ACM SURE Workshop @sureworkshop.bsky.social · 29/06/2026Less than 40 hours to go! Submit your research to SURE 2026 and help close the software understanding gap. We’re excited to see your work! sure26.hotcrp.com 000
ACM SURE Workshop @sureworkshop.bsky.social · 12/06/2026📢 We hit snooze! You have until June 30th to get your paper in. 📄 011
ACM SURE Workshop @sureworkshop.bsky.social · 10/06/2026⏰Deadline approaching! We'd love to see your awesome work, so get it in by June 19th, 11:59 pm AoE. sure26.hotcrp.com/ 000
ACM SURE Workshop @sureworkshop.bsky.social · 08/01/2026Reflecting on the success of our first SURE and beginning the planning for the next year! 011
ACM SURE Workshop @sureworkshop.bsky.social · 17/10/2025Finally, stay in touch. We have an associated Discord (unorthodox, we know) to connect academics and practitioners: discord.gg/eVySXH7ZQ8 In fact, some of the attendees this year only made it due to the outreach on Discord. Come and chat! discord.ggSUREThe Workshop on Software Understanding and Reverse Engineering (SURE), hosting conversations on associated topics. From decompilation to source visualizati 000
ACM SURE Workshop @sureworkshop.bsky.social · 17/10/2025Also, go read some of the papers: sure-workshop.org/pa... Keep, a lookout for our executive summary of papers/discussions/conclusions at SURE 2025 for those who could not attend IRL. We will post it in the coming days. sure-workshop.orgAccepted Papers | SURE 2025Papers and posters accepted for SURE 2025 110
ACM SURE Workshop @sureworkshop.bsky.social · 17/10/2025CCS has come to a close, and so has the first-ever SURE Workshop. We want to thank the authors, the PC, @moyix, our panel, and CCS for making SURE a success. We felt the support for this research area (the room was packed out for more than half the day). See you all next year! 120
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Check out the paper: sure-workshop.org/ac... 000
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025In the special sub-area of type inferencing on binary code, Noriki's work explores the recovery of structs and how different GNN architectures may have better performance. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025On our last presented work at SURE, we have Noriki Sakamoto presenting "Toward Inferring Structural Semantics from Binary Code Using Graph Neural Networks" 110
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Check out the paper: sure-workshop.org/ac... 000
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Indeed, LibIHT is more robust. They achieve better results on binaries that attempt to evade their analysis. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025The magic happens at the kernel level. Their new tool LibIHT (github.com/libiht/li...), is implemented both at the user-space and kernel-space level. This is important for speed and robustness against evasion techniques. github.comGitHub - libiht/libiht: Intel Hardware Trace Library - Kernel Space ComponmentIntel Hardware Trace Library - Kernel Space Componment - libiht/libiht 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Often, when static analysis tools do not work, you need to get down in the weeds of a program and start dynamically analyzing it. In Thomason's work, he explores a way to be more robust and efficient by utilizing hardware features for dynamic analysis. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025We're so back, and on our last session: Applications & Future Work. Changyu "Thomason" Zhao is presenting "LibIHT: A Hardware-Based Approach to Efficient and Evasion-Resistant Dynamic Binary Analysis". He is presenting virtually. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Find the paper here: sure-workshop.org/ac... 000
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Now, you got your crazy code, how do you select which functions in the code to obfuscate and evaluate on? Functions must be "sensitive" and "central". Sensitive: has sensitive info like a uid or gid or a password. Central: many other functions should depend on it (calls). 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Real world programs in their set need: - unique functionality - complex code - ... Some real programs: OpenSSL, QEMU, SQLite, curl, ... all difficult targets that are already hard to analyze, so they are not obfuscated. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025An interesting observation: obfuscation is really expensive on the CPU. Real programs don't obfuscate the entire program; they only obfuscate critical code locations like license checks. So they construct their dataset with that in mind. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Dongpeng argues that many modern works in deobfuscation don't work on large complex programs. Instead, they are mostly tested on toy programs that are not real-world. To make a more useful evaluation, they explore how real obfuscation is used. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025We're on our last talk of the session, remaining with the obfuscation topic. Dongpeng Xu is presenting "DEBRA: A Real-World Benchmark For Evaluating Deobfuscation Methods" in the place of Zheyun Feng. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Interesting question: do specific features seem to matter more for the models? Example: constants. So far, the answer is unclear. These models are very black-box and require more explainability. 000
