[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83153-en":3,"doc-seo-83153-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83153,687197207057,"Sage","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Auditable Machine Unlearning for Privacy-Compliant Ransomware Detection Using Multi-Shard SISA and Deep Reinforcement Learning","Ransomware increasingly evades static defenses by adapting behavioral patterns, while current ML detectors typically presume fixed training data and cannot selectively erase previously learned samples. Privacy regulations such as GDPR and CCPA require deletion of sensitive user data on request, demanding privacy-compliant unlearning. The work proposes an auditable ransomware detection-and-unlearning framework combining deep reinforcement learning with multi-shard SISA retraining. A DDQN learns a reward-guided policy under asymmetric security costs, and shard-level retraining supports validated forgetting and efficient removal. Experiments on Windows 11 show near-baseline detection performance with limited utility loss, strong forgetting auditing, and high efficiency compared with full retraining.","Auditable Machine Unlearning for Privacy-Compliant Ransomware Detection Using Multi-Shard SISA and Deep Reinforcement Learning  \nJannatul Ferdousa,∗ , Rafiqul Islamb and Md Zahidul Islamc,d  \na School of Computing, Mathematics and Engineering, Charles Sturt University, Wagga Wagga, NSW, 2650, Australia b School of Computing, Mathematics and Engineering, Charles Sturt University, Albury, NSW, 2640, Australia  \nc School of Computing, Mathematics and Engineering, Charles Sturt University, Panorama Avenue, Bathurst, NSW, 2795, Australia dAI and Cyber Futures Centre, Charles Sturt University, Panorama Avenue, Bathurst, NSW, 2795, Australia  \narXiv :2607 .06860v 1 [ cs .CR] 7 Jul 2026  \nARTICLE INFO  \nKeywords:  \nRansomware detection  \nmachine unlearning  \ndeep reinforcement learning Double Deep Q-Network (DDQN) SISA  \nprivacy-preserving machine learning GDPR compliance  \nmembership inference attacks  \nAB STRACT  \nRansomware poses an escalating cybersecurity threat as attackers continuously modify behavioural patterns to evade static defenses. Although existing machine learning-based detectors often achieve strong predictive performance, they generally assume fixed training data and do not support the selective removal of previously learned samples. This limitation conflicts with privacy regulations such as the GDPR and CCPA, which require the removal of sensitive user data upon request. To address this challenge, we propose an auditable ransomware detection and unlearning framework that integrates deep reinforcement learning with multi-shard SISA retraining. In the proposed system, a Double Deep Q-Network (DDQN) learns a reward-guided detection policy from behavioral features under asymmetric security costs, while multi-shard SISA enables privacy-compliant selective sample removal through shard-level retraining. The framework was evaluated using four criteria: utility preservation, oracle-based forgetting validation, membership inference auditing, and computational efficiency. On a balanced Windows 11 behavioral dataset comprising 2,000 samples and 103 features, the baseline DDQN detector achieved an F1 score of 0.9925 and an AUC of 0.9983 . The experimental results show that single-shard unlearning maintains minimal utility degradation and low oracle disagreement, whereas moderate shard counts (􀁍 = 5–10) provide the best efficiency-performance trade-off, reducing retraining time to 5–30 s compared with 80–330 s for full retraining. In addition, the membership inference scores remain close to 0.5 across most configurations, indicating limited privacy leakage after unlearning. These findings demonstrate that a privacy-compliant ransomware detection framework can jointly achieve high detection performance, auditable deletion verification, and efficient sample removal.  \n1. Introduction  \nRansomware remains one of the most severe cybersecurity threats, with projected global damages exceeding $265 billion annually by 2030 Braue (2025) . By encrypting user data and demanding payment for decryption, ransomware attacks have caused substantial financial and operational damage across industries including healthcare, finance, and government services Ferdous, Islam, Mahboubi and Zahidul Islam (2024) . As ransomware campaigns continue to evolve through obfuscation, packing techniques, and rapidly changing variants, traditional signature-based detection mechanisms are becoming increasingly ineffective.  \nBehavior-based detection approaches have been widely explored to overcome these limitations. Instead of relying on static signatures, these methods analyze dynamic behavioral traces collected during program execution, including filesystem activity, registry modifications, process behavior, and network interactions of the program. Machine learning (ML) and deep learning (DL) techniques have demonstrated strong capabilities in identifying ransomware patterns from such behavioral telemetry Cen, Jiang and Doss (2025); Huertas Celdrán, Sánchez Sánch","cbCairRirq0fymjP","https://ap.wps.com/l/cbCairRirq0fymjP","pdf",3929690,2,1,19,"English","en",105,"# Introduction\n## Ransomware and limitations of static detection\n## Behavior-based detection and reinforcement learning\n## Privacy regulations and the need for unlearning","[{\"question\":\"Why do traditional ransomware detectors conflict with privacy regulations like GDPR or CCPA?\",\"answer\":\"They typically assume fixed training data and do not support selective removal of specific previously learned samples. Privacy rules require erasing sensitive user data upon request, which makes conventional retraining costly and insufficient for continuous systems.\"},{\"question\":\"What does the proposed framework use to achieve both detection and selective unlearning?\",\"answer\":\"It integrates deep reinforcement learning with multi-shard SISA retraining. A DDQN learns a detection policy from behavioral features using a reward structure that encodes asymmetric security costs.\"},{\"question\":\"How is unlearning evaluated for both effectiveness and privacy leakage?\",\"answer\":\"The framework is assessed using utility preservation, oracle-based forgetting validation, membership inference auditing, and computational efficiency. Results indicate minimal utility degradation, low oracle disagreement, and membership inference scores near 0.5 after unlearning.\"}]",1784185639,48,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"auditable-machine-unlearning-for-privacy-compliant-ransomware-detection-using-multi-shard-sisa-and-deep-reinforcement-learning","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/auditable-machine-unlearning-for-privacy-compliant-ransomware-detection-using-multi-shard-sisa-and-deep-reinforcement-learning/83153/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why do traditional ransomware detectors conflict with privacy regulations like GDPR or CCPA?","Question",{"text":75,"@type":76},"They typically assume fixed training data and do not support selective removal of specific previously learned samples. Privacy rules require erasing sensitive user data upon request, which makes conventional retraining costly and insufficient for continuous systems.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What does the proposed framework use to achieve both detection and selective unlearning?",{"text":80,"@type":76},"It integrates deep reinforcement learning with multi-shard SISA retraining. A DDQN learns a detection policy from behavioral features using a reward structure that encodes asymmetric security costs.",{"name":82,"@type":73,"acceptedAnswer":83},"How is unlearning evaluated for both effectiveness and privacy leakage?",{"text":84,"@type":76},"The framework is assessed using utility preservation, oracle-based forgetting validation, membership inference auditing, and computational efficiency. Results indicate minimal utility degradation, low oracle disagreement, and membership inference scores near 0.5 after unlearning.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},"General","general"]