BinMirror is introduced, an approach that reformulates binary deobfuscation as a behavior-specification-guided program synthesis task that synthesizes high-quality source code and validates it against runtime observations collected from heavily obfuscated binaries.
Abstract
Deobfuscation is critical to reverse engineering and security analysis because it restores the readability and analyzability of obfuscated code. However, existing research primarily focuses on source-code deobfuscation, while binary-level deobfuscation remains largely underexplored despite its practical importance when source code is unavailable. Existing binary deobfuscation methods typically decompile binaries into pseudocode and then apply structural transformations. However, because compilation discards high-level semantics such as precise type information and source-level structures, this decompilation-based paradigm often produces low-quality code and provides limited assurance that the recovered code preserves the runtime behavior of the original program. To address these limitations, we propose a paradigm shift from structural transformation to behavior-driven synthesis. Our core insight is that although obfuscation distorts a program's internal structure, semantics-preserving transformations must retain its observable execution behavior. Based on this insight, we introduce BinMirror, an approach that reformulates binary deobfuscation as a behavior-specification-guided program synthesis task. By treating dynamic execution traces and interaction snapshots as behavioral specifications, BinMirror synthesizes high-quality source code and validates it against runtime observations collected from heavily obfuscated binaries. Extensive evaluations on 1.5 million synthetically obfuscated binaries show that BinMirror significantly outperforms state-of-the-art baselines, achieving a unit-test Pass@1 of 74.5% under extreme obfuscation. These results demonstrate the practical utility of BinMirror in restoring semantic clarity for real-world security analysis.
This paper investigates the capability of large language models (LLMs) to perform automated Wasm deobfuscation and introduces a three-tier evaluation hierarchy for assessing deobfuscation quality, consisting of syntax correctness, execution validity, and semantic similarity.
Reverse engineering is essential for software security analysis and vulnerability detection. Decompilation, the process of lifting binaries to high-level pseudocode, is central to this task. However, production binaries are hostile environments: aggressive compiler optimizations and adversarial obfuscation jointly mang...
Zhi-Ping Zhou, Xiaohong Li, Ruitao Feng et al.· 0 citations
The results show that point accuracy alone is insufficient for characterizing LLM reliability in assertion generation and motivate robustness-aware evaluation for AI-assisted hardware verification.
Results confirm that permutation-based MBA obfuscation offers a practical, composite, and resilient defense against symbolic execution, balancing strong protection with lightweight performance overhead.
Mo-Xuan Wang, Hai-Yan Hu, Hao-Hang Qin et al.· Journal of computing and sec...· 0 citations
This work presents CHISEL, a test suite-free framework to iteratively recover source code from Ghidra-derived pseudo-C, and systematically evaluates CHISEL for compilation and semantic recovery, feedback oracle soundness, and iteration overhead on 120 ExeBench functions compiled for the x86-64 architecture.
Varun Kohli, N. Raghava, B. Sikdar et al.· 1 citation
Recovering the structure of a Solidity smart contract from its deployed bytecode is a prerequisite for various downstream analyses, such as control-flow graph construction, decompilation, and clone detection. A central step in this task is identifying private functions. However, since all source-level function boundari...
Yi-Chuan Li, Wei Song, Jeff Huang et al.· Proceedings of the ACM on Pr...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.