GView: A Survey of Binary Forensics via Visual, Semantic, and AI-Enhanced Analysis

📅 2025-09-16
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Modern cybersecurity threats and the proliferation of heterogeneous binary artifacts challenge existing digital forensics approaches in interpretability, scalability, and human–machine collaboration efficiency. Method: This paper introduces an open-source binary forensics framework that integrates multi-granularity visualization, semantic modeling, large language model (LLM)-driven dynamic reasoning, and a predicate logic rule engine to establish a scalable, multi-tiered analytical architecture. Crucially, it proposes an LLM-augmented neuro-symbolic reasoning mechanism—uniquely combining symbolic logic with neural inference—to generate interpretable, semantically grounded recommendations regarding document content and user behavior. Contribution/Results: The framework bridges industrial practice and academic research, empirically demonstrating significant improvements in forensic workflow efficiency. It has already enabled multiple high-impact publications and supports ongoing research, including several manuscripts under preparation.

Technology Category

Computer Vision: Visual Reasoning & Symbolic RepresentationsMachine Learning: Neuro-Symbolic LearningCognitive Modeling & Cognitive Systems: Symbolic Representations

Application Category

Security and Privacy: Cyber-crime defenses and forensicsUser Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systemsWeb Mining and Content Analysis: Large pretrained models with web data
📝 Abstract
Cybersecurity threats continue to become more sophisticated and diverse in their artifacts, boosting both their volume and complexity. To overcome those challenges, we present GView, an open-source forensic analysis framework with visual and AI-enhanced reasoning. It started with focus on the practical cybersecurity industry. It has evolved significantly, incorporating large language models (LLMs) to dynamically enhance reasoning and ease the forensic workflows. This paper surveys both the current state of GView with its published papers alongside those that are in the publishing process. It also includes its innovative use of logical inference through predicates and inference rules for both the analyzed documents and the user's actions for better suggestions. We highlight the extensible architecture, showcasing its potential as a bridge between the practical forensics worlds with the academic research.
Problem

Research questions and friction points this paper is trying to address.

Analyzing complex cybersecurity threats with AI-enhanced forensic tools
Enhancing binary forensics through visual and semantic analysis techniques
Integrating LLMs for dynamic reasoning in cybersecurity workflows
Innovation

Methods, ideas, or system contributions that make the work stand out.

Visual and AI-enhanced forensic analysis framework
Incorporates large language models for reasoning
Uses logical inference with predicates and rules
🔎 Similar Papers
2024-03-27ACM Transactions on Software Engineering and MethodologyCitations: 2
💼 Related Jobs
No related jobs found.
Raul Zaharia
Raul Zaharia
Al. I. Cuza University, Bitdefender
Computer securityMalwareCompilers
D
Dragoş Gavriluţ
Al. I. Cuza University & Bitdefender, Iasi, Romania
G
Gheorghiţă Mutu
Al. I. Cuza University & Bitdefender, Iasi, Romania