{"id":"https://openalex.org/W4411688536","doi":"https://doi.org/10.1109/tifs.2025.3583552","title":"Malsight: Exploring Malicious Source Code and Benign Pseudocode for Iterative Binary Malware Summarization","display_name":"Malsight: Exploring Malicious Source Code and Benign Pseudocode for Iterative Binary Malware Summarization","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4411688536","doi":"https://doi.org/10.1109/tifs.2025.3583552"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2025.3583552","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3583552","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102696717","display_name":"Haolang Lu","orcid":null},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Haolang Lu","raw_affiliation_strings":["National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China"],"affiliations":[{"raw_affiliation_string":"National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100597771","display_name":"Hongrui Peng","orcid":null},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hongrui Peng","raw_affiliation_strings":["National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China"],"affiliations":[{"raw_affiliation_string":"National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020360628","display_name":"Guoshun Nan","orcid":"https://orcid.org/0000-0002-1987-2736"},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guoshun Nan","raw_affiliation_strings":["National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China"],"affiliations":[{"raw_affiliation_string":"National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102696718","display_name":"Jiaoyang Cui","orcid":null},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiaoyang Cui","raw_affiliation_strings":["National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China"],"affiliations":[{"raw_affiliation_string":"National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100417029","display_name":"Cheng Wang","orcid":"https://orcid.org/0000-0002-8795-0687"},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Cheng Wang","raw_affiliation_strings":["National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China"],"affiliations":[{"raw_affiliation_string":"National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102666389","display_name":"Weifei Jin","orcid":"https://orcid.org/0009-0002-8209-2713"},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Weifei Jin","raw_affiliation_strings":["National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China"],"affiliations":[{"raw_affiliation_string":"National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101517637","display_name":"Songtao Wang","orcid":"https://orcid.org/0000-0002-2073-8235"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Songtao Wang","raw_affiliation_strings":["Zhongguancun Laboratory, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Zhongguancun Laboratory, Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5086911783","display_name":"Shengli Pan","orcid":"https://orcid.org/0000-0002-1904-6557"},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shengli Pan","raw_affiliation_strings":["National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China"],"affiliations":[{"raw_affiliation_string":"National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100624765","display_name":"Xiaofeng Tao","orcid":"https://orcid.org/0000-0001-9518-1622"},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaofeng Tao","raw_affiliation_strings":["National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China"],"affiliations":[{"raw_affiliation_string":"National Engineering Research Center for Mobile Network Technologies, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5102696717"],"corresponding_institution_ids":["https://openalex.org/I139759216"],"apc_list":null,"apc_paid":null,"fwci":8.2885,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.97799887,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":"20","issue":null,"first_page":"6733","last_page":"6747"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.996399998664856,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9904999732971191,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.901195764541626},{"id":"https://openalex.org/keywords/automatic-summarization","display_name":"Automatic summarization","score":0.8335574865341187},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8128010034561157},{"id":"https://openalex.org/keywords/binary-number","display_name":"Binary number","score":0.5033795237541199},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.5009009838104248},{"id":"https://openalex.org/keywords/source-code","display_name":"Source code","score":0.4887959659099579},{"id":"https://openalex.org/keywords/binary-code","display_name":"Binary code","score":0.43490445613861084},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.41300126910209656},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.400473415851593},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.3689253330230713},{"id":"https://openalex.org/keywords/information-retrieval","display_name":"Information retrieval","score":0.28901275992393494},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.25310954451560974},{"id":"https://openalex.org/keywords/arithmetic","display_name":"Arithmetic","score":0.1169675886631012}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.901195764541626},{"id":"https://openalex.org/C170858558","wikidata":"https://www.wikidata.org/wiki/Q1394144","display_name":"Automatic summarization","level":2,"score":0.8335574865341187},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8128010034561157},{"id":"https://openalex.org/C48372109","wikidata":"https://www.wikidata.org/wiki/Q3913","display_name":"Binary number","level":2,"score":0.5033795237541199},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.5009009838104248},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.4887959659099579},{"id":"https://openalex.org/C63435697","wikidata":"https://www.wikidata.org/wiki/Q864135","display_name":"Binary