MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866911120577527808 |
|---|---|
| author | Sun, Tiezhu Alecci, Marco Pilgun, Aleksandr Song, Yewei Tang, Xunzhu Samhi, Jordan Bissyandé, Tegawendé F. Klein, Jacques |
| author_facet | Sun, Tiezhu Alecci, Marco Pilgun, Aleksandr Song, Yewei Tang, Xunzhu Samhi, Jordan Bissyandé, Tegawendé F. Klein, Jacques |
| contents | The rapid evolution of Android malware poses significant challenges to the maintenance and security of mobile applications (apps). Traditional detection techniques often struggle to keep pace with emerging malware variants that employ advanced tactics such as code obfuscation and dynamic behavior triggering. One major limitation of these approaches is their inability to localize malicious payloads at a fine-grained level, hindering precise understanding of malicious behavior. This gap in understanding makes the design of effective and targeted mitigation strategies difficult, leaving mobile apps vulnerable to continuously evolving threats.
To address this gap, we propose MalLoc, a novel approach that leverages the code understanding capabilities of large language models (LLMs) to localize malicious payloads at a fine-grained level within Android malware. Our experimental results demonstrate the feasibility and effectiveness of using LLMs for this task, highlighting the potential of MalLoc to enhance precision and interpretability in malware analysis. This work advances beyond traditional detection and classification by enabling deeper insights into behavior-level malicious logic and opens new directions for research, including dynamic modeling of localized threats and targeted countermeasure development. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2508_17856 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs Sun, Tiezhu Alecci, Marco Pilgun, Aleksandr Song, Yewei Tang, Xunzhu Samhi, Jordan Bissyandé, Tegawendé F. Klein, Jacques Cryptography and Security Software Engineering The rapid evolution of Android malware poses significant challenges to the maintenance and security of mobile applications (apps). Traditional detection techniques often struggle to keep pace with emerging malware variants that employ advanced tactics such as code obfuscation and dynamic behavior triggering. One major limitation of these approaches is their inability to localize malicious payloads at a fine-grained level, hindering precise understanding of malicious behavior. This gap in understanding makes the design of effective and targeted mitigation strategies difficult, leaving mobile apps vulnerable to continuously evolving threats. To address this gap, we propose MalLoc, a novel approach that leverages the code understanding capabilities of large language models (LLMs) to localize malicious payloads at a fine-grained level within Android malware. Our experimental results demonstrate the feasibility and effectiveness of using LLMs for this task, highlighting the potential of MalLoc to enhance precision and interpretability in malware analysis. This work advances beyond traditional detection and classification by enabling deeper insights into behavior-level malicious logic and opens new directions for research, including dynamic modeling of localized threats and targeted countermeasure development. |
| title | MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs |
| topic | Cryptography and Security Software Engineering |
| url | https://arxiv.org/abs/2508.17856 |