Deconstructing Obfuscation: A four-dimensional framework for evaluating Large Language Models assembly code deobfuscation capabilities

📅 2025-05-26
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This paper presents the first systematic evaluation of commercial large language models (LLMs) on assembly code deobfuscation. Addressing four prevalent obfuscation techniques—control-flow flattening, bogus control flow, instruction substitution, and their combinations—the authors propose a four-dimensional theoretical framework (reasoning depth, pattern recognition, noise filtering, and contextual integration) and develop a three-tier obfuscation resistance model. Through prompt engineering and semantic modeling, they conduct empirical analysis across diverse obfuscation scenarios. Results show that LLMs autonomously handle low-resistance obfuscations (e.g., bogus control flow) but completely fail on composite obfuscations. The study identifies five canonical error patterns, exposing fundamental limitations in deep semantic comprehension and structural recovery. Collectively, this work provides both theoretical characterization and empirical evidence delineating the applicability boundaries of LLMs in reverse engineering tasks.

Technology Category

Machine Learning: Large Multimodal Models (LMMs)Natural Language Processing: (Large) Language ModelsSearch and Optimization: Learning to Search

Application Category

Economics, Online Markets and Human Computation: Cost models of using LLMs in production systemsSemantics and Knowledge: Data modeling to support human-machine intelligence, including LLMs agents, intelligent system behavior, explanations, and user-friendly interactionsUser Modeling, Personalization and Recommendation: Large Language Models (LLM) for user modeling and recommendation
📝 Abstract
Large language models (LLMs) have shown promise in software engineering, yet their effectiveness for binary analysis remains unexplored. We present the first comprehensive evaluation of commercial LLMs for assembly code deobfuscation. Testing seven state-of-the-art models against four obfuscation scenarios (bogus control flow, instruction substitution, control flow flattening, and their combination), we found striking performance variations--from autonomous deobfuscation to complete failure. We propose a theoretical framework based on four dimensions: Reasoning Depth, Pattern Recognition, Noise Filtering, and Context Integration, explaining these variations. Our analysis identifies five error patterns: predicate misinterpretation, structural mapping errors, control flow misinterpretation, arithmetic transformation errors, and constant propagation errors, revealing fundamental limitations in LLM code processing.We establish a three-tier resistance model: bogus control flow (low resistance), control flow flattening (moderate resistance), and instruction substitution/combined techniques (high resistance). Universal failure against combined techniques demonstrates that sophisticated obfuscation remains effective against advanced LLMs. Our findings suggest a human-AI collaboration paradigm where LLMs reduce expertise barriers for certain reverse engineering tasks while requiring human guidance for complex deobfuscation. This work provides a foundation for evaluating emerging capabilities and developing resistant obfuscation techniques.x deobfuscation. This work provides a foundation for evaluating emerging capabilities and developing resistant obfuscation techniques.
Problem

Research questions and friction points this paper is trying to address.

Evaluating LLMs' ability to deobfuscate assembly code
Identifying performance variations across obfuscation scenarios
Proposing a framework to explain LLM deobfuscation limitations
Innovation

Methods, ideas, or system contributions that make the work stand out.

Four-dimensional framework for LLM evaluation
Testing seven models on obfuscation scenarios
Human-AI collaboration for reverse engineering
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Promon AS
B
Benjamin Adolphi
Research department, Promon AS