Exploring the Capabilities of LLMs in Binary Decompilation and Deobfuscation -- 2026 IEEE 5th International Conference on AI in Cybersecurity (ICAIC) 18-20 Feb. 2026, Houston, TX Academic Article uri icon

Abstract

  • Reverse engineering remains a critical yet time-consuming task, increasingly strained by sophisticated code-obfuscation techniques. Although modern decompilers offer strong baseline capabilities, their outputs often lack readability and semantic accuracy when analyzing obfuscated binaries. In this research, we evaluate decompilation capabilities, showing high efficacy on simple binaries (95% functional similarity) but revealing critical shortcomings when faced with obfuscation techniques such as control-flow flattening and virtualization. We propose LLM4Deobfuscate, a framework for training LLMs on synthetically generated obfuscation-deobfuscation pairs, leveraging datasets like ExeBench and automated obfuscation pipelines. Our results underscore the need for a hybrid static-dynamic analysis architecture and context-aware modeling to advance LLM-driven reverse engineering.

Publication Date

  • 2026-02-01

Published In

  •   Journal