code","level":3,"score":0.43490445613861084},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.41300126910209656},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.400473415851593},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.3689253330230713},{"id":"https://openalex.org/C23123220","wikidata":"https://www.wikidata.org/wiki/Q816826","display_name":"Information retrieval","level":1,"score":0.28901275992393494},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.25310954451560974},{"id":"https://openalex.org/C94375191","wikidata":"https://www.wikidata.org/wiki/Q11205","display_name":"Arithmetic","level":1,"score":0.1169675886631012},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2025.3583552","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3583552","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1809975003","display_name":null,"funder_award_id":"62271066","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G202601664","display_name":null,"funder_award_id":"62471064","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3023289842","display_name":null,"funder_award_id":"62301072","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5519730463","display_name":null,"funder_award_id":"CX20251025","funder_id":"https://openalex.org/F4320321470","funder_display_name":"Beijing University of Posts and Telecommunications"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320321470","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":47,"referenced_works":["https://openalex.org/W1970407057","https://openalex.org/W2056334958","https://openalex.org/W2070150502","https://openalex.org/W2082160726","https://openalex.org/W2101105183","https://openalex.org/W2157943826","https://openalex.org/W2509067210","https://openalex.org/W2962739339","https://openalex.org/W2966329817","https://openalex.org/W2970785793","https://openalex.org/W2982725903","https://openalex.org/W2997915791","https://openalex.org/W3025067198","https://openalex.org/W3035252911","https://openalex.org/W3098605233","https://openalex.org/W3133719257","https://openalex.org/W3178593045","https://openalex.org/W3198685994","https://openalex.org/W3203444100","https://openalex.org/W4206509861","https://openalex.org/W4285507391","https://openalex.org/W4293106276","https://openalex.org/W4309674289","https://openalex.org/W4376606797","https://openalex.org/W4385187234","https://openalex.org/W4386185625","https://openalex.org/W4388483715","https://openalex.org/W4389519352","https://openalex.org/W4389519375","https://openalex.org/W4394745967","https://openalex.org/W4402264058","https://openalex.org/W4404783570","https://openalex.org/W4405602529","https://openalex.org/W6621906925","https://openalex.org/W6628233427","https://openalex.org/W6636510571","https://openalex.org/W6682631176","https://openalex.org/W6704925373","https://openalex.org/W6753975912","https://openalex.org/W6755207826","https://openalex.org/W6769627184","https://openalex.org/W6784880316","https://openalex.org/W6810261015","https://openalex.org/W6810874553","https://openalex.org/W6854013397","https://openalex.org/W6869145669","https://openalex.org/W6891850042"],"related_works":["https://openalex.org/W2134880816","https://openalex.org/W2111298487","https://openalex.org/W4308157887","https://openalex.org/W2510680828","https://openalex.org/W2765199869","https://openalex.org/W2055498716","https://openalex.org/W1984130439","https://openalex.org/W4386075138","https://openalex.org/W2371359060","https://openalex.org/W2562873141"],"abstract_inverted_index":{"Binary":[0],"malware":[1,10,18,59,97,111],"summarization":[2,88],"aims":[3],"to":[4,50,162,197,225],"automatically":[5],"generate":[6,93],"human-readable":[7],"descriptions":[8,94],"of":[9,58,95,172,201,210],"behaviors":[11],"from":[12],"executable":[13],"files,":[14],"facilitating":[15],"tasks":[16],"like":[17],"cracking":[19],"and":[20,45,55,103,115,120,145,175,187],"detection.":[21],"Previous":[22],"methods":[23],"based":[24],"on":[25,142,204],"Large":[26],"Language":[27],"Models":[28],"(LLMs)":[29],"have":[30],"shown":[31],"great":[32],"promise.":[33],"However,":[34],"they":[35],"still":[36],"face":[37],"significant":[38],"issues,":[39],"including":[40],"poor":[41],"usability,":[42,185],"inaccurate":[43],"explanations,":[44],"incomplete":[46],"summaries,":[47],"primarily":[48],"due":[49],"the":[51,56,69,109,129,143,151,157,164,170,177,199,208,211],"obscure":[52],"pseudocode":[53,147,158,173],"structure":[54,174],"lack":[57],"training":[60,130],"summaries.":[61,202],"Further,":[62],"calling":[63],"relationships":[64],"between":[65,180],"functions,":[66,181],"which":[67],"involve":[68],"rich":[70],"interactions":[71,179],"within":[72],"a":[73,85,137,167,192],"binary":[74,96],"malware,":[75],"remain":[76],"largely":[77],"underexplored.":[78],"To":[79],"this":[80,123],"end,":[81],"we":[82,107,132,154,190],"propose":[83,191],"MALSIGHT,":[84],"novel":[86,138,193],"code":[87,102,140],"framework":[89],"that":[90],"can":[91],"iteratively":[92,155],"by":[98],"exploring":[99],"malicious":[100],"source":[101],"benign":[104,146],"pseudocode.":[105],"Specifically,":[106],"construct":[108],"first":[110],"summary":[112],"dataset,":[113],"MalS":[114,144],"MalP,":[116],"using":[117],"an":[118],"LLM":[119],"manually":[121],"refine":[122],"dataset":[124],"with":[125,218],"human":[126],"effort.":[127],"At":[128],"stage,":[131,153],"tune":[133],"our":[134,215],"proposed":[135,212,216],"MalT5,":[136,217],"LLM-based":[139],"model,":[141],"datasets.":[148],"Then,":[149],"at":[150],"test":[152],"feed":[156],"functions":[159],"into":[160],"MalT5":[161],"obtain":[163],"summary.":[165],"Such":[166],"procedure":[168],"facilitates":[169],"understanding":[171],"captures":[176],"intricate":[178],"thereby":[182],"benefiting":[183],"summaries\u2019":[184],"accuracy,":[186],"completeness.":[188],"Additionally,":[189],"evaluation":[194],"benchmark,":[195],"BLEURT-sum,":[196],"measure":[198],"quality":[200],"Experiments":[203],"three":[205],"datasets":[206],"show":[207],"effectiveness":[209],"MALSIGHT.":[213],"Notably,":[214],"only":[219],"0.77B":[220],"parameters,":[221],"delivers":[222],"comparable":[223],"performance":[224],"much":[226],"larger":[227],"Code-Llama.":[228]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":4}],"updated_date":"2026-04-15T08:11:43.952461","created_date":"2025-10-10T00:00:00"}
