Skip to main navigation Skip to search Skip to main content

Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages

  • Wenbo Guo
  • , Shiwen Song
  • , Jiaxun Guo
  • , Zhengzi Xu*
  • , Chengwei Liu*
  • , Haoran Ou
  • , Mengmeng Ge
  • , Yang Liu
  • *Corresponding author for this work
  • Nanyang Technological University
  • Singapore Management University
  • Sichuan University
  • Imperial Global Singapore

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Open-source ecosystems such as NPM and PyPI are increasingly targeted by supply chain attacks, yet existing detection methods either depend on fragile handcrafted rules or data-driven features that fail to capture evolving attack semantics. We present IntelGuard, a retrieval-augmented generation (RAG) based framework that integrates expert analytical reasoning into automated malicious package detection. IntelGuard constructs a structured knowledge base from over 8,000 threat intelligence reports, linking malicious code snippets with behavioral descriptions and expert reasoning. When analyzing new packages, it retrieves semantically similar malicious examples and applies LLM-guided reasoning to assess whether code behaviors align with intended functionality. Experiments on 4,027 real-world packages show that IntelGuard achieves 99% accuracy and a 0.50% false positive rate, while maintaining 96.5% accuracy on obfuscated code. Deployed on PyPI.org, it discovered 54 previously unreported malicious packages, demonstrating interpretable and robust detection guided by expert knowledge.

Original languageEnglish
Title of host publicationWWW 2026 - Proceedings of the ACM Web Conference 2026
PublisherAssociation for Computing Machinery, Inc
Pages3554-3565
Number of pages12
ISBN (Electronic)9798400723070
DOIs
StatePublished - 12 Apr 2026
Externally publishedYes
Event35th ACM Web Conference, WWW 2026 - Dubai, United Arab Emirates
Duration: 29 Jun 20263 Jul 2026

Publication series

NameWWW 2026 - Proceedings of the ACM Web Conference 2026

Conference

Conference35th ACM Web Conference, WWW 2026
Country/TerritoryUnited Arab Emirates
CityDubai
Period29/06/263/07/26

Keywords

  • large language models
  • open-source ecosystems
  • retrieval-augmented generation
  • supply chain security
  • threat intelligence

Fingerprint

Dive into the research topics of 'Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages'. Together they form a unique fingerprint.

Cite this