Skip to content
Preprint

Behavior Specification-Guided Program Synthesis for Binary Deobfuscation

Aug 2026 · 0 citations · 67 references
Computer Science

TL;DR

BinMirror is introduced, an approach that reformulates binary deobfuscation as a behavior-specification-guided program synthesis task that synthesizes high-quality source code and validates it against runtime observations collected from heavily obfuscated binaries.

Abstract

Deobfuscation is critical to reverse engineering and security analysis because it restores the readability and analyzability of obfuscated code. However, existing research primarily focuses on source-code deobfuscation, while binary-level deobfuscation remains largely underexplored despite its practical importance when source code is unavailable. Existing binary deobfuscation methods typically decompile binaries into pseudocode and then apply structural transformations. However, because compilation discards high-level semantics such as precise type information and source-level structures, this decompilation-based paradigm often produces low-quality code and provides limited assurance that the recovered code preserves the runtime behavior of the original program. To address these limitations, we propose a paradigm shift from structural transformation to behavior-driven synthesis. Our core insight is that although obfuscation distorts a program's internal structure, semantics-preserving transformations must retain its observable execution behavior. Based on this insight, we introduce BinMirror, an approach that reformulates binary deobfuscation as a behavior-specification-guided program synthesis task. By treating dynamic execution traces and interaction snapshots as behavioral specifications, BinMirror synthesizes high-quality source code and validates it against runtime observations collected from heavily obfuscated binaries. Extensive evaluations on 1.5 million synthetically obfuscated binaries show that BinMirror significantly outperforms state-of-the-art baselines, achieving a unit-test Pass@1 of 74.5% under extreme obfuscation. These results demonstrate the practical utility of BinMirror in restoring semantic clarity for real-world security analysis.

View source

Similar papers

Open access 2026

A Systematic LLM-Based Procedure for the Deobfuscation of WebAssembly: Benchmark and Security Evaluation

This paper investigates the capability of large language models (LLMs) to perform automated Wasm deobfuscation and introduces a three-tier evaluation hierarchy for assessing deobfuscation quality, consisting of syntax correctness, execution validity, and semantic similarity.

Sebeom Cheon, Jin-Ho Jung, Sangkyun Lee · 0 citations
Preprint Aug 2026

Decoupling is a Necessity: Transformation-Agnostic Decompiled Code Recovery under Optimization and Obfuscation

Reverse engineering is essential for software security analysis and vulnerability detection. Decompilation, the process of lifting binaries to high-level pseudocode, is central to this task. However, production binaries are hostile environments: aggressive compiler optimizations and adversarial obfuscation jointly mang...

Zhi-Ping Zhou, Xiaohong Li, Ruitao Feng et al. · 0 citations
Preprint Aug 2026

CHISEL-ing Back Source Code with AI-enabled Iterative Recovery

This work presents CHISEL, a test suite-free framework to iteratively recover source code from Ghidra-derived pseudo-C, and systematically evaluates CHISEL for compilation and semantic recovery, feedback oracle soundness, and iteration overhead on 120 ExeBench functions compiled for the x86-64 architecture.

Varun Kohli, N. Raghava, B. Sikdar et al. · 1 citation
Open access Oct 2026

ReFun: Reconstructing Function Boundaries in EVM Bytecode

Recovering the structure of a Solidity smart contract from its deployed bytecode is a prerequisite for various downstream analyses, such as control-flow graph construction, decompilation, and clone detection. A central step in this task is identifying private functions. However, since all source-level function boundari...

Yi-Chuan Li, Wei Song, Jeff Huang et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.