{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,13]],"date-time":"2026-02-13T17:13:31Z","timestamp":1771002811514,"version":"3.50.1"},"reference-count":46,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2026,2,13]],"date-time":"2026-02-13T00:00:00Z","timestamp":1770940800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Traditional signature-based anti-malware tools often fail to detect zero-day ransomware attacks due to their reliance on known patterns. This paper presents a real-time ransomware detection framework that models system behavior as a Reinforcement Learning (RL) environment. Behavioral features\u2014including file entropy, CPU usage, and registry changes\u2014are extracted from dynamic analysis logs generated by Cuckoo Sandbox. A (DQN) agent is trained to proactively block malicious actions by maximizing long-term rewards based on observed behavior. Experimental evaluation across multiple ransomware families such as WannaCry, Locky, Cerber, and Ryuk demonstrates that the proposed RL agent achieves a superior detection accuracy, precision, and F1-score compared to existing static and supervised learning methods. Furthermore, ablation tests and latency analysis confirm the model\u2019s robustness and suitability for real-time deployment. This work introduces a behavior-driven, generalizable approach to ransomware defense that adapts to unseen threats through continual learning.<\/jats:p>","DOI":"10.3390\/info17020194","type":"journal-article","created":{"date-parts":[[2026,2,13]],"date-time":"2026-02-13T16:09:32Z","timestamp":1770998972000},"page":"194","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Real-Time Ransomware Detection Using Reinforcement Learning Agents"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-4916-7026","authenticated-orcid":false,"given":"Kutub","family":"Thakur","sequence":"first","affiliation":[{"name":"College of Professional Studies, St. John\u2019s University, New York, NY 11439, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8945-3230","authenticated-orcid":false,"given":"Md Liakat","family":"Ali","sequence":"additional","affiliation":[{"name":"Department of Computer Science & Physics, Rider University, Lawrenceville, NJ 08648, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Suzanna","family":"Schmeelk","sequence":"additional","affiliation":[{"name":"College of Professional Studies, St. John\u2019s University, New York, NY 11439, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Joan","family":"Debello","sequence":"additional","affiliation":[{"name":"College of Professional Studies, St. John\u2019s University, New York, NY 11439, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Md Mustafizur","family":"Rahman","sequence":"additional","affiliation":[{"name":"Department of Mathematics and Computer Sciences, Mercy University, Dobbs Ferry, NY 10522, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,2,13]]},"reference":[{"key":"ref_1","first-page":"51","article-title":"Cyber threats to critical infrastructure: Assessing vulnerabilities across key sectors","volume":"2","author":"George","year":"2024","journal-title":"Partners Univers. Int. Innov. J."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"2942","DOI":"10.30574\/ijsra.2024.12.1.1210","article-title":"Encryption techniques for financial data security in fintech applications","volume":"12","author":"Olaiya","year":"2024","journal-title":"Int. J. Sci. Res. Arch."},{"key":"ref_3","first-page":"5","article-title":"An evaluation of current malware trends and defense techniques: A scoping review with empirical case studies","volume":"15","author":"Cletus","year":"2024","journal-title":"J. Adv. Inf. Technol."},{"key":"ref_4","first-page":"11","article-title":"Enhancing cyber threat detection through real-time threat intelligence and adaptive defense mechanisms","volume":"13","author":"Aminu","year":"2024","journal-title":"Int. J. Comput. Appl. Technol. Res."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"28898","DOI":"10.1109\/ACCESS.2024.3367122","article-title":"Diving deep with botlab-ds1: A novel ground truth-empowered botnet dataset","volume":"12","author":"Qasim","year":"2024","journal-title":"IEEE Access"},{"key":"ref_6","first-page":"60","article-title":"Anomaly detection with API calls by using machine learning: Systematic literature review","volume":"2","author":"Arat","year":"2024","journal-title":"Curr. Trends Comput."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Yu, R., Li, P., Hu, J., Chen, L., Zhang, L., Qiu, X., and Wang, F. (Authorea Prepr., 2024). Ransomware detection using dynamic behavioral profiling: A novel approach for real-time threat mitigation, Authorea Prepr., in press.","DOI":"10.36227\/techrxiv.173047864.44215173\/v1"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Thakur, K., Ali, M.L., Obaidat, M.A., and Kamruzzaman, A. (2023). A systematic review on deep-learning-based phishing email detection. Electronics, 12.","DOI":"10.3390\/electronics12214545"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Song, C., Shin, S.-Y., and Shin, K.