Detecting vibe-coded malware

dc.contributor.authorRoedig, Utz
dc.contributor.authorMurphy, Seán Óg
dc.contributor.authorRyan, Ita
dc.contributor.authorSreenan, Cormac
dc.contributor.editorFranke, Hubertus
dc.contributor.editorPalesi, Maurizio
dc.contributor.editorSalvador, Ruben
dc.contributor.editorSuarez, Estela
dc.contributor.funderTaighde Éireann - Research Ireland
dc.date.accessioned2026-06-30T14:50:01Z
dc.date.available2026-06-30T14:50:01Z
dc.date.issued2026-07-10
dc.description.abstractMalware is currently detected using predominantly static analysis techniques such as rule- and signature-based frameworks. Their effectiveness is largely due to attackers reusing well-known components and toolchains to lower skill requirements, reduce development effort and time to deployment. As a result, malware exhibits recognizable structural patterns that static detectors can reliably identify. The increasing availability of AI-assisted coding tools challenges this assumption by enabling and emboldening attackers to generate malicious software from scratch, producing samples with highly variable code structures but identical malicious intent. In this work, we demonstrate that AI-generated malware permutations can evade static analysis, while their runtime behavior remains largely invariant. We focus our work on malicious shell scripts as a specific class of malware. Such malicious shell scripts are commonly used in attacks against Linux based IoT devices such as routers, cameras, and smart home devices. Our experimental results show that dynamic and behavioral analysis techniques are more robust in this context, highlighting the need to lessen the prevailing dependency on static analysis and instead shift malware detection strategies for systems toward behavior-centric approaches.en
dc.description.sponsorshipResearch Ireland|23/US/3939
dc.description.versionPublished Version
dc.format.extent8
dc.format.mimetypeapplication/pdfen
dc.identifier.authororcidRoedig, Utz§0000-0002-4020-0889
dc.identifier.authororcidMurphy, Seán Óg§0000-0003-1273-6501
dc.identifier.authororcidRyan, Ita§0000-0001-6844-6365
dc.identifier.authororcidSreenan, Cormac§0000-0002-0767-7888
dc.identifier.authororcidFranke, Hubertus
dc.identifier.authororcidPalesi, Maurizio
dc.identifier.authororcidSalvador, Ruben
dc.identifier.authororcidSuarez, Estela
dc.identifier.citationRoedig, U, Murphy, S Ó, Ryan, I & Sreenan, C 2026, Detecting vibe-coded malware. in H Franke, M Palesi, R Salvador & E Suarez (eds), Proceedings of the 23rd ACM International Conference on Computing Frontiers 2026 Workshops and Special Sessions, CF 2026 Companion. Proceedings of the 23rd ACM International Conference on Computing Frontiers 2026 Workshops and Special Sessions, CF 2026 Companion, Association for Computing Machinery (ACM), pp. 57-64. https://doi.org/10.1145/3801488.3807898
dc.identifier.doi10.1145/3801488.3807898
dc.identifier.endpage64
dc.identifier.isbn9798400725692
dc.identifier.otherORCID: /0000-0003-1273-6501/work/219288342
dc.identifier.otherORCID: /0000-0001-6844-6365/work/219289033
dc.identifier.otherORCID: /0000-0002-4020-0889/work/219289093
dc.identifier.startpage57
dc.identifier.urihttps://hdl.handle.net/10468/18984
dc.language.isoen
dc.publisherAssociation for Computing Machinery (ACM)
dc.relation.ispartofseriesProceedings of the 23rd ACM International Conference on Computing Frontiers 2026 Workshops and Special Sessions, CF 2026 Companion
dc.relation.urihttps://www.scopus.com/pages/publications/105045300471
dc.rightsPublisher Copyright: © 2026 Copyright held by the owner/author(s).
dc.rights.accessrightsopen access
dc.rights.licensenameAttribution 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.statusPeer reviewed
dc.subjectMalware
dc.subjectPrivacy
dc.subjectSecurity
dc.subject[ComputerScience]
dc.titleDetecting vibe-coded malwareen
dc.typeConference item
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Vibe_Coded_Malware-4.pdf
Size:
456.76 KB
Format:
Adobe Portable Document Format