{"id":"https://openalex.org/W4403921876","doi":"https://doi.org/10.1145/3686215.3690147","title":"Understanding LLMs Ability to Aid Malware Analysts in Bypassing Evasion Techniques","display_name":"Understanding LLMs Ability to Aid Malware Analysts in Bypassing Evasion Techniques","publication_year":2024,"publication_date":"2024-10-30","ids":{"openalex":"https://openalex.org/W4403921876","doi":"https://doi.org/10.1145/3686215.3690147"},"language":"en","primary_location":{"id":"doi:10.1145/3686215.3690147","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3686215.3690147","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Companion Proceedings of the 26th International Conference on Multimodal Interaction","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3686215.3690147","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5086282775","display_name":"Miuyin Yong Wong","orcid":"https://orcid.org/0009-0001-5851-4851"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Miuyin Yong Wong","raw_affiliation_strings":["Georgia Institue of Technology, United States"],"raw_orcid":"https://orcid.org/0009-0001-5851-4851","affiliations":[{"raw_affiliation_string":"Georgia Institue of Technology, United States","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041185630","display_name":"Kevin Valakuzhy","orcid":"https://orcid.org/0009-0006-6565-3856"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kevin Valakuzhy","raw_affiliation_strings":["Georgia Institute of Technology, United States"],"raw_orcid":"https://orcid.org/0009-0006-6565-3856","affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology, United States","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5018826118","display_name":"Mustaque Ahamad","orcid":"https://orcid.org/0000-0002-7955-5126"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mustaque Ahamad","raw_affiliation_strings":["Georgia Institute of Technology, United States"],"raw_orcid":"https://orcid.org/0000-0002-7955-5126","affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology, United States","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5003154570","display_name":"Douglas M. Blough","orcid":"https://orcid.org/0000-0002-0803-7647"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Doug Blough","raw_affiliation_strings":["Georgia Institute of Technology, United States"],"raw_orcid":"https://orcid.org/0000-0002-0803-7647","affiliations":[{"raw_affiliation_string":"Georgia Institute of Technology, United States","institution_ids":["https://openalex.org/I130701444"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5069862528","display_name":"Fabian Monrose","orcid":"https://orcid.org/0000-0002-9805-2217"},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Fabian Monrose","raw_affiliation_strings":["ECE, Georgia Tech, United States"],"raw_orcid":"https://orcid.org/0000-0002-9805-2217","affiliations":[{"raw_affiliation_string":"ECE, Georgia Tech, United States","institution_ids":["https://openalex.org/I130701444"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5086282775"],"corresponding_institution_ids":["https://openalex.org/I130701444"],"apc_list":null,"apc_paid":null,"fwci":0.6576,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.68589302,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":95,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"36","last_page":"40"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9965000152587891,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9965000152587891,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/evasion","display_name":"Evasion (ethics)","score":0.8495715856552124},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.7811304330825806},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5684347748756409},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.517414927482605},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.34012937545776367},{"id":"https://openalex.org/keywords/medicine","display_name":"Medicine","score":0.06908541917800903},{"id":"https://openalex.org/keywords/immunology","display_name":"Immunology","score":0.06513723731040955}],"concepts":[{"id":"https://openalex.org/C2781251061","wikidata":"https://www.wikidata.org/wiki/Q5416089","display_name":"Evasion (ethics)","level":3,"score":0.8495715856552124},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.7811304330825806},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5684347748756409},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.517414927482605},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.34012937545776367},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.06908541917800903},{"id":"https://openalex.org/C203014093","wikidata":"https://www.wikidata.org/wiki/Q101929","display_name":"Immunology","level":1,"score":0.06513723731040955},{"id":"https://openalex.org/C8891405","wikidata":"https://www.wikidata.org/wiki/Q1059","display_name":"Immune