{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:34:41Z","timestamp":1783611281658,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,25]]},"DOI":"10.1145\/3708821.3736207","type":"proceedings-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T06:30:56Z","timestamp":1755066656000},"page":"1724-1740","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Enhancing Binary Code Similarity Analysis for Software Updates: A Contextual Diffing Framework"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-9588-7096","authenticated-orcid":false,"given":"August","family":"See","sequence":"first","affiliation":[{"name":"Universit\u00e4t Hamburg, Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-6428-4718","authenticated-orcid":false,"given":"Moritz","family":"M\u00f6nnich","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Hamburg, Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6254-8288","authenticated-orcid":false,"given":"Mathias","family":"Fischer","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Hamburg, Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,8,24]]},"reference":[{"key":"e_1_3_3_2_2_2","doi-asserted-by":"publisher","unstructured":"Saed Alrabaee Lingyu Wang and Mourad Debbabi. 2016. BinGold: Towards robust binary analysis by extracting the semantics of binary code as semantic flow graphs (SFGs). Digital Investigation 18 (2016) S11\u2013S22. 10.1016\/j.diin.2016.04.002","DOI":"10.1016\/j.diin.2016.04.002"},{"key":"e_1_3_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/2430553.2430557"},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"crossref","unstructured":"S\u00a0Sibi Chakkaravarthy D Sangeetha and V Vaidehi. 2019. A survey on malware analysis and mitigation techniques. Computer Science Review 32 (2019) 1\u201323.","DOI":"10.1016\/j.cosrev.2019.01.002"},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/2950290.2950350"},{"key":"e_1_3_3_2_6_2","volume-title":"30th Usenix Security Sympoisum","author":"Cheng Binlin","year":"2021","unstructured":"Binlin Cheng, Ming Jiang, Erika Leal, Haotian Zhang, Jianming Fu, Guojun Peng, and Jean-Yves Marion. 2021. Obfuscation-resilient executable payload extraction from packed malware. In 30th Usenix Security Sympoisum."},{"key":"e_1_3_3_2_7_2","unstructured":"Clearblue. 2023. Ghidriff: Ghidra Binary Diffing Engine. https:\/\/clearbluejar.github.io\/posts\/ghidriff-ghidra-binary-diffing-engine\/. Accessed: 2024-08-15."},{"key":"e_1_3_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420997"},{"key":"e_1_3_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939719"},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00003"},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24311"},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23296"},{"key":"e_1_3_3_2_13_2","volume-title":"Automated attacker correlation for malicious code","author":"Dullien Thomas","year":"2010","unstructured":"Thomas Dullien, Ero Carrera, Soeren-Meyer Eppler, and Sebastian Porst. 2010. Automated attacker correlation for malicious code. Technical Report. BOCHUM UNIV (GERMANY FR)."},{"key":"e_1_3_3_2_14_2","unstructured":"Thomas Dullien and Rolf Rolles. 2005. Graph-based comparison of executable objects (english version). SSTIC 5 (01 2005)."},{"key":"e_1_3_3_2_15_2","first-page":"303","volume-title":"23rd USENIX Security Symposium Security 14)","author":"Egele Manuel","year":"2014","unstructured":"Manuel Egele, Maverick Woo, Peter Chapman, and David Brumley. 2014. Blanket execution: Dynamic similarity testing for program binaries and components. In 23rd USENIX Security Symposium Security 14). 303\u2013317."},{"key":"e_1_3_3_2_16_2","first-page":"161","volume-title":"Detection of intrusions and malware & vulnerability assessment, GI SIG SIDAR workshop, DIMVA 2004","author":"Flake Halvar","year":"2004","unstructured":"Halvar Flake. 