{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T19:46:34Z","timestamp":1780602394289,"version":"3.54.1"},"reference-count":36,"publisher":"Elsevier BV","issue":"1","license":[{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272007"],"award-info":[{"award-number":["62272007"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008778","name":"University of Science and Technology Beijing","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100008778","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["FRF-IDRY-24-015"],"award-info":[{"award-number":["FRF-IDRY-24-015"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["High-Confidence Computing"],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1016\/j.hcc.2025.100338","type":"journal-article","created":{"date-parts":[[2025,7,2]],"date-time":"2025-07-02T04:19:28Z","timestamp":1751429968000},"page":"100338","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":1,"title":["A novel zero-day ransomware detection approach based on CVAE and 1D-CNN"],"prefix":"10.1016","volume":"6","author":[{"given":"Bohan","family":"Cui","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yan","family":"Hu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tianheng","family":"Qu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yunhua","family":"He","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Limin","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.hcc.2025.100338_b1","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2021.116198","article-title":"The rise of ransomware: Forensic analysis for windows based ransomware attacks","volume":"190","author":"Kara","year":"2022","journal-title":"Expert Syst. Appl."},{"issue":"5","key":"10.1016\/j.hcc.2025.100338_b2","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1109\/MITP.2017.3680961","article-title":"Do crypto-currencies fuel ransomware?","volume":"19","author":"Kshetri","year":"2017","journal-title":"IT Prof."},{"issue":"1","key":"10.1016\/j.hcc.2025.100338_b3","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s41125-019-00039-8","article-title":"On the economic impact of crypto-ransomware attacks: The state of the art on enterprise systems","volume":"4","author":"A","year":"2019","journal-title":"Eur. J. Secur. Res."},{"key":"10.1016\/j.hcc.2025.100338_b4","article-title":"Ant colony optimization based light weight binary search for efficient signature matching to filter ransomware","volume":"111","author":"Sreelaja","year":"2021","journal-title":"Appl. Soft Comput."},{"issue":"5","key":"10.1016\/j.hcc.2025.100338_b5","doi-asserted-by":"crossref","first-page":"1687","DOI":"10.1007\/s13198-023-02017-9","article-title":"Signature based ransomware detection based on optimizations approaches using RandomClassifier and CNN algorithms","volume":"15","author":"Sangher","year":"2024","journal-title":"Int. J. Syst. Assur. Eng. Manag."},{"key":"10.1016\/j.hcc.2025.100338_b6","article-title":"Ant colony optimization based light weight binary search for efficient signature matching to filter ransomware","volume":"111","author":"Sreelaja","year":"2021","journal-title":"Appl. Soft Comput."},{"key":"10.1016\/j.hcc.2025.100338_b7","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103349","article-title":"Cryptographic ransomware encryption detection: Survey","volume":"132","author":"Begovic","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.hcc.2025.100338_b8","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102512","article-title":"Rcryptect: Real-time detection of cryptographic function in the user-space filesystem","volume":"112","author":"Lee","year":"2022","journal-title":"Comput. Secur."},{"issue":"1","key":"10.1016\/j.hcc.2025.100338_b9","doi-asserted-by":"crossref","DOI":"10.1016\/j.hcc.2024.100235","article-title":"Data distribution inference attack in federated learning via reinforcement learning support","volume":"5","author":"Yu","year":"2025","journal-title":"High- Confid. Comput."},{"key":"10.1016\/j.hcc.2025.100338_b10","doi-asserted-by":"crossref","DOI":"10.1016\/j.hcc.2025.100318","article-title":"Linkable group signatures against malicious regulators for regulated privacy-preserving cryptocurrencies","author":"Wang","year":"2025","journal-title":"High- Confid. Comput."