{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T07:11:37Z","timestamp":1779174697041,"version":"3.51.4"},"reference-count":24,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T00:00:00Z","timestamp":1779148800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T00:00:00Z","timestamp":1779148800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100006407","name":"Natural Science Foundation of Henan Province","doi-asserted-by":"publisher","award":["No. 252300423348."],"award-info":[{"award-number":["No. 252300423348."]}],"id":[{"id":"10.13039\/501100006407","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    The large-scale deployment of IoT devices has led to widespread use of stripped firmware binaries, where function names are removed, leaving many functions anonymous. This obscures program semantics and heightens security risks by hiding vulnerabilities. Recovering meaningful function names is thus crucial for reverse engineering and security analysis. Existing approaches treat naming as an isolated prediction task or rely on static, limited calling contexts, struggling with deep call chains and severe semantic loss. To overcome this, we propose\n                    <jats:bold>SemFlow<\/jats:bold>\n                    , a call-graph-driven, hierarchical semantic propagation method. SemFlow reframes naming as an iterative process that progressively resolves anonymity by leveraging the call graph\u2019s structure: it first recovers bottom-layer functions with richer context and propagates their names upward as semantic anchors to enrich context for mid- and top-layer functions. We evaluate SemFlow on real-world binaries across four architectures (x86-64, x86-32, ARM, MIPS) and four optimization levels (O0\u2013O3). Results show consistent superiority over the state-of-the-art SYMGEN: F1 scores improve by up to 13.4% (x86-64), 20.3% (x86-32), 34.3% (ARM), and 158.5% (MIPS). Notably, on mid-layer anonymous functions\u2014where semantic scarcity is most acute\u2014SemFlow achieves an average F1 gain of 162.7%, demonstrating the effectiveness of hierarchical semantic propagation in mitigating context loss in deep call chains.\n                  <\/jats:p>","DOI":"10.1186\/s42400-026-00602-6","type":"journal-article","created":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T06:40:07Z","timestamp":1779172807000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A method for function name recovery in binaries via hierarchical semantic propagation"],"prefix":"10.1186","volume":"9","author":[{"given":"Debao","family":"Kong","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yangyang","family":"Geng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Guo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chaojie","family":"Wei","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haowen","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fang","family":"Jing","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liupeng","family":"He","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xueman","family":"Kong","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiang","family":"Wei","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,19]]},"reference":[{"key":"602_CR1","first-page":"27865","volume":"34","author":"M Allamanis","year":"2021","unstructured":"Allamanis M, Jackson-Flux H, Brockschmidt M (2021) Self-supervised bug detection and repair. Adv Neural Inf Process Syst 34:27865\u201327876","journal-title":"Adv Neural Inf Process Syst"},{"key":"602_CR2","doi-asserted-by":"publisher","unstructured":"Allamanis M, Brockschmidt M, Khademi M (2017) Learning to represent programs with graphs. arXiv preprint https:\/\/doi.org\/10.48550\/arXiv.1711.00740","DOI":"10.48550\/arXiv.1711.00740"},{"key":"602_CR3","unstructured":"Andriesse D, Chen X, Van Der\u00a0Veen V et al (2016) An in-depth analysis of disassembly on full-scale x86\/x64 binaries. In: Proceedings of the 25th USENIX security symposium (USENIX security), pp 583\u2013600"},{"key":"602_CR4","unstructured":"Basque ZL, Bajaj AP, Gibbs W, O\u2019Kain J, Miao D, Bao T et al (2024) Ahoy sailr! there is no need to dream of c: a compiler-aware structuring algorithm for binary decompilation. In: Proceedings of the 33rd USENIX security symposium (USENIX Security), pp 