{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T01:21:47Z","timestamp":1760059307800,"version":"build-2065373602"},"reference-count":43,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2025,6,3]],"date-time":"2025-06-03T00:00:00Z","timestamp":1748908800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Compilers play a crucial role in software development, as most software must be compiled into binaries before release. Analyzing the compiler version from binary files is of great importance in software reverse engineering, maintenance, traceability, and information security. In this work, we propose a novel framework for compiler version identification. Firstly, we generated 1000 C language source codes using CSmith and subsequently compiled them into 16,000 binary files using 16 distinct versions of compilers. The symmetric distribution of the dataset among different compiler versions may ensure unbiased model training. Then, IDA Pro was used to decompile the binary files into assembly instruction sequences. From these sequences, we extracted frequency-based features via the Bag-of-Words (BOW) model and sequence-based features derived from the grey-level co-occurrence matrix (GLCM). Finally, we introduced a divide-and-conquer framework (DIANA-SVM) to effectively classify compiler versions. The experimental results demonstrate that traditional Support Vector Machine (SVM) models struggle to accurately identify compiler versions using compiled executable files. In contrast, DIANA-SVM\u2019s symmetric data separation approach enhances performance, achieving an accuracy of 94% (\u00b10.375%). This framework enables precise identification of high-risk compiler versions, offering a reliable tool for software supply chain security. Theoretically, our GLCM-based sequence modeling and divide-and-conquer framework advance feature extraction methodologies for binary files, offering a scalable solution for similar classification tasks beyond compiler identification.<\/jats:p>","DOI":"10.3390\/sym17060867","type":"journal-article","created":{"date-parts":[[2025,6,3]],"date-time":"2025-06-03T08:01:07Z","timestamp":1748937667000},"page":"867","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Compiler Identification with Divisive Analysis and Support Vector Machine"],"prefix":"10.3390","volume":"17","author":[{"given":"Changlan","family":"Liu","sequence":"first","affiliation":[{"name":"College of Arts and Sciences, Northeast Agricultural University, Harbin 150000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yingsong","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Arts and Sciences, Northeast Agricultural University, Harbin 150000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng","family":"Zuo","sequence":"additional","affiliation":[{"name":"College of Arts and Sciences, Northeast Agricultural University, Harbin 150000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3164-1372","authenticated-orcid":false,"given":"Peng","family":"Wang","sequence":"additional","affiliation":[{"name":"College of Arts and Sciences, Northeast Agricultural University, Harbin 150000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,6,3]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"708","DOI":"10.1109\/TPDS.2020.3030548","article-title":"The Deep Learning Compiler: A Comprehensive Survey","volume":"32","author":"Li","year":"2021","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"ref_2","first-page":"62","article-title":"Support and Optimization of Multi-Granularity Quantization Framework for Deep Learning Compiler","volume":"51","author":"Wei","year":"2025","journal-title":"Comput. Eng."},{"key":"ref_3","first-page":"862","article-title":"Research on Risk Analysis of Open Source Software Supply Chain Security","volume":"10","author":"Wang","year":"2024","journal-title":"Chin. Acad. Cyberspace Stud."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"46717","DOI":"10.1109\/ACCESS.2019.2906934","article-title":"Robust Intelligent Malware Detection Using Deep Learning","volume":"7","author":"Vinayakumar","year":"2019","journal-title":"IEEE Access."},{"key":"ref_5","unstructured":"Liu, R. (2019). Research on Security Protection Technology Based on Clang Compiler in Linux System. [Master\u2019s Thesis, Beijing University of Posts and Telecommunications]."},{"key":"ref_6","unstructured":"Yao, Y. (2023). Feature Extraction and Recognition of C Language Compiler Based on Binary Files. [Master\u2019s Thesis, Xi\u2019an University of Technology]."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"49160","DOI":"10.1109\/ACCESS.2021.3069227","article-title":"Fine-grained compiler identification with sequence-oriented neural modeling","volume":"9","author":"Tian","year":"2021","journal-title":"IEEE Access"},{"key":"ref_8","first-page":"1","article-title":"A Survey on Text Classification: From Traditional to Deep Learning","volume":"13","author":"Li","year":"2022","journal-title":"ACM Trans. Intell. Syst. Technol."