Malware Detection and Analysis Using LLMs: A Review of Emerging Trends and Techniques
Mashel Albalooshi, Peter H. Chang, Suleiman Y. Yerima, Thekra Altamimi, Hamda AlFalasi, Abdulrahman Almarzooqi
British University in Dubai
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
The increasing sophistication of malware characterized by polymorphism, obfuscation, and adversarial behaviors poses a significant challenge to traditional detection methods. As cyber threats outpace conventional signature-based and heuristic techniques, Large Language Models (LLMs) have emerged as a promising solution in advancing malware detection and analysis. This systematic review consolidates findings from 10 recent studies published between 2021 and 2025 that explore the application of LLMs in malware detection across static, dynamic, and hybrid analysis environments. LLMs such as GPT4o, BERT, Gemini and Mistral 7B have demonstrated remarkable capabilities in semantic code understanding, behavioral pattern recognition, and zero-shot threat inference. These models enable automated extraction of malware capabilities, identification of Indicators of Compromise (IoCs), and generation of humanreadable threat summaries thus enhancing analyst efficiency and detection accuracy. Frameworks like LLM-MalDetect and GENTTP showcase how prompt engineering, string feature analysis, and transformer-based embeddings can be harnessed to detect evasive and novel malware. Despite their potential, the deployment of LLMs in operational settings remains constrained by challenges including explainability, latency, model size, and dual-use risks. This review identifies current gaps in benchmarking, generalization, and ethical governance, while outlining future directions involving multimodal data fusion, lightweight deployment, and integration with real-time security operations. It is evident from our research that LLMs are reshaping malware defense strategies, offering a scalable, contextaware, and semantically enriched approach to modern threat detection.
逐年被引趋势
暂无年度引用数据
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AIAdvanced Malware Detection Techniques
Network Security and Intrusion Detection · Spam and Phishing Detection
参考文献 11
此处列出前 3 条