arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.27994cs.CRcs.SE

Moirae:用于动态Android恶意软件检测的多模态智能体协作框架

Moirae: A Multimodal Agent Collaborative Framework for Dynamic Android Malware Detection

Xueying Zeng, Youquan Xian, Yanze Li, Bowen Hu, Ziqi Shan, Xu Luo, Danping Yang, Peng Liu, Lei Cui, Bo Li

首次发表
浏览论文内容

中文总结 AI 辅助

该研究提出多模态智能体协作框架Moirae,通过融合多维度运行时证据实现动态Android恶意软件检测,在未见过的数据集上零样本准确率达90.06%,优于现有基线且抗概念漂移。

中文摘要 AI 辅助

Android生态系统面临持续且快速演变的恶意软件威胁。现有机器学习检测器易受概念漂移影响,因为它们依赖特定实现的特征,其分布会随时间变化。大语言模型(LLM)具备强大的语义理解和零样本推理能力,但当前基于LLM的检测器通常依赖以代码为中心或单维度的证据,易受混淆技术影响,且限制了全面的行为分析。我们提出了{\textbackslash sysname}(Moirae),这是一个用于动态Android恶意软件检测的多模态智能体协作框架。该框架动态收集多模态运行时证据,并采用基于ReAct的专用智能体分析互补的行为视图。检测过程首先识别视觉欺骗线索,对UI状态转换进行建模,并整合运行时API行为,以融合跨用户可见界面和隐藏后端操作的多维度证据。在时间和分布上未见过的数据集上的实验表明,{\textbackslash sysname}在无需微调的情况下达到了90.06%的准确率,优于最先进的基线,且展现出针对Android恶意软件概念漂移的强大零样本泛化能力。

英文摘要

The Android ecosystem faces persistent and rapidly evolving malware threats. Existing machine learning detectors are vulnerable to concept drift because they rely on implementation-specific features whose distributions change over time. Large language models (LLMs) offer strong semantic understanding and zero-shot reasoning, but current LLM-based detectors typically depend on code-centric or single-dimensional evidence, making them susceptible to obfuscation and limiting comprehensive behavior analysis. We present Moirae, a multimodal agent collaborative framework for dynamic Android malware detection. Moirae dynamically collects multimodal runtime evidence and employs ReAct-based specialized agents to analyze complementary behavioral views. The detection process begins by identifying visual deception cues, modeling UI state transitions, and integrating runtime API behaviors to fuse multi-dimensional evidence across user-visible interfaces and hidden backend operations. Experiments on temporally and distributionally unseen datasets show that Moirae achieves an accuracy of 90.06\% without fine-tuning, outperforming state-of-the-art baselines and demonstrating strong zero-shot generalization against Android malware concept drift.

发表机构

  • School of Computer Science and Engineering, Beihang University(北京航空航天大学计算机科学与工程学院)
  • School of Cyberspace Security, Beijing University of Posts and Telecommunications(北京邮电大学网络空间安全学院)
  • School of Computer Science and Engineering, Guangxi Normal University(广西师范大学计算机科学与工程学院)

机构由 AI 辅助整理,请以论文原文为准。

↑