Physical Sciences › Computer Science › Signal Processing
Advanced Malware Detection Techniques
249 artículos indexados
Este asunto y su jerarquía proceden de la clasificación OpenAlex, el catálogo abierto de la investigación científica mundial.
Volumen mensual - últimos 12 meses
Países de los laboratorios
- Estados Unidos40 % · 63 artículos
- China28 % · 45 artículos
- Reino Unido12 % · 19 artículos
- India7,5 % · 12 artículos
- Australia6,9 % · 11 artículos
- Canadá5 % · 8 artículos
- Italia4,4 % · 7 artículos
- Singapur3,8 % · 6 artículos
Sobre 159 artículos de este tema con al menos un laboratorio localizado. 41 países representados.
Se trata del país del laboratorio, nunca de la nacionalidad de las personas. Un artículo firmado desde varios países cuenta para cada uno de ellos, por lo que las partes suman más del 100 %. La cobertura es parcial y el vacío no es aleatorio: un investigador cuya institución se desconoce suele publicar poco, lo que sobrerrepresenta a los laboratorios consolidados.
Últimos artículos
- SkillDRE: Dual-Stage Red-Team Evolution of Agent Skills via Pre-Execution and Runtime Feedback
Pengyu Zhu, Jingyi Yang, Yi Liu, Li Sun, Sen Su · 29 de septiembre de 2026
Agent skills package instructions, executable code, and task-specific resources into reusable artifacts that agents can improve using execution feedback. The same mechanism also enables attackers to evolve malicious skills, making them more effective and less detectable. However, a candidate skill m…
- Classifier-Dependent Benefits of Pseudo-Labeling for Semi-Supervised Android Malware Attribution
Md Rafid Islam, Zahid Hasan, Hafiz Abdur Rahman · 25 de septiembre de 2026
Detecting and classifying Android malware families remains challenging due to high feature dimensionality, class imbalance, and the high cost of expert-labeled data. Semi-supervised learning (SSL) offers a way to leverage unlabeled samples, but prior works rarely test whether SSL benefits generalize…
- Enhancing Multiclass Malware Classification in Resource-Constrained Environments
Abdul Khalek Alve, Alif Rahman, Saadman Zaman, Sazzad Hossen Himel, Muhammad Iqbal Hossain · 24 de septiembre de 2026
The emergence of multi-class malware attacks such as ransomware, spyware, trojans, etc., presents an increasing and serious threat to cybersecurity, particularly in resourceconstrained environments like IoT devices. Existing machine learning models have achieved nearly perfect accuracy in binary mal…
- On the Effect of Bit-Level Parameter Perturbations in Machine Learning and Deep Learning Models
Akanksha Raghapur, Mark Stamp · 23 de septiembre de 2026
In this chapter, we investigate how classical machine learning models respond to small, targeted modifications in their parameters. We compare and contrast these results to analogous experiments on deep learning models. For classical learning models, we consider Hidden Markov Models (HMM) and Suppor…
- Fast And Accurate Text Content File Type Identification
Manu Nandan, Michael Brautbar, Edward Raff · 21 de septiembre de 2026
A common requirement across organizations is to have a tool that can identify file types based on their contents, particularly in the cybersecurity domain where magic numbers and file extensions can not be trusted. While existing tools work well in practice, there is plenty of room for improvement e…
- Delphi Scanner: efficient and interpretable static malware detection via API sequence modeling
Bijied Brahimi, Vincent Cohadon, Gabriel Glazman, Rayan Al Mohaize, Omran Berjawi, Rida Khatoun · 18 de septiembre de 2026
Static malware detection for Windows Portable Executable files demands a careful balance between detection effectiveness, computational efficiency, and analytical interpretability. This paper introduces Delphi Scanner, a static malware detection system for Windows PE files that balances efficiency w…
- ALIBI: Adversarial Legitimacy Injection in Binary Input against LLM Malware Analyzers
Hyeongjun Choi, Wonyoung Jung, Haehoon Seo, Sungyup Nam · 18 de septiembre de 2026
Large language models are being integrated into malware triage workflows as reasoning components that summarize static evidence and produce analyst-facing verdicts. This paper shows that the same reasoning capability introduces a new attack surface. We present ALIBI, a semantic cover story attack ag…
