Moirae:用于动态Android恶意软件检测的多模态智能体协作框架
Moirae: A Multimodal Agent Collaborative Framework for Dynamic Android Malware Detection
浏览论文内容
中文总结 AI 辅助
该研究提出多模态智能体协作框架Moirae,通过融合多维度运行时证据实现动态Android恶意软件检测,在未见过的数据集上零样本准确率达90.06%,优于现有基线且抗概念漂移。
中文摘要 AI 辅助
Android生态系统面临持续且快速演变的恶意软件威胁。现有机器学习检测器易受概念漂移影响,因为它们依赖特定实现的特征,其分布会随时间变化。大语言模型(LLM)具备强大的语义理解和零样本推理能力,但当前基于LLM的检测器通常依赖以代码为中心或单维度的证据,易受混淆技术影响,且限制了全面的行为分析。我们提出了{\textbackslash sysname}(Moirae),这是一个用于动态Android恶意软件检测的多模态智能体协作框架。该框架动态收集多模态运行时证据,并采用基于ReAct的专用智能体分析互补的行为视图。检测过程首先识别视觉欺骗线索,对UI状态转换进行建模,并整合运行时API行为,以融合跨用户可见界面和隐藏后端操作的多维度证据。在时间和分布上未见过的数据集上的实验表明,{\textbackslash sysname}在无需微调的情况下达到了90.06%的准确率,优于最先进的基线,且展现出针对Android恶意软件概念漂移的强大零样本泛化能力。
英文摘要
The Android ecosystem faces persistent and rapidly evolving malware threats. Existing machine learning detectors are vulnerable to concept drift because they rely on implementation-specific features whose distributions change over time. Large language models (LLMs) offer strong semantic understanding and zero-shot reasoning, but current LLM-based detectors typically depend on code-centric or single-dimensional evidence, making them susceptible to obfuscation and limiting comprehensive behavior analysis. We present Moirae, a multimodal agent collaborative framework for dynamic Android malware detection. Moirae dynamically collects multimodal runtime evidence and employs ReAct-based specialized agents to analyze complementary behavioral views. The detection process begins by identifying visual deception cues, modeling UI state transitions, and integrating runtime API behaviors to fuse multi-dimensional evidence across user-visible interfaces and hidden backend operations. Experiments on temporally and distributionally unseen datasets show that Moirae achieves an accuracy of 90.06\% without fine-tuning, outperforming state-of-the-art baselines and demonstrating strong zero-shot generalization against Android malware concept drift.
发表机构
- School of Computer Science and Engineering, Beihang University(北京航空航天大学计算机科学与工程学院)
- School of Cyberspace Security, Beijing University of Posts and Telecommunications(北京邮电大学网络空间安全学院)
- School of Computer Science and Engineering, Guangxi Normal University(广西师范大学计算机科学与工程学院)
机构由 AI 辅助整理,请以论文原文为准。