arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

MARS:基于规则评分的LLM声明恶意软件分析

MARS: Malware Analysis with Rule-Based Scoring of LLM Claims

Hyeongjun Choi

arXiv 2610.09553首次发表:更新:

发表机构

ResearchLab(78研究实验室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对恶意软件分类,提出MARS框架,比较直接判定与声明评分,发现直接分类更准确,且保留声明支持策略修订。

AI 中文摘要

大型语言模型可以通过直接判定或由外部策略评分的行为声明来对恶意软件进行分类。我们提出了MARS,一个恶意软件分类框架,并比较了直接分类与单次声明评分,两者使用相同的证据收集器和相同的静态证据包,针对每个模型。评估覆盖了1,195个PE和ELF二进制文件,这些文件被分为1,001个近重复簇,并涉及六个语言模型,确定性规则作为基线。对于所有六个模型,直接分类更为准确。在两条路径均产生可用输出的样本上,其准确率优势范围为3.7至20.9个百分点,所有差异的95%簇自举置信区间均高于零。在十二个平台和模型组合中,直接分类在十个组合中实现了更高的恶意警报召回率。声明调解并未在不同模型间提供一致的性能变异性降低。单独的子集研究发现,直接分类的警报决策更一致,而移除预定义指示字段时,声明路径的召回损失更大。在家族识别探针中,声明产生的准确率高于判定标签,但低于证据文本。保留的声明暴露了判定计算的输入,并允许在无需再次调用模型的情况下进行策略修订。我们精确复现了存档的判定,并对相同记录应用了修订后的策略,包括提供商撤回的两个额外模型的输出。在评估的声明分类法和加性策略下,这些结果支持仅需判定时采用直接分类,同时表明保留的声明支持明确的策略检查和修订。

英文摘要

Large language models can triage malware through direct verdicts or behavioral claims scored by an external policy. We present MARS, a malware triage framework, and compare direct classification with single-pass claim scoring using the same evidence collector and identical static evidence bundles for each model. The evaluation covers 1,195 PE and ELF binaries grouped into 1,001 near-duplicate clusters and six language models, with deterministic rules providing a baseline. Direct classification is more accurate for all six models. On samples with usable outputs from both paths, its accuracy advantage ranges from 3.7 to 20.9 percentage points, with all 95% cluster-bootstrap confidence intervals for the differences above zero. It also achieves higher malicious alert recall in ten of twelve platform and model combinations. Claim mediation provides no consistent reduction in performance variation across models. Separate subset studies find more consistent alert decisions for direct classification and a larger recall loss for the claim path when predefined indicator fields are removed. In a family identification probe, claims yield higher accuracy than verdict labels but lower accuracy than evidence text. Retained claims expose the inputs to verdict computation and permit policy revision without another model call. We reproduce archived verdicts exactly and apply a revised policy to the same records, including outputs from two additional models withdrawn by their provider. Under the evaluated claim taxonomy and additive policy, these results favor direct classification when only a verdict is required, while demonstrating that retained claims support explicit policy inspection and revision.

Comments17 pages, 3 figures, 12 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