AutoMalDesc: Large-Scale Script Analysis for Cyber Threat Research

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Apostu, Alexandru-Mihai, Preda, Andrei, Damir, Alexandra Daniela, Bolocan, Diana, Ionescu, Radu Tudor, Croitoru, Ioana, Gaman, Mihaela
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866912715071553536
author Apostu, Alexandru-Mihai
Preda, Andrei
Damir, Alexandra Daniela
Bolocan, Diana
Ionescu, Radu Tudor
Croitoru, Ioana
Gaman, Mihaela
author_facet Apostu, Alexandru-Mihai
Preda, Andrei
Damir, Alexandra Daniela
Bolocan, Diana
Ionescu, Radu Tudor
Croitoru, Ioana
Gaman, Mihaela
contents Generating thorough natural language explanations for threat detections remains an open problem in cybersecurity research, despite significant advances in automated malware detection systems. In this work, we present AutoMalDesc, an automated static analysis summarization framework that, following initial training on a small set of expert-curated examples, operates independently at scale. This approach leverages an iterative self-paced learning pipeline to progressively enhance output quality through synthetic data generation and validation cycles, eliminating the need for extensive manual data annotation. Evaluation across 3,600 diverse samples in five scripting languages demonstrates statistically significant improvements between iterations, showing consistent gains in both summary quality and classification accuracy. Our comprehensive validation approach combines quantitative metrics based on established malware labels with qualitative assessment from both human experts and LLM-based judges, confirming both technical precision and linguistic coherence of generated summaries. To facilitate reproducibility and advance research in this domain, we publish our complete dataset of more than 100K script samples, including annotated seed (0.9K) and test (3.6K) datasets, along with our methodology and evaluation framework.
format Preprint
id arxiv_https___arxiv_org_abs_2511_13333
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle AutoMalDesc: Large-Scale Script Analysis for Cyber Threat Research
Apostu, Alexandru-Mihai
Preda, Andrei
Damir, Alexandra Daniela
Bolocan, Diana
Ionescu, Radu Tudor
Croitoru, Ioana
Gaman, Mihaela
Cryptography and Security
Artificial Intelligence
Computation and Language
Machine Learning
Generating thorough natural language explanations for threat detections remains an open problem in cybersecurity research, despite significant advances in automated malware detection systems. In this work, we present AutoMalDesc, an automated static analysis summarization framework that, following initial training on a small set of expert-curated examples, operates independently at scale. This approach leverages an iterative self-paced learning pipeline to progressively enhance output quality through synthetic data generation and validation cycles, eliminating the need for extensive manual data annotation. Evaluation across 3,600 diverse samples in five scripting languages demonstrates statistically significant improvements between iterations, showing consistent gains in both summary quality and classification accuracy. Our comprehensive validation approach combines quantitative metrics based on established malware labels with qualitative assessment from both human experts and LLM-based judges, confirming both technical precision and linguistic coherence of generated summaries. To facilitate reproducibility and advance research in this domain, we publish our complete dataset of more than 100K script samples, including annotated seed (0.9K) and test (3.6K) datasets, along with our methodology and evaluation framework.
title AutoMalDesc: Large-Scale Script Analysis for Cyber Threat Research
topic Cryptography and Security
Artificial Intelligence
Computation and Language
Machine Learning
url https://arxiv.org/abs/2511.13333