{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T15:32:19Z","timestamp":1764084739660,"version":"3.45.0"},"reference-count":17,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T00:00:00Z","timestamp":1764028800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T00:00:00Z","timestamp":1764028800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"DOI":"10.1007\/s11416-025-00572-2","type":"journal-article","created":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T15:26:10Z","timestamp":1764084370000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Firmware-level reverse engineering and AI-augmented deobfuscation for IoT malware detection in embedded systems"],"prefix":"10.1007","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-8471-0969","authenticated-orcid":false,"given":"Milad","family":"Rahmati","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8872-104X","authenticated-orcid":false,"given":"Nima","family":"Rahmati","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,11,25]]},"reference":[{"key":"572_CR1","doi-asserted-by":"publisher","first-page":"111054","DOI":"10.1109\/ACCESS.2023.3320366","volume":"11","author":"Y Nasser","year":"2023","unstructured":"Nasser, Y., Nassar, M.: Toward hardware-assisted malware detection utilizing explainable machine learning: a survey. IEEE Access 11, 111054\u2013111077 (2023). https:\/\/doi.org\/10.1109\/ACCESS.2023.3320366","journal-title":"IEEE Access"},{"issue":"9","key":"572_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3432893","volume":"54","author":"A Qasem","year":"2021","unstructured":"Qasem, A., Shirani, P., Debbabi, M., Wang, L.: Automatic vulnerability detection in embedded devices and firmware: Survey and layered taxonomies. ACM Comput. Surv. 54(9), 1\u201341 (2021). https:\/\/doi.org\/10.1145\/3432893","journal-title":"ACM Comput. Surv."},{"key":"572_CR3","unstructured":"Hevesi, G.: Machine learning-based malware detection for IoT devices using control-flow data. arXiv preprint, arXiv:2311.11605. (2023)"},{"issue":"3","key":"572_CR4","doi-asserted-by":"publisher","first-page":"160","DOI":"10.1109\/TMSCS.2016.2549043","volume":"2","author":"X Wang","year":"2016","unstructured":"Wang, X., Konstantinou, C., Maniatakos, M.: Malicious firmware detection with hardware performance counters. IEEE Trans. Multi-Scale Comput. Syst. 2(3), 160\u2013172 (2016). https:\/\/doi.org\/10.1109\/TMSCS.2016.2549043","journal-title":"IEEE Trans. Multi-Scale Comput. Syst."},{"issue":"7","key":"572_CR5","doi-asserted-by":"publisher","first-page":"705","DOI":"10.3390\/math9070705","volume":"9","author":"H Kim","year":"2021","unstructured":"Kim, H., Park, J., Kwon, H., Jang, K., Seo, H.: Convolutional neural network-based cryptography ransomware detection for low-end embedded processors. Mathematics 9(7), 705\u2013728 (2021). https:\/\/doi.org\/10.3390\/math9070705","journal-title":"Mathematics"},{"key":"572_CR6","unstructured":"Tsang, R., Joseph, D., Salehi, S., Mohapatra, P.: FFXE: Dynamic control flow graph recovery for embedded firmware binaries, in Proc. USENIX Security, [Online]. (2024). Available: https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/tsang"},{"key":"572_CR7","doi-asserted-by":"publisher","unstructured":"Sun, P., Garcia, L., Zonouz, S.: Tell me more than just assembly! Reversing cyber-physical execution semantics of embedded IoT controller software binaries, in Proc. 49th IEEE\/IFIP Int. Conf. Dependable Syst. Netw., pp. 81\u2013 92, (2019). https:\/\/doi.org\/10.1109\/DSN.2019.00020","DOI":"10.1109\/DSN.2019.00020"},{"key":"572_CR8","doi-asserted-by":"publisher","unstructured":"Omotosho, A., Welearegai, G., Hammer, C.: Detecting return-oriented programming on firmware-only embedded devices using hardware performance counters, in Proc. ACM Symp. Appl. Comput., pp. 470\u2013479, (2022). https:\/\/doi.org\/10.1145\/3477314.3507108","DOI":"10.1145\/3477314.3507108"},{"issue":"3","key":"572_CR9","doi-asserted-by":"publisher","first-page":"1182","DOI":"10.1109\/TDSC.2019.2895912","volume":"18","author":"D Zhao","year":"2021","unstructured":"Zhao, D., et al.: Cross-architecture vulnerability search in firmware based on support vector machine and attributed control flow graph. IEEE Trans. Dependable. Secure. Comput. 18(3), 1182\u20131196 (2021). https:\/\/doi.org\/10.1109\/TDSC.2019.2895912","journal-title":"IEEE Trans. Dependable. Secure. Comput."},{"issue":"1","key":"572_CR10","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s43926-023-00045-2","volume":"3","author":"S Ul Haq","year":"2023","unstructured":"Ul Haq, S., Singh, Y., Sharma, A., Gupta, R.: A survey on IoT & embedded device firmware security: Architecture, extraction techniques, and vulnerability analysis frameworks. Discover Internet Things 3(1), 1\u201316 . https:\/\/doi.org\/10.1007\/s43926-023-00045-2","journal-title":"Discover Internet Things"},{"key":"572_CR11","unstructured":"Palmarini, F.: Reverse engineering of embedded architectures, Ph.D. dissertation, Ca\u2019 Foscari Univ. Venice, (2015)"},{"key":"572_CR12","unstructured":"Forte, V.: Automatic binary analysis and instrumentation of embedded firmware for a control-flow integrity solution, M.Sc. thesis, Politecnico di Torino, (2021)"},{"issue":"2","key":"572_CR13","first-page":"24","volume":"18","author":"J Kumar","year":"2025","unstructured":"Kumar, J.: A deep learning approach for binary code similarity detection to detect vulnerabilities in firmware binaries. Int. J. Intell. Eng. Syst. 18(2), 24\u201334 (2025)","journal-title":"Int. J. Intell. Eng. Syst."},{"key":"572_CR14","doi-asserted-by":"publisher","unstructured":"Radu, A.I., Garcia, F.D.: Grey-box analysis and fuzzing of automotive electronic components via control- flow graph extraction, in Proc. 4th ACM Int. Workshop Cyber-Phys. Syst. Security, (2020). https:\/\/doi.org\/10.1145\/3385958.3430480","DOI":"10.1145\/3385958.3430480"},{"key":"572_CR15","unstructured":"Kuruvila, A.P.: Hardware-assisted malware detection for securing embedded systems, Ph.D. dissertation, Univ. Texas at Dallas, (2021)"},{"key":"572_CR16","unstructured":"Thomas, S.L.: Backdoor detection systems for embedded devices, Ph.D. dissertation, Univ. Birmingham, (2018)"},{"key":"572_CR17","unstructured":"Sickendick, K.A.:\u00a0\u201cFile carving and malware identification algorithms applied to firmware reverse engineering, \" M.Sc. thesis, Air force institute of technology (2013)"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-025-00572-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11416-025-00572-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-025-00572-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T15:26:16Z","timestamp":1764084376000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11416-025-00572-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,25]]},"references-count":17,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["572"],"URL":"https:\/\/doi.org\/10.1007\/s11416-025-00572-2","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,25]]},"assertion":[{"value":"22 June 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 September 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 November 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"5"}}