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Rohleder, R. (2019, January 15). Hands-on ghidra-a tutorial about the software reverse engineering framework. Proceedings of the 3rd ACM Workshop on Software Protection, London, UK.","DOI":"10.1145\/3338503.3357725"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"376","DOI":"10.1016\/j.cose.2019.04.005","article-title":"A feature-hybrid malware variants detection using CNN based opcode embedding and BPNN based API embedding","volume":"84","author":"Zhang","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_11","first-page":"1","article-title":"An investigation of byte n-gram features for malware classification","volume":"14","author":"Raff","year":"2021","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1007\/s11416-005-0002-9","article-title":"Malware phylogeny generation using permutations of code","volume":"1","author":"Karim","year":"2019","journal-title":"J. Comput. Virol."},{"key":"ref_13","first-page":"780","article-title":"Malicious code detection method based on perceptual hash algorithm and feature fusion","volume":"41","author":"Jiang","year":"2021","journal-title":"Comput. Appl."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Rosenblum, N.E., Miller, B.P., and Zhu, X. (2010, January 5\u20136). Extracting compiler provenance from program binaries. Proceedings of the 9th ACM SIGPLAN-SIGSOFT Workshop on Program Analysis for Software Tools and Engineering, Toronto, ON, Canada.","DOI":"10.1145\/1806672.1806678"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Rosenblum, N., Miller, B.P., and Zhu, X. (2011, January 17\u201321). Recovering the toolchain provenance of binary code. Proceedings of the 2011 International Symposium on Software Testing and Analysis, Toronto, ON, Canada.","DOI":"10.1145\/2001420.2001433"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11416-012-0171-2","article-title":"Chi-squared distance and metamorphic virus detection","volume":"9","author":"Toderici","year":"2013","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"S146","DOI":"10.1016\/j.diin.2015.05.015","article-title":"Bincomp: A stratified approach to compiler provenance attribution","volume":"14","author":"Rahimian","year":"2015","journal-title":"Digit. Investig."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1016\/j.aej.2021.04.076","article-title":"Malware classification based on double byte feature encoding","volume":"61","author":"Li","year":"2022","journal-title":"Alex. Eng. J."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"103118","DOI":"10.1016\/j.cose.2023.103118","article-title":"BHMDC: A byte and hex n-gram based malware detection and classification method","volume":"128","author":"Tang","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"548","DOI":"10.1016\/j.future.2018.12.028","article-title":"SaaS: A situational awareness and analysis system for massive android malware detection","volume":"95","author":"Zhang","year":"2019","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"102887","DOI":"10.1016\/j.cose.2022.102887","article-title":"A few-shot malware classification approach for unknown family recognition using malware feature visualization","volume":"122","author":"Conti","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Raff, E., Sylvester, J., and Nicholas, C. (2017, January 3). Learning the pe header, malware detection with minimal domain knowledge. Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, Dallas, TX, USA.","DOI":"10.1145\/3128572.3140442"},{"key":"ref_23","first-page":"301128","article-title":"CNN based zero-day malware detection using small binary segments","volume":"38","author":"Wen","year":"2021","journal-title":"Forensic Sci. Int. Digit. Investig."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Pizzolotto, D., and Inoue, K. (October, January 28). Identifying compiler and optimization options from binary code using deep learning approaches. Proceedings of the 2020 IEEE International Conference on Software Maintenance and Evolution (ICSME), Adelaide, SA, Australia.","DOI":"10.1109\/ICSME46990.2020.00031"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1968","DOI":"10.1016\/j.jksuci.2022.02.026","article-title":"Mal-Detect: An intelligent visualization approach for malware detection","volume":"34","author":"Falana","year":"2022","journal-title":"J. King Saud Univ. Comput. Inf. Sci."},{"key":"ref_26","first-page":"102953","article-title":"Function-level obfuscation detection method based on Graph Convolutional Networks","volume":"61","author":"Jiang","year":"2021","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_27","unstructured":"Liu, C., Saul, R., Sun, Y., Raff, E., Fuchs, M., Southard Pantano, T., Holt, J., and Micinski, K. (2024). Assemblage: Automatic Binary Dataset Construction for Machine Learning. arXiv."