Reading binaries with LLMs
Model-Agnostic Staged Pipeline for LLM Decompilation with Quality Inspection
Targeting IoT firmware and executables whose source code no longer exists, this study uses LLMs to recover C code and inspects, step by step, how far the result can be trusted.
Show details Hide details
Problem
Conventional LLM decompilation often takes the generated code as a single output, making it hard to see the gap between code that compiles and code that behaves like the original.
Approach
We built a pipeline that iterates generation and repair, combining Ghidra pseudo-C, function signatures, rule-based quality checks, compiler diagnostics, and execution results.
Key results
Evaluated on HumanEval, MBPP, ExeBench, and OpenWrt, the pipeline improved the recompilation rate on every dataset. We also show that successful recompilation does not guarantee matching behavior.