{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,27]],"date-time":"2026-05-27T23:05:58Z","timestamp":1779923158793,"version":"3.53.1"},"publisher-location":"New York, NY, USA","reference-count":78,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,10,16]],"date-time":"2023-10-16T00:00:00Z","timestamp":1697414400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,10,16]]},"DOI":"10.1145\/3607199.3607200","type":"proceedings-article","created":{"date-parts":[[2023,10,3]],"date-time":"2023-10-03T22:30:51Z","timestamp":1696372251000},"page":"1-16","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Black-box Attacks Against Neural Binary Function Detection"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4378-0185","authenticated-orcid":false,"given":"Joshua","family":"Bundt","sequence":"first","affiliation":[{"name":"Northeastern University, United States of America and Army Cyber Institute, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8735-1956","authenticated-orcid":false,"given":"Michael","family":"Davinroy","sequence":"additional","affiliation":[{"name":"Northeastern University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8610-6954","authenticated-orcid":false,"given":"Ioannis","family":"Agadakos","sequence":"additional","affiliation":[{"name":"Amazon, USA and Northeastern University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4979-5292","authenticated-orcid":false,"given":"Alina","family":"Oprea","sequence":"additional","affiliation":[{"name":"Northeastern University, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6968-0273","authenticated-orcid":false,"given":"William","family":"Robertson","sequence":"additional","affiliation":[{"name":"Northeastern University, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,10,16]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/1609956.1609960"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359823"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00020"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","unstructured":"Hyrum\u00a0S. Anderson Anant Kharkar Bobby Filar David Evans and Phil Roth. 2018. Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning. https:\/\/doi.org\/10.48550\/ARXIV.1801.08917","DOI":"10.48550\/ARXIV.1801.08917"},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Andriesse Dennis","year":"2016","unstructured":"Dennis Andriesse, Xi Chen, Victor van\u00a0der Deen, Asia Slowinska, and Herbert Bos. 2016. An In-Depth Analysis of Disassembly on Full-Scale X86\/X64 Binaries. In Proceedings of the USENIX Security Symposium (2016). 19."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2017.11"},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In Proceedings of the International Conference on Machine Learning (2018). PMLR, 274\u2013283."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/357830.357849"},{"key":"e_1_3_2_1_9_1","volume-title":"Proceedings of the USENIX Security Symposium (2014-08)","author":"Bao Tiffany","year":"2014","unstructured":"Tiffany Bao, Jonathan Burket, Maverick Woo, Rafael Turner, and David Brumley. 2014. ByteWeight: Learning to Recognize Functions in Binary Code. In Proceedings of the USENIX Security Symposium (2014-08). 17."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23300"},{"key":"e_1_3_2_1_11_1","unstructured":"Eli Bendersky. 2012. Pyelftools. https:\/\/github.com\/eliben\/pyelftools"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3264418"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","unstructured":"Tom\u00a0B. Brown Benjamin Mann Nick Ryder Melanie Subbiah Jared Kaplan Prafulla Dhariwal Arvind Neelakantan Pranav Shyam Girish Sastry Amanda Askell Sandhini Agarwal Ariel Herbert-Voss Gretchen Krueger Tom Henighan Rewon Child Aditya Ramesh Daniel\u00a0M. Ziegler Jeffrey Wu Clemens Winter Christopher Hesse Mark Chen Eric Sigler Mateusz Litwin Scott Gray Benjamin Chess Jack Clark Christopher Berner Sam McCandlish Alec Radford Ilya Sutskever and Dario Amodei. 2020. Language Models Are Few-Shot Learners. (2020). https:\/\/doi.org\/10.48550\/ARXIV.2005.14165","DOI":"10.48550\/ARXIV.2005.14165"},{"key":"e_1_3_2_1_15_1","unstructured":"Capstone Developers. 2014. Capstone Disassembler. https:\/\/www.capstone-engine.org"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_17_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Chua Zheng\u00a0Leong","year":"2017","unstructured":"Zheng\u00a0Leong Chua, Shiqi Shen, Prateek Saxena, and Zhenkai Liang. 2017. Neural Nets Can Learn Function Type Signatures From Binaries. In Proceedings of the USENIX Security Symposium (2017). 19."},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Cowan Crispan","year":"1998","unstructured":"Crispan Cowan, Calton Pu, Dave Maier, Jonathan Walpole, and Peat Bakke. 1998. StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks. In Proceedings of the USENIX Security Symposium (1998). 63\u201378."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","unstructured":"Hanjun Dai Bo Dai and Le Song. 2016. Discriminative Embeddings of Latent Variable Models for Structured Data. (2016). https:\/\/doi.org\/10.48550\/ARXIV.1603.05629","DOI":"10.48550\/ARXIV.1603.05629"},{"key":"e_1_3_2_1_20_1","unstructured":"DeepBits Developers. 