{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:58:00Z","timestamp":1782845880224,"version":"3.54.5"},"reference-count":70,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["No. 62402423"],"award-info":[{"award-number":["No. 62402423"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["No. 226202400143"],"award-info":[{"award-number":["No. 226202400143"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Binary code similarity detection (BCSD) serves as a fundamental technique for various software engineering tasks, e.g., vulnerability detection and classification. Attacks against such BCSD models have therefore drawn extensive attention, aiming at misleading the models to generate erroneous predictions. Prior works have explored various approaches to generating semantic-preserving variants, i.e., adversarial samples, to evaluate the robustness of the models against adversarial attacks. However, they have mainly relied on heuristic criteria or iterative greedy algorithms to locate salient code influencing the model output, which often leads to inefficient search and high computational cost. Moreover, when processing programs with high complexities, such attacks tend to be time-consuming.<\/jats:p>\n                  <jats:p>In this work, we unveil the fragility of BCSD models through a novel attack framework guided by model explanations. In particular, we focus on targeted attacks where the attack goal is to mislead the model\u2019s predictions to a specific target. Our attack leverages explainers to pinpoint critical code snippet for perturbations, reducing the exploration overhead. The evaluation results demonstrate that the proposed attacks effectively improve the attack efficiency, while maintaining comparable or higher success rates. Importantly, the speedup for perturbation target selection achieves up to 63.66\u00d7, demonstrating the practical value of explanation-guided localization. Our real-world case studies on vulnerability detection and classification further demonstrate the security implications of our attacks, highlighting fundamental robustness limitations in current BCSD models, and the urgent need for more robust designs.<\/jats:p>","DOI":"10.1145\/3808188","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:06:14Z","timestamp":1782839174000},"page":"4116-4139","source":"Crossref","is-referenced-by-count":0,"title":["Unveiling the Fragility of Binary Code Similarity Detection via Targeted Attacks with Model Explanations"],"prefix":"10.1145","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-6103-5681","authenticated-orcid":false,"given":"Mingjie","family":"Chen","sequence":"first","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-5323-1562","authenticated-orcid":false,"given":"Tiancheng","family":"Zhu","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8863-8751","authenticated-orcid":false,"given":"Mingxue","family":"Zhang","sequence":"additional","affiliation":[{"name":"Zhejiang University, The State Key Laboratory of Blockchain and Data Security, Hangzhou, China"},{"name":"Hangzhou High-Tech Zone (Binjiang) Institute of Blockchain and Data Security, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5977-1489","authenticated-orcid":false,"given":"Yiling","family":"He","sequence":"additional","affiliation":[{"name":"University College London, London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5776-4789","authenticated-orcid":false,"given":"Minghao","family":"Lin","sequence":"additional","affiliation":[{"name":"Independent Researcher, Los Angeles, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3077-5697","authenticated-orcid":false,"given":"Penghui","family":"Li","sequence":"additional","affiliation":[{"name":"Columbia University, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3441-6277","authenticated-orcid":false,"given":"Kui","family":"Ren","sequence":"additional","affiliation":[{"name":"Zhejiang University, The State Key Laboratory of Blockchain and Data Security, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"2025. Angr. https:\/\/github.com\/angr\/angr."},{"key":"e_1_2_1_2_1","unstructured":"2025. National Vulnerability Database (NVD). https:\/\/nvd.nist.gov\/."},{"key":"e_1_2_1_3_1","unstructured":"2025. Radare2. https:\/\/github.com\/radareorg\/radare2."},{"key":"e_1_2_1_4_1","unstructured":"2025. Software Assurance Reference Dataset (SARD). https:\/\/samate.nist.gov\/SARD\/."