Explainable Malware Detection from Noisy API Sequences with RAG-Based MITRE ATT&CK Mapping
As sophisticated evasion techniques like polymorphism and staged execution increasingly neutralize conventional signature-based defenses, dynamic API sequence analysis has emerged as an effective approach for malware detection. However, extracting actionable intelligence from noisy execution logs while maintaining mode...