Sep 2026· International Conference on Automated Software Engineering· Vol 33· 0 citations· 37 references
TL;DR
A survey of 50 binary type inference tools highlights recent progress, especially in learning-based methods, but also reveals ongoing limitations, which include limited scalability, lack of standardized output formats, and poor support for dynamically typed languages.
Abstract
Understanding binary programs is challenging due to the loss of high-level abstractions during compilation. Type inference plays a key role in recovering information such as variable types, data structures, and class hierarchies, which is crucial for reverse engineering (RE), decompilation, and security analysis. This paper presents a survey of 50 binary type inference tools. We categorize the tools based on the types they recover and the methods they use, including dynamic analysis, static reasoning, symbolic execution, and machine learning. We also compare their input formats, supported languages, and evaluation strategies. In addition, the survey discusses the scope and origins of the area, its evolution over the past two decades, and the challenges that lie ahead. Our study highlights recent progress, especially in learning-based methods, but also reveals ongoing limitations. These include limited scalability, lack of standardized output formats, and poor support for dynamically typed languages. We also observe a lack of user-friendly interfaces and limited availability of source code for many tools, which hinders adoption and further development. We conclude by outlining open research problems and recommending future directions to make type inference tools more accurate, accessible, and widely applicable.
Goanna is introduced, a novel type checker for Haskell that focuses on improving error diagnostics, and shows performance constraints when diagnosing large programs containing complex errors, but remains responsive enough to provide real-time debugging assistance for small to medium-sized programs.
Shuai Fu, Tim Dwyer, Peter James Stuckey et al.· International Conference on...· 0 citations
Recovering the structure of a Solidity smart contract from its deployed bytecode is a prerequisite for various downstream analyses, such as control-flow graph construction, decompilation, and clone detection. A central step in this task is identifying private functions. However, since all source-level function boundari...
Yi-Chuan Li, Wei Song, Jeff Huang et al.· Proceedings of the ACM on Pr...· 0 citations
The security of the modern web depends on the correctness of JavaScript (JS) engines, yet these complex systems remain vulnerable to high-impact bugs. A critical limitation of state-of-the-art fuzzers is the coverage plateau: once a fuzzer saturates the control-flow graph, edge coverage loses its ability to guide disco...
Wai-Kin Wong, Dong-Wei Xiao, Anthony Cheuk Tung Lai et al.· Proceedings of the ACM SIGOP...· 0 citations
Capture checking in Scala 3 enables lightweight and practical effect and resource tracking by recording capabilities in types. However, the system offers no way to reason about kinds of capabilities. Natural constraints such as “retaining only the control-flow capabilities of this closure” or “excluding all thread-loca...
C. Pham, Oliver Bračevac, Yi-Chen Xu et al.· Proceedings of the ACM on Pr...· 0 citations
This work introduces a static, decompiler-driven pipeline built on top of Ghidra that augments decompiled functions with binary-derived evidence including recovered stack regions, callgraph context, and p-code-derived features and presents the real-world evaluation as a diagnostic stress test rather than evidence of a...
Colin Smith, Nathan Keough, Jason Carter· Journal of Computer Virology...· 0 citations