| Title: | Detection of malicious software using large language models : master's degree thesis |
|---|
| Authors: | ID Tivadar, Martina (Author) ID Karakatič, Sašo (Mentor) More about this mentor...  |
| Files: | MAG_Tivadar_Martina_2025.pdf (29,72 MB) MD5: 9D547BEA2188C05F23797101E8DADDD1
|
|---|
| Language: | English |
|---|
| Work type: | Master's thesis/paper |
|---|
| Typology: | 2.09 - Master's Thesis |
|---|
| Organization: | FERI - Faculty of Electrical Engineering and Computer Science
|
|---|
| Abstract: | This thesis examines the success rate of large language models (LLM) in detecting macOS malware through Endpoint Security logs. A literature review and 144 experiments with three ChatGPT variants and six prompt types evaluated accuracy, precision, recall, specificity, and F1-score. Results show that prompt wording is crucial: zero-shot and chain-of-thought prompts performed best, while conservative prompts minimized false positives but missed threats. GPT-4o and o1 outperformed o4-mini but showed similar results. Findings suggest LLMs can support, but not replace, traditional detection, with prompt design proving as important as model choice. |
|---|
| Keywords: | malware, large language models, detection |
|---|
| Place of publishing: | Maribor |
|---|
| Place of performance: | Maribor |
|---|
| Publisher: | [M. Tivadar] |
|---|
| Year of publishing: | 2025 |
|---|
| Number of pages: | 1 spletni vir (1 datoteka PDF (XVI, 76 str.)) |
|---|
| PID: | 20.500.12556/DKUM-95400  |
|---|
| UDC: | 004.056.54(043.2) |
|---|
| COBISS.SI-ID: | 262071811  |
|---|
| Publication date in DKUM: | 03.11.2025 |
|---|
| Views: | 293 |
|---|
| Downloads: | 36 |
|---|
| Metadata: |  |
|---|
| Categories: | KTFMB - FERI
|
|---|
|
:
|
Copy citation |
|---|
| | | | Average score: | (0 votes) |
|---|
| Your score: | Voting is allowed only for logged in users. |
|---|
| Share: |  |
|---|
Hover the mouse pointer over a document title to show the abstract or click
on the title to get all document metadata. |