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Yang, X., Chen, Y., Eide, E., and Regehr, J. (2011, January 4\u20138). Finding and understanding bugs in C compilers. Proceedings of the 32nd ACM SIGPLAN Conference on Programming Language Design and Implementation, San Jose, CA, USA.","DOI":"10.1145\/1993498.1993532"},{"key":"ref_29","unstructured":"Pan, J. (2022, January 15\u201317). Exploring the Author Controversy in the Last Forty Chapters of \u201dDream of the Red Chamber\u201d from the Perspective of Word Frequency and Word Frequency: A Comparative Study Based on Mathematical Statistics Software. Proceedings of the International Academic Forum on Cultural and Artistic Innovation (III), Beijing, China."},{"key":"ref_30","first-page":"230","article-title":"Plagiarism Judgment Based on Language Model and Feature Classification","volume":"39","author":"Li","year":"2013","journal-title":"Comput. Eng."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1038\/s44159-024-00392-z","article-title":"Using Natural Language Processing to Analyse Text Data in Behavioural Science","volume":"4","author":"Feuerriegel","year":"2025","journal-title":"Nat. Rev. Psychol."},{"key":"ref_32","first-page":"210","article-title":"The Role of Assembly Language in Modern Compiler Design","volume":"35","author":"Stone","year":"2020","journal-title":"J. Comput. Sci. Technol."},{"key":"ref_33","first-page":"470","article-title":"Analysis of Malicious Application Detection Method Based on N-gram Algorithm","volume":"40","author":"Tian","year":"2023","journal-title":"Comput. Simul."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"261","DOI":"10.4103\/jmss.jmss_50_22","article-title":"Evaluating the Gray Level Co-Occurrence Matrix-Based Texture Features of Magnetic Resonance Images for Glioblastoma Multiform Patients\u2019 Treatment Response Assessment","volume":"13","author":"Alibabaei","year":"2023","journal-title":"J. Med. Signals Sens."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Nataraj, L., Karthikeyan, S., Jacob, G., and Manjunath, B.S. (2011, January 20). Malware images: Visualization and automatic classification. Proceedings of the 8th International Symposium on Visualization for Cyber Security, Pittsburgh, PA, USA.","DOI":"10.1145\/2016904.2016908"},{"key":"ref_36","first-page":"102995","article-title":"Permission-based Android malware analysis by using dimension reduction with PCA and LDA","volume":"63","author":"Kural","year":"2021","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"553","DOI":"10.1007\/s00357-022-09419-7","article-title":"Hierarchical means clustering","volume":"39","author":"Vichi","year":"2022","journal-title":"J. Classif."},{"key":"ref_38","first-page":"1","article-title":"Hierarchical Clustering: Objective Functions and Algorithms","volume":"66","author":"Kanade","year":"2019","journal-title":"J. ACM."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"24287","DOI":"10.1007\/s11042-021-10836-w","article-title":"Action unit classification for facial expression recognition using active learning and SVM","volume":"80","author":"Yao","year":"2021","journal-title":"Multimed. Tools Appl."},{"key":"ref_40","first-page":"755","article-title":"A Hybrid Heuristic Algorithm for Evolving Models in Simultaneous Scenarios of Classification and Clustering. Knowl","volume":"61","author":"Cerrada","year":"2019","journal-title":"Inf. Syst."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"2071","DOI":"10.1109\/TNSM.2022.3211254","article-title":"R1DIT: Privacy-Preserving Malware Traffic Classification With Attention-Based Neural Networks","volume":"20","author":"Barut","year":"2023","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"145","DOI":"10.1111\/coin.12551","article-title":"Attention-Based Convolutional Neural Network Deep Learning Approach for Robust Malware Classification","volume":"39","author":"Ravi","year":"2023","journal-title":"Comput. Intell."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"101740","DOI":"10.1016\/j.cose.2020.101740","article-title":"Byte-Level Malware Classification Based on Markov Images and Deep Learning","volume":"92","author":"Yuan","year":"2020","journal-title":"Comput. Secur."}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/17\/6\/867\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:46:34Z","timestamp":1760031994000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/17\/6\/867"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,3]]},"references-count":43,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2025,6]]}},"alternative-id":["sym17060867"],"URL":"https:\/\/doi.org\/10.3390\/sym17060867","relation":{},"ISSN":["2073-8994"],"issn-type":[{"type":"electronic","value":"2073-8994"}],"subject":[],"published":{"date-parts":[[2025,6,3]]}}}