system","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3686215.3690147","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3686215.3690147","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Companion Proceedings of the 26th International Conference on Multimodal Interaction","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3686215.3690147","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3686215.3690147","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Companion Proceedings of the 26th International Conference on Multimodal Interaction","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":23,"referenced_works":["https://openalex.org/W1538186256","https://openalex.org/W2008453980","https://openalex.org/W2087740020","https://openalex.org/W2098431065","https://openalex.org/W2100002952","https://openalex.org/W2102001185","https://openalex.org/W2111038628","https://openalex.org/W2140807364","https://openalex.org/W2162765234","https://openalex.org/W2405980203","https://openalex.org/W2514974017","https://openalex.org/W2574215789","https://openalex.org/W2708742135","https://openalex.org/W2891539454","https://openalex.org/W2963566160","https://openalex.org/W3015631052","https://openalex.org/W3213145987","https://openalex.org/W4225591807","https://openalex.org/W4299301436","https://openalex.org/W4308469411","https://openalex.org/W4383176079","https://openalex.org/W4385633412","https://openalex.org/W4394712905"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2783112941","https://openalex.org/W2526398307","https://openalex.org/W2470029541","https://openalex.org/W4387065217","https://openalex.org/W4368275542","https://openalex.org/W2470502009","https://openalex.org/W3152957156"],"abstract_inverted_index":{"Over":[0],"the":[1,5,53,61,70,85,150,155,182,231,236],"past":[2],"few":[3],"years,":[4],"threat":[6],"of":[7,55,63,73,146,184,208],"malware":[8,36,48,58,65,91,226],"has":[9],"become":[10],"increasingly":[11],"evident,":[12],"posing":[13],"a":[14,51,195],"significant":[15],"risk":[16],"to":[17,25,34,78,121,164],"cybersecurity":[18],"worldwide":[19],"and":[20,27,103,119,215],"driving":[21],"extensive":[22],"research":[23],"efforts":[24,33],"prevent":[26],"mitigate":[28],"these":[29,38],"attacks.":[30],"Despite":[31],"numerous":[32],"automate":[35],"analysis,":[37,105,199],"systems":[39],"are":[40],"constantly":[41],"thwarted":[42],"by":[43,47,235],"evasive":[44,57,76,110,178,210],"techniques":[45,211],"developed":[46],"authors.":[49],"As":[50],"result,":[52],"analysis":[54,148,153,175],"sophisticated":[56],"falls":[59],"into":[60],"hands":[62],"human":[64,225],"analysts,":[66],"who":[67],"must":[68],"undertake":[69],"time-consuming":[71],"process":[72],"overcoming":[74],"each":[75],"technique":[77],"uncover":[79],"malware\u2019s":[80],"malicious":[81],"behaviors.":[82],"This":[83],"highlights":[84],"need":[86],"for":[87,197],"approaches":[88],"that":[89,125,171,203],"aid":[90],"analysts":[92,126,227],"in":[93,129,157,176,181,212,221],"this":[94,134],"process.":[95],"Although":[96],"active":[97],"measures,":[98],"such":[99,188],"as":[100,189],"forced":[101],"execution":[102],"symbolic":[104,147,174,198],"can":[106,127,143,228],"automatically":[107],"circumvent":[108],"some":[109],"checks,":[111],"they":[112],"suffer":[113],"from":[114,230],"limitations":[115],"like":[116],"path":[117],"explosion":[118],"fail":[120],"provide":[122],"useful":[123],"insights":[124],"use":[128],"their":[130],"workflow.":[131],"To":[132],"fill":[133],"gap,":[135],"we":[136,169,201,217],"investigate":[137],"how":[138,219],"large":[139],"language":[140],"models":[141],"(LLMs)":[142],"address":[144],"shortcomings":[145],"through":[149],"first":[151],"comparative":[152],"between":[154],"two":[156],"bypassing":[158,177,209],"evasion":[159],"techniques.":[160],"Our":[161],"study":[162],"leads":[163],"three":[165],"key":[166],"findings:":[167],"(i)":[168],"find":[170],"LLMs":[172,204,222],"outperform":[173],"code,":[179],"especially":[180],"presence":[183],"common":[185],"code":[186],"patterns,":[187],"loops,":[190],"which":[191],"have":[192],"historically":[193],"posed":[194],"challenge":[196],"(ii)":[200],"show":[202],"correctly":[205],"identify":[206],"methods":[207],"real-world":[213],"malware,":[214],"(iii)":[216],"highlight":[218],"even":[220],"failure":[223],"modes,":[224],"benefit":[229],"step-by-step":[232],"reasoning":[233],"provided":[234],"model.":[237]},"counts_by_year":[{"year":2025,"cited_by_count":2}],"updated_date":"2025-12-27T23:08:20.325037","created_date":"2025-10-10T00:00:00"}