- Permutation-Based Stegomalware in Large Language Models: Threats and Countermeasures
Danny Wood, James Stringer · 16 de septiembre de 2026
The difficulty of training large language models (LLMs), together with their ubiquity, raises the threat of stegomalware, where malicious payloads are embedded into model weights. Recent work has demonstrated the use of permutation symmetry in model weights to mitigate these threats, but failed to s…
- PIDS-Bench: Evaluating Prompt-Injection Detectors Under Over-Defense, Obfuscation, and Distribution Shift
Yusuf Khalid Shire, Sang-Chul Kim · 15 de septiembre de 2026
Prompt-injection detectors are typically evaluated using aggregate F1 on in-distribution test data, which offers limited insight into behavior under distribution shift, particularly on the benign side of the decision boundary, where false positives impose direct operational cost yet are seldom measu…
- SENTINEL: A Multi-Pathway Architecture for Detecting Living-Off-the-Land APT Attacks on Windows Command Lines
Ahad Bin Islam Shoeb, Kamrul Hasan, Jamal Uddin Tanvin, Liang Hong, Imtiaz Ahmed, Md Arif Billah, Al Amin · 15 de septiembre de 2026
Living-Off-the-Land (LOTL) is the dominant evasion technique of Advanced Persistent Threat (APT) actors, exploiting legitimate Windows utilities to conduct malicious operations without deploying custom malware and enabling state-sponsored campaigns to maintain persistent access within military and c…
- Don't Trust the Super-App: A Case Study of Russia's Max
Richa Priyanka, Aaron Ortwein, Joel Reardon, Michael Specter, Piyush Kumar Sharma, Roya Ensafi · 11 de septiembre de 2026
Super-apps, an emerging mobile architecture, host third-party mini-apps inside a single app, allowing users to access diverse services. A decade of security research on the super-app ecosystem has all assumed super-apps to be a trusted intermediary. We argue this implicit trust is difficult to justi…
- Trust Me, I'm Your Developer: Self-Issued Authentication in Large Language Models
Syed Ghazanfar Abbas, Dongyan Xu · 10 de septiembre de 2026
Large language model (LLM) security has largely focused on role-playing jailbreaks, with less attention to what happens when a user asks an LLM to verify an identity claim through a test designed by the model itself. We study this behavior through a staged developer-identity experiment with ChatGPT,…
- WAPP: Safe Learning of Positive Security WAF Policies from Live Traffic
Heba Osama, Zeyad Ahmed, Mohamed Amgad, Ahmed Saafan, Jana Elfeky, Mariam Abdelati, Haitham Ghalwash · 9 de septiembre de 2026
Web Application Firewalls (WAFs) mainly rely on signatures to detect known attacks, which can leave gaps against modified or previously unseen payloads. Positive security provides a complementary approach by learning legitimate traffic and blocking inputs that fall outside the learned profile. Howev…
- A TTP by TTP Approach: Precise Malware Detection via Malicious TTP Recognition
Yashovardhan Sharma · 9 de septiembre de 2026
Machine learning methods, and especially neural networks, are now routinely used for malware detection in network traffic. Though very effective, systems based on such methods often (i) are purely data-driven, ignoring the substantial body of available knowledge about the tactics, techniques, and pr…
- SCRIPTIOC-BENCH: A Benchmark for Recognizing Actionable Threat Intelligence from Script-Based Malware using LLMs
Hanna Kim, Jian Cui, Minkyoo Song, Hwanjo Heo, Seungwon Shin, Kimin Lee, Xiaojing Liao · 9 de septiembre de 2026
Script-based malware remains a prevalent attack technique. These scripts often contain indicators of compromise (IOCs) that provide actionable threat intelligence. However, statically recovering such indicators is challenging, as relevant values may be dispersed or transformed within code. Although …
- Cost-Aware Hierarchical Multi-Agent Ransomware Detection and Family Attribution
Mubashar Iqbal, Asifullah Khan · 7 de septiembre de 2026
Ransomware detection and family attribution require analysis of different modalities because it can use packing, obfuscation, process manipulation and runtime evasion techniques. However, conventional multimodal usually uses all available modalities for every sample resulting in unnecessary computat…