361\u2013378"},{"issue":"5","key":"602_CR5","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1145\/175290.175300","volume":"37","author":"TJ Biggerstaff","year":"1994","unstructured":"Biggerstaff TJ, Mitandar BG, Webster DE (1994) Program understanding and the concept assignment problem. Commun ACM 37(5):72\u201382. https:\/\/doi.org\/10.1145\/175290.175300","journal-title":"Commun ACM"},{"issue":"9","key":"602_CR6","doi-asserted-by":"publisher","first-page":"3280","DOI":"10.1109\/TSE.2021.3087402","volume":"48","author":"S Chakraborty","year":"2021","unstructured":"Chakraborty S, Krishna R, Ding Y, Ray B et al (2021) Deep learning based vulnerability detection: are we there yet? IEEE Trans Softw Eng 48(9):3280\u20133296. https:\/\/doi.org\/10.1109\/TSE.2021.3087402","journal-title":"IEEE Trans Softw Eng"},{"issue":"3","key":"602_CR7","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1145\/24039.24041","volume":"9","author":"J Ferrante","year":"1987","unstructured":"Ferrante J, Ottenstein KJ, Warren JD (1987) The program dependence graph and its use in optimization. ACM Trans Program Lang Syst (TOPLAS) 9(3):319\u2013349","journal-title":"ACM Trans Program Lang Syst (TOPLAS)"},{"key":"602_CR8","doi-asserted-by":"publisher","unstructured":"Gao H, Cheng S, Xue Y, Zhang W et al (2021) A lightweight framework for function name reassignment based on large-scale stripped binaries. In: Proceedings of the ACM SIGSOFT international symposium on software testing and analysis, pp 607\u2013619. https:\/\/doi.org\/10.1145\/3460319.3464804","DOI":"10.1145\/3460319.3464804"},{"key":"602_CR9","doi-asserted-by":"publisher","unstructured":"He J, Ivanov P, Tsankov P, Raychev V, Vechev M, et al (2018) Debin: predicting debug information in stripped binaries. In: Proceedings of the ACM SIGSAC conference on computer and communications security, pp 1667\u20131680. https:\/\/doi.org\/10.1145\/3243734.3243866","DOI":"10.1145\/3243734.3243866"},{"key":"602_CR10","unstructured":"Hu EJ, Shen Y, Wallis P, Allen-Zhu Z, Li Y, Wang S, et al (2022) Lora: low-rank adaptation of large language models. In: Proceedings of the international conference on learning representations (ICLR), vol 1, p 3"},{"issue":"12","key":"602_CR11","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3571730","volume":"55","author":"Z Ji","year":"2023","unstructured":"Ji Z, Lee N, Frieske R, Yu T, Su D, Xu Y et al (2023) Survey of hallucination in natural language generation. ACM Comput Surv 55(12):1\u201338. https:\/\/doi.org\/10.1145\/3571730","journal-title":"ACM Comput Surv"},{"key":"602_CR12","doi-asserted-by":"publisher","unstructured":"Jiang L, Jin X, Lin Z (2025) Beyond classification: Inferring function names in stripped binaries via domain-adapted llms. In: Proceedings of the 32nd network and distributed system security symposium (NDSS). https:\/\/doi.org\/10.14722\/ndss.2025.240797","DOI":"10.14722\/ndss.2025.240797"},{"key":"602_CR13","doi-asserted-by":"publisher","unstructured":"Jin X, Pei K, Won JY, Lin Z et al (2022) Symlm: predicting function names in stripped binaries via context-sensitive execution-aware code embeddings. In: Proceedings of the 2022 ACM SIGSAC conference on computer and communications security (CCS), pp. 1631\u20131645. https:\/\/doi.org\/10.1145\/3548606.3560612","DOI":"10.1145\/3548606.3560612"},{"key":"602_CR14","doi-asserted-by":"publisher","unstructured":"Kaddour J, Harris J, Mozes M, Bradley H, Raileanu R, McHardy R et al (2023) Challenges and applications of large language models. arXiv preprint https:\/\/doi.org\/10.48550\/arXiv.2307.10169","DOI":"10.48550\/arXiv.2307.10169"},{"key":"602_CR15","doi-asserted-by":"publisher","unstructured":"Kim H, Bak J, Cho K, Koo, H (2023) A transformer-based function symbol name inference model from an assembly language for binary reversing. In: Proceedings of the 2023 ACM Asia conference on computer and communications security, pp 951\u2013965. https:\/\/doi.org\/10.1145\/3579856.3582823","DOI":"10.1145\/3579856.3582823"},{"key":"602_CR16","doi-asserted-by":"crossref","unstructured":"Lauren\u00e7on H, Saulnier L, Wang T, Akiki C, Moral A, Le\u00a0Scao T, et al (2022) The bigscience roots corpus: a 1.6 tb composite multilingual dataset. In: Advances in neural information processing systems, vol 35, pp 