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3264418"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/access.2024.3488204"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/eurosp63326.2025.00060"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","unstructured":"Mingjie Chen Tiancheng Zhu Mingxue Zhang Yiling He Minghao Lin Penghui Li and Kui Ren. 2026. Artifact for \"Unveiling the Fragility of Binary Code Similarity Detection via Targeted Attacks with Model Explanations\". doi:10.5281\/zenodo.19709683 10.5281\/zenodo.19709683","DOI":"10.5281\/zenodo.19709683"},{"key":"e_1_2_1_10_1","unstructured":"Mingjie Chen Tiancheng Zhu Mingxue Zhang Yiling He Minghao Lin Penghui Li and Kui Ren. 2026. Explainer- Guided-Adv-Attack-BCSD (Code Repository). https:\/\/github.com\/zju-ws-seclab\/Explainer-Guided-Adv-Attack-BCSD. GitHub repository."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598051"},{"key":"e_1_2_1_12_1","unstructured":"CVE. 2025. CWE Top 25 Most Dangerous Software Weaknesses. https:\/\/cwe.mitre.org\/top25\/."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3672608.3707944"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3428206"},{"key":"e_1_2_1_15_1","unstructured":"FFmpeg. https:\/\/ffmpeg.org\/. Accessed: 2025-05-30."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3392391"},{"key":"e_1_2_1_17_1","unstructured":"Gsl. https:\/\/www.gnu.org\/software\/gsl\/. Accessed: 2025-05-30."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243792"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2513228.2513294"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2022.3168285"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616599"},{"key":"e_1_2_1_22_1","unstructured":"Hex-Rays. [n. d.]."},{"key":"e_1_2_1_23_1","unstructured":"IDA Pro. https:\/\/www.hex-rays.com\/products\/ida\/. Accessed: 2025-05-30."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2208.14191"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-emnlp.673"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639100"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"e_1_2_1_28_1","unstructured":"junk code. 2021. Foudation of CTF reverse engineering. https:\/\/blog.csdn.net\/u011642058\/article\/details\/114757503."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.23919\/EUSIPCO.2018.8553214"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1802.04528"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484587"},{"key":"e_1_2_1_33_1","volume-title":"International conference on machine learning. PMLR, 3835-3845","author":"Li Yujia","year":"2019","unstructured":"Yujia Li, Chenjie Gu, Thomas Dullien, Oriol Vinyals, and Pushmeet Kohli. 2019. Graph matching networks for learning the similarity of graph structured objects. In International conference on machine learning. PMLR, 3835-3845."},{"key":"e_1_2_1_34_1","unstructured":"Libconfig Project. [n. d.]. Libconfig. https:\/\/github.com\/hyperrealm\/libconfig. Accessed: 2025-05-30."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453086"},{"key":"e_1_2_1_36_1","first-page":"I","article-title":"A Unified Approach to Interpreting Model Predictions","volume":"30","author":"Lundberg Scott M","year":"2017","unstructured":"Scott M Lundberg and Su-In Lee. 2017. A Unified Approach to Interpreting Model Predictions. In Advances in Neural Information Processing Systems 30, I. Guyon, U. V. Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett (Eds.). Curran Associates, Inc., 4765-4774. https:\/\/proceedings.neurips.cc\/paper\/2017\/hash\/ 8a20a8621978632d76c43dfd28b67767-Abstract.html","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_2_1_37_1","first-page":"400","article-title":"Parameterized explainer for graph neural network","volume":"33","author":"Luo Dongsheng","year":"2020","unstructured":"Dongsheng Luo, Wei Cheng, Dongkuan Xu, Wenchao Yu, Bo Zong, Haifeng Chen, and Xiang Zhang. 2020. Parameterized explainer for graph neural network. In Advances in Neural Information Processing Systems (NeurIPS), Vol. 33. 400-411. https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/e37b08dd3015330dcbb5d6663667b8b8-Abstract.html","journal-title":"Advances in Neural Information Processing Systems (NeurIPS)"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2017.2655046"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2021.3051852"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1273442.1250746"},{"key":"e_1_2_1_41_1","unstructured":"OpenSSL Project. [n. d.]. OpenSSL: The Open Source Toolkit for SSL\/TLS. https:\/\/www.openssl.org\/. Accessed: 2025-05-30."},{"key":"e_1_2_1_42_1","volume-title":"Proceedings of the 36th International Conference on Machine Learning (ICML) (Proceedings of Machine Learning Research","volume":"4979","author":"Pang Tianyu","year":"2019","unstructured":"Tianyu Pang, Kun Xu, Chao Du, Ning Chen, and Jun Zhu. 2019. Improving Adversarial Robustness via Promoting Ensemble Diversity. In Proceedings of the 36th International Conference on Machine Learning (ICML) (Proceedings of Machine Learning Research, Vol. 97). 