arrow
Return

Cross-Architecture Software Vulnerability Analysis in Binary Code

delete2026-08-12
delete0
PRE
AI
S
Shigang Liu
D
Di Cao
C
Chao Chen
Z
Zhengdao Li
J
Jun Zhang
S
Seyit Camtepe
向阳 (Yang Xiang)
DOI:10.1109/tifs.2026.3723092delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Software security has been a long-standing and prominent topic in both industry and academia. However, with the increasing deployment of smart devices across various architectures, there is now a significant demand for cross-architecture software. For instance, the Heartbleed vulnerability (CVE-2014-0160), classified as CWE-125 (Out-of-bounds Read) and disclosed in the OpenSSL library in 2014, serves as a prime example of a widely-deployed software vulnerability capable of affecting systems across diverse computing environments due to OpenSSL’s broad adoption. More broadly, memory-related vulnerabilities remain a persistent and significant threat, accounting for a substantial proportion of reported CVEs in recent years. Moreover, performing static cross-architecture vulnerability analysis on binary code poses particular challenges due to the variations in instruction sets across different architectures. In this paper, we present a novel static approach, called BinCros, to identify known vulnerabilities across different optimization levels and CPU architectures in binary code. It mainly consists of three phases: 1) Generating ground-truth intermediate representation (IR) data from binary code based on domain knowledge. To address the cross-architecture problem, we consider IR, which is a set of smaller, lower-level instructions that break down, describe, and capture all the effects of an instruction from standard architectures like x86, ARM, and MIPS; 2) Learning good embeddings based on the cross-architecture ground-truth datasets. We employ a code-code learning method to capture the semantic differences and maximize the distribution divergences between vulnerable and non-vulnerable samples; 3) Building a prediction model based on high-level feature representations. To demonstrate the effectiveness of BinCros, we conducted experiments with a series of baselines including single architecture-based techniques, cross-architecture-based techniques, and so on. Experimental results show that BinCros outperforms the baselines by at least 15% in terms of F1-measure in almost all cases. We believe this work will inspire other researchers to consider natural language processing-related techniques for cross-architecture software vulnerability detection.
Keywords:
Software security
binary code
deep learning

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

G
Guangzhou University
Scholars:
1.7W
Papers: 1.3W
Citations: 1.8W
R
RMIT University
Scholars:
2.8K
Papers: 1.6K
Citations: 2.6W
M
monash university
Scholars:
8.4K
Papers: 3.8K
Citations: 0
C
csiro technology
Scholars:
6
Papers: 3
Citations: 0
S
swinburne university of technology
Scholars:
860
Papers: 465
Citations: 0
researcher View more organizations