Oxidizer: Toward Concise and High-fidelity Rust Decompilation
Yibo Liu, Zion Leonahenahe Basque, Arvind S. Raj, Chavin Udomwongsa, Chang Zhu, Jie Hu, Changyu Zhao, Fangzhou Dong, Adam Doupé, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang
Abstract
Rust is an increasingly popular language that has gained traction among developers. As a memory-safe language, Rust reduces the burden for developers to create reliable and fast software. However, the same features can also hinder reverse engineering tasks. For instance, malware developers have also picked up on the trend of Rust, using it to make their malware more reliable and difficult to analyze.
Reverse engineering tasks often rely on decompilers to recover the source code from these binaries. However, analysts find it difficult to analyze Rust binaries using modern C decompilers. Modern C decompilers fail on Rust binaries because they fail to recover high-level Rust abstractions from low-level implementations. As a result, the decompiled output is often verbose and inaccurate. Therefore, we believe that to achieve high-quality Rust decompilation, a decompiler must bridge the gap between high-level Rust abstractions and lowlevel implementations.
In this paper, we study how C decompilers fail at decompiling Rust binaries. We identify a comprehensive list of decompilation failures, find the root causes of these failures, and develop a novel decompiler, OXIDIZER, for decompiling Rust binaries to Rust pseudocode. We evaluate OXIDIZER on 28 popular Rust projects across multiple optimization levels and compiler versions, comparing it against angr, Hex-Rays, Ghidra, and Binary Ninja. OXIDIZER outperforms all baselines on most conciseness and fidelity metrics, and is the only tool capable of recovering Rust enums and macros. A human study further shows that participants using OXIDIZER achieved 28% higher accuracy and completed tasks 20% faster than those using Hex-Rays.
We then develop novel techniques to address the fidelity issues in Rust decompilation and implement them in OXIDIZER, a prototype Rust decompiler built on top of angr [18]. OXIDIZER performs binary-level analyses to overcome challenges introduced by the Rust compiler, enabling Rust standard library function identification and the application of known struct and function types. OXIDIZER also addresses identified fidelity issues by designing the three core components of decompilation, control-flow recovery, type recovery, and structuring, specifically for Rust. With these Rust-oriented designs, OXIDIZER is able to recover Rust high-level abstractions such as macros, enums, and pattern matching. OXIDIZER takes a first step toward highquality Rust decompilation by generating concise, faithful, and human-readable code that enables more effective reverse engineering of real-world Rust binaries.
Finally, we evaluate OXIDIZER on our dataset consisting of 27 projects from the top 50 Rust projects on GitHub (ranked by stars) and the Rust reimplementation of GNU Coreutils [19], with various optimization levels and two different Rust compiler versions. OXIDIZER generates output that is significantly more concise and faithful to the original program compared to existing binary decompilers. It produces 15% fewer lines of code and 7% lower cyclomatic complexity than the best-performing C decompiler on average. Moreover, OXIDIZER effectively reduces extraneous function calls and achieves the highest matched macro recovery rate among all evaluated decompilers. For type inference, OXIDIZER outperforms other decompilers on recovering struct and enum types, which are the most prevalent types in our dataset. In our user study with 37 participants of different reverse engineering expertise, participants using OXIDIZER achieved 28% higher task scores and completed tasks 20% faster than with Hex-Rays, demonstrating improved efficiency and accuracy. Participants also rated OXIDIZER more favorably, with an average score of 4.49 out of 5, compared to 2.61 for Hex-Rays.
Contributions. We make the following contributions:
- We empirically study the performance of state-of-theart C decompilers on Rust binaries, identifying key fidelity issues and Rust-specific challenges that hinder effective decompilation. 2) We propose the first Rust decompilation pipeline to address these challenges and implement it in our opensource prototype, OXIDIZER, providing a foundation for future research in Rust decompilation. 3) We introduce the first systematic methodology for evaluating Rust decompilation in terms of conciseness and fidelity, and use it to benchmark OXIDIZER against state-of-the-art C decompilers, showing its superior performance. We further demonstrate OXI-DIZER's practical benefits through case studies on realworld malware samples and a human study involving reverse engineering tasks.
To further open science, we release OXIDIZER and all our evaluation artifacts at https://github.com/sefcom/oxidizer and integrate OXIDIZER into angr.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on18
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Ramblr: Making Reassembly Great AgainRuoyu Wang, Yan Shoshitaishvili, Antonio Bianchi, Aravind Machiry et al.NDSS 2017 · 155 citations
- Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User StudyKhaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew SmithS&P 2016 · 128 citations
- OSPREY: Recovery of Variable and Data Structure via Probabilistic Analysis for Stripped BinaryZhuo Zhang, Yapeng Ye, Wei You, Guanhong Tao et al.S&P 2021 · 78 citations
- BinRec: dynamic binary lifting and recompilationAnil Altinay, Joseph Nash, Taddeus Kroes, Prabhu Rajasekaran et al.EuroSys 2020 · 51 citations
Related papers
- RustSan: Retrofitting AddressSanitizer for Efficient Sanitization of RustKyuwon Cho, Jongyoon Kim, Kha Dinh Duy, Hajeong Lim et al.USENIX Security 2024 · 7 citations
- Rust-twins: Automatic Rust Compiler Testing through Program Mutation and Dual Macros GenerationWenzhang Yang, Cuifeng Gao, Xiaoyuan Liu, Yuekang Li et al.ASE 2024 · 5 citations
- Aliasing Limits on Translating C to Safe RustMehmet Emre, Peter Boyland, Aesha Parekh, Ryan Schroeder et al.OOPSLA 2023 · 32 citations
- Scylla: Translating an Applicative Subset of C to Safe RustAymeric Fromherz, Jonathan ProtzenkoOOPSLA 2026 · 6 citations
- Don't Panic! Finding Bugs Hidden Behind Rust Runtime Safety ChecksZeyang Zhuang, Zilun Wang, Wei Meng, Michael R. LyuCCS 2025
