{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,14]],"date-time":"2025-10-14T00:51:30Z","timestamp":1760403090460,"version":"build-2065373602"},"reference-count":29,"publisher":"Association for Computing Machinery (ACM)","issue":"4","funder":[{"name":"FARE","award":["PNRR M4.C2.1.1 PRIN 2022, Cod. 202225BZJC, CUP D53D23008380006, Avviso D.D 104 02.02.2022"],"award-info":[{"award-number":["PNRR M4.C2.1.1 PRIN 2022, Cod. 202225BZJC, CUP D53D23008380006, Avviso D.D 104 02.02.2022"]}]},{"name":"SETA","award":["PNRR M4.C2.1.1 PRIN 2022 PNRR, Cod. P202233M9Z, CUP F53D23009120001, Avviso D.D 1409 14.09.2022"],"award-info":[{"award-number":["PNRR M4.C2.1.1 PRIN 2022 PNRR, Cod. P202233M9Z, CUP F53D23009120001, Avviso D.D 1409 14.09.2022"]}]},{"name":"Italian NRRP MUR program funded by the European Union - NextGenerationEU"},{"name":"SERICS","award":["PE00000014"],"award-info":[{"award-number":["PE00000014"]}]},{"name":"MUR National Recovery and Resilience Plan","award":["PNRR M4.C2.1.3"],"award-info":[{"award-number":["PNRR M4.C2.1.3"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2025,11,30]]},"abstract":"<jats:p>\n            The complexities introduced by compiler optimization have long stood as a significant obstacle in binary analysis and reverse engineering. Function inlining, in particular, complicates function recognition by replacing function calls with the entire body of the callee, mixing code from multiple functions. State-of-the-art approaches can identify inlined functions at basic block granularity, but cannot determine which instructions belong to each function and precisely deduce inlined boundaries. Without this information, further analyses such as decompilation cannot be performed effectively. This article presents Highliner, a novel approach that improves state-of-the-art approaches by identifying inline instances at instruction-level granularity. Highliner operates downstream of block-level detectors: given basic blocks reported by state-of-the-art approaches as belonging to a specific inlined function, it labels each instruction as\n            <jats:italic toggle=\"yes\">Inlined<\/jats:italic>\n            or\n            <jats:italic toggle=\"yes\">Not inlined<\/jats:italic>\n            and recovers the inlined-function boundaries. We treat the problem as a sequence tagging task typical of NLP and implement a learning-based technique involving instruction embedding and recurrent neural networks. We compile a dataset of open-source projects with different optimizations and use the DWARF debug information standard to construct labeled sequences of inline instructions. We use this dataset to train, validate, and test a sequence labeling architecture in which instructions are encoded via the pre-trained assembly language transformer PalmTree and then processed by an RNN-based classifier to produce binary predictions. When evaluated as a binary classifier, Highliner achieves an F1-score of 0.94 overall. In addition, when specifically tested on recognizing function boundaries, Highliner achieves an Accuracy of 0.82 on initial boundaries and 0.83 on final boundaries.\n          <\/jats:p>","DOI":"10.1145\/3765521","type":"journal-article","created":{"date-parts":[[2025,9,2]],"date-time":"2025-09-02T10:48:37Z","timestamp":1756810117000},"page":"1-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Highliner: Enhancing Binary Analysis through NLP-Based Instruction-Level Detection of C++ Inline Functions"],"prefix":"10.1145","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-0274-7417","authenticated-orcid":false,"given":"Lorenzo","family":"Dall'Aglio","sequence":"first","affiliation":[{"name":"Politecnico di Milano","place":["Milan, Italy"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7476-0166","authenticated-orcid":false,"given":"Lorenzo","family":"Binosi","sequence":"additional","affiliation":[{"name":"Politecnico di Milano","place":["Milan, Italy"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8284-6074","authenticated-orcid":false,"given":"Michele","family":"Carminati","sequence":"additional","affiliation":[{"name":"DIPARTIMENTO DI ELETTRONICA, INFORMAZIONE E BIOINGENGERIA, POLITECNICO DI MILANO","place":["Milan, Italy"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4710-5283","authenticated-orcid":false,"given":"Stefano","family":"Zanero","sequence":"additional","affiliation":[{"name":"DIPARTIMENTO DI ELETTRONICA, INFORMAZIONE E BIOINGENGERIA, POLITECNICO DI MILANO","place":["Milan, Italy"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0925-2306","authenticated-orcid":false,"given":"Mario","family":"Polino","sequence":"additional","affiliation":[{"name":"DIPARTIMENTO DI ELETTRONICA, INFORMAZIONE E BIOINGENGERIA, POLITECNICO DI MILANO","place":["Milan, Italy"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,10,13]]},"reference":[{"key":"e_1_3_4_2_2","unstructured":"2017. Dwarf debugging information format version 5 published standard. February 21 2024. Retrieved from http:\/\/dwarfstd.org\/doc\/DWARF5.pdf"},{"key":"e_1_3_4_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3106572"},{"key":"e_1_3_4_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567975"},{"key":"e_1_3_4_5_2","volume-title":"Optimizing Compilers for Modern Architectures: A Dependence-based Approach","author":"Allen Randy","year":"2001","unstructured":"Randy Allen and Ken Kennedy. 