0단 자동
AI가 규칙대로 쓰고 그대로 게시했습니다. 사람이 따로 보지 않았습니다.
- 규칙 판
- 규칙 판 도입 이전 기사입니다.
- 남기는 것
- 규칙 판 · 모델 · 시각
- 판 기록
- 아직 없습니다.
MARS: Malware Analysis with Rule-Based Scoring of LLM Claims
- 1.MARS: LLM 악성코드 분류에서 '직접 판정'이 '근거 주장 채점' 방식보다 일관되게 정확
- 2.PE·ELF 1,195개(1,001개 클러스터), 6개 LLM 평가에서 정확도 3.7~20.9%p 우위
- 3.근거 주장 매개 방식은 성능 변동 감소 효과 없고, 지표 제거 시 재현율 손실이 더 큼
- 4.다만 주장(claim) 보존 시 평결 입력을 투명하게 노출해 정책 재검토·재적용 가능
왜 중요한가?
설명가능성을 위해 LLM에 근거를 먼저 서술시키는 방식이 악성코드 탐지 정확도를 오히려 낮출 수 있음을 보여, 보안 운영에서 '정확도냐 투명성이냐'의 트레이드오프를 구체적 수치로 제시한다.
언급 프로젝트
본문 미리보기
arXiv:2610.09553v1 Announce Type: new Abstract: Large language models can triage malware through direct verdicts or behavioral claims scored by an external policy. We present MARS, a malware triage framework, and compare direct classification with single-pass claim scoring using the same evidence collector and identical static evidence bundles for each model. The evaluation covers 1,195 PE and ELF binaries grouped into 1,001 near-duplicate clusters and six language models, with deterministic ru
전체 내용이 궁금하다면?
원문을 직접 읽어보세요
이 글이 만들어진 과정
- 11:24AI 초안

