[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84720-en":3,"doc-seo-84720-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84720,549758252649,"Ivy","https://ap-avatar.wpscdn.com/avatar/8000253669c5317157?_k=1778319167496531819",8,"Research & Report","Agentic SABRE: An Uncertainty-Aware Neuro-Symbolic Multi-Agent Framework for Adaptive Ransomware Detection","Adaptive ransomware detection requires uncertainty-aware systems because static signatures and monolithic classifiers fail under concept drift, evasion, and behavioural polymorphism. Agentic SABRE (Semantic–Behavioural Arbitration for Ransomware Evaluation) combines semantic evidence and time-window forensic telemetry, using Monte Carlo Dropout to estimate epistemic uncertainty per agent. A decision-layer orchestrator performs risk/uncertainty triage with interpretable thresholds and escalates uncertain cases to analysts. Post-hoc explainability enables local and global auditing, while evaluations on RDset and RanSMAP show strong discrimination and improved robustness under weak signals.","arXiv :2607 .04292v 1 [ cs .AI ] 5 Jul 2026  \nAgentic SABRE: An Uncertainty-Aware Neuro-Symbolic Multi-Agent Framework for Adaptive Ransomware Detection  \nHenry Kabuyea , Biju Issaca,∗, Jeyamohan Neeraa  \na School of Computer Science, Northumbria University, Newcastle Upon Tyne, UK  \nAbstract  \nRansomware has evolved into a complex, adaptive, and fast–moving adversary category in which static signatures and monolithic classifiers fail to generalise under concept drift, evasion, and behavioural polymorphism. In this paper we present Agentic SABRE (Semantic–Behavioural Arbitration for Ransomware Evaluation): an uncertainty–aware, neuro–symbolic, multi–agent framework for adaptive ransomware detection. SABRE fuses semantic (representation–based) and behavioural (time–window forensic telemetry) evidence, and employs Monte Carlo Dropout inference to quantify epistemic uncertainty for each agent.  \nWe introduce a decision–layer orchestrator that performs risk– and uncertainty–aware triage via two interpretable thresholds: a risk score τ and an uncertainty budget κ . High–confidence, high–risk samples are automatically contained, while uncertain or borderline cases are escalated to human analysts, establishing a flexible computational contract between autonomous response and analyst oversight. To support auditability and trust, SABRE integrates post–hoc explainability mechanisms including gradient saliency, permutation importance, and counterfactual analysis, enabling both local and global interpretation of agent decisions.  \nExtensive evaluation on RDset and RanSMAP demonstrates that Agentic SABRE preserves perfect discrimination on saturated semantic datasets (AUC = 1 .0) while improving robustness under weak behavioural signals, achieving up to a 4.9% relative reduction in false escalations at equal recall and maintaining calibrated predictive uncertainty. Counterfactual analysis further shows that semantic and behavioural decisions can be flipped with bounded perturbation cost, indicating stable and interpretable decision boundaries. Overall, Agentic SABRE is not merely a higher–accuracy detector but an agentic cyber–defence system that combines uncertainty–aware automation, explainable reasoning, and adaptive triage under evolving ransomware threats.  \nKeywords: Ransomware Detection, Explainable Artificial Intelligence, Uncertainty Estimation, Multi-Agent Systems, Semantic Embeddings, Data Augmentation  \n1. Introduction  \nRansomware has become one of the most disruptive forms of cybercrime, with modern families exhibiting rapid mutation, behavioural polymorphism, and highly adaptive strategies designed to evade both traditional signature-based defences and contemporary machine learning detectors [1, 2] . These strains frequently employ advanced obfuscation, polymorphism, and metamorphism to alter operational behaviour and code signatures, undermining static detection techniques and forcing dependence on behavioural and AI-based methods [1, 3] . Enterprise environments now operate under continuous concept drift, where benign and malicious behaviours evolve over time and trained models degrade in performance unless retrained or adapted [4] . Static classifiers that assume fixed data distributions consequently suffer rapid decay in effectiveness as attacker strategies evolve [5, 2] . These trends expose the limitations of monolithic ransomware classifiers that  \n∗ Corresponding author  \nEmail address: [bissac@ieee.org](bissac@ieee.org) (Biju Issac)  \nlack explicit representations of uncertainty, fail to adapt to temporal distributional changes without costly retraining, and provide no mechanism for calibrated human–AI interaction, a gap increasingly recognised in both malware analytics and adaptive learning research.  \nMachine learning has been increasingly applied to ransomware detection, ranging from classical featurebased models to deep learning approaches that operate on system call traces, filesystem activity, API semantics, a","cbCaipXdsPsqwRRJ","https://ap.wps.com/l/cbCaipXdsPsqwRRJ","pdf",1229170,3,1,34,"English","en",105,"# Abstract\n# 1. Introduction\n## Background: Evolution and limitations of ransomware detection\n## Motivation: Uncertainty and human–AI interaction\n## Proposed approach: Agentic SABRE framework","[{\"question\":\"What problem does Agentic SABRE address in ransomware detection?\",\"answer\":\"It addresses the failure of static signatures and monolithic classifiers to generalize under concept drift, evasion, and behavioural polymorphism, especially due to the lack of calibrated uncertainty for safe autonomous containment.\"},{\"question\":\"How does Agentic SABRE quantify uncertainty?\",\"answer\":\"Each agent uses Monte Carlo Dropout inference to produce calibrated estimates of epistemic uncertainty, allowing the system to identify high-confidence versus ambiguous predictions.\"},{\"question\":\"How are decisions made and communicated to analysts?\",\"answer\":\"A decision-layer orchestrator fuses agent scores and applies interpretable thresholds: a risk score (τ) and an uncertainty budget (κ). High-risk, low-uncertainty samples are contained automatically, while uncertain or borderline cases are escalated for human review.\"}]",1784197844,86,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"agentic-sabre-an-uncertainty-aware-neuro-symbolic-multi-agent-framework-for-adaptive-ransomware-detection","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/agentic-sabre-an-uncertainty-aware-neuro-symbolic-multi-agent-framework-for-adaptive-ransomware-detection/84720/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-22","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does Agentic SABRE address in ransomware detection?","Question",{"text":75,"@type":76},"It addresses the failure of static signatures and monolithic classifiers to generalize under concept drift, evasion, and behavioural polymorphism, especially due to the lack of calibrated uncertainty for safe autonomous containment.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does Agentic SABRE quantify uncertainty?",{"text":80,"@type":76},"Each agent uses Monte Carlo Dropout inference to produce calibrated estimates of epistemic uncertainty, allowing the system to identify high-confidence versus ambiguous predictions.",{"name":82,"@type":73,"acceptedAnswer":83},"How are decisions made and communicated to analysts?",{"text":84,"@type":76},"A decision-layer orchestrator fuses agent scores and applies interpretable thresholds: a risk score (τ) and an uncertainty budget (κ). High-risk, low-uncertainty samples are contained automatically, while uncertain or borderline cases are escalated for human review.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]