2001. Optimizing Compilers for Modern Architectures: A Dependence-based Approach. Morgan Kaufmann."},{"key":"e_1_3_4_6_2","unstructured":"Stefano Bagarin. 2023. MemRec: Automatic recognition of inlined binary functions from template classes. (2023)."},{"key":"e_1_3_4_7_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-77560-7_26"},{"key":"e_1_3_4_8_2","doi-asserted-by":"publisher","DOI":"10.1016\/J.COSE.2023.103312"},{"key":"e_1_3_4_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/2950290.2950350"},{"key":"e_1_3_4_10_2","unstructured":"Jacob Devlin Ming-Wei Chang Kenton Lee and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv:1810.04805. Retrieved from https:\/\/arxiv.org\/abs\/1810.04805"},{"key":"e_1_3_4_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939719"},{"key":"e_1_3_4_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00003"},{"key":"e_1_3_4_13_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24311"},{"key":"e_1_3_4_14_2","unstructured":"Lorenzo Fratus. 2021. ByteMatcher: A tool for semantic equivalence of bytecode through symbolic execution. (2021)."},{"key":"e_1_3_4_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3240480"},{"key":"e_1_3_4_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3446371"},{"key":"e_1_3_4_17_2","volume-title":"Proceedings of the 33rd USENIX Security Symposium, USENIX Security 2024, Philadelphia, PA, USA, August 14-16, 2024","author":"He Haojie","year":"2024","unstructured":"Haojie He, Xingwei Lin, Ziang Weng, Ruijie Zhao, Shuitao Gan, Libo Chen, Yuede Ji, Jiashui Wang, and Zhi Xue. 2024. Code is not natural language: Unlock the power of semantics-oriented graph representation for binary code similarity detection. In Proceedings of the 33rd USENIX Security Symposium, USENIX Security 2024, Philadelphia, PA, USA, August 14-16, 2024. Davide Balzarotti and Wenyuan Xu (Eds.), USENIX Association. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/he-haojie"},{"key":"e_1_3_4_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3561385"},{"key":"e_1_3_4_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3561385"},{"key":"e_1_3_4_20_2","doi-asserted-by":"crossref","unstructured":"Ang Jia Ming Fan Xi Xu Wuxia Jin Haijun Wang and Ting Liu. 2024. Cross-inlining binary function similarity detection. arXiv:2401.05739. Retrieved from https:\/\/arxiv.org\/abs\/2401.05739","DOI":"10.1145\/3597503.3639080"},{"key":"e_1_3_4_21_2","unstructured":"Hyungjoon Koo Soyeon Park Daejin Choi and Taesoo Kim. 2021. Semantic-aware binary code representation with bert. arXiv:2106.05478. Retrieved from https:\/\/arxiv.org\/abs\/2106.05478"},{"key":"e_1_3_4_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484587"},{"key":"e_1_3_4_23_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-51476-0_24"},{"key":"e_1_3_4_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446695"},{"key":"e_1_3_4_25_2","first-page":"2099","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security 22)","author":"Marcelli Andrea","year":"2022","unstructured":"Andrea Marcelli, Mariano Graziano, Xabier Ugarte-Pedrero, Yanick Fratantonio, Mohamad Mansouri, and Davide Balzarotti. 2022. How machine learning is solving the binary function similarity problem. In Proceedings of the 31st USENIX Security Symposium (USENIX Security 22). 2099\u20132116."},{"key":"e_1_3_4_26_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-58469-0_23"},{"key":"e_1_3_4_27_2","first-page":"2479","volume-title":"Proceedings of the 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10-12, 2022","author":"Pang Chengbin","year":"2022","unstructured":"Chengbin Pang, Tiantai Zhang, Ruotong Yu, Bing Mao, and Jun Xu. 2022. Ground truth for binary disassembly is not easy. In Proceedings of the 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10-12, 2022. Kevin R. B. Butler and Kurt Thomas (Eds.), USENIX Association, 2479\u20132495. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/pang-chengbin"},{"key":"e_1_3_4_28_2","unstructured":"Kexin Pei Zhou Xuan Junfeng Yang Suman Jana and Baishakhi Ray. 2020. Trex: Learning execution semantics from micro-traces for binary similarity. arXiv:2012.08680. Retrieved from https:\/\/arxiv.org\/abs\/2012.08680"},{"key":"e_1_3_4_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.17"},{"key":"e_1_3_4_30_2","article-title":"Attention is all you need","volume":"30","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N. Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. Advances in Neural Information Processing Systems 30 (2017).","journal-title":"Advances in Neural Information Processing Systems"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3765521","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T14:33:25Z","timestamp":1760366005000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3765521"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,13]]},"references-count":29,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,11,30]]}},"alternative-id":["10.1145\/3765521"],"URL":"https:\/\/doi.org\/10.1145\/3765521","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"type":"print","value":"2471-2566"},{"type":"electronic","value":"2471-2574"}],"subject":[],"published":{"date-parts":[[2025,10,13]]},"assertion":[{"value":"2025-03-14","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-08-19","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-10-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}