SBridge: Identifying Source-to-Binary Function Similarity via Cross-Domain Control Block Matching
Heedong Yang, Jeongwoo Lee, Hajin Yun, Seunghoon Woo
Abstract
We present SBridge, a precise approach for identifying functions in binaries that are similar to the given source code functions. Identifying reused code in binaries is critical for security, particularly for detecting propagated vulnerabilities. Although binary-to-binary comparison is feasible, leveraging source code as the reference is more practical because source code is easier to collect and analyze directly without compilation. However, significant gaps between source and binary representations, including function inlining, create challenges in cross-domain function detection. Existing approaches primarily rely on string literals or structural similarities between entire functions, failing to capture detailed code behavior and generating many false alarms. SBridge addresses these limitations through a key innovation: control block-based function matching, which encapsulates essential functional features by segmenting functions into meaningful units such as conditionals and loops. Leveraging control blocks as a cross-domain representation, SBridge enables precise measurement of function similarity between source and binary code, effectively overcoming challenges posed by function inlining and stripped binaries. For evaluation, we collected 3,904 real-world C/C++ binaries from BinKit. In experiments identifying binary functions identical to input source functions, despite approximately 40% of binary functions being inlined, SBridge achieved 75.13% recall@1 and 80.98% recall@5, outperforming existing approaches, which achieved up to 43.31% recall@1 and 50.2% recall@5. Our further analysis confirmed that SBridge effectively identifies propagated vulnerabilities in binaries.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7ed2ab84-a551-4185-b723-cbd380b8150bBuilds on25
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 388 citations
- Order Matters: Semantic-Aware Neural Networks for Binary Code Similarity DetectionZeping Yu, Rui Cao, Qiyi Tang, Sen Nie et al.AAAI 2020 · 265 citations
- jTrans: jump-aware transformer for binary code similarity detectionHao Wang, Wenjie Qu, Gilad Katz, Wenyu Zhu et al.ISSTA 2022 · 139 citations
- Identifying Open-Source License Violation and 1-day Security Risk at Large ScaleRuian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim et al.CCS 2017 · 126 citations
- BinSim: Trace-based Semantic Binary Diffing via System Call Sliced Segment Equivalence CheckingJiang Ming, Dongpeng Xu, Yufei Jiang, Dinghao WuUSENIX Security 2017 · 118 citations
Related papers
- BINALIGNER: Aligning Binary Code for Cross-Compilation Environment DiffingYiran Zhu, Tong Tang, Jie Wan, Ziqi Yang et al.NDSS 2026 · 1 citation
- From Similarity Ranking to Definitive Verdict: LLM-Enhanced Source-to-Binary Function LocalizationJingyi Shi, Chengyue Liu, Zhengzi Xu, Yang Xiao et al.OOPSLA 2026
- Cross-Inlining Binary Function Similarity DetectionAng Jia, Ming Fan, Xi Xu, Wuxia Jin et al.ICSE 2024 · 11 citations
- REVDECODE: Enhancing Binary Function Matching with Context-Aware Graph Representations and Relevance DecodingTongwei Ren, Ronghan Che, Guin Gilman, Lorenzo De Carli et al.USENIX Security 2025
- Interpretation-enabled Software Reuse Detection Based on a Multi-Level Birthmark ModelXi Xu, Qinghua Zheng, Zheng Yan, Ming Fan et al.ICSE 2021 · 24 citations