4970-4979."},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/eurosp.2016.36"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2022.3231621"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/sp40000.2020.00073"},{"key":"e_1_2_1_46_1","unstructured":"Postgresql Project. [n. d.]. Postgresql. https:\/\/www.postgresql.org\/. Accessed: 2025-05-30."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3579856.3582818"},{"key":"e_1_2_1_48_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Quiring Erwin","year":"2019","unstructured":"Erwin Quiring, Alwin Maier, and Konrad Rieck. 2019. Misleading authorship attribution of source code using adversarial learning. In 28th USENIX Security Symposium (USENIX Security 19). 479-496. https:\/\/www.usenix.org\/conference\/ usenixsecurity19\/presentation\/quiring"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/p19-1103"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939778"},{"key":"e_1_2_1_51_1","volume-title":"30th USENIX security symposium (USENIX security 21). 1487-1504.","author":"Severi Giorgio","unstructured":"Giorgio Severi, Jim Meyer, Scott Coull, and Alina Oprea. 2021. {Explanation-Guided} backdoor poisoning attacks against malware classifiers. In 30th USENIX security symposium (USENIX security 21). 1487-1504."},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3264820.3264821"},{"key":"e_1_2_1_53_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Shimmi Samiha","year":"2024","unstructured":"Samiha Shimmi, Ashiqur Rahman, Mohan Gadde, Hamed Okhravi, and Mona Rahimi. 2024. {VulSim}: Leveraging Similarity of {Multi-Dimensional} Neighbor Embeddings for Vulnerability Detection. In 33rd USENIX Security Symposium (USENIX Security 24). 1777-1794. https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/shimmi"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3497768"},{"key":"e_1_2_1_55_1","unstructured":"Sqlite Project. [n. d.]."},{"key":"e_1_2_1_56_1","unstructured":"Sqlite. https:\/\/www.sqlite.org\/. Accessed: 2025-05-30."},{"key":"e_1_2_1_57_1","volume-title":"Proceedings of the 44th International Conference on Software Engineering (ICSE). ACM, 1-12","author":"Sun Zeyu","year":"2022","unstructured":"Zeyu Sun, Changjian Li, Junda Yao, Yin Wang, Qingshan Zheng, and Yang Liu. 2022. Understanding and Improving Graph Neural Networks for Vulnerability Detection. In Proceedings of the 44th International Conference on Software Engineering (ICSE). ACM, 1-12."},{"key":"e_1_2_1_58_1","unstructured":"Vector 35 Inc. [n. d.]. Binary Ninja. https:\/\/binary.ninja\/. Accessed: 2025-05-30."},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3721481"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-007-0074-9"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3650212.3652145"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534367"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/FG52635.2021.9667076"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/icsme55016.2022.00019"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134018"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3428230"},{"key":"e_1_2_1_67_1","volume-title":"Gnnexplainer: Generating explanations for graph neural networks. Advances in neural information processing systems 32","author":"Ying Zhitao","year":"2019","unstructured":"Zhitao Ying, Dylan Bourgeois, Jiaxuan You, Marinka Zitnik, and Jure Leskovec. 2019. Gnnexplainer: Generating explanations for graph neural networks. Advances in neural information processing systems 32 (2019). https:\/\/ proceedings.neurips.cc\/paper_files\/paper\/2019\/hash\/d80b7040b773199015de6d3b4293c8ff-Abstract.html"},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/tpami.2022.3204236"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2023.3240118"},{"key":"e_1_2_1_70_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Zhang Zhuo","year":"2023","unstructured":"Zhuo Zhang, Guanhong Tao, Guangyu Shen, Shengwei An, Qiuling Xu, Yingqi Liu, Yapeng Ye, Yaoxuan Wu, and Xiangyu Zhang. 2023. {PELICAN}: Exploiting Backdoors of Naturally Trained Deep Learning Models In Binary Code Analysis. In 32nd USENIX Security Symposium (USENIX Security 23). 2365-2382. https:\/\/www.usenix.org\/conference\/ usenixsecurity23\/presentation\/zhang-zhuo-pelican"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3808188","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:59:43Z","timestamp":1782842383000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3808188"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":70,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3808188"],"URL":"https:\/\/doi.org\/10.1145\/3808188","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]}}}