Researchers Test LLMs to Identify Processors in Bare-Metal Binaries via Ghidra
A reverse engineering project is exploring automated methods to identify the processor architecture of undocumented bare-metal binaries, with the second strategy combining Ghidra disassembly across 177 architectures and LLM-based analysis. Test binaries were compiled from a single C source file for roughly 30 processors in both raw and ELF formats, with three firmware samples selected to cover supported, unsupported, and misformatted scenarios. Five local LLMs — including qwen2.5-coder, qwen3-coder:30b, gemma4:26b, dolphinMistral24b, and dolphin3-cyber — were benchmarked using an identical system prompt and a strict JSON response schema. For the first firmware, qwen2.5-coder flagged 69 candidate processors and qwen3-coder:30b narrowed it to 35, both correctly including the true target, while gemma4:26b largely failed due to severe formatting errors. The findings highlight significant variation in LLM reliability for structured reverse engineering tasks, informing which models are viable for building a scalable disassembly identification pipeline.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in