arXiv:2607. 03350v1 Announce Type: cross Abstract: Malicious Python packages have become a major threat to software supply chain ecosystems due to the widespread adoption of open-source repositories such as PyPI.
By Hang Gao, Xiaoyu Chen, Baoquan Cui, Zhen Tang, Peng Qiao, Fengge Wu, Jian Zhang
arXiv:2606. 06815v1 Announce Type: cross Abstract: As malware illustrates a complex structure and behavior, detection of these has been a significant challenge in the domain of cybersecurity along with related services in daily life.
By Parthajit Borah, Sakshi Singh, D. K. Bhattacharyya, J. K. Kalita
arXiv:2509. 14335v2 Announce Type: replace-cross Abstract: Automated malware classifiers achieve strong detection performance, but auditing requires more than flagging a sample: analysts must explain malicious behaviors and justify them with code evidence.
By Xinran Zheng, Xingzhi Qian, Yiling He, Shuo Yang, Lorenzo Cavallaro
arXiv:2512. 20872v2 Announce Type: replace-cross Abstract: Function call graphs (FCGs) have emerged as a powerful abstraction for malware detection, capturing the behavioral structure of applications beyond surface-level signatures.
By Jakir Hossain, Jue Guo, Gurvinder Singh, Lukasz Ziarek, Ahmet Erdem Sar{\i}y\"uce
The paper introduces a new benchmark for assessing out-of-distribution robustness in graph-based Android malware classifiers, highlighting that current models drop up to 45% accuracy on unseen malware variants. It presents two scenarios—MalNet-Tiny-Common for covariate shift and MalNet-Tiny-Distinct for domain shift—and identifies a limitation in existing benchmarks that rely solely on structure-only function call graphs. To address this, the authors propose a semantic enrichment framework that augments graph topology with function-level attributes and LLM-based code embeddings, demonstrating that this data-centric approach improves robustness under distribution shift and complements model-based methods.
By Ngoc N. Tran, Anwar Said, Waseem Abbas, Tyler Derr, Xenofon D. Koutsoukos
arXiv:2608. 02348v1 Announce Type: cross Abstract: Malware clustering is a critical task in cybersecurity that helps discover threats and analyze evolving malware families.
By Martin Mocko, Daniela Chud\'a
arXiv:2606. 06570v1 Announce Type: cross Abstract: Malware detection remains largely reactive: machine learning models trained on known samples degrade as threats evolve.
By Akash Amalan, Georgios Smaragdakis, Tom J. Viering
The paper evaluates how graph neural networks (GNNs) built on control flow graphs (CFGs) perform when trained on one time period and tested on a later one, using a strict temporal split. Twelve GNN variants and a flat-feature baseline were trained on 459 CFGs from 2024‑2025 and evaluated on 223 CFGs from 2026, revealing that the choice of message‑passing operator strongly affects robustness to distribution shift. Attribution stability varied by architecture, and the best-performing operator on the later corpus was also the hardest to explain, leading the authors to design a new architecture that matches its performance without search.
By Md. Asif Sajeed, Md. Nazrul Islam Mondal, Md Ashraful Hossen Akash
Delphi Scanner is a static malware detection system for Windows PE files that balances efficiency and interpretability. It employs a convolutional neural network to model Windows API sequences and a rule‑based interpretation layer to map APIs to high‑level malicious capabilities. Tested on over 190,000 PE files, it achieves 95.35% accuracy with a 1.53 MB model, and demonstrates robustness against out‑of‑distribution samples and adversarial manipulations.
By Bijied Brahimi, Vincent Cohadon, Gabriel Glazman, Rayan Al Mohaize, Omran Berjawi, Rida Khatoun
Large Language Models (LLMs) and generative AI (GenAI) systems, such as ChatGPT, Claude, Gemini, LLaMA, Copilot, Stable Diffusion by OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, respectively, are revolutionizing cybersecurity, enabling both automated defense and sophisticated attacks. These technologies power real-time threat detection, phishing defense, secure code generation, and vulnerability exploitation at unprecedented scales.
arXiv:2607. 06963v1 Announce Type: cross Abstract: Large Language Models (LLMs) and generative AI (GenAI) systems, such as ChatGPT, Claude, Gemini, LLaMA, Copilot, Stable Diffusion by OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, respectively, are revolutionizing cybersecurity, enabling both automated defense and sophisticated attacks.
By Kiarash Ahi, Saeed Valizadeh
arXiv:2606. 07792v1 Announce Type: cross Abstract: MOLOT (Malicious Operational Logic Observation Transformer) is a static malicious-code detection system designed for SAST setup where package metadata, maintainer history, and dynamic execution traces may be unavailable or unreliable.
By Daniil Lopatkin, Maksim Mitrofanov, Stanislav Rakovsky, Aleksandr Khalikov