Ilmu Komputer & AI editorial
Open AccessOA2026
DEFEAT: Stitching Fragmented File I/O Contexts for Early Ransomware Detection
Reconstructing scattered file-operation context into File Event Gadgets for single-file encryption detection
Muhammad Ejaz Ahmed; Hyoungshick Kim; Mohsen Ali Alawami; Alsharif Abuadbba; Seyit Camtepe; Surya Nepal; Junaid Qadirยท 2026ยท DOI 10.48550/arXiv.2609.21426
The core problem
Ransomware has evolved to fragment its file operations across temporary and intermediate files, deliberately scattering the semantic context that links individual I/O events to an overarching encryption campaign. This fragmentation defeats existing detectors that reason over isolated file streams. Pattern-based methods match rigid event sequences and fail when the sequence is split across dynamically created files; learning-based methods require accumulating statistical evidence across many files before they can classify, which delays detection until substantial damage has occurred. The paper introduces DEFEAT, a framework that reconstructs this fragmented, scattered context by grouping causally related file events into **File Event Gadgets (FEGs)**. An FEG is a semantically coherent unit that captures the full intent behind sequences of file operations spanning multiple dynamically created files. Unlike provenance graphs, which are system-wide causal graphs recording relationships among all OS entities (processes, files, sockets, registry keys) across the entire system, FEGs are scoped to the file-operation context of a single user asset. This scoping enables lightweight, targeted
Innovation
DEFEAT was evaluated on a corpus of **97,816,471 file I/O events** spanning **67 ransomware families**. The framework achieves **99.2% detection accuracy**. It outperforms state-of-the-art methods including UNVEIL, RWGuard, and Peeler by **6.57 to 7.56 percentage points**. The unsupervised clustering approach reduces analyst annotation effort by **94%** compared to sample-level labelling. Crucially, because detection can occur at the first encrypted file, DEFEAT provides early warning before widespread encryption. The evaluation demonstrates that scoping analysis to a single user asset's file-operation context is sufficient for high-accuracy detection, without requiring whole-system provenance instrumentation.
Ransomware has evolved to fragment its file operations across temporary and intermediate files, deliberately scattering the semantic context that links individual I/O events to an overarching encryption campaign. This fragmentation defeats existing detectors that reason over isolated file streams. Pattern-based methods match rigid event sequences and fail when the sequence is split across dynamically created files; learning-based methods require accumulating statistical evidence across many files before they can classify, which delays detection until substantial damage has occurred. The paper introduces DEFEAT, a framework that reconstructs this fragmented, scattered context by grouping causally related file events into **File Event Gadgets (FEGs)**. An FEG is a semantically coherent unit that captures the full intent behind sequences of file operations spanning multiple dynamically created files. Unlike provenance graphs, which are system-wide causal graphs recording relationships among all OS entities (processes, files, sockets, registry keys) across the entire system, FEGs are scoped to the file-operation context of a single user asset. This scoping enables lightweight, targeted analysis without whole-system instrumentation. The central research question is whether reconstructing fragmented file I/O context at the granularity of a single user asset can enable early, accurate ransomware detection.
DEFEAT operates in three main stages: (1) FEG construction, (2) ACFG modelling and embedding, and (3) unsupervised clustering with analyst-in-the-loop labelling.
Why it matters
The key insight of DEFEAT is that fragmentation of file operations is not merely an evasion tactic but a structural property that can be exploited if the scattered context is reconstructed. By stitching causally related events into FEGs, the framework recovers the semantic intent that isolated file-stream detectors miss. The use of ACFGs and GNN embeddings allows the system to generalise across ransomware families without hand-crafted patterns. The unsupervised clustering step shifts the human effort from labelling individual samples to labelling behavioural clusters, a 94% reduction that makes deployment practical in real security operations centres. The single-file detection granularity is a significant operational advantage: defenders can respond at the first encrypted file rather than after many files have been compromised. Limitations include the need for file-system-level instrumentation to capture I/O events, and the assumption that causal relationships among dynamically created files can be reliably reconstructed. Future work may extend FEGs to network and registry contexts, and explore adversarial robustness against deliberate fragmentation designed to break causal stitching. Overall, DEFEAT advances the state of the art in early ransomware detection by reframing the problem as one of context reconstruction rather than pattern matching or statistical accumulation.
Who should read this
CS practitioners and researchers
Opening member contentโฆ