Detecting vibe-coded malware
| dc.contributor.author | Roedig, Utz | |
| dc.contributor.author | Murphy, Seán Óg | |
| dc.contributor.author | Ryan, Ita | |
| dc.contributor.author | Sreenan, Cormac | |
| dc.contributor.editor | Franke, Hubertus | |
| dc.contributor.editor | Palesi, Maurizio | |
| dc.contributor.editor | Salvador, Ruben | |
| dc.contributor.editor | Suarez, Estela | |
| dc.contributor.funder | Taighde Éireann - Research Ireland | |
| dc.date.accessioned | 2026-06-30T14:50:01Z | |
| dc.date.available | 2026-06-30T14:50:01Z | |
| dc.date.issued | 2026-07-10 | |
| dc.description.abstract | Malware is currently detected using predominantly static analysis techniques such as rule- and signature-based frameworks. Their effectiveness is largely due to attackers reusing well-known components and toolchains to lower skill requirements, reduce development effort and time to deployment. As a result, malware exhibits recognizable structural patterns that static detectors can reliably identify. The increasing availability of AI-assisted coding tools challenges this assumption by enabling and emboldening attackers to generate malicious software from scratch, producing samples with highly variable code structures but identical malicious intent. In this work, we demonstrate that AI-generated malware permutations can evade static analysis, while their runtime behavior remains largely invariant. We focus our work on malicious shell scripts as a specific class of malware. Such malicious shell scripts are commonly used in attacks against Linux based IoT devices such as routers, cameras, and smart home devices. Our experimental results show that dynamic and behavioral analysis techniques are more robust in this context, highlighting the need to lessen the prevailing dependency on static analysis and instead shift malware detection strategies for systems toward behavior-centric approaches. | en |
| dc.description.sponsorship | Research Ireland|23/US/3939 | |
| dc.description.version | Published Version | |
| dc.format.extent | 8 | |
| dc.format.mimetype | application/pdf | en |
| dc.identifier.authororcid | Roedig, Utz§0000-0002-4020-0889 | |
| dc.identifier.authororcid | Murphy, Seán Óg§0000-0003-1273-6501 | |
| dc.identifier.authororcid | Ryan, Ita§0000-0001-6844-6365 | |
| dc.identifier.authororcid | Sreenan, Cormac§0000-0002-0767-7888 | |
| dc.identifier.authororcid | Franke, Hubertus | |
| dc.identifier.authororcid | Palesi, Maurizio | |
| dc.identifier.authororcid | Salvador, Ruben | |
| dc.identifier.authororcid | Suarez, Estela | |
| dc.identifier.citation | Roedig, U, Murphy, S Ó, Ryan, I & Sreenan, C 2026, Detecting vibe-coded malware. in H Franke, M Palesi, R Salvador & E Suarez (eds), Proceedings of the 23rd ACM International Conference on Computing Frontiers 2026 Workshops and Special Sessions, CF 2026 Companion. Proceedings of the 23rd ACM International Conference on Computing Frontiers 2026 Workshops and Special Sessions, CF 2026 Companion, Association for Computing Machinery (ACM), pp. 57-64. https://doi.org/10.1145/3801488.3807898 | |
| dc.identifier.doi | 10.1145/3801488.3807898 | |
| dc.identifier.endpage | 64 | |
| dc.identifier.isbn | 9798400725692 | |
| dc.identifier.other | ORCID: /0000-0003-1273-6501/work/219288342 | |
| dc.identifier.other | ORCID: /0000-0001-6844-6365/work/219289033 | |
| dc.identifier.other | ORCID: /0000-0002-4020-0889/work/219289093 | |
| dc.identifier.startpage | 57 | |
| dc.identifier.uri | https://hdl.handle.net/10468/18984 | |
| dc.language.iso | en | |
| dc.publisher | Association for Computing Machinery (ACM) | |
| dc.relation.ispartofseries | Proceedings of the 23rd ACM International Conference on Computing Frontiers 2026 Workshops and Special Sessions, CF 2026 Companion | |
| dc.relation.uri | https://www.scopus.com/pages/publications/105045300471 | |
| dc.rights | Publisher Copyright: © 2026 Copyright held by the owner/author(s). | |
| dc.rights.accessrights | open access | |
| dc.rights.licensename | Attribution 4.0 International | |
| dc.rights.uri | https://creativecommons.org/licenses/by/4.0/ | |
| dc.status | Peer reviewed | |
| dc.subject | Malware | |
| dc.subject | Privacy | |
| dc.subject | Security | |
| dc.subject | [ComputerScience] | |
| dc.title | Detecting vibe-coded malware | en |
| dc.type | Conference item |
Files
Original bundle
1 - 1 of 1
