PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 24, 2026International Journal of Software Engineering and Knowledge Engineering0 citations

An LLM-Enhanced Code-Space Adversarial Attack Method Against Malware Detection Models

View Full Paper
SGShengduo GanMLMingqi LvHZHuan Zeng

Key Points

  • This research aims to improve adversarial attack methods against malware detection by utilizing code-space modifications via LLMs.
  • Developed a feature-space adversarial attack algorithm to alter feature vectors and analyze dynamic behavior changes.
  • Introduced a prompt mechanism using LLMs to modify malware source code based on observed behavior changes.
  • Conducted experiments on five malware types to validate the effectiveness of the proposed method.
  • The method successfully altered the malware source code while maintaining its functionality.
  • Outperformed existing methods in evasion capabilities, achieving higher success rates in bypassing detection.
  • Demonstrated significant improvements in functional retention compared to traditional feature-space approaches.

Abstract

Adversarial attacks on machine learning–based malware detection models could enable attackers to craft evasive malware variants that remain functional while bypassing detection. However, existing methods primarily focus on feature-space adversarial attacks, lacking effective mapping from feature-space to code-space (i.e., the modifications of source code of malware to implement the adversarial attacks), which limits its practical application. To address this issue, this paper proposes an LLM (Large Language Model) enhanced code-space adversarial attack method against the dynamic malware detection models, achieving end-to-end generation of executable and source code-level adversarial samples. First, we apply a feature-space adversarial attack algorithm to perturb the feature vectors and pinpoint the changes of dynamic behaviors (e.g., API calls). Second, we propose a prompt mechanism guided by the dynamic behavior changes and code generation hints to automatically modify the source code of malware samples by leveraging an LLM. Experiments on five types of typical malware demonstrate that the proposed method can effectively modify the source code of malware based on the adversarial perturbations, and consistently outperforms existing approaches in terms of evasion capability and functionality retention.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Gan et al. (2026) studied this question.

synapsesocial.com/papers/6a12968148a0ea1665673503https://doi.org/10.1142/s0218194026500427
Ask AI
Helpful
Bookmark
Share
View Full Paper