USENIX Security2024Top-tier venue
D-Helix: A Generic Decompiler Testing Framework Using Symbolic Differentiation
Muqi Zou, Arslan Khan, Ruoyu Wu, Han Gao, Antonio Bianchi, Dave (Jing) Tian
Abstract
Decompilers, one of the widely used security tools, transform low-level binary programs back into their high-level source representations, such as C/C++. While state-of-the-art decompilers try to generate more human-readable outputs, for instance, by eliminating goto statements in their decompiled code, the correctness of a decompilation process is largely ignored due to the complexity of decompilers, e.g., involving hundreds of heuristic rules. As a result, outputs from decompilers are often not accurate, which affects the effectiveness of downstream security tasks.
In this paper, we propose D-HELIX, a generic decompiler testing framework that can automatically vet the decompilation correctness on the function level. D-HELIX uses RECOMPILER to compile the decompiled code at the functional level. It then uses SYMDIFF to compare the symbolic model of the original binary with the one of the decompiled code, detecting potential errors introduced by the decompilation process. D-HELIX further provides TUNER to help debug the incorrect decompilation via toggling decompilation heuristic rules automatically. We evaluated D-HELIX on Ghidra and angr using 2,004 binaries and object files ending up with 93K decompiled functions in total. D-HELIX detected 4,515 incorrectly decompiled functions, reproduced 8 known bugs, found 17 distinct previously unknown bugs within these two decompilers, and fixed 7 bugs automatically.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6b374663-3c8a-4749-ad26-4075caae917eCited by top-tier papers6
- Idioms: A Simple and Effective Framework for Turbo-Charging Local Neural Decompilation with Well-Defined TypesLuke Dramko, Claire Le Goues, Edward J. SchwartzNDSS 2026 · 7 citations
- Bin2Wrong: a Unified Fuzzing Framework for Uncovering Semantic Errors in Binary-to-C DecompilersZao Yang, Stefan NagyUSENIX ATC 2025 · 6 citations
- Beyond Raw Bytes: Towards Large Malware Language ModelsLuke Kurlandski, Harel Berger, Yin Pan, Matthew WrightNDSS 2026 · 5 citations
- Decompiling for Constant-Time AnalysisSantiago Arranz-Olmos, Gilles Barthe, Lionel Blatter, Youcef Bouzid et al.OOPSLA 2026 · 1 citation
- VeriBin: Adaptive Verification of Patches at the Binary LevelHongwei Wu, Jianliang Wu, Ruoyu Wu, Ayushi Sharma et al.NDSS 2025
Builds on14
- Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User StudyKhaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew SmithS&P 2016 · 128 citations
- Alive2: bounded translation validation for LLVMNuno P. Lopes, Juneyoung Lee, Chung-Kil Hur, Zhengyang Liu et al.PLDI 2021 · 109 citations
- OSPREY: Recovery of Variable and Data Structure via Probabilistic Analysis for Stripped BinaryZhuo Zhang, Yapeng Ye, Wei You, Guanhong Tao et al.S&P 2021 · 78 citations
- Unleashing the hidden power of compiler optimization on binary code difference: an empirical studyXiaolei Ren, Michael Ho, Jiang Ming, Yu Lei et al.PLDI 2021 · 57 citations
- How far we have come: testing decompilation correctness of C decompilersZhibo Liu, Shuai WangISSTA 2020 · 53 citations
Related papers
- Understanding and Finding Java Decompiler BugsYifei Lu, Weidong Hou, Minxue Pan, Xuandong Li et al.OOPSLA 2024 · 5 citations
- DTD: Comprehensive and Scalable Testing for DebuggersHongyi Lu, Zhibo Liu, Shuai Wang, Fengwei ZhangFSE 2024 · 2 citations
- TRex: Practical Type Reconstruction for Binary CodeJay Bosamiya, Maverick Woo, Bryan ParnoUSENIX Security 2025
- Reassembly is Hard: A Reflection on Challenges and StrategiesHyungseok Kim, Soomin Kim, Junoh Lee, Kangkook Jee et al.USENIX Security 2023
- Augmenting Decompiler Output with Learned Variable Names and TypesQibin Chen, Jeremy Lacomis, Edward J. Schwartz, Claire Le Goues et al.USENIX Security 2022
