LATIDIA · Ciberseguridad
MARS: Análisis de malware con puntuación basada en reglas de reclamaciones de LLM
arXiv: 2610.09553v1Tipo de anuncio: nuevo Resumen: Los modelos de lenguaje grandes pueden clasificar el malware a través de veredictos directos o reclamos de comportamiento calificados por una política externa. Presentamos MARS, un marco de clasificación de malware, y comparamos
WhatsApp ↗Telegram ↗
La noticia
arXiv:2610.09553v1 Announce Type: new Abstract: Large language models can triage malware through direct verdicts or behavioral claims scored by an external policy. We present MARS, a malware triage framework, and compare direct classification with single-pass claim scoring using the same evidence collector and identical static evidence bundles for each model. The evaluation covers 1,195 PE and ELF binaries grouped into 1,001 near-duplicate clusters and six language models, with deterministic rules providing a baseline. Direct classification is more accurate for all six models. On samples with usable outputs from both paths, its accuracy advantage ranges from 3.7 to 20.9 percentage points, with all 95% cluster-bootstrap confidence intervals for the differences above