Syntia / MBA-Blast 这条路 [15][17]:表达式级化简极强,但不管 VM 结构、不管上下文工程。本框架把它们的技术收编为"压缩层的提议通道",产出统一过 Z3。
纯 LLM 反混淆这条路 [25]:DIMVA'25 的实测表明微调后的小模型在源码级混淆(Tigress)上确实能取得不错的化简效果——但它做的是 C 源码级,不管二进制、不管 VM 结构,且产出没有求解器背书,对了错了没人判。本框架补的正是"机器生成的真值 IR"和"求解器判定"这两根柱子,同时把免微调的通用大模型当作提议器来用。
VTIL [26]:开源界的 VMP 去虚拟化实现,本框架的 IR 设计大量参考它,值得 star。
参考文献
[1] Collberg C, Thomborson C, Low D. A Taxonomy of Obfuscating Transformations. 1997. [2] Collberg C, Nagra J. Surreptitious Software: Obfuscation, Watermarking, and Tamperproofing for Software Protection. Addison-Wesley, 2009. [3] Coogan K, Lu G, Debray S. Deobfuscation of Virtualization-Obfuscated Software: A Semantics-Based Approach. ACM CCS, 2011. [4] Kinder J. Towards Static Analysis of Virtualization-Obfuscated Binaries. WCRE, 2012. [5] Yadegari B, Johannesmeyer B, Whitely B, Debray S. A Generic Approach to Automatic Deobfuscation of Executable Code. IEEE S&P, 2015. [6] Yadegari B, Debray S. Symbolic Execution of Obfuscated Code. ACM CCS, 2015. [7] Xu D, Ming J, Fu Y, Wu D. VMHunt: A Verifiable Approach to Partially-Virtualized Binary Code Simplification. ACM CCS, 2018. [8] Salwan J, Bardin S, Potet M-L. Symbolic Deobfuscation: From Virtualized Code Back to the Original. DIMVA, 2018.(配套工具 Triton,SSTIC 2015) [9] Kochberger P, Schrittwieser S, Schweighofer S, Kieseberg P, Weippl E. SoK: Automatic Deobfuscation of Virtualization-Protected Applications. ARES, 2021. [10] Cadar C, Dunbar D, Engler D. KLEE: Unassisted and Automatic Generation of High-Coverage Tests for Complex Systems Programs. OSDI, 2008. [11] Baldoni R, Coppa E, D'Elia D C, Demetrescu C, Finocchi I. A Survey of Symbolic Execution Techniques. ACM Computing Surveys, 2018. [12] de Moura L, Bjørner N. Z3: An Efficient SMT Solver. TACAS, 2008. [13] Eyrolles N, Goubin L, Videau M. Defeating MBA-Based Obfuscation. ACM SPRO, 2016. [14] Eyrolles N. Obfuscation with Mixed Boolean-Arithmetic Expressions: Reconstruction, Analysis and Simplification Tools. PhD Thesis, Université Paris-Saclay, 2017. [15] Blazytko T, Contag M, Aschermann C, Holz T. Syntia: Synthesizing the Semantics of Obfuscated Code. USENIX Security, 2017. [16] David R, Coniglio L, Ceccato M. QSynth: A Program Synthesis Based Approach for Binary Code Deobfuscation. BAR Workshop (NDSS), 2020. [17] Liu B, Shen J, Ming J, Zheng Q, Li J, Xu D. MBA-Blast: Unveiling and Simplifying Mixed Boolean-Arithmetic Obfuscation. USENIX Security, 2021. [18] Xu D, Liu B, Feng W, Ming J, Zheng Q, Li J, Yu Q. Boosting SMT Solver Performance on Mixed-Bitwise-Arithmetic Expressions. PLDI, 2021. [19] Schkufza E, Sharma R, Aiken A. Stochastic Superoptimization. ASPLOS, 2013. [20] Sasnauskas R, Chen Y, Collingbourne P, et al. Souper: A Synthesizing Superoptimizer. 2017. [21] Banescu S, Collberg C, Ganesh V, Newsham Z, Pretschner A. Code Obfuscation Against Symbolic Execution Attacks. ACSAC, 2016. [22] Schloegel M, Blazytko T, Contag M, et al. Loki: Hardening Code Obfuscation Against Automated Attacks. USENIX Security, 2022. [23] Feng W, Liu B, Xu D, Zheng Q, Xu Y. NeuReduce: Reducing Mixed Boolean-Arithmetic Expressions by Recurrent Neural Network. EMNLP (Findings), 2020. [24] Lachaux M-A, Rozière B, Szafraniec M, Lample G. DOBF: A Deobfuscation Pre-Training Objective for Programming Languages. NeurIPS, 2021. [25] Beste D, Menguy G, Hajipour H, et al. Exploring the Potential of LLMs for Code Deobfuscation. DIMVA, 2025. [26] can1357. VTIL: Virtual-machine Translation Intermediate Language. GitHub 开源项目.