2022. DeepDi. DeepBits. https:\/\/www.deepbitstech.com\/deepdi.html"},{"key":"e_1_3_2_1_21_1","volume-title":"BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding.","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. (2019). arxiv:1810.04805\u00a0[cs] http:\/\/arxiv.org\/abs\/1810.04805"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00003"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24311"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978370"},{"key":"e_1_3_2_1_25_1","volume-title":"Proceedings of the Conference on Neural Information Processing Systems (2019-06-27)","author":"Fu Cheng","year":"2019","unstructured":"Cheng Fu, Huili Chen, Haolan Liu, Xinyun Chen, Yuandong Tian, Farinaz Koushanfar, and Jishen Zhao. 2019. Coda: An End-to-End Neural Program Decompiler. In Proceedings of the Conference on Neural Information Processing Systems (2019-06-27). arxiv:1906.12029http:\/\/arxiv.org\/abs\/1906.12029"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1704.01212"},{"key":"e_1_3_2_1_27_1","unstructured":"Ian\u00a0J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. (2014)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","unstructured":"Aditya Grover and Jure Leskovec. 2016. Node2vec: Scalable Feature Learning for Networks. (2016). https:\/\/doi.org\/10.48550\/ARXIV.1607.00653","DOI":"10.48550\/ARXIV.1607.00653"},{"key":"e_1_3_2_1_29_1","unstructured":"Ilfak Guilfanov. 2022. IDA Pro. Hex Rays. https:\/\/hex-rays.com\/ida-pro\/"},{"key":"e_1_3_2_1_30_1","volume-title":"International Conference on Machine Learning","author":"Guo Chuan","year":"2019","unstructured":"Chuan Guo, Jacob Gardner, Yurong You, Andrew\u00a0Gordon Wilson, and Kilian Weinberger. 2019. Simple black-box adversarial attacks. In International Conference on Machine Learning (2019). PMLR, 2484\u20132493."},{"key":"e_1_3_2_1_31_1","volume-title":"Proceedings of the USENIX Security Symposium (2019","author":"Guo Wenbo","year":"2019","unstructured":"Wenbo Guo, Dongliang Mu, Xinyu Xing, Min Du, and Dawn Song. 2019. DeepVSA: Facilitating Value-set Analysis with Deep Learning for Postmortem Program Analysis. In Proceedings of the USENIX Security Symposium (2019). 1787\u20131804. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/guo"},{"key":"e_1_3_2_1_32_1","unstructured":"Irfan\u00a0Ul Haq and Juan Caballero. 2019. A Survey of Binary Code Similarity. (2019). arxiv:1909.11424\u00a0[cs] http:\/\/arxiv.org\/abs\/1909.11424"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_20"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4684-2001-2_9"},{"key":"e_1_3_2_1_35_1","unstructured":"Kexin Pei. 2021. XDA. Columbia University. https:\/\/github.com\/CUMLSec\/XDA"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3187689"},{"key":"e_1_3_2_1_37_1","volume-title":"Code-Pointer Integrity. In Proceedings of the USENIX Conference on Operating Systems Design and Implementation","author":"Kuznetsov Volodymyr","year":"2014","unstructured":"Volodymyr Kuznetsov, L\u00e1szl\u00f3 Szekeres, Mathias Payer, George Candea, R. Sekar, and Dawn Song. 2014. Code-Pointer Integrity. In Proceedings of the USENIX Conference on Operating Systems Design and Implementation (Broomfield, CO, 2014-10-06) (OSDI\u201914). USENIX Association, 147\u2013163."},{"key":"e_1_3_2_1_38_1","unstructured":"Jeff Law. 2020. Stack Clash Mitigation in GCC Part 3. Red Hat Developer. https:\/\/developers.redhat.com\/blog\/2020\/05\/22\/stack-clash-mitigation-in-gcc-part-3"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1405.4053"},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of the ISOC Network and Distributed System Security Symposium","author":"Lee JongHyup","year":"2011","unstructured":"JongHyup Lee, Thanassis Avgerinos, and David Brumley. 2011. TIE: Principled Reverse Engineering of Types in Binary Programs. In Proceedings of the ISOC Network and Distributed System Security Symposium (2011). 18."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.3390\/app9194086"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484587"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453086"},{"key":"e_1_3_2_1_44_1","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2019. Towards Deep Learning Models Resistant to Adversarial Attacks. (2019). arxiv:1706.06083\u00a0[cs stat] http:\/\/arxiv.org\/abs\/1706.06083"},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Marcelli Andrea","year":"2022","unstructured":"Andrea Marcelli, Mariano Graziano, Xabier Ugarte-Pedrero, Yanick Fratantonio, Mohamad Mansouri, and Davide Balzarotti. 2022. How Machine Learning Is Solving the Binary Function Similarity Problem. In Proceedings of the USENIX Security Symposium (2022). 18."},{"key":"e_1_3_2_1_46_1","volume-title":"SAFE: Self-Attentive Function Embeddings for Binary Similarity. In Detection of Intrusions and Malware, and Vulnerability Assessment","author":"Massarelli Luca","year":"2019","unstructured":"Luca Massarelli, Giuseppe\u00a0Antonio Di\u00a0Luna, Fabio Petroni, Leonardo Querzoni, and Roberto Baldoni. 2019. SAFE: Self-Attentive Function Embeddings for Binary Similarity. In Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, Cham, 309\u2013329."