[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86349-en":3,"doc-seo-86349-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},86349,1099513958762,"Logic","https://ap-avatar.wpscdn.com/avatar/1000023916a998db790?x-image-process=image/resize,m_fixed,w_180,h_180&k=1784791008015729253",8,"Research & Report","Decompiling for Constant-Time Analysis","Constant-time programming helps protect cryptographic libraries from timing side-channel attacks, yet writing and compiling such code can introduce constant-time violations. The work evaluates the Decompile-then-Analyze approach, where decompilers feed static analysis tools, and identifies a key risk: current decompilers can remove constant-time vulnerabilities before CT analysis. The paper formalizes CT transparency, provides proof methods and examples, extends the idea to speculative constant-time, and implements a CT-transparent LLVM-based decompiler (CT-RetDec) to assess verification impact on real binary vulnerabilities.","arXiv :2501 .04 183v4 [ cs .PL] 13 Jul 2026  \nDecompiling for Constant-Time Analysis  \nSANTIAGO ARRANZ-OLMOS, MPI-SP, Germany  \nGILLES BARTHE, MPI-SP, Germany and IMDEA Software Institute, Spain LIONEL BLATTER, MPI-SP, Germany  \nYOUCEF BOUZID, ENS Paris-Saclay, France SÖREN VAN DER WALL, TU Braunschweig, Germany ZHIYUAN ZHANG, MPI-SP, Germany  \nThe constant-time programming discipline is commonly used to protect cryptographic libraries against side-channel attacks. However, it is hard to write constant-time code; moreover, compilers can introduce constant-time violations. Therefore, it is important to ensure that assembly code is constant-time. One approach is to show that source programs are constant-time, and that constant-timeness is preserved by compilation. In this paper, we explore the methodological soundness and scalability of the Decompile-then-Analyze approach, a less conventional alternative that has been suggested in the broader setting of static analysis. Informally, the Decompile-then-Analyze approach uses decompilers a front-end for static analysis tools. As a motivation for our study, we show that current decompilers eliminate CT vulnerabilities before CT analysis, leading to non-CT programs being accepted as constant-time. Independently, we provide constructed examples of non-CT, exploitable, programs that are accepted by two popular CT analysis tools; in both cases the culprit are program transformations that are used internally prior to CT analysis and eliminate CT violations. While our examples do not invalidate the general approach of these tools, they emphasize the need for studying the Decompile-then-Analyze approach.  \nOn the methodological side, we define the notion of CT transparency. Informally, a program transformation is CT transparent if does not eliminate nor introduce CT violations. We also provide general methods for proving that a transformation is CT transparent, and show that several transformations of interest are transparent. We also sketch an extension of CT transparency to speculative constant-time, which is used by cryptographic software as a protection against Spectre attacks.  \nOn the practical side, we build a CT-transparent version of the popular LLVM-based decompiler RetDec, and combine it with CT-LLVM, an existing CT verification tool for LLVM. We evaluate the resulting tool, called CT-RetDec on a benchmark set of real-world vulnerabilities in binaries, and show that the modifications had significant impact on how well CT-RetDec performs.  \n1 Introduction  \nDecompilers1 are routinely used in vulnerability analysis to transform binary programs into source or IR programs on which (manual) analysis can be carried out. To maximize their benefits, decompilers aim to produce source or IR programs that are both readable and correctly capture the behavior of their corresponding binary programs. Of course, achieving correctness and readability simultaneously is intrinsically hard. Yet, in spite of the challenge, there has been significant progress towards this goal, through a combination of technical developments [17, 21, 22, 38, 57, 69, 74], and extensive evaluations [7, 24, 30, 32, 46, 49, 68] .  \nMore recently, researchers have started to explore the possibility to use decompilation to conduct static analysis for properties such as memory layout and memory safety violations [47, 48, 72] . The idea is simple: take a binary program, use a decompiler to produce an IR or source program, and  \n1 See [https://decompilation](https://decompilation.wiki/ for an overview and pointers)[.](https://decompilation.wiki/ for an overview and pointers)[wiki/ for an overview and pointers](https://decompilation.wiki/ for an overview and pointers) to the literature.  \nAuthors’ Contact Information: Santiago Arranz-Olmos, MPI-SP, Bochum, Germany, [santiago](santiago.arranz-olmos@mpi-sp.org)[.](santiago.arranz-olmos@mpi-sp.org)[arranz-olmos@mpi-sp](santiago.arranz-olmos@mpi-sp.org)[.](santiago.arranz-olmos@mpi","cbCaiuqgH1VKx647","https://ap.wps.com/l/cbCaiuqgH1VKx647","pdf",890796,1,39,"English","en",105,"# Introduction\n## Problem Statement\n# Decompile-then-Analyze Approach\n## Methodological Results: CT Transparency\n## Practical Results: CT-RetDec","[{\"question\":\"Why is ensuring constant-time behavior difficult in practice?\",\"answer\":\"Constant-time code is hard to write correctly, and compilers may introduce constant-time violations during compilation, which undermines the intended security guarantees.\"},{\"question\":\"What problem does the paper highlight in the Decompile-then-Analyze workflow?\",\"answer\":\"It shows that many decompilers eliminate constant-time vulnerabilities before CT analysis, so non-constant-time programs can be incorrectly accepted as constant-time.\"},{\"question\":\"How does the paper address preservation of constant-time properties?\",\"answer\":\"It defines CT transparency for program transformations that neither eliminate nor introduce constant-time violations, provides general proof methods, and applies this framework to construct sound transformations and an extended treatment for speculative constant-time.\"}]",1784210727,98,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"decompiling-for-constant-time-analysis","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/decompiling-for-constant-time-analysis/86349/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-28","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is ensuring constant-time behavior difficult in practice?","Question",{"text":75,"@type":76},"Constant-time code is hard to write correctly, and compilers may introduce constant-time violations during compilation, which undermines the intended security guarantees.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What problem does the paper highlight in the Decompile-then-Analyze workflow?",{"text":80,"@type":76},"It shows that many decompilers eliminate constant-time vulnerabilities before CT analysis, so non-constant-time programs can be incorrectly accepted as constant-time.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the paper address preservation of constant-time properties?",{"text":84,"@type":76},"It defines CT transparency for program transformations that neither eliminate nor introduce constant-time violations, provides general proof methods, and applies this framework to construct sound transformations and an extended treatment for speculative constant-time.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":45,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":45,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":45,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":45,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]