Ransomware Detection

GIN · full_fcg

Standard SplitFeb 17, 2026

d790cb53338f4e109fbfc6c3e41744cf

Description

Train GIN on the full_fcg dataset (all methods, internal + external) to compare with the internal_only result from Experiment 02.

Conclusion

Lower accuracy than internal_only (95.4% vs 98.2%) despite the richer graph representation. Still achieves perfect malware recall. Suggests the larger graphs introduce noise without improving discriminative power for GIN.

Test Metrics

Accuracy

95.4%

F1 Macro

94.7%

F1 Malware

92.8%

Precision

86.5%

Recall

100.0%

AUROC

97.7%

Best Val Loss

0.0935

Training Time

935.0000s

Confusion Matrix

Pred BenignPred Malware
Actual Benign715
Actual Malware032

Configuration

Hidden Dim128
Num Layers3
Dropout0.5
Batch Size4
Learning Rate0.001
Weight Decay0.0001
Max Epochs200
ES Patience20
ES Min Epochs100
LR Patience10
LR Factor0.5
Mixed PrecisionYes
Random Seed42
Epochs Trained113