Prompt Chaining-Assisted Malware Detection: A Hybrid Approach Utilizing Fine-Tuned LLMs and Domain Knowledge-Enriched Cybersecurity Knowledge Graphs

Neha Mohan Kumar, Fahmida Tasnim Lisa, Sheikh Rabiul Islam · 2024

As malware threats continue to evolve in complexity, developing accurate and explainable detection systems is crucial for robust cybersecurity. This paper introduces a hybrid malware classification system that leverages fine-tuned large language models (LLMs) and an enriched cybersecurity knowledge graph (KG) to enhance both detection accuracy and interpretability. The system processes two types of input data—network packets and memory dumps, and classifies applications as benign or malign. Fine-tuned Llama models provide initial classifications, along with reasoning, which are further refined through prompt chaining using a knowledge graph populated with MITRE ATT&CK data and SecureBERT embeddings. The KG facilitates contextual reasoning, resulting in more accurate detection and informed decision-making. Experimental results demonstrate classification accuracies of 91.2% for network packet data and 94.35% for memory dump data, despite challenges related to LLM hallucinations and output parsing.

Read the paper · More papers on PaperTik