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Takeaways: - Training on obfuscation does help models, but it is not a silver bullet. This solution does not work well on obfuscation tech it has never seen before. Check out the work: sure-workshop.org/ac... 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Some results: you train on obfuscation, and it turns out the model does do better (with BinShot) on obfuscated code. However, training it on specific types of obfuscation tech matters. For instance, training on control flow flattening may not help at all with MBA. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025The reasoning task: binary code similarity detection. Do these two code snippets come from an identical source, and does obfuscation stop it? 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025They evaluate public obfuscation tools such as an LLVM obfuscator and the classic tool Tigress. They have a few questions, one interesting one is: Does training on obfuscated code actually make the models better at reasoning on them? 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025When reasoning on code, does it matter if it is obfuscated? The answer feels like a strong YES; however, how much does it matter for AI? Jiyong's work explores this idea in a measurable way. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Next up is "On the Learnability, Robustness, and Adaptability of Deep Learning Models for Obfuscation-applied Code," presented by Jiyong Uhm of Sungkyunkwan University. 110
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025To run those tests, you can use LLMs! They get the input from decompilation and try to take the multiple-choice guess. It's important you measure probabilities along the way. Check out the paper: sure-workshop.org/ac... 000
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Decoys are wrong answers on a test that could be reasonably guessed more closely. Instead of just having random answers, have highly guessed answers as decoys. See if things still work the same. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Something cool: You get the following choices: A: return *(x + 8) B: return x._length Both give you a similar probability of being chosen as `getLength` on a random test, which is unexpected. This is why you need stronger decoys! 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Florian's work argues that we need to start integrated work in natural sciences, like multiple-choice tests that evaluate how good your data is at helping people on the test. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Let's start with variable/property naming inside of decompilation. Given many different choices for the same name, does one lead to an LLM or a human to make a decision that is more correct or predictable? 110
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Speaking of evaluating things, how do you evaluate if your decompilation (or other tool) is actually helping you more in understanding software? Florian Magin is back to present: "Towards Scalable Evaluation of Software Understanding: A Methodology Proposal" 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025An interesting finding: - Decompilers seem to perform better for type inference on O2 instead of O0 on coverage, but, as expected, it does not hold on other metrics Find the paper here: sure-workshop.org/ac... 000
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025While evaluating, they focus on a few essential types: Primitives: -> Char, int, lono long... -> Pointers Complex Types: -> Structs -> Arrays They find that complex types is where much work still exists. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025One problem is not every one is speaking the same language. Some decompiler report types as a QWORD some say Int some say undefined. Vedant's work normalizes these differences to make the evaluation more fair. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Type inference research focuses on recovering high-level types in binary code that humans often find useful. However, there is not much work exploring whether our current approaches are effective and on what data we should test them. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025New session, who this? In this session, we are talking about benchmarking! We start with "Benchmarking Binary Type Inference Techniques in Decompilers," presented by Vedant Soni. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Check out the paper: sure-workshop.org/ac... 000
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025 Interesting question from the session: "I thought Apple did not allow interpreted languages?", yet their analysis showed that some languages that are interpreted are used in actual applications. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025We had some technical issues, but the "spark notes" give us a good overview: these higher-level languages are being used at scale in real systems and they post a real problem. 110
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025So you are thinking about approaching decompilation in the non-C sense, but you are not sure if it is impactful? Well, Florian Magin, is presenting "Measuring While Playing Fair: An Empirical Analysis of Language and Framework Usage in the iOS App Store" to answer that! 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Go check out the paper: sure-workshop.org/ac... 000
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025But how usable is the recovered Swift (or other language) code? You can get a good guess by asking LLMs to do tasks with the decompilation. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Applying this, ideco turns Swift code that is represented as C (150 lines) into something that is significantly shorter. 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Well, ideco creates a framework for describing the language you actually want to decompile to (like Swift) and attempts to turn the decompilation into that! How is it done? With a Domain Specific Language (DSL)! 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025His motivation is this: a near 15-line Swift program, when decompiled into C, is now around 150 lines. That is a 10x increase! And it sucks. So, what can we do about it? 100
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Speaking of decompilation, that is not just C; we are now on "ideco: A Framework for Improving Non-C Decompilation," presented by Sam Lerner, an independent researcher. 110
ACM SURE Workshop @sureworkshop.bsky.social · 13/10/2025Go check out the paper: sure-workshop.org/ac... 000