-S. (2024). Implementing the dynamic feedback-driven learning optimization framework: A machine learning approach to personalize educational pathways. Appl. Sci., 14.","DOI":"10.20944\/preprints202401.0811.v1"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"955","DOI":"10.1613\/jair.1.12233","article-title":"Constrained multiagent Markov decision processes: A taxonomy of problems and algorithms","volume":"70","author":"Walraven","year":"2021","journal-title":"J. Artif. Intell. Res."},{"key":"ref_11","first-page":"38","article-title":"A Comprehensive review of machine learning approaches for android malware detection","volume":"1","author":"Davarasan","year":"2024","journal-title":"J. Cyber Secur. Risk Audit."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Ali, M.L., Thakur, K., Schmeelk, S., Debello, J., and Dragos, D. (2025). Deep Learning vs. Machine Learning for Intrusion Detection in Computer Networks: A Comparative Study. Appl. Sci., 15.","DOI":"10.3390\/app15041903"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"e2021WR029927","DOI":"10.1029\/2021WR029927","article-title":"A state-of-the-art review of optimal reservoir control for managing conflicting demands in a changing world","volume":"57","author":"Giuliani","year":"2021","journal-title":"Water Resour. Res."},{"key":"ref_14","first-page":"36","article-title":"Deep learning for zero-day malware detection and classification: A survey","volume":"56","author":"Deldar","year":"2023","journal-title":"ACM Comput. Surv."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Ding, Y., Steenhoek, B., Pei, K., Kaiser, G., Le, W., and Ray, B. (2024, January 14\u201320). Traced: Execution-aware pre-training for source code. Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering, Lisbon, Portugal.","DOI":"10.1145\/3597503.3608140"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Akalin, N., and Loutfi, A. (2021). Reinforcement learning approaches in social robotics. Sensors, 21.","DOI":"10.3390\/s21041292"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"9515","DOI":"10.1109\/JSEN.2021.3055898","article-title":"A hybrid posture detection framework: Integrating machine learning and deep neural networks","volume":"21","author":"Liaqat","year":"2021","journal-title":"IEEE Sens. J."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"3","DOI":"10.63180\/jsrm.thestap.2025.1.1","article-title":"Enhancing intrusion detection systems by using machine learning in smart cities: Issues, challenges and future research direction","volume":"1","author":"Almarshood","year":"2025","journal-title":"STAP J. Secur. Risk Manag."},{"key":"ref_19","first-page":"20","article-title":"Comprehensive analysis of ransomware evolution and countermeasures in the era of digital transformation","volume":"8","author":"Karim","year":"2024","journal-title":"Int. J. Adv. Cybersecur. Syst. Technol. Appl."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"699","DOI":"10.1007\/s10207-023-00766-z","article-title":"Cashing out crypto: State of practice in ransom payments","volume":"23","author":"Patsakis","year":"2024","journal-title":"Int. J. Inf. Secur."},{"key":"ref_21","unstructured":"Triantafyllou, G.P. (2024). Malware Analysis. [Master\u2019s Thesis, University of Piraeus]."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Thakur, K., Debello, J., Kamruzzaman, A., and Ali, M.L. (2024, January 24\u201326). Safeguarding Network: Mechanisms and Prevention Strategies of DNS Hijacking. Proceedings of the 2024 IEEE 15th Annual Information Technology, Electronics and Mobile Communication Conference (IEMCON), Berkeley, CA, USA.","DOI":"10.1109\/IEMCON62851.2024.11093501"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Anikolova, E., Martins, S., Rozental, D., Fontana, J., and Maier, P. (Authorea Prepr., 2024). Ransomware detection through behavioral attack signatures evaluation: A novel machine learning framework for improved accuracy and robustness, Authorea Prepr., in press.","DOI":"10.36227\/techrxiv.173092022.26611647\/v1"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"1035","DOI":"10.1038\/s41559-022-01761-8","article-title":"Detecting signatures of selection on gene expression","volume":"6","author":"Price","year":"2022","journal-title":"Nat. Ecol. Evol."},{"key":"ref_25","first-page":"167","article-title":"Dynamic malware analysis through system call tracing and API monitoring","volume":"1","author":"Kamaluddin","year":"2023","journal-title":"ESP Int. J. Adv. Comput. Technol."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Redhu, A., Choudhary, P., Srinivasan, K., and Das, T.K. (2024). Deep learning-powered malware detection in cyberspace: A contemporary review. Front. Phys., 12.","DOI":"10.3389\/fphy.2024.1349463"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Mansfield, D., and Montazeri, A. (2024). A survey on autonomous environmental monitoring approaches: Towards unifying active sensing and reinforcement learning. Front. Robot. AI, 11.","DOI":"10.3389\/frobt.2024.1336612"},{"key":"ref_28","unstructured":"Mahboubi, A., Aboutorab, H., Camtepe, S., Bui, H.T., Luong, K., Ansari, K., Wang, S., and Barry, B. (2025). Data encryption battlefield: A deep dive into the dynamic confrontations in ransomware attacks. arXiv."},{"key":"ref_29","first-page":"589","article-title":"Deep reinforcement learning in the advanced cybersecurity threat detection and protection","volume":"25","author":"Sewak","year":"2023","journal-title":"Inf. Syst. Front."