Recon 2026

Mixed Boolean-Arithmetic Obfuscation: What We Build, What We Break, and What We Can’t
21/06/2026 , Grand Salon Opera
Langue: English

Mixed Boolean-Arithmetic (MBA) obfuscation has drawn substantial work in both construction and simplification. Yet the conversation often conflates distinct problems: linear MBA results read as general, restricted-operator techniques read as full-space solutions, benchmarks built by the same techniques they evaluate. Progress is real, but much of it has happened inside a narrow region of a much larger design space.

This talk is a benevolent rant: an attempt to map the space well enough to ask the right questions, including ones whose answers may be unwelcome (infeasibility, hard limits). It organizes the discussion around three: what we build, what we break, what we don’t know (and probably can’t), and argues the third is larger than the literature treats it.

On the construction side, we attempt to lay out a formal hierarchy of expressions, separate the operators used to build an expression from those targeted by simplification, and look at how identity equivalences are generated (iteratively, compositionally, otherwise).

On the simplification side, once an MBA expression is in hand, much of what real binaries contain is reachable with existing tools: not because the problem is solved, but because constructions in the wild align with how current attacks decompose them. The real difficulty lies in expression retrieval: MBA split across blocks or functions, destructured by optimizers, mangled by lifters, and in general entangled with virtualization and other obfuscation transformations.

We close on foundational obstacles: normal forms, what “simpler” even means. We observe that stronger constructions sit in the unexplored part of the map (with no reason to expect current tools would handle them), and ask what we’d need to push past that, with some opinionated takes on directions worth pursuing.

Voir aussi : Slides

Arnau is a hacker, security researcher and mathematician with over a decade of experience across academia and industry, spanning software protection research and practical defenses in anti-malware and anti-cheating.

He is a Principal Research Engineer/Scientist at Hex-Rays, where he works on advancing binary semantic analysis within IDA. He is also Founder of Fura Labs, a boutique firm specializing in software protection and reverse engineering consulting and training, and an external PhD researcher at the University of London.

Arnau is a regular speaker and trainer at international security conferences.