Can LLMs Deobfuscate Binary Code? A Systematic Analysis of Large Language Models into Pseudocode Deobfuscation

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Hu, Li, Shang, Xiuwei, Shi, Jieke, Cheng, Shaoyin, Zhang, Junqi, Li, Gangyang, Yang, Zhou, Zhang, Weiming, Lo, David
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866911578416218112
author Hu, Li
Shang, Xiuwei
Shi, Jieke
Cheng, Shaoyin
Zhang, Junqi
Li, Gangyang
Yang, Zhou
Zhang, Weiming
Lo, David
author_facet Hu, Li
Shang, Xiuwei
Shi, Jieke
Cheng, Shaoyin
Zhang, Junqi
Li, Gangyang
Yang, Zhou
Zhang, Weiming
Lo, David
contents Deobfuscating binary code remains a fundamental challenge in reverse engineering, as obfuscation is widely used to hinder analysis and conceal program logic. Although large language models (LLMs) have shown promise in recovering semantics from obfuscated binaries, a systematic evaluation of their effectiveness is still lacking. In this work, we present BinDeObfBench, the first comprehensive benchmark for assessing LLM-based binary deobfuscation across diverse transformations spanning pre-compilation, compile-time, and post-compilation stages. Our evaluation shows that deobfuscation performance depends more on reasoning capability and domain expertise than on model scale, and that task-specific supervised fine-tuning consistently outperforms broad domain pre-training. Reasoning models can maintain robustness under severe obfuscation, generalize across different instruction set architectures (ISAs) and optimization levels. In-context learning benefits standard models but yields limited gains for reasoning models. Overall, our study highlights the importance of task-specific fine-tuning and reasoning-driven strategies, and positions BinDeObfBench as a basis for future work in binary deobfuscation.
format Preprint
id arxiv_https___arxiv_org_abs_2604_08083
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Can LLMs Deobfuscate Binary Code? A Systematic Analysis of Large Language Models into Pseudocode Deobfuscation
Hu, Li
Shang, Xiuwei
Shi, Jieke
Cheng, Shaoyin
Zhang, Junqi
Li, Gangyang
Yang, Zhou
Zhang, Weiming
Lo, David
Software Engineering
Deobfuscating binary code remains a fundamental challenge in reverse engineering, as obfuscation is widely used to hinder analysis and conceal program logic. Although large language models (LLMs) have shown promise in recovering semantics from obfuscated binaries, a systematic evaluation of their effectiveness is still lacking. In this work, we present BinDeObfBench, the first comprehensive benchmark for assessing LLM-based binary deobfuscation across diverse transformations spanning pre-compilation, compile-time, and post-compilation stages. Our evaluation shows that deobfuscation performance depends more on reasoning capability and domain expertise than on model scale, and that task-specific supervised fine-tuning consistently outperforms broad domain pre-training. Reasoning models can maintain robustness under severe obfuscation, generalize across different instruction set architectures (ISAs) and optimization levels. In-context learning benefits standard models but yields limited gains for reasoning models. Overall, our study highlights the importance of task-specific fine-tuning and reasoning-driven strategies, and positions BinDeObfBench as a basis for future work in binary deobfuscation.
title Can LLMs Deobfuscate Binary Code? A Systematic Analysis of Large Language Models into Pseudocode Deobfuscation
topic Software Engineering
url https://arxiv.org/abs/2604.08083