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Herath, J.D., Yang, P., and Yan, G. (2021, January 26\u201328). Real-time evasion attacks against deep learning-based anomaly detection from distributed system logs. Proceedings of the Eleventh ACM Conference on Data and Application Security and Privacy, Virtual.","DOI":"10.1145\/3422337.3447833"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Gazzan, M., and Sheldon, F.T. (2023). Opportunities for early detection and prediction of ransomware attacks against industrial control systems. Future Internet, 15.","DOI":"10.3390\/fi15040144"},{"key":"ref_32","first-page":"106","article-title":"Beyond defense: Proactive approaches to disaster recovery and threat intelligence in modern enterprises","volume":"15","author":"Tahmasebi","year":"2024","journal-title":"J. Inf. Secur."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Thakur, K., Ali, M.L., Schmeelk, S., Debello, J., and Dragos, D. (2025, January 18\u201321). Obesity Risk Prediction Using Machine Learning by Combining Lifestyle Factors. Proceedings of the Tenth International Congress on Information and Communication Technology: ICICT 2025, London, UK.","DOI":"10.1007\/978-981-96-6929-5_8"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Al E\u2019mari, S., Sanjalawe, Y., and Fataftah, F. (2025). AI-driven security systems and intelligent threat response using autonomous cyber defense. AI-Driven Security Systems and Intelligent Threat Response Using Autonomous Cyber Defense, IGI Global.","DOI":"10.4018\/979-8-3373-0954-5.ch002"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"von der Assen, J., Celdr\u00e1n, A.H., Luechinger, J., S\u00e1nchez, P.M.S., Bovet, G., P\u00e9rez, G.M., and Stiller, B. RansomAI: AI-powered ransomware for stealthy encryption. Proceedings of the GLOBECOM 2023.","DOI":"10.1109\/GLOBECOM54140.2023.10437393"},{"key":"ref_36","unstructured":"Anderson, H.S., Kharkar, A., Filar, B., Evans, D., and Roth, P. (2018). Learning to evade static PE machine learning malware models via reinforcement learning. arXiv."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Wang, S., Dong, F., Yang, H., Xu, J., and Wang, H. (2024, January 14\u201318). Cancal: Towards real-time and lightweight ransomware detection and response in industrial environments. Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, Salt Lake City, UT, USA.","DOI":"10.1145\/3658644.3690269"},{"key":"ref_38","unstructured":"Svet, L., Brightwell, A., Wildflower, A., and Marshwood, C. (2025). Unveiling zero-space detection: A novel framework for autonomous ransomware identification in high-velocity environments. arXiv."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"118299","DOI":"10.1016\/j.eswa.2022.118299","article-title":"Crypto-ransomware detection using machine learning models in file-sharing network scenarios with encrypted traffic","volume":"209","author":"Berrueta","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"ref_40","first-page":"4069","article-title":"Real-time ransomware detection and visualization framework using machine learning","volume":"11","author":"Sakthidevi","year":"2025","journal-title":"Int. J. Innov. Res. Technol."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Gazzan, M., and Sheldon, F.T. (2024). Novel ransomware detection exploiting uncertainty and calibration quality measures using deep learning. Information, 15.","DOI":"10.3390\/info15050262"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Rani, N., and Dhavale, S.V. (2022). Leveraging machine learning for ransomware detection. arXiv.","DOI":"10.1007\/978-981-16-6890-6_13"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Choi, S.-H., Choi, S.-M., and Buu, S.-J. (2025). Proximal policy-guided hyperparameter optimization for mitigating model decay in cryptocurrency scam detection. Electronics, 14.","DOI":"10.3390\/electronics14061192"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Amaizu, G.C., Sai, A.M.V.V., Bwardwaj, S., Kim, D.-S., Siddula, M., and Li, Y. (2025). FedVitBloc: Secure and privacy-enhanced medical image analysis with federated vision transformer and blockchain. High-Confid. Comput., 100302.","DOI":"10.1016\/j.hcc.2025.100302"},{"key":"ref_45","first-page":"9610","article-title":"MalBotDRL: Malware botnet detection using deep reinforcement learning in IoT networks","volume":"11","author":"Szewczyk","year":"2023","journal-title":"IEEE Internet Things J."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Hurley, R., Kruger, P., Nascimento, H., and Keller, S. (2024). Real-time ransomware detection through adaptive behavior fingerprinting for improved cybersecurity resilience and defense. OSF.","DOI":"10.31219\/osf.io\/7d2y5"}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/17\/2\/194\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,13]],"date-time":"2026-02-13T16:24:09Z","timestamp":1770999849000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/17\/2\/194"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,13]]},"references-count":46,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2026,2]]}},"alternative-id":["info17020194"],"URL":"https:\/\/doi.org\/10.3390\/info17020194","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,13]]}}}