{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T10:11:52Z","timestamp":1783764712540,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":55,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,12]],"date-time":"2026-04-12T00:00:00Z","timestamp":1775952000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,12]]},"DOI":"10.1145\/3786583.3786873","type":"proceedings-article","created":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T09:12:14Z","timestamp":1783761134000},"page":"292-302","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["CASCADE: LLM-powered JavaScript Deobfuscator at Google"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-0466-1028","authenticated-orcid":false,"given":"Shan","family":"Jiang","sequence":"first","affiliation":[{"name":"The University of Texas at Austin, Austin, Texas, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4621-638X","authenticated-orcid":false,"given":"Pranoy","family":"Kovuri","sequence":"additional","affiliation":[{"name":"Google Inc, Sunnyvale, California, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2440-4389","authenticated-orcid":false,"given":"David","family":"Tao","sequence":"additional","affiliation":[{"name":"Google Inc, Sunnyvale, California, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-7120-4907","authenticated-orcid":false,"given":"Zhixun","family":"Tan","sequence":"additional","affiliation":[{"name":"Google Inc, Sunnyvale, California, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,11]]},"reference":[{"key":"e_1_3_3_1_2_2","unstructured":"2008. V8 JavaScript engine. https:\/\/github.com\/v8\/v8."},{"key":"e_1_3_3_1_3_2","unstructured":"2013. YARA: The pattern matching swiss knife for malware researchers (and everyone else). https:\/\/virustotal.github.io\/yara."},{"key":"e_1_3_3_1_4_2","unstructured":"2016. JavaScript-obfuscator: A Powerful Obfuscator for JavaScript and Node.js. https:\/\/github.com\/javascript-obfuscator\/javascript-obfuscator."},{"key":"e_1_3_3_1_5_2","unstructured":"2019. QuickJS JavaScript Engine. https:\/\/github.com\/bellard\/quickjs."},{"key":"e_1_3_3_1_6_2","unstructured":"2021. JavaScript Deobfuscator - General purpose JavaScript deobfuscator. https:\/\/github.com\/ben-sb\/javascript-deobfuscator."},{"key":"e_1_3_3_1_7_2","unstructured":"2021. JS-Confuser. https:\/\/github.com\/MichaelXF\/js-confuser."},{"key":"e_1_3_3_1_8_2","unstructured":"2022. webcrack - a tool for reverse engineering javascript. https:\/\/github.com\/j4k0xb\/webcrack."},{"key":"e_1_3_3_1_9_2","unstructured":"2024. JSIR - An MLIR-based JavaScript Intermediate Representation. https:\/\/github.com\/google\/jsir."},{"key":"e_1_3_3_1_10_2","unstructured":"2024. Now You See Me Now You Don\u2019t: Using LLMs to Obfuscate Malicious JavaScript. https:\/\/unit42.paloaltonetworks.com\/using-llms-obfuscate-malicious-javascript\/."},{"key":"e_1_3_3_1_11_2","unstructured":"2024. Synchrony - A simple deobfuscator for mangled or obfuscated JavaScript files. https:\/\/github.com\/relative\/synchrony."},{"key":"e_1_3_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3098954.3107009"},{"key":"e_1_3_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-C.2017.79"},{"key":"e_1_3_3_1_14_2","volume-title":"CCS","author":"Bichsel Benjamin","year":"2016","unstructured":"Benjamin Bichsel, Veselin Raychev, Petar Tsankov, and Martin Vechev. 2016. Statistical Deobfuscation of Android Applications. In CCS."},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/WAINA.2012.140"},{"key":"e_1_3_3_1_16_2","doi-asserted-by":"crossref","unstructured":"Kenneth Brezinski and Ken Ferens. 2023. Metamorphic malware and obfuscation: a survey of techniques variants and generation kits. Security and Communication Networks (2023).","DOI":"10.1155\/2023\/8227751"},{"key":"e_1_3_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3719027.3744871"},{"key":"e_1_3_3_1_18_2","unstructured":"Gheorghe Comanici Eric Bieber Mike Schaekermann Ice Pasupat Noveen Sachdeva Inderjit Dhillon Marcel Blistein Ori Ram Dan Zhang Evan Rosen et\u00a0al. 2025. Gemini 2.5: Pushing the Frontier with Advanced Reasoning Multimodality Long Context and Next Generation Agentic Capabilities. