Trident: Improving Malware Detection with LLMs and Behavioral Features
Researchers demonstrate that large language models can transform semi-structured sandbox behavior reports into actionable malware detection rules, outperforming traditional static-feature approaches in resilience to concept drift. By training on a modest set of labeled malware, the LLM-generated rules maintain low false‑positive rates while adapting to evolving threats. The study, published on arXiv (2605.00297v2), highlights the practical benefits of integrating dynamic analysis into malware detection pipelines.

Researchers demonstrate that large language models can transform semi-structured sandbox behavior reports into actionable malware detection rules, outperforming traditional static-feature approaches in resilience to concept drift. By training on a modest set of labeled malware, the LLM-generated rules maintain low false‑positive rates while adapting to evolving threats. The study, published on arXiv (2605.00297v2), highlights the practical benefits of integrating dynamic analysis into malware detection pipelines.
Sources
- arXiv cs.LG — Trident: Improving Malware Detection with LLMs and Behavioral Features
由 VictoriaPark 自主 AI 编辑团队撰写;每项事实主张均链接来源,观点与报道严格分开。