Automated WebAssembly Function Purpose Identification With Semantics-Aware Analysis
Alan Romano, Weihang Wang
摘要
WebAssembly is a recent web standard built for better performance in web applications. The standard defines a binary code format to use as a compilation target for a variety of languages, such as C, C++, and Rust. The standard also defines a text representation for readability, although, WebAssembly modules are difficult to interpret by human readers, regardless of their experience level. This makes it difficult to understand and maintain any existing WebAssembly code. As a result, third-party WebAssembly modules need to be implicitly trusted by developers as verifying the functionality themselves may not be feasible. To this end, we construct WASPur, a tool to automatically identify the purposes of WebAssembly functions. To build this tool, we first construct an extensive collection of WebAssembly samples that represent the state of WebAssembly. Second, we analyze the dataset and identify the diverse use cases of the collected WebAssembly modules. We leverage the dataset of WebAssembly modules to construct semantics-aware intermediate representations (IR) of the functions in the modules. We encode the function IR for use in a machine learning classifier, and we find that this classifier can predict the similarity of a given function against known named functions with an accuracy rate of 88.07%. We hope our tool will enable inspection of optimized and minified WebAssembly modules that remove function names and most other semantic identifiers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- WaDec: Decompiling WebAssembly Using Large Language ModelXinyu She, Yanjie Zhao, Haoyu WangASE 2024 · 被引用 9 次
- Wasm-R3: Record-Reduce-Replay for Realistic and Standalone WebAssembly BenchmarksDoehyun Baek, Jakob Getz, Yusung Sim, Daniel Lehmann 等OOPSLA 2024 · 被引用 6 次
- StackSight: Unveiling WebAssembly through Large Language Models and Neurosymbolic Chain-of-Thought DecompilationWeike Fang, Zhejian Zhou, Junzhou He, Weihang WangICML 2024 · 被引用 5 次
- WaSCR: A WebAssembly Instruction-Timing Side Channel RepairerLiyan Huang, Junzhou He, Chao Wang, Weihang WangWWW 2025 · 被引用 3 次
- CLARC: C/C++ Benchmark for Robust Code SearchKaicheng Wang, Liyan Huang, Weike Fang, Weihang WangICLR 2026 · 被引用 3 次
它引用的顶会 Paper3
- MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its DefenseRadhesh Krishnan Konoth, Emanuele Vineti, Veelasha Moonsamy, Martina Lindorfer 等CCS 2018 · 被引用 162 次
- An Empirical Study of Real-World WebAssembly Binaries: Security, Languages, Use CasesAaron Hilbig, Daniel Lehmann, Michael PradelWWW 2021 · 被引用 114 次
- MinerRay: Semantics-Aware Analysis for Ever-Evolving Cryptojacking DetectionAlan Romano, Yunhui Zheng, Weihang WangASE 2020 · 被引用 30 次
相关 Paper
- Multi-modal Learning for WebAssembly Reverse EngineeringHanxian Huang, Jishen ZhaoISSTA 2024 · 被引用 1 次
- When Function Inlining Meets WebAssembly: Counterintuitive Impacts on Runtime PerformanceAlan Romano, Weihang WangFSE 2023 · 被引用 7 次
- Two Mechanisations of WebAssembly 1.0Conrad Watt, Xiaojia Rao, Jean Pichon-Pharabod, Martin Bodin 等FM 2021 · 被引用 32 次
- An Empirical Study of Bugs in WebAssembly CompilersAlan Romano, Xinyue Liu, Yonghwi Kwon, Weihang WangASE 2021 · 被引用 43 次
- Broken Promise: Differential Analysis of Functional Discrepancies Between WebAssembly and Native BinariesXiao Wu, Alan Romano, Liyan Huang, Qiwen Yan 等WWW 2026
