Ransomware Detection

GAT · internal_only

Standard SplitFeb 18, 2026

8ab380c0fd39416682e3fcc3a42eb0e7

Description

Train GAT on the internal_only dataset to complete the three-model architecture comparison (GIN, GCN, GAT).

Conclusion

GAT performs comparably to GCN (96.3% accuracy) with slightly better recall (96.9% vs 93.8%). Attention mechanism does not provide a clear advantage over simpler aggregation on the internal_only graphs.

Test Metrics

Accuracy

96.3%

F1 Macro

95.6%

F1 Malware

93.9%

Precision

91.2%

Recall

96.9%

AUROC

98.5%

Best Val Loss

0.1853

Training Time

2046.8000s

Confusion Matrix

Pred BenignPred Malware
Actual Benign733
Actual Malware131

Configuration

Hidden Dim128
Num Layers3
Dropout0.5
Batch Size4
Learning Rate0.001
Weight Decay0.0001
Max Epochs200
ES Patience20
ES Min Epochs100
LR Patience10
LR Factor0.5
Mixed PrecisionYes
Random Seed42
Epochs Trained100