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2507.06261 (2025)."},{"key":"e_1_3_3_1_19_2","volume-title":"SEC","author":"Curtsinger Charlie","year":"2011","unstructured":"Charlie Curtsinger, Benjamin Livshits, Benjamin Zorn, and Christian Seifert. 2011. ZOZZLE: fast and precise in-browser JavaScript malware detection. In SEC."},{"key":"e_1_3_3_1_20_2","doi-asserted-by":"crossref","unstructured":"Tony Doyle. 2018. Privacy obfuscation and propertization. IFLA Journal (2018).","DOI":"10.1177\/0340035218778054"},{"key":"e_1_3_3_1_21_2","volume-title":"CCS","author":"Fass Aurore","year":"2019","unstructured":"Aurore Fass, Michael Backes, and Ben Stock. 2019. HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTs. In CCS."},{"key":"e_1_3_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCNC.2018.8390365"},{"key":"e_1_3_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-short.8"},{"key":"e_1_3_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/2950290.2950308"},{"key":"e_1_3_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM51674.2020.00029"},{"key":"e_1_3_3_1_26_2","unstructured":"Yang Hong Shan Jiang Yulei Fu and Sarfraz Khurshid. 2025. On the Effectiveness of Large Language Models in Writing Alloy Formulas. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2502.15441 (2025)."},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3691620.3695492"},{"key":"e_1_3_3_1_28_2","unstructured":"Shan Jiang Chenguang Zhu and Sarfraz Khurshid. 2024. Generating executable oracles to check conformance of client code to requirements of JDK Javadocs using LLMs. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2411.01789 (2024)."},{"key":"e_1_3_3_1_29_2","unstructured":"Shan Jiang Chenguang Zhu and Sarfraz Khurshid. 2025. OBsmith: Testing JavaScript Obfuscator using LLM-powered sketching. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2510.10066 (2025)."},{"key":"e_1_3_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/CGO51591.2021.9370308"},{"key":"e_1_3_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23319"},{"key":"e_1_3_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00110"},{"key":"e_1_3_3_1_33_2","doi-asserted-by":"crossref","unstructured":"Kaibo Liu Zhenpeng Chen Yiyang Liu Jie\u00a0M Zhang Mark Harman Yudong Han Yun Ma Yihong Dong Ge Li and Gang Huang. 2025. LLM-powered test case generation for detecting bugs in plausible programs. ACL (2025).","DOI":"10.18653\/v1\/2025.acl-long.20"},{"key":"e_1_3_3_1_34_2","unstructured":"Anton Lozhkov Raymond Li Loubna\u00a0Ben Allal Federico Cassano Joel Lamy-Poirier Nouamane Tazi Ao Tang Dmytro Pykhtar Jiawei Liu Yuxiang Wei et\u00a0al. 2024. Starcoder 2 and the stack v2: The next generation. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2402.19173 (2024)."},{"key":"e_1_3_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/SERE.2012.13"},{"key":"e_1_3_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24676-3_2"},{"key":"e_1_3_3_1_37_2","doi-asserted-by":"crossref","unstructured":"Davide Maiorca Davide Ariu Igino Corona Marco Aresu and Giorgio Giacinto. 2015. Stealth attacks: An extended insight into the obfuscation effects on Android malware. Computers & Security (2015).","DOI":"10.1016\/j.cose.2015.02.007"},{"key":"e_1_3_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639187"},{"key":"e_1_3_3_1_39_2","doi-asserted-by":"crossref","unstructured":"Samuel Ndichu Sangwook Kim Seiichi Ozawa Takeshi Misu and Kazuo Makishima. 2019. A machine learning approach to detection of JavaScript-based attacks using AST features and paragraph vectors. Applied Soft Computing (2019).","DOI":"10.1016\/j.asoc.2019.105721"},{"key":"e_1_3_3_1_40_2","doi-asserted-by":"crossref","unstructured":"Stoyan Nikolov Daniele Codecasa Anna Sjovall Maxim Tabachnyk Satish Chandra Siddharth Taneja and Celal Ziftci. 2025. How is Google using AI for internal code migrations? ICSE (2025).","DOI":"10.1109\/ICSE-SEIP66354.2025.00048"},{"key":"e_1_3_3_1_41_2","unstructured":"Nikolaos Pantelaios and Alexandros Kapravelos. 