Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
Fuente:
arXiv
Saved in:
| Main Authors: | Guo, Wenbo, Song, Shiwen, Guo, Jiaxun, Xu, Zhengzi, Liu, Chengwei, Ou, Haoran, Ge, Mengmeng, Liu, Yang |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
Understanding NPM Malicious Package Detection: A Benchmark-Driven Empirical Analysis
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026)
by: Toda, Takaaki, et al.
Published: (2026)
An Analysis of Malicious Packages in Open-Source Software in the Wild
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
by: Zhang, Junan, et al.
Published: (2023)
by: Zhang, Junan, et al.
Published: (2023)
FCGHunter: Towards Evaluating Robustness of Graph-Based Android Malware Detection
by: Song, Shiwen, et al.
Published: (2025)
by: Song, Shiwen, et al.
Published: (2025)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
by: Ryan, Ahmed, et al.
Published: (2026)
by: Ryan, Ahmed, et al.
Published: (2026)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
by: Mehedi, Sk Tanzir, et al.
Published: (2025)
MirrorFuzz: Leveraging LLM and Shared Bugs for Deep Learning Framework APIs Fuzzing
by: Ou, Shiwen, et al.
Published: (2025)
by: Ou, Shiwen, et al.
Published: (2025)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
by: Liu, Shuhan, et al.
Published: (2025)
by: Liu, Shuhan, et al.
Published: (2025)
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
by: Wang, Shenao, et al.
Published: (2026)
by: Wang, Shenao, et al.
Published: (2026)
Malicious ML Model Detection by Learning Dynamic Behaviors
by: Nambiar, Sarang, et al.
Published: (2026)
by: Nambiar, Sarang, et al.
Published: (2026)
AgentGuard: A Multi-Agent Framework for Robust Package Confusion Detection via Hybrid Search and Metadata-Content Fusion
by: Li, Yu, et al.
Published: (2026)
by: Li, Yu, et al.
Published: (2026)
Automatically Generating Rules of Malicious Software Packages via Large Language Model
by: Zhang, XiangRui, et al.
Published: (2025)
by: Zhang, XiangRui, et al.
Published: (2025)
MCGMark: An Encodable and Robust Online Watermark for Tracing LLM-Generated Malicious Code
by: Ning, Kaiwen, et al.
Published: (2024)
by: Ning, Kaiwen, et al.
Published: (2024)
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
by: Ni, Ronghao, et al.
Published: (2026)
by: Ni, Ronghao, et al.
Published: (2026)
BandFuzz: An ML-powered Collaborative Fuzzing Framework
by: Shi, Wenxuan, et al.
Published: (2025)
by: Shi, Wenxuan, et al.
Published: (2025)
Detecting Malicious Intents in Smart Contracts with Pre-trained Programming Language Models
by: Huang, Youwei, et al.
Published: (2025)
by: Huang, Youwei, et al.
Published: (2025)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
by: Huang, Yiheng, et al.
Published: (2026)
by: Huang, Yiheng, et al.
Published: (2026)
GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program Analysis
by: Sun, Yuqiang, et al.
Published: (2023)
by: Sun, Yuqiang, et al.
Published: (2023)
IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence
by: Guo, Wenbo, et al.
Published: (2024)
by: Guo, Wenbo, et al.
Published: (2024)
Guiding Symbolic Execution with Static Analysis and LLMs for Vulnerability Discovery
by: Shafiuzzaman, Md, et al.
Published: (2026)
by: Shafiuzzaman, Md, et al.
Published: (2026)
A Large Scale Study of AI-based Binary Function Similarity Detection Techniques for Security Researchers and Practitioners
by: Shi, Jingyi, et al.
Published: (2025)
by: Shi, Jingyi, et al.
Published: (2025)
Semantics-Aligned, Curriculum-Driven, and Reasoning-Enhanced Vulnerability Repair Framework
by: Yang, Chengran, et al.
Published: (2025)
by: Yang, Chengran, et al.
Published: (2025)
MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
by: Sun, Tiezhu, et al.
Published: (2025)
by: Sun, Tiezhu, et al.
Published: (2025)
Casting a SPELL: Sentence Pairing Exploration for LLM Limitation-breaking
by: Huang, Yifan, et al.
Published: (2025)
by: Huang, Yifan, et al.
Published: (2025)
PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
by: Liu, Xiting, et al.
Published: (2026)
by: Liu, Xiting, et al.
Published: (2026)
VulInstruct: Teaching LLMs Root-Cause Reasoning for Vulnerability Detection via Security Specifications
by: Zhu, Hao, et al.
Published: (2025)
by: Zhu, Hao, et al.
Published: (2025)
LLM-Powered Detection of Price Manipulation in DeFi
by: Liu, Lu, et al.
Published: (2025)
by: Liu, Lu, et al.
Published: (2025)
Semantic-Aware Fuzzing: An Empirical Framework for LLM-Guided, Reasoning-Driven Input Mutation
by: Lu, Mengdi, et al.
Published: (2025)
by: Lu, Mengdi, et al.
Published: (2025)
From LLMs to Agents: A Comparative Evaluation of LLMs and LLM-based Agents in Security Patch Detection
by: Han, Junxiao, et al.
Published: (2025)
by: Han, Junxiao, et al.
Published: (2025)
Generating API Parameter Security Rules with LLM for API Misuse Detection
by: Liu, Jinghua, et al.
Published: (2024)
by: Liu, Jinghua, et al.
Published: (2024)
Synergistic Directed Execution and LLM-Driven Analysis for Zero-Day AI-Generated Malware Detection
by: Edwards, George, et al.
Published: (2026)
by: Edwards, George, et al.
Published: (2026)
CKGFuzzer: LLM-Based Fuzz Driver Generation Enhanced By Code Knowledge Graph
by: Xu, Hanxiang, et al.
Published: (2024)
by: Xu, Hanxiang, et al.
Published: (2024)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
by: Masud, Md Rayhanul, et al.
Published: (2024)
by: Masud, Md Rayhanul, et al.
Published: (2024)
Co-PatcheR: Collaborative Software Patching with Component(s)-specific Small Reasoning Models
by: Tang, Yuheng, et al.
Published: (2025)
by: Tang, Yuheng, et al.
Published: (2025)
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
by: Jiang, Wenxin, et al.
Published: (2025)
by: Jiang, Wenxin, et al.
Published: (2025)
PROMFUZZ: Leveraging LLM-Driven and Bug-Oriented Composite Analysis for Detecting Functional Bugs in Smart Contracts
by: Lin, Xingshuang, et al.
Published: (2025)
by: Lin, Xingshuang, et al.
Published: (2025)
LLM4Vuln: A Unified Evaluation Framework for Decoupling and Enhancing LLMs' Vulnerability Reasoning
by: Sun, Yuqiang, et al.
Published: (2024)
by: Sun, Yuqiang, et al.
Published: (2024)
A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
by: Zhou, Xiaoyan, et al.
Published: (2024)
by: Zhou, Xiaoyan, et al.
Published: (2024)
Similar Items
-
Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
by: Guo, Wenbo, et al.
Published: (2026) -
Understanding NPM Malicious Package Detection: A Benchmark-Driven Empirical Analysis
by: Guo, Wenbo, et al.
Published: (2026) -
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026) -
An Analysis of Malicious Packages in Open-Source Software in the Wild
by: Zhou, Xiaoyan, et al.
Published: (2024) -
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
by: Zhang, Junan, et al.
Published: (2023)