Not so fast: understanding and mitigating negative impacts of compiler optimizations on code reuse gadget sets
Michael D. Brown, Matthew Pruett, Robert Bigelow, Girish Mururu, Santosh Pande
Abstract
Despite extensive testing and correctness certification of their functional semantics, a number of compiler optimizations have been shown to violate security guarantees implemented in source code. While prior work has shed light on how such optimizations may introduce semantic security weaknesses into programs, there remains a significant knowledge gap concerning the impacts of compiler optimizations on non-semantic properties with security implications. In particular, little is currently known about how code generation and optimization decisions made by the compiler affect the availability and utility of reusable code segments called gadgets required for implementing code reuse attack methods such as return-oriented programming.
In this paper, we bridge this gap through a study of the impacts of compiler optimization on code reuse gadget sets. We analyze and compare 1,187 variants of 20 different benchmark programs built with two production compilers (GCC and Clang) to determine how their optimization behaviors affect the code reuse gadget sets present in program variants with respect to both quantitative and qualitative metrics. Our study exposes an important and unexpected problem; compiler optimizations introduce new gadgets at a high rate and produce code containing gadget sets that are generally more useful to an attacker than those in unoptimized code. Using differential binary analysis, we identify several undesirable behaviors at the root of this phenomenon. In turn, we propose and evaluate several strategies to mitigate these behaviors. In particular, we show that post-production binary recompilation can effectively mitigate these behaviors with negligible performance impacts, resulting in optimized code with significantly smaller and less useful gadget sets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8477af1f-34d8-4cb5-b75f-145d80bed420Cited by top-tier papers4
- Improving Security Tasks Using Compiler Provenance Information Recovered At the Binary-LevelYufei Du, Omar Alrawi, Kevin Z. Snow, Manos Antonakakis et al.CCS 2023 · 8 citations
- Automatic Recovery of Fine-grained Compiler Artifacts at the Binary LevelYufei Du, Ryan Court, Kevin Z. Snow, Fabian MonroseUSENIX ATC 2022
- Silent Bugs Matter: A Study of Compiler-Introduced Security BugsJianhao Xu, Kangjie Lu, Zhengjie Du, Zhu Ding et al.USENIX Security 2023
- Protecting Source Code Privacy When Hunting Memory BugsJielun Wu, Bing Shui, Hongcheng Fan, Shengxin Wu et al.ASE 2025
Builds on5
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 153 citations
- The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years LaterVictor van der Veen, Dennis Andriesse, Manolis Stamatogiannakis, Xi Chen et al.CCS 2017 · 74 citations
- Egalito: Layout-Agnostic Binary RecompilationDavid Williams-King, Hidenori Kobayashi, Kent Williams-King, Graham Patterson et al.ASPLOS 2020 · 68 citations
- Dead Store Elimination (Still) Considered HarmfulZhaomo Yang, Brian Johannesmeyer, Anders Trier Olesen, Sorin Lerner et al.USENIX Security 2017 · 37 citations
- BlankIt library debloating: getting what you want instead of cutting what you don'tChris Porter, Girish Mururu, Prithayan Barua, Santosh PandePLDI 2020 · 31 citations
Related papers
- WarpAttack: Bypassing CFI through Compiler-Introduced Double-FetchesJianhao Xu, Luca Di Bartolomeo, Flavio Toffalini, Bing Mao et al.S&P 2023
- Revisiting Optimization-Resilience Claims in Binary Diffing Tools: Insights from LLVM Peephole Optimization AnalysisXiaolei Ren, Mengfei Ren, Yu Lei, Jiang MingFSE 2025
- Methodologies for Quantifying (Re-)randomization Security and Timing under JIT-ROPSalman Ahmed, Ya Xiao, Kevin Z. Snow, Gang Tan et al.CCS 2020 · 21 citations
- Unleashing the hidden power of compiler optimization on binary code difference: an empirical studyXiaolei Ren, Michael Ho, Jiang Ming, Yu Lei et al.PLDI 2021 · 57 citations
- CLower: Detecting Compiler Pessimization Bugs through Redundant Memory AccessesJianhao Xu, Kunbo Zhang, Mathias Payer, Kangjie Lu et al.OOPSLA 2026
