AI 中文总结
针对二进制反混淆领域的局限,本文提出BinMirror方法,将二进制反混淆转化为行为规范引导的程序合成任务,在150万个合成混淆二进制文件上的评估显示其性能优于现有基线,单元测试Pass@1达74.5%。
AI 中文摘要
反混淆对于逆向工程和安全分析至关重要,因为它能恢复混淆代码的可读性和可分析性。然而,现有研究主要聚焦于源代码反混淆,尽管在源代码不可用时二进制级反混淆具有实际重要性,但该领域仍未得到充分探索。现有的二进制反混淆方法通常将二进制文件反编译为伪代码,再应用结构变换。但由于编译过程会丢失精确类型信息、源代码级结构等高级语义,这种基于反编译的范式往往生成低质量代码,且难以保证恢复的代码保留原始程序的运行时行为。为解决这些局限,我们提出从结构变换向行为驱动合成的范式转变。核心见解是,尽管混淆会扭曲程序内部结构,但保持语义的变换必须保留其可观测的执行行为。基于此,我们引入BinMirror,一种将二进制反混淆重新表述为行为规范引导的程序合成任务的方法。通过将动态执行轨迹和交互快照视为行为规范,BinMirror合成高质量源代码,并针对从高度混淆的二进制文件收集的运行时观测结果对其进行验证。对150万个合成混淆二进制文件的广泛评估表明,BinMirror显著优于最先进的基线方法,在极端混淆条件下达到单元测试Pass@1为74.5%。这些结果证明了BinMirror在为实际安全分析恢复语义清晰度方面的实用价值。
英文摘要
Deobfuscation is critical to reverse engineering and security analysis because it restores the readability and analyzability of obfuscated code. However, existing research primarily focuses on source-code deobfuscation, while binary-level deobfuscation remains largely underexplored despite its practical importance when source code is unavailable. Existing binary deobfuscation methods typically decompile binaries into pseudocode and then apply structural transformations. However, because compilation discards high-level semantics such as precise type information and source-level structures, this decompilation-based paradigm often produces low-quality code and provides limited assurance that the recovered code preserves the runtime behavior of the original program. To address these limitations, we propose a paradigm shift from structural transformation to behavior-driven synthesis. Our core insight is that although obfuscation distorts a program's internal structure, semantics-preserving transformations must retain its observable execution behavior. Based on this insight, we introduce BinMirror, an approach that reformulates binary deobfuscation as a behavior-specification-guided program synthesis task. By treating dynamic execution traces and interaction snapshots as behavioral specifications, BinMirror synthesizes high-quality source code and validates it against runtime observations collected from heavily obfuscated binaries. Extensive evaluations on 1.5 million synthetically obfuscated binaries show that BinMirror significantly outperforms state-of-the-art baselines, achieving a unit-test Pass@1 of 74.5% under extreme obfuscation. These results demonstrate the practical utility of BinMirror in restoring semantic clarity for real-world security analysis.