2609005145
  • Open Access
  • Article

EvoPatch-IoT: Evolution-Aware Cross-Architecture Vulnerability Retrieval and Patch-State Profiling for BusyBox-Based IoT Firmware

  • Yinhao Xiao,   
  • Huixi Li *,   
  • Yongluo Shen *

Received: 12 Jun 2026 | Revised: 17 Aug 2026 | Accepted: 10 Sep 2026 | Published: 01 Oct 2026

Abstract

BusyBox is widely reused in Linux-based Internet-of-Things (IoT) firmware, but stripped symbols, heterogeneous instruction sets, uncertain component versions, and selective patch backports make N-day vulnerability localization difficult. We propose EvoPatch-IoT, an evolution-aware retrieval framework whose novelty lies not in another standalone encoder, but in coupling target-local geometric localization, architecture-normalized anonymous multi-view evidence, and a version-causal historical prototype memory for reference-guided retrieval. We also release an original benchmark constructed by collecting official BusyBox releases and compiling each selected version separately for AArch64, ARM, MIPS, MIPSEL, and x86_64 in both stripped and unstripped forms. It contains 57 compiled versions and 555 binaries, together with 155,845 high-confidence stripped-to-unstripped anchors; the dataset is available in the public record. On the original symmetric 57-version benchmark (1020 directed architecture pairs), EvoPatch-IoT obtains 34.56% Hit@1 and 56.24% Hit@10. Relative to the actual strongest baseline, the in-house geometry-only ShapeStat control, these are gains of 8.00% and 5.50%, rather than gains over a weaker literature-inspired control. A stricter historical-only evaluation on 15 chronologically held-out recent versions gives 28.76% Hit@1 and 49.93% Hit@10 versus 26.55% and 47.83% for geometry alone; paired tests over 300 architecture pairs yield p < 1.6 × 10−16, with version-block 95% confidence intervals excluding zero. Direct ablations show that geometry and historical prototypes provide most of the gain, while fusion mainly improves first-rank precision and MRR. A single-CVE patch-state study is retained as supporting, not general, evidence.

References 

  • 1.

    Kim, M.; Kim, D.; Kim, E.; et al. FirmAE: Towards Large-Scale Emulation of IoT Firmware for Dynamic Analysis. In Proceedings of the Annual Computer Security Applications Conference, Austin, TX, USA, 7–11 December 2020; pp. 733–745. https://doi.org/10.1145/3427228.3427294.

  • 2.

    Cheng, Y.; Yang, S.; Lang, Z.; et al. VERI: A Large-scale Open-Source Components Vulnerability Detection in IoT Firmware. Comput. Secur. 2023, 126, 103068. https://doi.org/10.1016/j.cose.2022.103068.

  • 3.

    Zhang, Y.; Yu, B.; Zhou, L.; et al. Comprehensive IoT Firmware Characterization Based on a Large-Scale Firmware Dataset. In Proceedings of the 2024 9th International Conference on Cyber Security and Information Engineering, Kuala Lumpur, Malaysia, 15–17 September 2024; pp. 35–40. https://doi.org/10.1145/3689236.3689262.

  • 4.

    Xiao, H.; Zhang, Y.; Shen, M.; et al. Accurate and Efficient Recurring Vulnerability Detection for IoT Firmware. In Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security, Salt Lake City, UT, USA, 14–18 October 2024; pp. 3317–3331. https://doi.org/10.1145/3658644.3670275.

  • 5.

    Gao, Z.; Zhang, C.; Liu, H.; et al. Faster and Better: Detecting Vulnerabilities in Linux-Based IoT Firmware with Optimized Reaching Definition Analysis. In Proceedings of the Network and Distributed System Security Symposium, San Diego, CA, USA, 26 February–1 March 2024. https://doi.org/10.14722/ndss.2024.24346.

  • 6.

    Yue, S.; Li, Q.; Zhang, G.; et al. NPFTaint: Detecting Highly Exploitable Vulnerabilities in Linux-Based IoT Firmware with Network Parsing Functions. Comput. Secur. 2025, 159, 104679. https://doi.org/10.1016/j.cose.2025.104679.

  • 7.

    Yang, S.; Xu, Z.; Xiao, Y.; et al. Towards Practical Binary Code Similarity Detection: Vulnerability Verification via Patch Semantic Analysis. ACM Trans. Softw. Eng. Methodol. 2023, 32, 1–29. https://doi.org/10.1145/3604608.

  • 8.

    Xu, X.; Zheng, Q.; Yan, Z.; et al. PatchDiscovery: Patch Presence Test for Identifying Binary Vulnerabilities Based on Key Basic Blocks. IEEE Trans. Softw. Eng. 2023, 49, 5279–5294. https://doi.org/10.1109/tse.2023.3332732.

  • 9.

    Zhan, Q.; Hu, X.; Xia, X.; et al. REACT: IR-Level Patch Presence Test for Binary. In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering, Sacramento, CA, USA, 27 October–1 November 2024; pp. 381–392. https://doi.org/10.1145/3691620.3695012.

  • 10.

    Li, X.; Qu, Y.; Yin, H. PalmTree: Learning an Assembly Language Model for Instruction Embedding. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, Online, 15–19 November 2021; pp. 3236–3251. https://doi.org/10.1145/3460120.3484587.

  • 11.

    Wang, H.; Qu, W.; Katz, G.; et al. jTrans: Jump-Aware Transformer for Binary Code Similarity Detection. In Proceedings of the ACM SIGSOFT International Symposium on Software Testing and Analysis, Online, 18–22 July 2022; pp. 1–13. https://doi.org/10.1145/3533767.3534367.

  • 12.

