arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

当二进制文件进行反击:对大语言模型辅助逆向工程的表示混淆攻击

When Binaries Talk Back: Representation-Confusion Attacks on LLM-Assisted Reverse Engineering

Igor Santos-Grueiro

arXiv 2607.12507首次发表:更新:

AI 中文总结

研究大语言模型辅助逆向工程中的表示混淆攻击,通过RARE-Bench衡量,测试RARE-Guard控制,发现无运行时控制时模型有不安全提议,工具授权、支持门和来源门在处理虚假声明上表现不同,二进制派生内容可指导分析且多工具视图不一定提供独立证据。

AI 中文摘要

大语言模型辅助逆向工程(RE)系统分析来自攻击者控制的二进制文件的字符串、反编译器输出和工具报告。二进制文件可能使数据看起来像指令,或使来自一个来源的记录看起来像独立证据。我们将这种失败称为逆向工程中的表示混淆攻击(RARE)。RARE-Bench使用行为检查的干净和对抗性二进制文件来衡量这些失败。经过探索性的11520次调用研究后,我们在20个新程序和两个模型上测试了RARE-Guard的授权和证据控制。没有运行时控制时,模型在35/40个对抗性案例中提出植入的不安全操作,在40个干净案例中为0。当二进制派生内容仅作为数据显示时,它们仍提出15个不安全提议。工具授权拒绝所有15个提议并授权所有40个匹配的分析师请求。在相同报告草稿上,支持门通过分别计算来自一个来源的记录来验证23/40个虚假声明。来源门在计算支持之前对这些记录进行分组,验证0/40个虚假声明并保留所有40个支持的声明。然后我们在16个程序上对Ghidra、r2pipe和angr进行检测。在预选的8个程序子集中,没有单个工具草稿达到支持门对虚假声明的验证阈值。在所有16个程序的融合草稿中,支持门验证32/32个虚假声明。来源门阻止所有32个声明的验证并保留所有32个支持的声明。确定性渲染器可防止降级声明在最终报告中再次出现。因此,二进制派生内容可指导分析而无需获得对工具的控制权,并且来自多个工具的视图不一定提供独立证据。

英文摘要

LLM-assisted reverse-engineering (RE) systems analyze strings, decompiler output, and tool reports derived from ttacker-controlled binaries. A binary can make data look like instructions or records from one origin look like independent evidence. We call such failures Representation-Confusion Attacks in Reverse Engineering (RARE): the pipeline promotes a correctly extracted observation to instruction authority, claim-validating evidence, or trusted analysis state without the authority or support that role requires. RARE-Bench measures these failures with behavior-checked clean and adversarial binaries. After an exploratory 11,520-call study, we test RARE-Guard's authorization and evidence controls on 20 new programs and two models. Without runtime controls, the models propose a planted unsafe action in 35/40 adversarial cases and 0/40 clean cases. When binary-derived content is shown only as data (Data-Only rendering), they still make 15 unsafe proposals. Tool Authorization denies all 15 and authorizes all 40 matched analyst requests. On identical report drafts, Support Gate validates 23/40 false claims by counting records from one origin separately. Provenance Gate groups those records before counting support, validates 0/40 false claims, and retains all 40 supported claims. We then instrument Ghidra, r2pipe, and angr on 16 further programs. In a preselected eight-program subset, no single-tool draft reaches Support Gate's validation threshold for the false claim. In fused drafts across all 16 programs, Support Gate validates 32/32 false claims. Provenance Gate prevents validation of all 32 and retains all 32 supported claims. A deterministic renderer prevents downgraded claims from reappearing in the final report. Binary-derived content may therefore guide analysis without gaining authority over tools, and views from several tools do not necessarily provide independent evidence.

Comments20 pages

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