},{"issue":"4","key":"10.1016\/j.hcc.2025.100338_b11","doi-asserted-by":"crossref","first-page":"2597","DOI":"10.1007\/s11277-020-07166-9","article-title":"Two-stage ransomware detection using dynamic analysis and machine learning techniques","volume":"112","author":"Hwang","year":"2020","journal-title":"Wirel. Pers. Commun."},{"issue":"2","key":"10.1016\/j.hcc.2025.100338_b12","doi-asserted-by":"crossref","DOI":"10.1016\/j.hcc.2023.100114","article-title":"A survey on security analysis of machine learning-oriented hardware and software intellectual property","volume":"3","author":"Tauhid","year":"2023","journal-title":"High- Confid. Comput."},{"key":"10.1016\/j.hcc.2025.100338_b13","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1016\/j.future.2018.07.052","article-title":"Classification of ransomware families with machine learning based onN-gram of opcodes","volume":"90","author":"Zhang","year":"2019","journal-title":"Future Gener. Comput. Syst."},{"key":"10.1016\/j.hcc.2025.100338_b14","article-title":"Improving ransomware detection based on portable executable header using xception convolutional neural network","volume":"130","author":"C","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.hcc.2025.100338_b15","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102691","article-title":"A few-shot meta-learning based siamese neural network using entropy features for ransomware classification","volume":"117","author":"Zhu","year":"2022","journal-title":"Comput. Secur."},{"issue":"9","key":"10.1016\/j.hcc.2025.100338_b16","first-page":"1","article-title":"A survey on ransomware: Evolution","volume":"55","author":"\u00d6z","year":"2022","journal-title":"Taxon. D\u00e9f. Solutions. ACM Comput. Surv."},{"issue":"3","key":"10.1016\/j.hcc.2025.100338_b17","first-page":"10","article-title":"Static malware analysis to identify ransomware properties","volume":"16","author":"Vidyarthi","year":"2019","journal-title":"Int. J. Comput. Sci. Issues"},{"issue":"4","key":"10.1016\/j.hcc.2025.100338_b18","doi-asserted-by":"crossref","first-page":"285","DOI":"10.1007\/s11416-021-00414-x","article-title":"A novel approach for ransomware detection based on PE header using graph embedding","volume":"18","author":"Manavi","year":"2022","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"10.1016\/j.hcc.2025.100338_b19","article-title":"Swiftr: Cross-platform ransomware fingerprinting using hierarchical neural networks on hybrid features","volume":"225","author":"Karbab","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.hcc.2025.100338_b20","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103703","article-title":"Xran: Explainable deep learning-based ransomware detection using dynamic analysis","volume":"139","author":"G\u00fclmez","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.hcc.2025.100338_b21","doi-asserted-by":"crossref","first-page":"107","DOI":"10.1007\/978-3-319-73951-9_6","article-title":"Leveraging support vector machine for opcode density based detection of crypto-ransomware","author":"Baldwin","year":"2018","journal-title":"Cyber Threat. Intell."},{"issue":"1","key":"10.1016\/j.hcc.2025.100338_b22","first-page":"131","article-title":"Texture-based automated classification of ransomware","volume":"102","author":"Sharma","year":"2021","journal-title":"J. Inst. Eng. (India): Ser."},{"key":"10.1016\/j.hcc.2025.100338_b23","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102512","article-title":"Rcryptect: Real-time detection of cryptographic function in the user-space filesystem","volume":"112","author":"Lee","year":"2022","journal-title":"Comput. Secur."},{"issue":"2","key":"10.1016\/j.hcc.2025.100338_b24","doi-asserted-by":"crossref","first-page":"341","DOI":"10.1109\/TETC.2017.2756908","article-title":"Know abnormal, find evil: frequent pattern mining for ransomware threat hunting and intelligence","volume":"8","author":"Homayoun","year":"2017","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"issue":"3","key":"10.1016\/j.hcc.2025.100338_b25","first-page":"337","article-title":"Multilayer ransomware detection using grouped registry key operations","volume":"28","author":"Jethva","year":"2020","journal-title":"File Entropy File Signat. Monit. J. Comput. Secur."