PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
September 30, 20251 citationsOpen Access

Deconstructing Obfuscation: A four-dimensional framework for evaluating Large Language Models assembly code deobfuscation capabilities

View Full Paper
ATAnton TkachenkoDSDmitrij SuskevicBABenjamin Adolphi

Key Points

  • Performance varied significantly across seven models on assembly code deobfuscation, pointing to limitations.
  • Tests showed universal failure against combined obfuscation techniques, indicating challenges in sophisticated scenarios.
  • A proposed framework focuses on reasoning depth and noise filtering, explaining LLM performance discrepancies.
  • The study promotes a human-AI collaboration approach, highlighting the need for human intervention in complex deobfuscation tasks.

Abstract

Large language models (LLMs) have shown promise in software engineering, yet their effectiveness for binary analysis remains unexplored. We present the first comprehensive evaluation of commercial LLMs for assembly code deobfuscation. Testing seven state-of-the-art models against four obfuscation scenarios (bogus control flow, instruction substitution, control flow flattening, and their combination), we found striking performance variations--from autonomous deobfuscation to complete failure. We propose a theoretical framework based on four dimensions: Reasoning Depth, Pattern Recognition, Noise Filtering, and Context Integration, explaining these variations. Our analysis identifies five error patterns: predicate misinterpretation, structural mapping errors, control flow misinterpretation, arithmetic transformation errors, and constant propagation errors, revealing fundamental limitations in LLM code processing.We establish a three-tier resistance model: bogus control flow (low resistance), control flow flattening (moderate resistance), and instruction substitution/combined techniques (high resistance). Universal failure against combined techniques demonstrates that sophisticated obfuscation remains effective against advanced LLMs. Our findings suggest a human-AI collaboration paradigm where LLMs reduce expertise barriers for certain reverse engineering tasks while requiring human guidance for complex deobfuscation. This work provides a foundation for evaluating emerging capabilities and developing resistant obfuscation techniques.x deobfuscation. This work provides a foundation for evaluating emerging capabilities and developing resistant obfuscation techniques.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Tkachenko et al. (2025) studied this question.

synapsesocial.com/papers/68dc12c58a7d58c25ebb0938https://doi.org/10.48550/arxiv.2505.19887
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Evaluation of Large Language Models on Code Obfuscation (Student Abstract)2024 · 1 citations
  2. 2Large Language Models for Opaque Predicate Resolution: A Universal Control Flow Deobfuscation Framework2026
  3. 3Disassembling Obfuscated Executables with LLM2024
  4. 4Assessing LLMs in Malicious Code Deobfuscation of Real-world Malware Campaigns2024
  5. 5Assessing LLMs in malicious code deobfuscation of real-world malware campaigns2024 · 66 citations