Research
A Fake Security-Product Story in an Unexecuted Binary Section Flipped 30 of 35 Malware Verdicts
ALIBI (arXiv 2609.19722, 17 Sep 2026) attacks LLM-based malware triage without issuing a single instruction to the model. It adds a small read-only section to a compiled binary containing a coherent but false narrative about a benign endpoint security tool, leaving imports and executable behavior untouched, which reframes the suspicious evidence as expected. On 50 malicious PE samples the payload flipped 30 of 35 baseline-malicious verdicts to benign on Gemini 2.5 Pro, with substantial severity downgrades on GPT-5.5 Pro and Claude Opus 4.7, transferring to ELF where Gemini flipped 16 of 40, and a verification-guided defense prompt still left 42.9% reaching benign.
↳ Follow the thread