GRENZE International Journal of Engineering and Technology
Vol. 12
(2026), Issue 1
Ransomware Detection using Explainable AI For Endpoint Systems
Authors
Anu Prabhakar, Suganya R, Janani V, Narthika K, Thenmozhi H
Abstract
Ransomware is a rapidly evolving cyber threat that encrypts critical files and disrupts system availability, often bypassing traditional signature-based antivirus solutions and static machine learning models trained on controlled datasets. To address these limitations, an Explainable AI approach is employed to detect ransomware by monitoring endpoint behavior and distinguishing between normal and abnormal activities. Machine learning model is employed to classify five ransomware families Phobos, WannaCry, Hive, GandCrab, and LockBit using behavioral analysis. Key indicators such as unusual file encryption, rapid file modifications, suspicious process execution, and anomalous network activity are analyzed to identify malicious patterns. Explainable AI helps make the system’s decisions easier to understand by showing which behaviors caused it to detect ransomware. A safe simulation environment supports the testing of ransomware-like behaviors without risk to actual systems.
Pages:
2309 - 2316