Publication Date

Spring 2026

Degree Type

Thesis

Degree Name

Master of Science (MS)

Department

Applied Data Science

Advisor

Mohammad Masum; Guannan Liu; Keeyong Han; Shih-Yu Chang

Abstract

Large language models (LLMs) have demonstrated strong reasoning and pattern-recognition abilities beyond traditional language tasks, yet their application to malware detection remains underexplored. This thesis investigates LLM-driven approaches for static malware classification using features extracted from Windows Portable Executable (PE) files via the EMBER dataset, proposing two complementary frameworks designed to improve interpretability. To establish a reference point, we first benchmark over 100 combinations of Machine Learning (ML) feature selectors, LLMs, and prompting strategies on raw EMBER features, finding that naive numerical prompting yields at most 67% accuracy. The first framework is a prompting-based hybrid pipeline that combines LLM-guided feature selection, entropy-based summarization, and byte-histogram compression to convert high-dimensional PE features into compact natural-language representations, achieving up to 73% accuracy across three evaluated LLMs. The second is a modular multi-agent architecture in which EMBER feature groups are assigned to specialized fine-tuned agents whose outputs are aggregated into a final verdict and detailed, feature-grounded explanation, achieving 90% test accuracy with 88% malicious recall while enabling parameter-efficient fine-tuning without end-to-end training on raw binaries. Overall, this work demonstrates that LLM-driven malware detection can be both effective and interpretable using structured PE signals as inputs.

Available for download on Sunday, July 25, 2027

Share

COinS