A single commercial LLM can cheaply generate large populations of behaviorally equivalent yet structurally diverse malware payloads.
Lamd: Context-driven android malware detection and classification with llms
4 Pith papers cite this work. Polarity classification is still indexing.
citation-role summary
citation-polarity summary
fields
cs.CR 4years
2026 4verdicts
UNVERDICTED 4roles
background 2polarities
background 2representative citing papers
Trident combines static decision trees, LLM-generated behavioral rules from sandbox reports, and direct LLM analysis via majority voting to outperform static methods while resisting concept drift without retraining.
Multi-decompiler prompting improves LLM malware classification F1 by supplying complementary views of the same binary.
Agentic LLM systems for reverse engineering fail on obfuscation, timing, and unique architectures due to token limits and missing guardrails, with challenges and directions proposed.
citing papers explorer
-
The Infinite Mutation Engine? Measuring Polymorphism in LLM-Generated Offensive Code
A single commercial LLM can cheaply generate large populations of behaviorally equivalent yet structurally diverse malware payloads.
-
Trident: Improving Malware Detection with LLMs and Behavioral Features
Trident combines static decision trees, LLM-generated behavioral rules from sandbox reports, and direct LLM analysis via majority voting to outperform static methods while resisting concept drift without retraining.
-
Multi-View Decompilation for LLM-Based Malware Classification
Multi-decompiler prompting improves LLM malware classification F1 by supplying complementary views of the same binary.
-
Challenges and Future Directions in Agentic Reverse Engineering Systems
Agentic LLM systems for reverse engineering fail on obfuscation, timing, and unique architectures due to token limits and missing guardrails, with challenges and directions proposed.