{"id":"W7126218964","doi":"10.1109/raid67961.2025.00047","title":"Evaluating LLM-Based Detection of Malicious Package Updates in npm","year":2025,"lang":"","type":"article","venue":"","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Calgary","funders":"","keywords":"Flagging; Malware; Exploit; Software; Task (project management); Code (set theory); Preprocessor; Key (lock); Cryptovirology","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"codex-gemma-dda1882f352a","candidate_categories":["metaepi_narrow"],"consensus_categories":[],"category_scores_codex":[0.001405439,0.0003485981,0.0004932922,0.001191252,0.0001604632,0.0001109189,0.0008409888,0.0002543968,0.00009162795],"category_scores_gemma":[0.0006481579,0.0003814759,0.0001620691,0.003057022,0.0001561706,0.0006078671,0.0003983484,0.0004359422,0.00001730499],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0003459656,"about_ca_system_score_gemma":0.0003309967,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0003885995,"about_ca_topic_score_gemma":0.0003871726,"domain_scores_codex":[0.9965778,0.0004031723,0.001136162,0.0008873129,0.0004874478,0.0005080922],"domain_scores_gemma":[0.9975141,0.0004184531,0.0004362415,0.001131398,0.0004312866,0.00006852089],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.0000879842,0.0003086309,0.0005160469,0.0002257826,0.0000195885,0.000008908308,0.0001910511,0.003766129,0.2561337,0.003286987,0.00003134678,0.7354239],"study_design_scores_gemma":[0.0005607401,0.0005678181,0.0009522501,0.0002384183,0.00001335437,0.000002323942,0.00005352136,0.3326124,0.6565011,0.008143762,0.0001421978,0.0002121827],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.07533108,0.0003989877,0.9205438,0.000348796,0.0006598528,0.0007619667,0.000003668707,0.0004916298,0.001460158],"genre_scores_gemma":[0.8820399,0.00003952253,0.1168967,0.0004287796,0.0000207616,0.00008991749,0.000001159902,0.00001688156,0.0004663655],"genre_candidate":"methods","genre_consensus":null,"teacher_disagreement_score":0.8067089,"threshold_uncertainty_score":0.9998637,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.0246453377315002,"score_gpt":0.3530087305352491,"score_spread":0.3283633928037489,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}