{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T19:44:02Z","timestamp":1782848642540,"version":"3.54.5"},"reference-count":61,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100004739","name":"Youth Innovation Promotion Association, CAS","doi-asserted-by":"crossref","award":["No.2023170"],"award-info":[{"award-number":["No.2023170"]}],"id":[{"id":"10.13039\/501100004739","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Code obfuscation is a process that complicates reverse engineering, protects intellectual property, and conceals malware. Existing deobfuscation approaches often lack generality or struggle with complex, mixed, or unknown transformations. To address this issue, this paper proposes LUCID, a Large Language Model (LLM) based Universal Control-flow Integrated Deobfuscation framework. We first formalizes the control-flow deobfuscation task and introduce the Topologically Feasible Path Set (TFPS) as a new evaluation metrics. Building upon this foundation, LUCID leverages an LLM to infer Predicate Mapping Rules between basic blocks in linear time, which then guide the precise expansion of the Runtime Feasible Path Set to identify and eliminate spurious control flows. Finally, semantically equivalent paths are merged to reconstruct a clean, compilable, and behaviorally faithful control-flow graph, from which security-analyst-friendly C-like pseudocode is generated. Comprehensive evaluation on 780 binaries employing 13 distinct obfuscation techniques demonstrates that our method reduces average cyclomatic complexity by 52.4%, achieves full deobfuscation in 53.8% of cases, and suppresses TFPS inflation caused by bogus control flow by over 99%. The framework demonstrates superiority over existing state-of-the-art tools in terms of both generality and semantic consistency, thus evidencing the transformative potential of LLMs in facilitating scalable malware reverse engineering.<\/jats:p>","DOI":"10.1145\/3808099","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:06:14Z","timestamp":1782839174000},"page":"2049-2071","source":"Crossref","is-referenced-by-count":0,"title":["Large Language Models for Opaque Predicate Resolution: A Universal Control Flow Deobfuscation Framework"],"prefix":"10.1145","volume":"3","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0007-7077-5943","authenticated-orcid":false,"given":"Xiao","family":"Chen","sequence":"first","affiliation":[{"name":"Institute of Information Engineering at Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-6101-9715","authenticated-orcid":false,"given":"Qiuyun","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering at Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0006-1471-9317","authenticated-orcid":false,"given":"Shuwei","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering at Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0009-3424-6272","authenticated-orcid":false,"given":"Weize","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering at Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-2740-9362","authenticated-orcid":false,"given":"Yuling","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering at Chinese Academy of Sciences, Beijing, China"},{"name":"University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-9973-0294","authenticated-orcid":false,"given":"Baoxu","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering at Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-0843-4482","authenticated-orcid":false,"given":"Zhengwei","family":"Jiang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering at Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","unstructured":"Jacob Austin Augustus Odena Maxwell Nye Maarten Bosma Henryk Michalewski David Dohan Ellen Jiang Carrie Cai Michael Terry Quoc Le et al. 2021. Program synthesis with large language models. arXiv preprint arXiv:2108.07732 (2021). doi:10.48550\/arXiv.2108.07732 10.48550\/arXiv.2108.07732","DOI":"10.48550\/arXiv.2108.07732"},{"key":"e_1_2_1_2_1","unstructured":"Avast. 2025. RetDec. GitHub repository. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/avast\/retdec Accessed: 2025-06-05."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991114"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-97620-9_15"},{"key":"e_1_2_1_5_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17). 643-659. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/ conference\/usenixsecurity17\/technical-sessions\/presentation\/blazytko","author":"Blazytko Tim","year":"2017","unstructured":"Tim Blazytko, Moritz Contag, Cornelius Aschermann, and Thorsten Holz. 2017. Syntia: Synthesizing the semantics of obfuscated code. In 26th USENIX Security Symposium (USENIX Security 17). 643-659. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/ conference\/usenixsecurity17\/technical-sessions\/presentation\/blazytko"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2025.108318"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3719027.3744871"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2107.03374"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-96-1624-4_12"},{"key":"e_1_2_1_10_1","unstructured":"Christian Collberg. 2023. Flatten. Online. https:\/\/2.zoppoz.workers.dev:443\/https\/tigress.wtf\/flatten.html Accessed: 2023-04-10."