发表机构
Ludwig-Maximilians-Universität München; Munich Center for Machine Learning; Center for Digital Technology and Management(慕尼黑大学; 慕尼黑机器学习中心; 数字技术与管理中心)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究探究调用图对二进制分析任务的影响,发现结合过程间上下文可提升嵌入鲁棒性但未必泛化到下游任务,且对命名空间相关函数更有益。
AI 中文摘要
二进制函数嵌入模型被训练为对二进制代码的语义进行编码,使其可泛化到各类逆向工程任务,例如二进制代码搜索、漏洞检测或恶意软件分类。尽管许多模型仅将目标函数作为上下文输入,但已有成功尝试通过利用调用图的信息来改进函数嵌入。本研究剖析了这些嵌入优化的影响。我们在两种最先进的二进制函数嵌入模型生成的嵌入上,使用一系列基于图的模型开展实验。结合过程间上下文后,我们发现二进制代码相似度检测(BCSD)的改进不一定能泛化到下游任务,无论是语义还是句法性质的任务。更普遍地说,我们发现针对语义相似度任务的优化与句法任务上更差的性能相关。通过对数据集进行解释性分析,我们发现基于调用图的增强显著提升了嵌入的鲁棒性,尤其在初始模型表现不佳的场景中。此外,我们观察到,添加的上下文对与命名空间相关的函数比专注于单个逻辑的函数更有益,这证实调用图可在依赖上下文的场景中得到最有效的利用。
英文摘要
Binary function embedding models are trained to encode the semantics of binary code in such a way that they can be generalized to a variety of reverse engineering tasks, such as binary code search, vulnerability detection, or malware classification. While many models only take the function in question as contextual input, there have been successful attempts to improve function embeddings by leveraging information from the call graph. In this study, we dissect the implications of these embedding refinements. We conduct experiments using a range of graph-based models on the embeddings generated by two state-of-the-art binary function embedding models. Integrating inter-procedural context, we show that improvements on binary code similarity detection (BCSD) will not necessarily generalize to downstream tasks, neither of semantic nor of syntactic nature. More generally, we find that optimizing for semantic similarity tasks correlates with worse performance on syntactic tasks. By conducting an explanatory analysis on the dataset, we find that the call graph-based enhancements significantly enhance the robustness of embeddings, particularly in scenarios where the initial models struggle. Furthermore, we observe that the added context is more beneficial for namespace-related functions than for those focused on individual logic, confirming that the call graph can be leveraged most effectively in context-dependent scenarios.
Comments12 pages, 5 figures. Accepted at ICPC '26
Journal refProceedings of the 34th IEEE/ACM International Conference on Program Comprehension, pp. 14-25, 2026