{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:WADBN5L4RPXGHAG4WFZ4T7OKTH","short_pith_number":"pith:WADBN5L4","schema_version":"1.0","canonical_sha256":"b00616f57c8bee6380dcb173c9fdca99f18efb9bb5ae8810967a7faa84333fd3","source":{"kind":"arxiv","id":"2505.19887","version":2},"attestation_state":"computed","paper":{"title":"Deconstructing Obfuscation: A four-dimensional framework for evaluating Large Language Models assembly code deobfuscation capabilities","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.SE","authors_text":"Anton Tkachenko, Benjamin Adolphi, Dmitrij Suskevic","submitted_at":"2025-05-26T12:16:44Z","abstract_excerpt":"Large language models (LLMs) have shown promise in software engineering, yet their effectiveness for binary analysis remains unexplored. We present the first comprehensive evaluation of commercial LLMs for assembly code deobfuscation. Testing seven state-of-the-art models against four obfuscation scenarios (bogus control flow, instruction substitution, control flow flattening, and their combination), we found striking performance variations--from autonomous deobfuscation to complete failure. We propose a theoretical framework based on four dimensions: Reasoning Depth, Pattern Recognition, Nois"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2505.19887","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-05-26T12:16:44Z","cross_cats_sorted":["cs.AI","cs.CR"],"title_canon_sha256":"e5947f2a8234cd86fb124bf553d7d40c8b1abae0d494e5b0923b821c554424dd","abstract_canon_sha256":"89b454e45d83eb61a82ad525e2bfbae3c10e0406e01f95b0d764ab1d16b6ce53"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:16:35.389204Z","signature_b64":"rFos4T/KTGfrGPmw6p0vz94nxlAVRkjLAZkEYMYY82om9uORukEO7HCm+C5/HOkJkON361E4fe113d93okY7Dw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b00616f57c8bee6380dcb173c9fdca99f18efb9bb5ae8810967a7faa84333fd3","last_reissued_at":"2026-07-05T11:16:35.388688Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:16:35.388688Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Deconstructing Obfuscation: A four-dimensional framework for evaluating Large Language Models assembly code deobfuscation capabilities","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.SE","authors_text":"Anton Tkachenko, Benjamin Adolphi, Dmitrij Suskevic","submitted_at":"2025-05-26T12:16:44Z","abstract_excerpt":"Large language models (LLMs) have shown promise in software engineering, yet their effectiveness for binary analysis remains unexplored. We present the first comprehensive evaluation of commercial LLMs for assembly code deobfuscation. Testing seven state-of-the-art models against four obfuscation scenarios (bogus control flow, instruction substitution, control flow flattening, and their combination), we found striking performance variations--from autonomous deobfuscation to complete failure. We propose a theoretical framework based on four dimensions: Reasoning Depth, Pattern Recognition, Nois"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.19887","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2505.19887/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2505.19887","created_at":"2026-07-05T11:16:35.388751+00:00"},{"alias_kind":"arxiv_version","alias_value":"2505.19887v2","created_at":"2026-07-05T11:16:35.388751+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.19887","created_at":"2026-07-05T11:16:35.388751+00:00"},{"alias_kind":"pith_short_12","alias_value":"WADBN5L4RPXG","created_at":"2026-07-05T11:16:35.388751+00:00"},{"alias_kind":"pith_short_16","alias_value":"WADBN5L4RPXGHAG4","created_at":"2026-07-05T11:16:35.388751+00:00"},{"alias_kind":"pith_short_8","alias_value":"WADBN5L4","created_at":"2026-07-05T11:16:35.388751+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.11755","citing_title":"Acoda: Adversarial Code Obfuscation for Defending against LLM-based Analysis","ref_index":36,"is_internal_anchor":false},{"citing_arxiv_id":"2606.29155","citing_title":"OASIF: An Efficient Obfuscation-Aware Self-Improving Framework for LLM-Based Assembly Code Instruction Following and Comprehension","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2604.08083","citing_title":"Can LLMs Deobfuscate Binary Code? A Systematic Analysis of Large Language Models into Pseudocode Deobfuscation","ref_index":49,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/WADBN5L4RPXGHAG4WFZ4T7OKTH","json":"https://pith.science/pith/WADBN5L4RPXGHAG4WFZ4T7OKTH.json","graph_json":"https://pith.science/api/pith-number/WADBN5L4RPXGHAG4WFZ4T7OKTH/graph.json","events_json":"https://pith.science/api/pith-number/WADBN5L4RPXGHAG4WFZ4T7OKTH/events.json","paper":"https://pith.science/paper/WADBN5L4"},"agent_actions":{"view_html":"https://pith.science/pith/WADBN5L4RPXGHAG4WFZ4T7OKTH","download_json":"https://pith.science/pith/WADBN5L4RPXGHAG4WFZ4T7OKTH.json","view_paper":"https://pith.science/paper/WADBN5L4","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2505.19887&json=true","fetch_graph":"https://pith.science/api/pith-number/WADBN5L4RPXGHAG4WFZ4T7OKTH/graph.json","fetch_events":"https://pith.science/api/pith-number/WADBN5L4RPXGHAG4WFZ4T7OKTH/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/WADBN5L4RPXGHAG4WFZ4T7OKTH/action/timestamp_anchor","attest_storage":"https://pith.science/pith/WADBN5L4RPXGHAG4WFZ4T7OKTH/action/storage_attestation","attest_author":"https://pith.science/pith/WADBN5L4RPXGHAG4WFZ4T7OKTH/action/author_attestation","sign_citation":"https://pith.science/pith/WADBN5L4RPXGHAG4WFZ4T7OKTH/action/citation_signature","submit_replication":"https://pith.science/pith/WADBN5L4RPXGHAG4WFZ4T7OKTH/action/replication_record"}},"created_at":"2026-07-05T11:16:35.388751+00:00","updated_at":"2026-07-05T11:16:35.388751+00:00"}