arXiv AI By Mubashar Iqbal, Asifullah Khan, Hifsa Asif, Saddam Hussain Khan, Umme Zahoora, Asifullah Khan

Cost-Aware Hierarchical Multi-Agent Ransomware Detection and Family Attribution under Analysis Budgets

Read the original on arXiv AI →

The paper introduces a cost‑aware Hierarchical Multi‑Agent System (HMAS) for ransomware detection and family attribution that prioritizes static analysis and escalates to dynamic and memory analysis only when necessary, thereby reducing analysis time and resource usage. In experiments on 12,439 samples from 16 ransomware families, the deterministic HMAS achieved high F1 scores (0.93) while resolving nearly 58% of cases with static evidence alone and cutting average internal analysis cost by 44.6% compared to exhaustive methods. The system also records a complete provenance trace for each decision and includes optional local LLM review for limited verdict adjustment.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
Sep 7

Cost-Aware Hierarchical Multi-Agent Ransomware Detection and Family Attribution

The paper introduces a Cost-Aware Hierarchical Multi-Agent System (HMAS) for ransomware detection and family attribution that adaptively selects analysis modalities to balance accuracy and computational cost. Static analysis is used first, with dynamic and memory modalities added only when confidence is low or specialist agents disagree, guided by a cost model. Experiments show HMAS achieves high accuracy (96.57% binary detection, 0.90 macro‑F1 attribution) while reducing analysis cost by 43.97% and latency, with 56.05% of cases resolved using static evidence alone.

By Mubashar Iqbal, Asifullah Khan
arXiv AI
Jul 31

SecRespond: Benchmarking AI Agents for Real-World Post-Compromise Incident Response

arXiv:2607. 26791v1 Announce Type: cross Abstract: Large Language Model (LLM) agents are increasingly adopted in real-world security operations with access to host artifacts and command-line interfaces (CLIs), making it critical to thoroughly assess their security capabilities.

By Lehan Wang, Boli Chen, Ruixue Ding, Pengjun Xie, Jinwei Huang, Zhendong Liu, Shuo Wang, Tao Lei, Xin Ouyang, Xiaomeng Li