2004. Structural comparison of executable objects. In Detection of intrusions and malware & vulnerability assessment, GI SIG SIDAR workshop, DIMVA 2004, Ulrich Flegel and Michael Meier (Eds.). Gesellschaft f\u00fcr Informatik e.V., Bonn, 161\u2013173."},{"key":"e_1_3_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88625-9_16"},{"key":"e_1_3_3_2_18_2","doi-asserted-by":"publisher","unstructured":"Irfan\u00a0Ul Haq and Juan Caballero. 2021. A Survey of Binary Code Similarity. ACM Comput. Surv. 54 3 Article 51 (April 2021) 38\u00a0pages. 10.1145\/3446371","DOI":"10.1145\/3446371"},{"key":"e_1_3_3_2_19_2","unstructured":"Austin Heath. [n. d.]. Binary diffing tools. https:\/\/one2bla.me\/the-dark-arts\/reverse-engineering\/binary-diffing-tools.html. Accessed: 2024-08-15."},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3052974"},{"key":"e_1_3_3_2_21_2","unstructured":"Alissa Irei. 2022. An introduction to binary diffing for ethical hackers. https:\/\/www.techtarget.com\/searchsecurity\/feature\/An-introduction-to-binary-diffing-for-ethical-hackers. Accessed: 2024-08-15."},{"key":"e_1_3_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2010.5665794"},{"key":"e_1_3_3_2_23_2","unstructured":"Dongkwan Kim Eunsoo Kim Sang\u00a0Kil Cha Sooel Son and Yongdae Kim. 2022. Revisiting binary code similarity analysis using interpretable feature engineering and lessons learned. IEEE Transactions on Software Engineering (2022)."},{"key":"e_1_3_3_2_24_2","volume-title":"Machine Learning for Program Aanalysis (MLPA) Workshop","author":"Koo Hyungjoon","year":"2021","unstructured":"Hyungjoon Koo, Soyeon Park, and Taesoo Kim. 2021. Revisiting Function Identification with Machine Learning. In Machine Learning for Program Aanalysis (MLPA) Workshop."},{"key":"e_1_3_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/2430553.2430558"},{"key":"e_1_3_3_2_26_2","series-title":"(ICML\u201914)","first-page":"II\u20131188\u2013II\u20131196","volume-title":"Proceedings of the 31st International Conference on International Conference on Machine Learning - Volume 32","author":"Le Quoc","year":"2014","unstructured":"Quoc Le and Tomas Mikolov. 2014. Distributed Representations of Sentences and Documents. In Proceedings of the 31st International Conference on International Conference on Machine Learning - Volume 32 (Beijing, China) (ICML\u201914). JMLR.org, II\u20131188\u2013II\u20131196."},{"key":"e_1_3_3_2_27_2","first-page":"3835","volume-title":"International conference on machine learning","author":"Li Yujia","year":"2019","unstructured":"Yujia Li, Chenjie Gu, Thomas Dullien, Oriol Vinyals, and Pushmeet Kohli. 2019. Graph matching networks for learning the similarity of graph structured objects. In International conference on machine learning. PMLR, 3835\u20133845."},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24415"},{"key":"e_1_3_3_2_29_2","first-page":"2099","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Marcelli Andrea","year":"2022","unstructured":"Andrea Marcelli, Mariano Graziano, Xabier Ugarte-Pedrero, Yanick Fratantonio, Mohamad Mansouri, and Davide Balzarotti. 2022. How machine learning is solving the binary function similarity problem. In 31st USENIX Security Symposium (USENIX Security 22). 2099\u20132116."},{"key":"e_1_3_3_2_30_2","first-page":"309","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"Massarelli Luca","year":"2019","unstructured":"Luca Massarelli, Giuseppe\u00a0Antonio Di\u00a0Luna, Fabio Petroni, Roberto Baldoni, and Leonardo Querzoni. 2019. SAFE: Self-Attentive Function Embeddings for Binary Similarity. In Detection of Intrusions and Malware, and Vulnerability Assessment, Roberto Perdisci, Clementine Maurice, Giorgio Giacinto, and Magnus Almgren (Eds.). Springer International Publishing, Cham, 309\u2013329."},{"key":"e_1_3_3_2_31_2","unstructured":"Tomas Mikolov Ilya Sutskever Kai Chen Greg\u00a0S Corrado and Jeff Dean. 2013. Distributed representations of words and phrases and their compositionality. Advances in neural information processing systems 26 (2013)."