arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.27058cs.SE

阶段监督的潜在推理用于单次JavaScript反混淆

Stage-Supervised Latent Reasoning for Single-Shot JavaScript Deobfuscation

  • The Pennsylvania State University(宾夕法尼亚州立大学)

机构由 AI 辅助整理,请以论文原文为准。

Rong Feng, Suman Saha

AI总结:

针对现有LLM反混淆方法忽略阶段结构的问题,提出阶段感知潜在推理框架,利用Coconut训练从多阶段重写学习,推理时单次生成,在JsDeObsBench上语法有效性达50%,语义正确性达80%。

AI中文摘要:

JavaScript混淆被广泛用于保护代码,但它也使程序分析和安全审查变得相当困难。现有的基于LLM的反混淆方法通常将任务视为一步翻译,忽略了实际反混淆流水线的阶段结构。这篇WIP论文提出了一个阶段感知的潜在推理框架,将确定性反混淆工具的中间输出转换为基于Coconut的训练监督。模型在训练期间从多阶段重写中学习,但在推理时以单次生成最终清理后的程序。在JsDeObsBench上的初步结果显示,基于Coconut的模型将语法有效性提高到50%,而直接微调为15%,零样本基线为25%,并且在有效输出中达到80%的语义正确性,表明在反混淆中比两个比较模型具有更好的语义保真度。

英文摘要:

JavaScript obfuscation is widely used to protect code, but it also makes program analysis and security review substantially harder. Existing LLM-based deobfuscation methods usually treat the task as one-step translation, ignoring the staged structure of practical deobfuscation pipelines. This WIP paper proposes a stage-aware latent reasoning framework that converts intermediate outputs from a deterministic deobfuscation tool into supervision for Coconut-based training. The model learns from multi-stage rewrites during training but generates the final cleaned program in a single shot at inference time. Preliminary results on JsDeObsBench show that the Coconut-based model improves syntactic validity to 50%, compared with 15% for direct fine-tuning and 25% for a zero-shot baseline, and reaches 80% semantic correctness among valid outputs, indicating better semantic faithfulness than either comparison model in deobfuscation.

↑