MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sun, Tiezhu, Alecci, Marco, Pilgun, Aleksandr, Song, Yewei, Tang, Xunzhu, Samhi, Jordan, Bissyandé, Tegawendé F., Klein, Jacques
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911120577527808
author Sun, Tiezhu
Alecci, Marco
Pilgun, Aleksandr
Song, Yewei
Tang, Xunzhu
Samhi, Jordan
Bissyandé, Tegawendé F.
Klein, Jacques
author_facet Sun, Tiezhu
Alecci, Marco
Pilgun, Aleksandr
Song, Yewei
Tang, Xunzhu
Samhi, Jordan
Bissyandé, Tegawendé F.
Klein, Jacques
contents The rapid evolution of Android malware poses significant challenges to the maintenance and security of mobile applications (apps). Traditional detection techniques often struggle to keep pace with emerging malware variants that employ advanced tactics such as code obfuscation and dynamic behavior triggering. One major limitation of these approaches is their inability to localize malicious payloads at a fine-grained level, hindering precise understanding of malicious behavior. This gap in understanding makes the design of effective and targeted mitigation strategies difficult, leaving mobile apps vulnerable to continuously evolving threats. To address this gap, we propose MalLoc, a novel approach that leverages the code understanding capabilities of large language models (LLMs) to localize malicious payloads at a fine-grained level within Android malware. Our experimental results demonstrate the feasibility and effectiveness of using LLMs for this task, highlighting the potential of MalLoc to enhance precision and interpretability in malware analysis. This work advances beyond traditional detection and classification by enabling deeper insights into behavior-level malicious logic and opens new directions for research, including dynamic modeling of localized threats and targeted countermeasure development.
format Preprint
id arxiv_https___arxiv_org_abs_2508_17856
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
Sun, Tiezhu
Alecci, Marco
Pilgun, Aleksandr
Song, Yewei
Tang, Xunzhu
Samhi, Jordan
Bissyandé, Tegawendé F.
Klein, Jacques
Cryptography and Security
Software Engineering
The rapid evolution of Android malware poses significant challenges to the maintenance and security of mobile applications (apps). Traditional detection techniques often struggle to keep pace with emerging malware variants that employ advanced tactics such as code obfuscation and dynamic behavior triggering. One major limitation of these approaches is their inability to localize malicious payloads at a fine-grained level, hindering precise understanding of malicious behavior. This gap in understanding makes the design of effective and targeted mitigation strategies difficult, leaving mobile apps vulnerable to continuously evolving threats. To address this gap, we propose MalLoc, a novel approach that leverages the code understanding capabilities of large language models (LLMs) to localize malicious payloads at a fine-grained level within Android malware. Our experimental results demonstrate the feasibility and effectiveness of using LLMs for this task, highlighting the potential of MalLoc to enhance precision and interpretability in malware analysis. This work advances beyond traditional detection and classification by enabling deeper insights into behavior-level malicious logic and opens new directions for research, including dynamic modeling of localized threats and targeted countermeasure development.
title MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2508.17856