- REPLICANT: Learning Policies for Evading and Hardening Malware Detectors
Shae McFadden, Ilias Tsingenopoulos, Mario D'Onghia, Alexander Herzog, Myles Foley, Chris Hicks, Lorenzo Cavallaro, Fabio Pierazzi · 31 de agosto de 2026
To determine the real-world effectiveness of machine learning based malware detection, it is vital to evaluate its robustness against highly capable adversaries. However, state-of-the-art attacks do not effectively model realistic adversaries, as they often assume access to privileged information su…
- Beyond F1: Evaluating Coverage and Failure Recovery in AI Model Security Scanners
Qianlong Lan, Vinothini Pandurangan, Anuj Kaul, Indranil Sanyal · 28 de agosto de 2026
Static scanners are increasingly used to identify executable or otherwise unsafe content in machine- learning artifacts, yet conventional evaluation metrics characterize only cases where a scanner yields a usable security judgment. We evaluate ModelScan, ModelAudit, and Fickling using a controlled, …
- Adapter-Based Few-Shot Continual Learning for Malicious Packet Recognition
Kyle Stein, Guillermo Francia, III Eman El-Sheikh, Andrew Arash Mahyari · 25 de agosto de 2026
The continual evolution of malware variants necessitates detection systems that can adapt to new threats without retraining from scratch. However, continually updating models on new data often leads to catastrophic forgetting, where previously learned knowledge is overwritten. While continual learni…
- Cross-Corpus Evaluation of Generalizable Vulnerability Detection in IoT Firmware
Sadib Hassan Rumman, Md. Shariful Islam, Md. Rayhanur Rahman · 13 de agosto de 2026
IoT firmware vulnerability detection remains challenging due to heterogeneous firmware ecosystems, resource-constrained platforms, and limitations in existing benchmarks. Many datasets are synthetic or general-purpose and lack human-verified, contamination-screened annotations, limiting evidence on …
- The Next Challenge for Agentic Cybersecurity: A Realistic, Contamination-Free Reverse Engineering Benchmark
Jeremy Spence, Nicholas Assaderaghi, Jinhao Zhu, Nikil Ravi, Raluca Ada Popa, Guannan Wei, Yangruibo Ding, Zhuo Zhang · 13 de agosto de 2026
AI agents are rapidly improving in cybersecurity capabilities when the source code is available for analysis, yet much of the software most consequential to cybersecurity, including malware, firmware, and proprietary applications, is available only as binaries. Analyzing such software requires rever…
- Security and Privacy Taxonomy Generation from Mobile App Reviews
Moghis Fereidouni, Vinaik Chhetri, Umar Farooq, A. B. Siddique · 11 de agosto de 2026
Mobile app reviews are a rich, continuously renewing source of how users experience privacy and security, yet existing taxonomies of these concerns are hand-crafted and cannot keep pace with the evolving nature of the data. Automating taxonomy construction is the natural response, but scalability is…
- Robust Context-Aware Detection of Malicious Instructions in Text
Buzhao Liu, Xinhang Ma, Yevgeniy Vorobeychik · 7 de agosto de 2026
The remarkable instruction-following ability of modern LLMs has enabled their practical use as the minds of agents that can autonomously complete increasingly complex tasks. Therein, however, also lies their vulnerability to attacks which embed malicious instructions in text, common variants of whic…
- AegisShield: Democratizing Cyber Threat Modeling with Generative AI
Matthew Grofsky · 7 de agosto de 2026
The increasing sophistication of technology systems makes traditional threat modeling hard to scale, especially for small organizations with limited resources. This paper develops and evaluates AegisShield, a generative AI enhanced threat modeling tool that implements STRIDE and MITRE ATT&CK to auto…
- ShielDroid: A Hybrid Approach Integrating Machine and Deep Learning for Android Malware Detection
Md Faisal Ahmed, Zarin Tasnim Biash, Abu Raihan Shakil, Ahmed Ann Noor Ryen, Arman Hossain, Faisal Bin Ashraf, Muhammad Iqbal Hossain · 5 de agosto de 2026
The rapid advancement of modern technology has led to a significant increase in the use of smart devices, such as smartphones and tablets, resulting in the widespread adoption of mobile applications. Although applications are required to undergo malware screening before being published on official a…