    Wang, H.; Gao, Z.; Zhang, C.; et al. CLAP: Learning Transferable Binary Code Representations with Natural Language Supervision. In Proceedings of the ACM SIGSOFT International Symposium on Software Testing and Analysis, Vienna, Austria, 16–20 September 2024; pp. 503–515. https://doi.org/10.1145/3650212.3652145.

  • 13.

    Zhang, Y.; Liu, Y.; Cheng, G.; et al. GTrans: Graph Transformer-Based Obfuscation-Resilient Binary Code Similarity Detection. In Proceedings of the Workshop on Binary Analysis Research (BAR) 2024, San Diego, CA, USA, 1 March 2024. https://doi.org/10.14722/bar.2024.23006.

  • 14.

    Li, W.; Lu, J.; Xiao, R.; et al. RCFG2Vec: Considering Long-Distance Dependency for Binary Code Similarity Detection. In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering, Sacramento, CA, USA, 27 October–1 November 2024; pp. 770–782. https://doi.org/10.1145/3691620.3695070.

  • 15.

    He, K.; Hu, Y.; Li, X.; et al. StrTune: Data Dependence-Based Code Slicing for Binary Similarity Detection With Fine-Tuned Representation. IEEE Trans. Inf. Forensics Secur. 2024, 19, 10233–10245. https://doi.org/10.1109/tifs.2024.3484944.

  • 16.

    Jiang, S.; Fu, C.; He, S.; et al. BinCola: Diversity-Sensitive Contrastive Learning for Binary Code Similarity Detection. IEEE Trans. Softw. Eng. 2024, 50, 2485–2497. https://doi.org/10.1109/tse.2024.3411072.

  • 17.

    VenkataKeerthy, S.; Banerjee, S.; Dey, S.; et al. VexIR2Vec: An Architecture-Neutral Embedding Framework for Binary Similarity. ACM Trans. Softw. Eng. Methodol. 2025, 34, 1–54. https://doi.org/10.1145/3721481.

  • 18.

    BusyBox Release Archive. Available online: https://busybox.net/downloads/ (accessed on 17 August 2026).

  • 19.

    Xiao, Y.; Li, H.; Shen, Y. Cross-Architecture Cross-Version BusyBox Binaries. Available online: https://cstr.cn/31253.11.sciencedb.34638 (accessed on 21 September 2026).

  • 20.

    Massarelli, L.; Di Luna, G.A.; Petroni, F.; et al. SAFE: Self-Attentive Function Embeddings for Binary Similarity. In Proceedings of the 16th International Conference, DIMVA 2019, Gothenburg, Sweden, 19–20 June 2019; pp. 309–329. https://doi.org/10.1007/978-3-030-22038-9_15.

  • 21.

    Feng, Y.; Li, H.; Cao, Y.; et al. CRABS-former: CRoss-Architecture Binary Code Similarity Detection based on Transformer. In Proceedings of the 15th Asia-Pacific Symposium on Internetware, Macau, China, 24–26 July 2024; pp. 11–20. https://doi.org/10.1145/3671016.3671390.

  • 22.

    Gao, Z.; Xiao, L.; Weng, W.; et al. Binary2vec: Cross-Architecture Binary Embeddings with Global Attention-Enhanced Graph Neural Networks. Array 2025, 27, 100491. https://doi.org/10.1016/j.array.2025.100491.

  • 23.

    Gong, X.; Xu, Y.; Zhang, S.; et al. Ex2Vec: Enhancing Assembly Code Semantics with End-to-End Execution-Aware Embeddings. Neural Netw. 2025, 189, 107506. https://doi.org/10.1016/j.neunet.2025.107506.

  • 24.

    Gu, Y.; Shu, H.; Kang, F.; et al. UniASM: Binary Code Similarity Detection without Fine-Tuning. Neurocomputing 2025, 630, 129646. https://doi.org/10.1016/j.neucom.2025.129646.

  • 25.

    Wan, B.; Wang, S.; Wei, Z.; et al. Binary Code Similarity Detection via LLM-Based Source Code Conversion. IEEE Internet Things J. 2025, 12, 51842–51853. https://doi.org/10.1109/jiot.2025.3579231.

  • 26.

    Zhang, B.; Gao, Z.; Wang, H.; et al. BinQuery: A Novel Framework for Natural Language-Based Binary Code Retrieval. Proc. ACM Softw. Eng. 2025, 2, 1167–1189. https://doi.org/10.1145/3728927.

  • 27.

    Zhang, Y.; Yu, B. FirmCVI: Taint Analysis-Based Component Version Identification Method for Large-Scale IoT Firmware. In Proceedings of the 2023 IEEE 29th International Conference on Parallel and Distributed Systems (ICPADS), Ocean Flower Island, China, 17–21 December 2023; pp. 920–927. https://doi.org/10.1109/icpads60453.2023.00137.

  • 28.

    Xiang, J.; Fu, L.; Ye, T.; et al. LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices. IEEE Internet Things J. 2025, 12, 5970–5984. https://doi.org/10.1109/jiot.2024.3490661.

  • 29.

    National Institute of Standards and Technology. CVE-2021-42386 Detail. Available online: https://nvd.nist.gov/vuln/detail/CVE-2021-42386 (accessed on 17 August 2026).

Share this article:
How to Cite
Xiao, Y.; Li, H.; Shen, Y. EvoPatch-IoT: Evolution-Aware Cross-Architecture Vulnerability Retrieval and Patch-State Profiling for BusyBox-Based IoT Firmware. Pragmatic Cybersecurity 2026, 1 (3), 19. https://doi.org/10.53941/pc.2026.100019.
RIS
BibTex
Copyright & License
article copyright Image
Copyright (c) 2026 by the authors.
Article Metrics
15
Article Views
0
Citations