Institution profile

Fortinet

Industry researchnorthamerica · us
Official website
Research library2linked papers
Opportunities0open roles
Selected work

Representative Papers

Malware analysis assisted by AI with R2AI

Apr 10, 2025

This study addresses quality, efficiency, and cost bottlenecks in AI-assisted Linux and IoT malware analysis for 2024–2025. Methodologically, it introduces an “AI–expert collaborative” reverse-engineering paradigm: first systematically validating the practical boundaries of Claude 3.5/3.7 Sonnet on real-world malware; then integrating R2AI (an AI extension for Radare2), static/dynamic analysis, human-in-the-loop prompt engineering, and a feedback-closed loop—where domain experts provide real-time guidance to mitigate hallucination and cyclic reasoning. Results demonstrate: (1) analytical accuracy matching or exceeding manual analysis; (2) significantly accelerated end-to-end analysis—including error correction; and (3) per-sample cost substantially lower than a senior analyst’s daily rate. The core contribution is a deployable, empirically validated AI–human collaborative framework, rigorously demonstrated for state-of-the-art LLMs applied to complex binary reverse engineering—proving both technical efficacy and operational cost-efficiency.

0 citationsRead paper
Recent publications

Latest Papers

Malware analysis assisted by AI with R2AI

Apr 10, 2025

This study addresses quality, efficiency, and cost bottlenecks in AI-assisted Linux and IoT malware analysis for 2024–2025. Methodologically, it introduces an “AI–expert collaborative” reverse-engineering paradigm: first systematically validating the practical boundaries of Claude 3.5/3.7 Sonnet on real-world malware; then integrating R2AI (an AI extension for Radare2), static/dynamic analysis, human-in-the-loop prompt engineering, and a feedback-closed loop—where domain experts provide real-time guidance to mitigate hallucination and cyclic reasoning. Results demonstrate: (1) analytical accuracy matching or exceeding manual analysis; (2) significantly accelerated end-to-end analysis—including error correction; and (3) per-sample cost substantially lower than a senior analyst’s daily rate. The core contribution is a deployable, empirically validated AI–human collaborative framework, rigorously demonstrated for state-of-the-art LLMs applied to complex binary reverse engineering—proving both technical efficacy and operational cost-efficiency.

0 citationsRead paper