersecurity Education, Research and Practice, 2024(2), Article 5.
Hussain, F., Abbas, S. G., et al. (2025). Ransomware detection and classification using machine learning. Computers, Materials & Continua, 82(2), 3175–3201.
Imran, M., Afzal, M. T., & Qadir, M. A. (2024). Evaluating machine learning classifiers for Android malware detection. Intelligent Decision Technologies, 18(2), 1133–1153.
Kalhana, R. S., Gadekalu, T. R., et al. (2024). Prediction and mitigation of ransomware attacks using machine learning. Peer-to-Peer Networking and Applications, 17, 3045–3060.
Kara, I. (2023). Fileless malware threats: Recent advances, analysis approach through memory forensics and research challenges. Expert Systems with Applications, 214, Article 119133.
Kauser, S. K., & Showkath Ali, M. (2025). Hybrid ensemble-based machine learning approach for ransomware detection. International Journal of Computational Intelligence Systems, 18, Article 49.
Kharraz, A., Robertson, W., & Kirda, E. (2020). Redemption: Real-time protection against ransomware at end-hosts. ACM Transactions on Privacy and Security, 23(3), 1–30.
Kirubavathi, G., & Deepa, N. (2024). Behavioural analysis and classification of Android malware using machine learning. Multimedia Tools and Applications, 83, 73291–73314.
Lv, Z., Fang, L., et al. (2024). CTIMD: Cyber threat intelligence enhanced Android malware detection using feature selection. IEEE Transactions on Information Forensics and Security, 19, 6797–6811.
Madanayaka, M., et al. (2023). A proactive approach against Android ransomware: Frameworks, detection, and analysis. IEEE Access, 11, 81978–82004.
Momposhi, L., Isafiade, O., & Bagula, A. (2025). A comparative study of machine learning algorithms for Android ransomware detection. Computers & Security, 147, Article 104094.
Nguyen, Q. U., & Lee, S. (2021). LightGBM-based ransomware detection using API call sequences. Applied Sciences, 11(13), 6068.
Sangher, L. S., Bhatia, A., & Singh, K. (2024). Signature-based malware detection: An imminent concern. International Journal of Network Security & Its Applications, 16(5), 97–110.
Stritch, T., & Allyn, J. (2021). The Conti ransomware gang: An overview. https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-265a
Woralert, C., Liu, C., & Zuo, Z. (2024). Towards robust ransomware detection: A deep learning and explainability approach. SN Computer Science, 5, Article 365.
Zahoora, U., Khan, A., et al. (2022). Ransomware analysis using cyber kill chain-based taxonomy and machine learning. Computers & Security, 115, Article 102618.
Zhou, Q., et al. (2024). A novel Android malware detection method using LightGBM. Neural Computing and Applications, 36, 12301–12316.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Indonesian Journal of Cybersecurity and Emerging Risks

This work is licensed under a Creative Commons Attribution 4.0 International License.
This work is licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0)


