| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Detection of malicious software using large language models : master's degree thesis
Authors:ID Tivadar, Martina (Author)
ID Karakatič, Sašo (Mentor) More about this mentor... New window
Files:.pdf MAG_Tivadar_Martina_2025.pdf (29,72 MB)
MD5: 9D547BEA2188C05F23797101E8DADDD1
 
Language:English
Work type:Master's thesis/paper
Typology:2.09 - Master's Thesis
Organization:FERI - Faculty of Electrical Engineering and Computer Science
Abstract:This thesis examines the success rate of large language models (LLM) in detecting macOS malware through Endpoint Security logs. A literature review and 144 experiments with three ChatGPT variants and six prompt types evaluated accuracy, precision, recall, specificity, and F1-score. Results show that prompt wording is crucial: zero-shot and chain-of-thought prompts performed best, while conservative prompts minimized false positives but missed threats. GPT-4o and o1 outperformed o4-mini but showed similar results. Findings suggest LLMs can support, but not replace, traditional detection, with prompt design proving as important as model choice.
Keywords:malware, large language models, detection
Place of publishing:Maribor
Place of performance:Maribor
Publisher:[M. Tivadar]
Year of publishing:2025
Number of pages:1 spletni vir (1 datoteka PDF (XVI, 76 str.))
PID:20.500.12556/DKUM-95400 New window
UDC:004.056.54(043.2)
COBISS.SI-ID:262071811 New window
Publication date in DKUM:03.11.2025
Views:293
Downloads:36
Metadata:XML DC-XML DC-RDF
Categories:KTFMB - FERI
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:16.09.2025

Secondary language

Language:Slovenian
Title:Detekcija zlonamerne programske opreme z velikimi jezikovnimi modeli
Abstract:Magistrska naloga preučuje uspešnost velikih jezikovnih modelov (LLM) pri zaznavanju zlonamerne programske opreme v okolju macOS prek dnevnikov Endpoint Security. Na podlagi pregleda literature in 144 eksperimentov s tremi ChatGPT modeli ter šestimi vrstami pozivov so bili ocenjeni natančnost, priklic, specifičnost, F1-merilo in točnost. Rezultati kažejo, da je oblikovanje pozivov ključno: t.i. zero-shot in chain-of-thought pozivi so se izkazali kot najbolj učinkoviti, medtem ko so konzervativni pozivi sicer zmanjšali število lažnih pozitivnih zaznav, a so hkrati spregledali grožnje. GPT-4o in o1 sta presegla model o4-mini, a dosegla podobne rezultate. Ugotovitve nakazujejo, da lahko LLM-i dopolnjujejo, ne pa nadomestijo tradicionalne metode zaznavanja, pri čemer se je oblikovanje pozivov izkazalo za enako pomembno kot izbira modela.
Keywords:zlonamerna programska oprema, veliki jezikovni modeli, detekcija


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica