arrow
Return

FunSp: countering binary code similarity detection through function splitting

delete2026-05-01
delete0
PRE
AI
W
Wei, Ran
H
Hui Shu *
F
Fei Kang
X
Xiong, Xiaobing
杨岚 cover
杨岚 (Lan Yang)
L
Li, Cong
DOI:10.1093/comjnl/bxag054delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Binary code similarity detection (BCSD) poses a significant threat to software security by enabling reverse engineers to identify critical functions in binaries. Code obfuscation is a primary defense, yet existing techniques often incur high performance overhead and introduce recognizable patterns. To address these limitations, we present FunSp, a lightweight code obfuscation method based on function splitting at the compiler intermediate representation level. FunSp partitions a function's control flow graph into multiple subgraphs via dominator-tree analysis, repairs inter-subgraph data dependencies, reconstructs control flow, and finally rewrites the code to produce semantically equivalent sub-functions. This approach redistributes basic blocks across subfunctions without injecting substantial redundant code, thereby minimizing overhead. Experimental results show that FunSp effectively undermines state-of-the-art BCSD models, reducing Recall@1 to 0.016 in a 10 000-function pool. It maintains practicality, introducing a mean code expansion ratio of 1.353 $ imes $ and a runtime overhead of 12.7%. Compared with Obfuscator-LLVM and Tigress, FunSp reduces code bloat by 73.5% and runtime overhead by 5.5%.
Keywords:
function split
code obfuscation
binary code similarity detection
dominator tree

Journal

C
COMPUTER JOURNAL
IF:
1.5
Papers:
103
Citations:
0

Organization

No organization information available
Cited Papers

Cited Papers

No cited papers available