},{"issue":"1","key":"10.1016\/j.hcc.2025.100338_b26","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1109\/TNSM.2021.3112056","article-title":"On ransomware family attribution using pre-attack paranoia activities","volume":"19","author":"Molina","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.hcc.2025.100338_b27","doi-asserted-by":"crossref","first-page":"6113","DOI":"10.1109\/TIFS.2024.3410511","article-title":"Ranker: Early ransomware detection through kernel-level behavioral analysis","volume":"19","author":"Zhang","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.hcc.2025.100338_b28","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103849","article-title":"Zero-Ran Sniff: A zero-day ransomware early detection method based on zero-shot learning","volume":"142","author":"Cen","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.hcc.2025.100338_b29","first-page":"1","article-title":"Machine learning-based intrusion detection for zero-day ransomware in unseen data","author":"Brinkley","year":"2024","journal-title":"Authorea"},{"issue":"12","key":"10.1016\/j.hcc.2025.100338_b30","doi-asserted-by":"crossref","first-page":"1396","DOI":"10.1007\/s10489-022-03244-6","article-title":"Zero-day ransomware attack detection using deep contractive autoencoder and voting based ensemble classifier","volume":"52","author":"Zahoora","year":"2022","journal-title":"Appl. Intell."},{"issue":"1","key":"10.1016\/j.hcc.2025.100338_b31","doi-asserted-by":"crossref","first-page":"69","DOI":"10.4103\/2395-5414.157577","article-title":"Chi-square test and its application in hypothesis testing","volume":"1","author":"Rana","year":"2015","journal-title":"J. Pr. Cardiovasc. Sci."},{"key":"10.1016\/j.hcc.2025.100338_b32","series-title":"Automated dynamic analysis of ransomware: Benefits, limitations and use for detection","author":"Sgandurra","year":"2016"},{"issue":"11","key":"10.1016\/j.hcc.2025.100338_b33","doi-asserted-by":"crossref","first-page":"2528","DOI":"10.3390\/s19112528","article-title":"Improving the classification effectiveness of intrusion detection by using improved conditional variational autoencoder and deep neural network","volume":"19","author":"Yang","year":"2019","journal-title":"Sensors"},{"issue":"1","key":"10.1016\/j.hcc.2025.100338_b34","doi-asserted-by":"crossref","first-page":"100","DOI":"10.1038\/s43586-022-00184-w","article-title":"Principal component analysis","volume":"2","author":"Greenacre","year":"2022","journal-title":"Nat. Rev. Methods Prim."},{"issue":"1","key":"10.1016\/j.hcc.2025.100338_b35","first-page":"1210","article-title":"Dynamic malware analysis with feature engineering and feature learning","volume":"34","author":"Zhang","year":"2020","journal-title":"Proc. the AAAI Conf. Artif. Intell."},{"key":"10.1016\/j.hcc.2025.100338_b36","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102785","article-title":"Malware-SMELL: A zero-shot learning strategy for detecting zero-day vulnerabilities","volume":"120","author":"Barros","year":"2022","journal-title":"Comput. Secur."}],"container-title":["High-Confidence Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S266729522500042X?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S266729522500042X?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T11:26:34Z","timestamp":1774869994000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S266729522500042X"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":36,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,3]]}},"alternative-id":["S266729522500042X"],"URL":"https:\/\/doi.org\/10.1016\/j.hcc.2025.100338","relation":{},"ISSN":["2667-2952"],"issn-type":[{"value":"2667-2952","type":"print"}],"subject":[],"published":{"date-parts":[[2026,3]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"A novel zero-day ransomware detection approach based on CVAE and 1D-CNN","name":"articletitle","label":"Article Title"},{"value":"High-Confidence Computing","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.hcc.2025.100338","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2025 The Author(s). Published by Elsevier B.V. on behalf of Shandong University.","name":"copyright","label":"Copyright"}],"article-number":"100338"}}