arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

DistillGuard:通过静态图与LLM蒸馏实现恶意NPM包检测及API攻击链分析

DistillGuard: Malicious NPM Package Detection and API Attack Chain Analysis via Static Graph and LLM Distillation

Siyuan Pang, Yepeng Yao, Zhengwei Jiang, Zijing Fan, Baoxu Liu

arXiv 2609.28996首次发表:更新:

发表机构

Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, University of Chinese Academy of Sciences(中国科学院信息工程研究所; 中国科学院大学网络空间安全学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

DistillGuard通过静态图语义分析与LLM知识蒸馏,实现轻量级恶意NPM包检测,准确率达95.3%,并揭示攻击阶段与八种API攻击链,提升供应链安全防御。

AI 中文摘要

npm生态系统高度依赖NPM包,针对恶意NPM包的软件供应链攻击十分猖獗。恶意代码主要在包安装、导入和运行时触发。传统静态分析无法理解代码语义;基于机器学习的方法依赖特征提取,存在概念漂移问题;现有的LLM解决方案面临高调用成本、高数据安全风险和性能不佳的问题。为克服这些局限,我们提出DistillGuard,一个结合静态图语义分析和LLM知识蒸馏的轻量级恶意NPM包检测框架。DistillGuard首先通过三个静态分析模块获取多粒度特征。然后,它利用在线LLM蒸馏高质量的安全知识和结构化标签。最后,它使用LoRa高效微调开源Qwen3-8B模型以支持离线部署。实验表明,DistillGuard实现了95.3%的准确率、99.4%的精确率和93.8%的F1分数,优于最先进的工具,相比基线将F1分数提高了11.1至30.0个百分点。我们的实证研究进一步揭示了恶意攻击的阶段和恶意行为的分布。我们还总结了八种典型的恶意活动API攻击链,为NPM供应链安全防御提供了实用见解。

英文摘要

The Node.js ecosystem heavily relies on NPM packages, and software supply chain attacks targeting malicious NPM packages are rampant. Malicious code primarily triggers during package installation, import, and runtime. Traditional static analysis fails to understand code semantics; machine learning-based methods rely on feature extraction, which suffers from concept drift; existing LLM solutions suffer from high invocation costs, high data security risks, and poor performance. To overcome these limitations, we propose DistillGuard, a lightweight malicious NPM package detection framework that combines static graph semantic analysis and LLM knowledge distillation. DistillGuard first acquires multi-granular features through three static analysis modules. Then, it leverages online LLM to distill high-quality security knowledge and structured labels. Finally, it uses LoRa to efficiently fine-tune the open-source Qwen3-8B model to support offline deployment. Experiments show that DistillGuard achieves an accuracy of 95.3\%, a precision of 99.4\%, and an F1 score of 93.8\%, outperforming state-of-the-art tools, improving the F1-score by 11.1 to 30.0 percentage points over the baselines. Our empirical research further reveals the stages of malicious attacks and the distribution of malicious behaviors. We also summarized eight typical API attack chains for malicious activities, providing practical insights for NPM supply chain security defense.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