AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

ALIBI: Adversarial Legitimacy Injection in Binary Input against LLM Malware Analyzers

arXiv · AI, language, vision and robotics · article · Sep 17, 2026 · UTC

Large language models are being integrated into malware triage workflows as reasoning components that summarize static evidence and produce analyst-facing verdicts. This paper shows that the same reasoning capability introduces a new attack surface. We present ALIBI, a semantic cover story attack against frontier LLM-based malware analyzers. ALIBI adds a small, non-executed read-only section to a compiled binary, containing a coherent but false security product narrative, without altering imports or executable behavior. Instead of issuing direct instructions to the model, it reframes suspiciou

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-19T20:28:21.856Z. This is not the publication date.