},{"key":"e_1_3_2_1_47_1","unstructured":"Tomas Mikolov Kai Chen Greg Corrado and Jeffrey Dean. 2013. Efficient Estimation of Word Representations in Vector Space. (2013). arxiv:1301.3781\u00a0[cs] http:\/\/arxiv.org\/abs\/1301.3781"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00121"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_1_50_1","unstructured":"NSA. 2019. Ghidra. US National Security Agency. https:\/\/ghidra-sre.org"},{"key":"e_1_3_2_1_51_1","volume-title":"NAACL-HLT 2019: Demonstrations","author":"Ott Mott","year":"2019","unstructured":"Mott Ott, Sergey Edunov, Alexey Baevski, Angela Fan, Sam Gross, Nathan Ng, David Grangier, and Michael Auli. 2019. Fairseq. In NAACL-HLT 2019: Demonstrations (2019). https:\/\/github.com\/pytorch\/fairseq"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00012"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.23112"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00073"},{"key":"e_1_3_2_1_56_1","unstructured":"Qualys. 2017. Qualys Security Advisory: The Stack Clash. https:\/\/www.qualys.com\/2017\/06\/19\/stack-clash\/stack-clash.txt"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1710.09435"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140442"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3453483.3454035"},{"key":"e_1_3_2_1_60_1","volume-title":"Classes of recursively enumerable sets and their decision problems. 74, 2","author":"Rice Henry\u00a0Gordon","year":"1953","unstructured":"Henry\u00a0Gordon Rice. 1953. Classes of recursively enumerable sets and their decision problems. 74, 2 (1953), 358\u2013366."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93417-4_38"},{"key":"e_1_3_2_1_62_1","volume-title":"Proceedings of the USENIX Security Symposium (2013-08)","author":"Schwartz J","year":"2013","unstructured":"Edward\u00a0J Schwartz, JongHyup Lee, Maverick Woo, and David Brumley. 2013. Native X86 Decompilation Using Semantics-Preserving Structural Analysis and Iterative Control-Flow Structuring. In Proceedings of the USENIX Security Symposium (2013-08). 17."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3337167.3337175"},{"key":"e_1_3_2_1_64_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Chul\u00a0Richard Shin Eui","year":"2015","unstructured":"Eui Chul\u00a0Richard Shin, Dawn Song, and Reza Moazzezi. 2015. Recognizing Functions in Binaries with Neural Networks. In Proceedings of the USENIX Security Symposium (2015). 17."},{"key":"e_1_3_2_1_65_1","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. (2013)."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","unstructured":"Kai\u00a0Sheng Tai Richard Socher and Christopher\u00a0D. Manning. 2015. Improved Semantic Representations From Tree-Structured Long Short-Term Memory Networks. (2015). https:\/\/doi.org\/10.48550\/ARXIV.1503.00075","DOI":"10.48550\/ARXIV.1503.00075"},{"key":"e_1_3_2_1_67_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Tice Caroline","year":"2014","unstructured":"Caroline Tice, Tom Roeder, Peter Collingbourne, Stephen Checkoway, \u00dalfar Erlingsson, Luis Lozano, and Geoff Pike. 2014. Enforcing Forward-Edge Control-Flow Integrity in GCC & LLVM. In Proceedings of the USENIX Security Symposium (2014). 16."},{"key":"e_1_3_2_1_68_1","volume-title":"Proceedings of the Conference on Neural Information Processing Systems","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan\u00a0N Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention Is All You Need. In Proceedings of the Conference on Neural Information Processing Systems (2017). 11."},{"key":"e_1_3_2_1_69_1","unstructured":"Vector 35. 2016. Binary Ninja. Vector 35. https:\/\/binary.ninja"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2906934"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378470"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134018"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23185"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3056139"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484759"},{"key":"e_1_3_2_1_76_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Yu Sheng","year":"2022","unstructured":"Sheng Yu, Yu Qu, Xunchao Hu, and Heng Yin. 2022. DeepDi: Learning a Relational Graph Convolutional Network Model on Instructions for Fast and Accurate Disassembly. In Proceedings of the USENIX Security Symposium (2022). 17."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5466"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23492"}],"event":{"name":"RAID 2023: The 26th International Symposium on Research in Attacks, Intrusions and Defenses","location":"Hong Kong China","acronym":"RAID 2023"},"container-title":["Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3607199.3607200","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3607199.3607200","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:37:34Z","timestamp":1750178254000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3607199.3607200"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,16]]},"references-count":78,"alternative-id":["10.1145\/3607199.3607200","10.1145\/3607199"],"URL":"https:\/\/doi.org\/10.1145\/3607199.3607200","relation":{},"subject":[],"published":{"date-parts":[[2023,10,16]]},"assertion":[{"value":"2023-10-16","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}