Skip to content
Review Open access

To Compare Various Frameworks that Integrate XAI, GANs and LLMs for Dynamic Malware Behavior Analysis

Aug 2026 · International Journal of Innovations in Science, Engineering And Management · pp. 426-439 · 0 citations · 15 references

TL;DR

A unified approach of malware analysis incorpo-rating XAI, GAN and LLM is proposed to enable the development of more effective malware detection tools with more transparency, deeper analytical insight and advanced forensic decision-making.

Abstract

Modern malware frameworks use advanced evasion techniques that bypass traditional detection methods; thus entail advanced analytical frameworks for comprehensive and robust analysis. This study provides a comparative analysis of several frameworks that utilize Explainable Artificial Intelligence (XAI), Generative Adversarial Networks (GANs), and Large Language Models (LLMs) to provide a dynamic approach to malware behaviour. The review consisted of five key metrics to assess these three frameworks: detection performance, explainability, robustness against adversarial attacks, behavioral interpretation, and automated reporting capabilities. The results indicate that Deep Learning models have attained high accuracy in detect-ing and identifying malicious code, but are not interpretable. The GAN-based frameworks are highly effective in generating adversarial samples for robustness testing. Conversely, LLM-based approaches are highly effective for generating automated forensic reports, but are not yet fully integrated into malware detection workflows. The analysis highlights a research gap pertaining to the lack of integrated frameworks for adversarial analysis, explainability and automated forensic reporting. This study proposes a unified approach of malware analysis incorpo-rating XAI, GAN and LLM to enable the development of more effective malware detection tools with more transparency, deeper analytical insight and advanced forensic decision-making.

Read PDF

Similar papers

Review Open access Aug 2026

Generative Adversarial Networks for Anomaly and Malware Detection

A comprehensive survey of how GAN-based methods are utilized for identifying unusual and harmful activities in cyber settings and addresses ongoing challenges and potential future avenues for employing GANs to counteract emerging cybersecurity threats.

A. Thakore, Neha Gupta, Akash Saxena et al. · 0 citations
Preprint Aug 2026

Generating Attacks for LLMs with GFlowNets

This study proposes an automated, human-independent, and adaptive approach leveraging GFlowNets to identify LLM vulnerabilities by utilizing one large language model to test another, and introduces a model capable of generating attack inputs in the Turkish language.

Berkay Ozcam, Irem Onen, M. Amasyalı et al. · 0 citations

Detection and Explanation of PowerShell Malware with Large Language Models

The application of LLMs for detecting malicious PowerShell scripts and producing human-interpretable explanations for their classification decisions are investigated, showing that LLMs are capable of identifying and explaining malicious PowerShell scripts, although performance varies across different models.

Meng Wang, Emma Topolovec, B. Arana et al. · 0 citations
Open access Aug 2026

Analyzing Malware Behavior Using Generative Neural Networks

The results demonstrate that GNN-based malware detection not only addresses the limitations of conventional approaches in terms of scalability but also provides a more robust and adaptable framework that could be integrated into future real-time threat intelligence and automated defense systems.

Wurood A. Jbara, N. A. Hussein · 0 citations
Preprint Sep 2026

Windows Malware Detector as a Compound AI System: Trade-Offs in Accuracy, Efficiency, and Adversarial Robustness

Industrial Windows malware detectors are commonly described as Compound AI Systems composed of multiple heterogeneous components, including rule-based mechanisms as well as machine-learning-based static and dynamic analyses. However, due to industrial secrecy and limited public disclosure, the internal architectures of...

Andrea Ponte, Luca Demetrio, Luca Oneto et al. · 0 citations
#artificial intelligence Preprint Sep 2026

SCRIPTIOC-BENCH: A Benchmark for Recognizing Actionable Threat Intelligence from Script-Based Malware using LLMs

Script-based malware remains a prevalent attack technique. These scripts often contain indicators of compromise (IOCs) that provide actionable threat intelligence. However, statically recovering such indicators is challenging, as relevant values may be dispersed or transformed within code. Although large language model...

Hanna Kim, Jian Cui, Minkyoo Song et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.