USENIX Security2025
REVDECODE: Enhancing Binary Function Matching with Context-Aware Graph Representations and Relevance Decoding
Tongwei Ren, Ronghan Che, Guin Gilman, Lorenzo De Carli, Robert J. Walls
Abstract
Binary reverse engineering is important for security tasks, including vulnerability discovery, malware analysis, and code reuse detection. These tasks often involve analyzing binaries without source code or debug symbols. A common yet challenging step in this process is function matching, i.e., comparing functions in unknown binaries to known reference corpora. Function matching becomes complicated due to variations introduced by differences in compilers, optimization levels, and versions. Existing matching techniques primarily focus on similarity but reverse engineers prioritize relevancewhether a match provides meaningful insights. We present REVDECODE, a context-aware framework designed to improve function matching by leveraging interdependencies within binaries through relevance decoding, a technique that identifies meaningful matches based on contextual information. REVDECODE represents binaries as directed layered graphs and employs a Viterbi-inspired algorithm to determine the most relevant matches. Additionally, we propose GPU-optimized variants of REVDECODE which partition the graph traversal workload into independent subsets, maximizing GPU resource utilization and enabling greater parallelization. Experimental results demonstrate that REVDECODE significantly enhances the performance of existing function matchers, improving rankings for 56.3% to 98.8% of the evaluated functions across multiple datasets and matchers.