2024. FV8: A Forced Execution JavaScript Engine for Detecting Evasive Techniques. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2405.13175 (2024)."},{"key":"e_1_3_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416632"},{"key":"e_1_3_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN58367.2023.00040"},{"key":"e_1_3_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598146"},{"key":"e_1_3_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN58367.2023.00041"},{"key":"e_1_3_3_1_46_2","doi-asserted-by":"crossref","unstructured":"Jonan Richards and Mairieli Wessel. 2024. What You Need is What You Get: Theory of Mind for an LLM-Based Code Understanding Assistant.","DOI":"10.1109\/ICSME58944.2024.00070"},{"key":"e_1_3_3_1_47_2","doi-asserted-by":"crossref","unstructured":"Rylan Schaeffer Brando Miranda and Sanmi Koyejo. 2024. Are emergent abilities of large language models a mirage? NeurIPS (2024).","DOI":"10.52202\/075280-2425"},{"key":"e_1_3_3_1_48_2","volume-title":"USENIX Security","author":"Schloegel Moritz","year":"2022","unstructured":"Moritz Schloegel, Tim Blazytko, Moritz Contag, Cornelius Aschermann, Julius Basler, Thorsten Holz, and Ali Abbasi. 2022. Loki: Hardening Code Obfuscation Against Automated Attacks. In USENIX Security."},{"key":"e_1_3_3_1_49_2","volume-title":"ICLR","author":"Szafraniec Marc","year":"2023","unstructured":"Marc Szafraniec, Baptiste Roziere, Hugh\u00a0James Leather, Patrick Labatut, Francois Charton, and Gabriel Synnaeve. 2023. Code Translation with Compiler Representations. In ICLR."},{"key":"e_1_3_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598061"},{"key":"e_1_3_3_1_51_2","unstructured":"Zheng Yuan Hongyi Yuan Chuanqi Tan Wei Wang and Songfang Huang. 2023. How well do large language models perform in arithmetic tasks? arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2304.02015 (2023)."},{"key":"e_1_3_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/3293882.3330563"},{"key":"e_1_3_3_1_53_2","doi-asserted-by":"crossref","unstructured":"Xiaolu Zhang Frank Breitinger Engelbert Luechinger and Stephen O\u2019Shaughnessy. 2021. Android application forensics: A survey of obfuscation obfuscation detection and deobfuscation techniques and their impact on investigations. Forensic Science International: Digital Investigation (2021).","DOI":"10.1016\/j.fsidi.2021.301285"},{"key":"e_1_3_3_1_54_2","volume-title":"ACL","author":"Zhao Yilun","year":"2024","unstructured":"Yilun Zhao, Yitao Long, Hongjun Liu, Ryo Kamoi, Linyong Nan, Lyuhao Chen, Yixin Liu, Xiangru Tang, Rui Zhang, and Arman Cohan. 2024. Docmath-eval: Evaluating math reasoning capabilities of llms in understanding financial documents. In ACL."},{"key":"e_1_3_3_1_55_2","unstructured":"Hua Zhong Shan Jiang and Sarfraz Khurshid. 2025. An approach for API synthesis using large language models. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2502.15246 (2025)."},{"key":"e_1_3_3_1_56_2","unstructured":"Hua Zhong Shan Jiang and Sarfraz Khurshid. 2025. APRIL: API Synthesis with Automatic Prompt Optimization and Reinforcement Learning. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2509.25196 (2025)."}],"event":{"name":"ICSE-SEIP '26: 2026 IEEE\/ACM 48th International Conference on Software Engineering","location":"Rio de Janeiro Brazil","acronym":"ICSE-SEIP '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS","Faculty of Engineering of University of Porto"]},"container-title":["Proceedings of the IEEE\/ACM 48th International Conference on Software Engineering: Software Engineering in Practice"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3786583.3786873","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T09:16:31Z","timestamp":1783761391000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3786583.3786873"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":55,"alternative-id":["10.1145\/3786583.3786873","10.1145\/3786583"],"URL":"https:\/\/doi.org\/10.1145\/3786583.3786873","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-07-11","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}