[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82238-en":3,"doc-seo-82238-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},82238,962075114765,"Quinn","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Malaika Understanding Malware through Tri-Grounded Agentic Reasoning","Recent LLM-based systems improve security-focused code analysis, but malware understanding requires reconstructing high-level malicious behaviors from sparse, dispersed evidence under partial observability. The work formulates malware understanding as grounded reasoning and argues that reliability needs three complementary grounding forms: domain grounding for hypothesis generation and evaluation, semantics grounding for linking program evidence to behavioral claims, and knowledge grounding for externally verifiable threat attribution. It introduces Malaika, a tri-grounded multi-agent framework evaluated on Android malware tasks with analyst-validated annotations, showing higher quality and auditable conclusions.","Malaika: Understanding Malware through Tri-Grounded Agentic Reasoning  \nXingzhi Qian, Xinran Zheng, Yiling HeB and Lorenzo Cavallaro University College London  \n{xingzhi.qian.23, xinran.zheng.23, yiling-he, [l.cavallaro](l.cavallaro}@ucl.ac.uk)[}](l.cavallaro}@ucl.ac.uk)[@ucl.ac.uk](l.cavallaro}@ucl.ac.uk)  \narXiv :2607 .09 179v 1 [ cs .CR] 10 Jul 2026  \nAbstract—Recent LLM-based systems have shown promising capabilities for security-focused code analysis, including vulnerability identification and reverse engineering. Malware understanding, however, poses a distinct challenge: analysts must reconstruct high-level malicious behaviors under partial observability from sparse, dispersed evidence intertwined with benign functionality. While static analysis can expose security-relevant signals, the central challenge is not merely identifying suspicious code, but determining whether the evidence sufficiently supportsan auditable behavior-level conclusion. We formulate malware understanding as a grounded reasoning problem and argue that reliable behavior reconstruction requires three complementary forms of grounding. Domain grounding constrains how behavior hypotheses are generated and evaluated, semantics grounding localizes and connects supporting program evidence, and knowledge grounding supports behavioral attribution through externally verifiable threat knowledge. To study this hypothesis, we present Malaika, a tri-grounded multi-agent framework that operationalizes the three grounding mechanisms through analyst-inspired reasoning, tool-mediated evidence localization, explicit review, and retrieval-based behavioral attribution. We instantiate Malaika for Android malware analysis and evaluate it on malware-understanding tasks with analyst-validated behaviorlevel annotations. Our results show that Malaika improves analysis quality over prior LLM-based malware-analysis frameworksand demonstrate that reliability depends not only on model capability but also on the structure of the reasoning process itself. In particular, comparisons against both malware-analysis systems and frontier agentic frameworks show that behavioral attribution is strongly influenced by the surrounding reasoning process, with grounding-aware reasoning producing substantially more precise and auditable conclusions. More importantly, ablation studies support the grounding hypothesis: domain grounding, semantics grounding, and knowledge grounding address complementary failure modes by contributing distinct capabilities for hypothesis generation, evidence localization, and behavioral attribution, respectively. These findings suggest that grounding-aware reasoning provides a principled foundation for reliable malware understanding and, more broadly, for evidence-grounded software analysis.  \nI. INTRODUCTION  \nMalware analysis remains a central problem in software security. In practice, a binary prediction of whether an application is malicious is rarely enough for analysts. They need to understand what the program does, how the behavior is triggered, and which concrete code-level evidence supports each conclusion. Reliable malware understanding therefore requires  \nB Corresponding Author.  \nmore than detecting suspicious signals. It requires linking lowlevel program facts to high-level behavioral interpretations ina way that is both auditable and grounded in evidence.  \nExisting malware detection systems have made substantial progress in scalable classification. Conventional learningbased detectors abstract applications into classificationoriented representations, from manually engineered features [1], [2] to learned representations over richer program structures and temporal signals [3],[4],[5],[6] . These methods are useful as front-line detectors, but their outputs are usually malware labels or feature-level explanations [7] . Such outputs provide limited support for the downstream task of reconstructing concrete malicious behavior and checking whether each clai","cbCaio0TZosJKfcc","https://ap.wps.com/l/cbCaio0TZosJKfcc","pdf",538589,1,12,"English","en",105,"# Abstract\n# Introduction\n## Malware understanding as grounded reasoning\n## Limits of existing detectors\n## LLM-based malware analysis\n## Agentic frameworks and prompt sensitivity","[{\"question\":\"What makes malware understanding harder than malware detection?\",\"answer\":\"Detection often reduces outputs to a malicious/benign label, while understanding requires linking low-level program facts to high-level behavioral interpretations that can be audited by concrete evidence.\"},{\"question\":\"What are the three grounding mechanisms proposed in Malaika?\",\"answer\":\"Malaika relies on domain grounding to constrain hypothesis generation/evaluation, semantics grounding to localize and connect supporting program evidence, and knowledge grounding to enable behavioral attribution using externally verifiable threat knowledge.\"},{\"question\":\"How does Malaika operationalize tri-grounded reasoning?\",\"answer\":\"It uses a tri-grounded multi-agent framework combining analyst-inspired reasoning, tool-mediated evidence localization, explicit review, and retrieval-based behavioral attribution.\"}]",1784179048,30,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"malaika-understanding-malware-through-tri-grounded-agentic-reasoning","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/malaika-understanding-malware-through-tri-grounded-agentic-reasoning/82238/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What makes malware understanding harder than malware detection?","Question",{"text":75,"@type":76},"Detection often reduces outputs to a malicious/benign label, while understanding requires linking low-level program facts to high-level behavioral interpretations that can be audited by concrete evidence.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What are the three grounding mechanisms proposed in Malaika?",{"text":80,"@type":76},"Malaika relies on domain grounding to constrain hypothesis generation/evaluation, semantics grounding to localize and connect supporting program evidence, and knowledge grounding to enable behavioral attribution using externally verifiable threat knowledge.",{"name":82,"@type":73,"acceptedAnswer":83},"How does Malaika operationalize tri-grounded reasoning?",{"text":84,"@type":76},"It uses a tri-grounded multi-agent framework combining analyst-inspired reasoning, tool-mediated evidence localization, explicit review, and retrieval-based behavioral attribution.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":28,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]