Program analysis. Reverse engineering. Backdoor detection. Head of Research @RevEng_AI. Creator of @VulHuntRE.

United Kingdom
Wrote some slides on symbolic exploit search / synthesis... kmicinski.com/ai-security-co…
1
7
26
1,390
Sam Thomas retweeted
DecBench is growing fast, but I want to remind people that I manually verify results and submissions on the site. That means two things: 1) if you see results elsewhere and not on DecBench.com, I can't speak to their quality. 2) Result updates can be slower, so please don't spam 👍
5
11
758
I am recruiting a postdoc to work with me here in Paris on fuzzing and backdoor detection! ➡️ Do not hesitate to apply or share the offer!
🚨 Postdoc opening (24 months) in software security & fuzzing! Join our @BinsecTool team @CEA_List to work on smarter fuzzing for supply‑chain security 📍 Paris‑Saclay 🇫🇷 🔗 Apply: binsec.github.io/jobs/open/2… #Postdoc #Cybersecurity #Fuzzing #BinaryAnalysis
2
3
170
I'm pleased to announce a new release of the #idalib #Rust bindings for @HexRaysSA IDA Pro! This release provides new APIs and bug fixes. Thanks to new and existing contributors @mcbbugu, Amaan Qureshi, and @0xdea for their work on this release. github.com/idalib-rs/idalib.…
2
19
90
4,993
Sam Thomas retweeted
A new decompiler approach enters the ring!
today, we @RevEng_AI released the next generation of our decompiler: Ventris the new model comes with improved struct layout recovery, better PE support, and more. on decbench, we beat all other available decompilers in structure recovery, and achieve #2 rank overall
3
25
3,970
Sam Thomas retweeted
Super interesting work, and improving on structure recovery is really impressive; that's a seriously hard problem that has had a lot of previous work
today, we @RevEng_AI released the next generation of our decompiler: Ventris the new model comes with improved struct layout recovery, better PE support, and more. on decbench, we beat all other available decompilers in structure recovery, and achieve #2 rank overall
1
2
20
4,142
Sam Thomas retweeted
it's great that with decbench, we have a high-quality public benchmark. yet, decompiler evaluation remains hard, and I see two primary challenges right now: 1. high-quality, real-world-like, fully private data. Frontier LLMs have seen virtually every open source function in existence and leakage is not fully avoidable, something we also cannot rule out for our model. 2. finding a better proxy for semantic fidelity. A program can recompile, but do something entirely different. A program can also recompile, have a totally different byte-level structure from the groundtruth, and still do the same job. Dynamic-execution based attestation is tough to get correct at scale, but might be a better signal in the long run.
1
7
958
Sam Thomas retweeted
we submitted and verified our results via the public site: decbench.com/leaderboard/?da… (`normalize` as there is no arch-specific view right now) it's cool to see that our {static context collection -> one-shot decompilation} approach can compete with fully agentic frontier LLMs
1
1
9
1,397
Sam Thomas retweeted
today, we @RevEng_AI released the next generation of our decompiler: Ventris the new model comes with improved struct layout recovery, better PE support, and more. on decbench, we beat all other available decompilers in structure recovery, and achieve #2 rank overall
3
19
107
18,262
Sam Thomas retweeted
I've shared the list of malicious models detected by MLTracer, along with a systematic analysis of techniques for evading existing model scanners, in the following GitHub repo. github.com/binarly-io/ai-sup… In short, the AI supply chain security field still likely has a lot of room for improvement.
🚨 Our research found that multiple major Hugging Face scanners missed more than 20% of malicious model files. We systematized the 21 static-scanner evasion techniques behind these misses. Most of these were based on known techniques or concepts, highlighting an inherent limitation of static pattern matching: it is practically infeasible to cover every concrete malicious variant. binarly.io/blog/malicious-mo…
2
6
21
3,788
Sam Thomas retweeted
"Software protection is futile, AI will break it", they said. But, does it? how? To shine some light read about Rémy Salim's experiments in "Defeating AI-Assisted Reverse Engineering" Where is the fair play, Claude? blog.quarkslab.com/defeating…
12
36
2,640
Sam Thomas retweeted
Schrödinger’s TOCTOU — a bug class where a struct’s size mod 16 decides if you’re exploitable, where -O2 saves you and -O3 kills you, where a compiler upgrade introduces the bug, and a downgrade… introduces it too. Invisible, intractable, everywhere. github.com/xoreaxeaxeax/schr…
4
37
219
30,662
Sam Thomas retweeted
Static Devirtualization of Tencent VM. There are many others with similar results to ours, we have had the VM devirtualized for several months now. Others are posting full devirt bins, so we feel it is ok to release our research now. back.engineering/blog/31/07/…
4
94
511
27,275
Sam Thomas retweeted
We are approaching perfect binary decompilation, and, crazier still, LLMs may soon be the best decompilers on the planet. I'd like to introduce DecBench, an evaluation site to determine how close we are to completing the field of perfect decompilation. Links and more in 🧵
21
134
931
105,731
Sam Thomas retweeted
Really exciting to see the latest research from the RevEng.AI team tackling one of cybersecurity's biggest challenges: detecting malicious code at scale. As attackers continue to evolve, signature-based approaches alone are no longer enough. This research highlights how AI can identify malicious behaviour in compiled binaries by understanding the underlying semantics of machine code, enabling the detection of previously unseen malware variants without relying on constant rule updates. reveng.ai/blog/detecting-mal…
3
6
861
Sam Thomas retweeted
📢 IDA 9.4 is here! Huge thanks to our beta testers for spending the last several weeks refining this release. • The Apple Dyld Shared Cache workflow has been rebuilt from the ground up. • The decompiler now speaks Swift, with proper ABI modelling for self, async context, and error paths. • Two new processor modules land — Qualcomm Hexagon and MCore. • Navigation gets a major upgrade with Pathfinder and a redesigned Jump Anywhere. • The Teams add-on now runs on Git. • And idalib, previously Pro-only, now ships with IDA Home. 👉 Read the blog for the full breakdown and/or jump ahead to the release notes, then grab your update in the Download Center. hex-rays.com/blog/ida-9.4-re…
4
25
105
13,278
Sam Thomas retweeted
interesting new paper on LLM-based decompilation: AutoDecompiler is an RL-optimized model for feedback-driven, multi-turn decompilation. although previous one-shot approaches might have optimized for recompilation or even executability, they did not utilize feedback directly.
2
14
70
4,340
Sam Thomas retweeted
today I had the pleasure of presenting our work on high-throughput type recovery for binaries at ACM CODASPY! lots of great presentations and discussions all around. slides: github.com/pr0me/xtride/blob… paper: arxiv.org/pdf/2603.08225
1
4
19
1,455