Selective AI Augmentation for Scalable and Cost-Efficient Malware Triage - Cybersecurity Conference

Selective AI Augmentation for Scalable and Cost-Efficient Malware Triage

Modern anti-malware systems generate large volumes of static analysis artifacts, yet the classification of unknown or borderline samples remains a persistent challenge that relies heavily on human analysts. This paper presents a practical framework for integrating lightweight AI models into malware triage pipelines, emphasizing data minimization, selective processing, and cost-efficiency.

Rather than submitting complete files or full analysis reports to AI systems, the proposed approach extracts high-value indicators—such as structural metadata, behavioral signals, and suspicious features—from diverse file types including scripts, document formats, and executables. These features are normalized into a structured representation and selectively provided to AI models to produce explainable risk assessments and confidence-based decisions.

A key contribution of this work is demonstrating that targeted AI usage on uncertain samples can significantly reduce computational cost while maintaining meaningful detection performance. By restricting AI invocation to samples within an ambiguous classification range, the framework avoids unnecessary processing and enables scalable deployment across high-volume environments.

The paper further discusses the integration of AI outputs into existing decision-making workflows through normalized schemas and structured outputs, enabling downstream automation such as rule-based enforcement and threat intelligence mapping. Experimental evaluation across multiple file types highlights the trade-offs between model size, cost, and detection effectiveness, showing that compact models can deliver competitive triage outcomes when combined with intelligent feature selection.

This work demonstrates that selective and controlled AI augmentation, rather than full-scale adoption, provides a viable path toward scalable, explainable, and privacy-aware malware analysis. The approach is particularly suited to modern antivirus and threat detection systems seeking to optimize analyst workload, reduce operational costs, and maintain strict data handling constraints.

Tonmoy Jitu – Sophos

Tonmoy Jitu is a cybersecurity researcher and malware analyst with a background spanning frontline incident response and advanced threat research. Their career began in incident response, investigating active compromises and helping organizations contain large-scale intrusions. That hands-on experience now informs their work at Sophos, where they dissect malware, reverse engineer suspicious binaries, and investigate elusive threats that often sit below the industry’s radar.

Tonmoy is particularly drawn to the grey areas of malware analysis: samples with weak reputation signals, inconsistent detections, or behaviours that only reveal their purpose through deep technical investigation. Their research focuses on understanding how threats propagate, evade detection, and leave behind artifacts that stand up to rigorous scrutiny. Beyond their day-to-day work, Tonmoy regularly writes about emerging malware, unconventional attack techniques, and lesser-known campaigns, helping shine a light on threats that rarely make headlines but often matter most.

Rowland Yu – Sophos

Rowland Yu is a Senior Threat Researcher at SophosLabs, the threat intelligence and security research division of Sophos. Working within the Reputation Services team, he focuses on malware analysis, threat intelligence, detection engineering, and AI-assisted security operations. His recent work explores selective AI augmentation for malware triage, combining structured threat intelligence, analyst expertise, and lightweight AI models to improve detection efficiency while reducing operational cost. He is particularly interested in scalable, explainable, and privacy-aware approaches to modern malware detection and analysis.