LATIDIA · Ciberseguridad
COARTADA: Inyección de legitimidad contradictoria en entrada binaria contra analizadores de malware LLM
arXiv: 2609.19722v1Tipo de anuncio: nuevo Resumen: Los grandes modelos de lenguaje se están integrando en los flujos de trabajo de triaje de malware como componentes de razonamiento que resumen la evidencia estática y producen veredictos orientados al analista. Esta pa
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.19722v1 Announce Type: new Abstract: Large language models are being integrated into malware triage workflows as reasoning components that summarize static evidence and produce analyst-facing verdicts. This paper shows that the same reasoning capability introduces a new attack surface. We present ALIBI, a semantic cover story attack against frontier LLM-based malware analyzers. ALIBI adds a small, non-executed read-only section to a compiled binary, containing a coherent but false security product narrative, without altering imports or executable behavior. Instead of issuing direct instructions to the model, it reframes suspicious evidence as expected behavior of a benign endpoint security tool. On a frozen PE set of 50 malicious samples, the payload flips