31809\u201331826","DOI":"10.52202\/068431-2306"},{"issue":"1","key":"602_CR17","doi-asserted-by":"publisher","first-page":"7283","DOI":"10.1038\/s41467-023-42992-y","volume":"14","author":"K Li","year":"2023","unstructured":"Li K, Persaud D, Choudhary K, DeCost B, Greenwood M, Hattrick-Simpers J et al (2023) Exploiting redundancy in large materials datasets for efficient machine learning with less data. Nat Commun 14(1):7283. https:\/\/doi.org\/10.1038\/s41467-023-42992-y","journal-title":"Nat Commun"},{"key":"602_CR18","doi-asserted-by":"publisher","unstructured":"Luo Z, Wang P, Wang B, Tang Y, Xie W, Zhou X et al (2023) Vulhawk: cross-architecture vulnerability detection with entropy-based binary code search. In: Proceedings of the network and distributed system security symposium (NDSS). https:\/\/doi.org\/10.14722\/ndss.2023.24415","DOI":"10.14722\/ndss.2023.24415"},{"issue":"12","key":"602_CR19","doi-asserted-by":"publisher","first-page":"2591","DOI":"10.1109\/TIFS.2015.2469253","volume":"10","author":"S Naval","year":"2015","unstructured":"Naval S, Laxmi V, Rajarajan M, Gaur MS, Conti M et al (2015) Employing program semantics for malware detection. IEEE Trans Inf Forensics Secur 10(12):2591\u20132604. https:\/\/doi.org\/10.1109\/TIFS.2015.2469253","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"602_CR20","doi-asserted-by":"publisher","unstructured":"Patrick-Evans J, Dannehl M, Kinder JX (2023) Xfl: naming functions in binaries with extreme multi-label learning. In: Proceedings of the IEEE symposium on security and privacy, pp 2375\u20132390. https:\/\/doi.org\/10.1109\/SP46215.2023.10179439","DOI":"10.1109\/SP46215.2023.10179439"},{"issue":"1","key":"602_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10664-025-10748-5","volume":"31","author":"X Shang","year":"2026","unstructured":"Shang X, Fu Z, Cheng S, Chen G, Li G, Hu L et al (2026) An empirical study on the effectiveness of large language models for binary code understanding. Empir Softw Eng 31(1):1\u201338. https:\/\/doi.org\/10.1007\/s10664-025-10748-5","journal-title":"Empir Softw Eng"},{"key":"602_CR22","doi-asserted-by":"publisher","unstructured":"Theodoridis T, Grosser T, Su Z (2022) Understanding and exploiting optimal function inlining. In: Proceedings of the ACM international conference on architectural support for programming languages and operating systems, pp 977\u2013989. https:\/\/doi.org\/10.1145\/3503222.3507744","DOI":"10.1145\/3503222.3507744"},{"key":"602_CR23","doi-asserted-by":"publisher","unstructured":"Touvron H, Lavril T, Izacard G, Martinet X, Lachaux M-A, Lacroix T et al (2023) Llama: open and efficient foundation language models. arXiv preprint https:\/\/doi.org\/10.48550\/arXiv.2302.13971","DOI":"10.48550\/arXiv.2302.13971"},{"issue":"FSE","key":"602_CR24","doi-asserted-by":"publisher","first-page":"1679","DOI":"10.1145\/3660782","volume":"1","author":"X Zhang","year":"2024","unstructured":"Zhang X, Xu Z, Yang S, Li Z, Shi Z, Sun L et al (2024) Enhancing function name prediction using votes-based name tokenization and multi-task learning. Proc ACM Softw Eng 1(FSE):1679\u20131702. https:\/\/doi.org\/10.1145\/3660782","journal-title":"Proc ACM Softw Eng"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00602-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-026-00602-6","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00602-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T06:40:12Z","timestamp":1779172812000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-026-00602-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,19]]},"references-count":24,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["602"],"URL":"https:\/\/doi.org\/10.1186\/s42400-026-00602-6","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,19]]},"assertion":[{"value":"21 January 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"5 May 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval and consent to participate"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"Project name: SemFlow. Programming language: Python. Operating system(s): Linux. License: Not applicable (available upon reasonable request).","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Code availability"}},{"value":"The author(s) declare(s) no conflicts of interest to report regarding the present study.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"170"}}