Pyfet: Forensically Equivalent Transformation for Python Binary Decompilation
Ali Ahad, Chijung Jung, Ammar Askar, Doowon Kim, Taesoo Kim, Yonghwi Kwon
Abstract
Decompilation is a crucial capability in forensic analysis, facilitating analysis of unknown binaries. The recent rise of Python malware has brought attention to Python decompilers that aim to obtain source code representation from a Python binary. However, Python decompilers fail to handle various binaries, limiting their capabilities in forensic analysis.This paper proposes a novel solution that transforms a decompilation error-inducing Python binary into a decompilable binary. Our key intuition is that we can resolve the decompilation errors by transforming error-inducing code blocks in the input binary into another form. The core of our approach is the concept of Forensically Equivalent Transformation (FET) which allows non-semantic preserving transformation in the context of forensic analysis. We carefully define the FETs to minimize their undesirable consequences while fixing various error-inducing instructions that are difficult to solve when preserving the exact semantics. We evaluate the prototype of our approach with 17,117 real-world Python malware samples causing decompilation errors in five popular decompilers. It successfully identifies and fixes 77,022 errors. Our approach also handles anti-analysis techniques, including opcode remapping, and helps migrate Python 3.9 binaries to 3.8 binaries.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2d55c8fe-fa3f-4004-8494-0dc42503d3e6Cited by top-tier papers4
- StackSight: Unveiling WebAssembly through Large Language Models and Neurosymbolic Chain-of-Thought DecompilationWeike Fang, Zhejian Zhou, Junzhou He, Weihang WangICML 2024 · 5 citations
- Walking The Last Mile: Studying Decompiler Output Correction in PracticeJoshua Wiedemeier, Simon Klancher, Joel Flores, Max Zheng et al.CCS 2025
- PyFEX: Uncovering Evasive Python-based Threats via Resilient and Exhaustive Path ExplorationMeng Wang, Yue Ma, Majid Garoosi, Wenting Fan et al.CCS 2026
- PyLingual: Toward Perfect Decompilation of Evolving High-Level LanguagesJoshua Wiedemeier, Elliot Tarbet, Max Zheng, Sangsoo Ko et al.S&P 2025
Builds on9
- T-Fuzz: Fuzzing by Program TransformationHui Peng, Yan Shoshitaishvili, Mathias PayerS&P 2018 · 326 citations
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 187 citations
- Neural Nets Can Learn Function Type Signatures From BinariesZheng Leong Chua, Shiqi Shen, Prateek Saxena, Zhenkai LiangUSENIX Security 2017 · 175 citations
- An In-Depth Analysis of Disassembly on Full-Scale x86/x64 BinariesDennis Andriesse, Xi Chen, Victor van der Veen, Asia Slowinska et al.USENIX Security 2016 · 162 citations
- Binary rewriting without control flow recoveryGregory J. Duck, Xiang Gao, Abhik RoychoudhuryPLDI 2020 · 77 citations
Related papers
- Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User StudyKhaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew SmithS&P 2016 · 128 citations
- TransMap: Pinpointing Mistakes in Neural Code TranslationBo Wang, Ruishi Li, Mingkai Li, Prateek SaxenaFSE 2023 · 4 citations
- Decomperson: How Humans Decompile and What We Can Learn From ItKevin Burk, Fabio Pagani, Christopher Kruegel, Giovanni VignaUSENIX Security 2022
- Bin2Wrong: a Unified Fuzzing Framework for Uncovering Semantic Errors in Binary-to-C DecompilersZao Yang, Stefan NagyUSENIX ATC 2025 · 6 citations
- How far we have come: testing decompilation correctness of C decompilersZhibo Liu, Shuai WangISSTA 2020 · 53 citations
