Paper published in a book (Scientific congresses, symposiums and conference proceedings)
MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
SUN, Tiezhu; ALECCI, Marco; PILGUN, Aleksandr et al.
2025In The 41st International Conference on Software Maintenance and Evolution (ICSME) 2025 conference
Peer reviewed
 

Files


Full Text
_ICSME_2025__MalLoc__Toward_Fine_grained_Android_Malicious_Payload_Localization_via_LLMs.pdf
Author postprint (2.69 MB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Android Malware Analysis; Malicious Payload Localization; Large Language Models
Abstract :
[en] The rapid evolution of Android malware poses significant challenges to the maintenance and security of mobile applications (apps). Traditional detection techniques often struggle to keep pace with emerging malware variants that employ advanced tactics such as code obfuscation and dynamic behavior triggering. One major limitation of these approaches is their inability to localize malicious payloads at a fine-grained level, hindering precise understanding of malicious behavior. This gap in understanding makes the design of effective and targeted mitigation strategies difficult, leaving mobile apps vulnerable to continuously evolving threats. To address this gap, we propose MalLoc, a novel approach that leverages the code understanding capabilities of large language models (LLMs) to localize malicious payloads at a fine-grained level within Android malware. Our experimental results demonstrate the feasibility and effectiveness of using LLMs for this task, highlighting the potential of MalLoc to enhance precision and interpretability in malware analysis. This work advances beyond traditional detection and classification by enabling deeper insights into behavior-level malicious logic and opens new directions for research, including dynamic modeling of localized threats and targeted countermeasure development.
Disciplines :
Computer science
Author, co-author :
SUN, Tiezhu  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
ALECCI, Marco  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
PILGUN, Aleksandr  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
SONG, Yewei  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
TANG, Xunzhu  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
SAMHI, Jordan  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
BISSYANDE, Tegawendé François d Assise  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
KLEIN, Jacques  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
External co-authors :
no
Language :
English
Title :
MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
Publication date :
07 September 2025
Event name :
The 41st International Conference on Software Maintenance and Evolution (ICSME) 2025 conference
Event date :
7 - 12 September 2025
By request :
Yes
Audience :
International
Main work title :
The 41st International Conference on Software Maintenance and Evolution (ICSME) 2025 conference
Publisher :
IEEE
Peer reviewed :
Peer reviewed
FnR Project :
FNR16344458 - REPROCESS - Pre And Post Processing For Comprehensive And Practical Android App Static Analysis, 2021 (01/07/2022-30/06/2025) - Jacques Klein
FNR18154263 - UNLOCK - Breaking The Barriers Of Android Dynamic Analysis With Static Analysis, 2023 (01/01/2024-31/12/2026) - Jacques Klein
Available on ORBilu :
since 09 September 2025

Statistics


Number of views
68 (7 by Unilu)
Number of downloads
52 (5 by Unilu)

Scopus citations®
 
0
Scopus citations®
without self-citations
0
OpenAlex citations
 
0

Bibliography


Similar publications



Contact ORBilu