},{"key":"e_1_2_1_11_1","unstructured":"Christian Collberg Clark Thomborson and Douglas Low. 1997. A taxonomy of obfuscating transformations. https: \/\/researchspace.auckland.ac.nz\/bitstreams\/990cb7de-2b44-4a24-acee-82b0efa8e689\/download"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/268946.268962"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046739"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2020.23009"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3545258.3545269"},{"key":"e_1_2_1_16_1","unstructured":"Stephen Drape. 2010. Intellectual property protection using obfuscation. (2010). https:\/\/2.zoppoz.workers.dev:443\/https\/www.cs.ox.ac.uk\/people\/ stephen.drape\/papers\/siemens.pdf"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom50675.2020.00015"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.findings-emnlp.139"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2204.05999"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338503.3357721"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/947825.947829"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","unstructured":"Dan Hendrycks Steven Basart Saurav Kadavath Mantas Mazeika Akul Arora Ethan Guo Collin Burns Samir Puranik Horace He Dawn Song et al. 2021. Measuring coding challenge competence with apps. arXiv preprint arXiv:2105.09938 (2021). doi:10.48550\/arXiv.2105.09938 10.48550\/arXiv.2105.09938","DOI":"10.48550\/arXiv.2105.09938"},{"key":"e_1_2_1_23_1","volume-title":"Hikari: LLVM Obfuscator. GitHub repository (Archived). https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/HikariObfuscator\/ Hikari Accessed: 2023-10-26.","year":"2023","unstructured":"HikariObfuscator. 2023. Hikari: LLVM Obfuscator. GitHub repository (Archived). https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/HikariObfuscator\/ Hikari Accessed: 2023-10-26."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5121\/csit.2022.120409"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3703155"},{"key":"e_1_2_1_26_1","unstructured":"Anusthika Jeyashankar. 2022. Most Common Malware Obfuscation Techniques. https:\/\/2.zoppoz.workers.dev:443\/https\/www.socinvestigation.com\/ most-common-malware-obfuscation-techniques\/ Security Investigation."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1806799.1806833"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2507.17691"},{"key":"e_1_2_1_29_1","unstructured":"joydo. 2020. D810. GitHub repository. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/joydo\/d810 Accessed: 2025-06-05."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPRO.2015.10"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-Companion.2019.00135"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1809.11037"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3573834.3574541"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom60117.2023.00073"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-89500-0_28"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2507.22447"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2410.05797"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2102.04664"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.5281\/zenodo.13863694"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1976.233837"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485250"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i23.34672"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1510.07211"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2203.13474"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2024.124912"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3015135"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.23940\/ijpe.18.09.p27.21812188"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.203"},{"key":"e_1_2_1_49_1","unstructured":"TheAlgorithms. 2023. The Algorithms -C. GitHub repository. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/TheAlgorithms\/C Accessed: 2025-06-13."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2505.19887"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3371307.3371313"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338503.3357719"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3289239.3289243"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/WCRE.2005.13"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3418463"},{"key":"e_1_2_1_56_1","unstructured":"Chenxi Wang Jonathan Hill John Knight and Jack Davidson. 2000. Software tamper resistance: Obstructing static analysis of programs. Technical Report. Technical Report CS-2000-12 University of Virginia 12 2000. doi:10.18130\/V36T9V 10.18130\/V36T9V"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2954165"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.685"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3426020.3426089"},{"key":"e_1_2_1_60_1","unstructured":"za233. 2025. Polaris-Obfuscator. GitHub repository. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/za233\/Polaris-Obfuscator Accessed: 2025-06-05."},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3808099","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:49:41Z","timestamp":1782845381000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3808099"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":61,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3808099"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3808099","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]}}}