},{"key":"e_1_3_3_2_32_2","series-title":"(SEC\u201917)","first-page":"253","volume-title":"Proceedings of the 26th USENIX Conference on Security Symposium","author":"Ming Jiang","year":"2017","unstructured":"Jiang Ming, Dongpeng Xu, Yufei Jiang, and Dinghao Wu. 2017. BinSim: Trace-Based Semantic Binary Diffing via System Call Sliced Segment Equivalence Checking. In Proceedings of the 26th USENIX Conference on Security Symposium (Vancouver, BC, Canada) (SEC\u201917). USENIX Association, USA, 253\u2013270."},{"key":"e_1_3_3_2_33_2","unstructured":"Alex Petrov. 2023. Plugin focus: Diaphora. https:\/\/hex-rays.com\/blog\/plugin-focus-diaphora\/. Accessed: 2024-08-15."},{"key":"e_1_3_3_2_34_2","unstructured":"radareorg. 2024. The Official Radare2 Book (3rd edition). https:\/\/book.rada.re\/tools\/radiff2\/binary_diffing.html. Accessed: 2024-08-15."},{"key":"e_1_3_3_2_35_2","unstructured":"John\u00a0W Ratcliff and David\u00a0E Metzener. 1988. Pattern matching: the gestalt approach. Dr Dobbs Journal 13 7 (1988) 46. https:\/\/web.archive.org\/web\/20200209031652\/https:\/\/www.drdobbs.com\/database\/pattern-matching-the-gestalt-approach\/184407970"},{"key":"e_1_3_3_2_36_2","unstructured":"Ole Andr\u00e9\u00a0Vadla Ravn\u00e5s. 2020. Frida \u2022 A World-Class Dynamic Instrumentation Toolkit. https:\/\/frida.re\/ visited 2023-06-26."},{"key":"e_1_3_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17143-7_6"},{"key":"e_1_3_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627139"},{"key":"e_1_3_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3678890.3678918"},{"key":"e_1_3_3_2_40_2","doi-asserted-by":"crossref","unstructured":"Anastasia Shuba and Athina Markopoulou. 2020. Nomoats: Towards automatic detection of mobile tracking. Proceedings on Privacy Enhancing Technologies 2020 2 (2020).","DOI":"10.2478\/popets-2020-0017"},{"key":"e_1_3_3_2_41_2","doi-asserted-by":"crossref","unstructured":"Rahim Taheri Meysam Ghahramani Reza Javidan Mohammad Shojafar Zahra Pooranian and Mauro Conti. 2020. Similarity-based Android malware detection using Hamming distance of static binary features. Future Generation Computer Systems 105 (2020) 230\u2013247.","DOI":"10.1016\/j.future.2019.11.034"},{"key":"e_1_3_3_2_42_2","first-page":"3789","volume-title":"31st USENIX security symposium (USENIX security 22)","author":"Trimananda Rahmadi","year":"2022","unstructured":"Rahmadi Trimananda, Hieu Le, Hao Cui, Janice\u00a0Tran Ho, Anastasia Shuba, and Athina Markopoulou. 2022. { OVRseen} : Auditing Network Traffic and Privacy Policies in Oculus { VR}. In 31st USENIX security symposium (USENIX security 22). 3789\u20133806."},{"key":"e_1_3_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534367"},{"key":"e_1_3_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.5555\/3155562.3155606"},{"key":"e_1_3_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1145\/3395363.3397361"},{"key":"e_1_3_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/RE.2005.61"},{"key":"e_1_3_3_2_47_2","unstructured":"Zynamics. [n. d.]. Zynamics.Com - BinDiff. https:\/\/www.zynamics.com\/bindiff.html visited 2022-09-08."}],"event":{"name":"ASIA CCS '25: 20th ACM Asia Conference on Computer and Communications Security","location":"Hanoi Vietnam","acronym":"ASIA CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 20th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708821.3736207","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T07:28:43Z","timestamp":1755070123000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708821.3736207"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,24]]},"references-count":46,"alternative-id":["10.1145\/3708821.3736207","10.1145\/3708821"],"URL":"https:\/\/doi.org\/10.1145\/3708821.3736207","relation":{},"subject":[],"published":{"date-parts":[[2025,8,24]]},"assertion":[{"value":"2025-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}