Towards Semantic-Preserving Obfuscation for Analysis-Resistant EVM Bytecode
DOI:
https://doi.org/10.54654/isj.v2i28.6410Keywords:
Ethereum, smart contract, EVM Bytecode obfuscationTóm tắt
With the transparency of the Ethereum platform, deployed smart contracts remain permanently public, exposing their virtual machine code to risks such as reverse engineering, control-flow analysis and malicious behavior identification. Although several obfuscation approaches for the EVM have been proposed, existing solutions often suffer from limited resistance against advanced analysis techniques, insufficient structural transformation capability or excessive execution overhead. In this work, we propose a novel obfuscation framework for EVM bytecode that enhances security by combining semantic-aware transformations with control-flow perturbation techniques. The proposed framework significantly increases structural complexity, hinders Control Flow Graph (CFG) recovery and alters discriminative virtual machine code characteristics while preserving the semantic correctness of smart contracts. Experimental results demonstrate that the proposed framework achieves a 100% obfuscation success rate with an average cyclomatic complexity of 90.80. Across all 15 evaluated transformation combinations, the framework introduces an overall mean virtual machine code size increase of 15.99% and a mean gas overhead of 7.04%. Notably, the complete multi-layer pipeline (T1+T2+T3+T4) exhibits overheads of 29.73% for virtual machine code size and 12.58% for gas, which remain acceptable considering the achieved robust resistance against reverse engineering and automated static analysis.
Downloads
References
REFERENCES
Z. Sheng, T. K. Quang, S. Wang, S. Duan, K. Li and Y. Duan, "Understanding and Characterizing Obfuscated Funds Transfers in Ethereum Smart Contracts", Cryptography and Security, 2026. DOI: 10.48550/arXiv.2505.11320.
P. V. Huong, N. D. Tuyen, D. H. Long, T. Q. Toanh and N. N. Tuyen, "A Novel Model of Comprehensive Data Encryption for the Website Using Blockchain", Journal of Science and Technology on Information Security, vol 1, no. 27, pp. 87-98, 2026. DOI: 10.54654/isj.v1i27.1252.
Y. Liu, J. He, X. Li, J. Chen, X. Liu, S. Peng, H. Cao and Y. Wang, "An overview of blockchain smart contract execution mechanism", Journal of Industrial Information Integration, vol. 41, 2024. DOI: 10.1016/j.jii.2024.100674.
David, L. Zhou, D. Song, A. Gervais and K. Qin, "Decompiling Smart Contracts with a Large Language Model", Computer Science, 2025. DOI: 10.48550/arXiv.2506.19624.
Github, "Mythril", Access time: 18/5/2026, https://github.com/ConsenSysDiligence/mythril.
Ethereum, "Ethereum.org" (2026), Access time: 10/5/2026, https://ethereum.org/developers/docs/evm/.
A. Olaoye, "HackMD" (12/01/2026), Access time: 05/5/2026, https://hackmd.io/@ayoola/SJ5jMdGrZg.
Hannah, "Medium", Access time: 30/4/2026, https://medium.com/@hannah.scherz.23/the-basic-structure-of-computer-systems-von-neumann-architecture-18c1cc546ab2.
M. Ogawa, "Malware Analysis: A Perspective from Dynamic Symbolic Execution of Binary Code," Journal of Science and Technology on Information Security, vol. 2, no. 25, pp. 5-20, 2025. DOI: 10.54654/isj.v2i25.1093
Z. Zhong, R. Wu, J. Wan, M. Zou and D. Tian, "Hardening Deep Neural Network Binaries against Reverse Engineering Attacks", CCS '25: Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security, pp 201 – 215, 2025. DOI: 10.1145/3719027.3765144.
D. Wang, J. He, Y. Yang, L. Wu, R. Chang and Y. Zhou, "Building Reuse-Sensitive Control Flow Graphs (CFGs) for EVM Bytecode", Computer Science, 2025.
P. D. Rosa, P. Felber and V. Schiavoni, "Seeing Through EVM Bytecode Obfuscation", IEEE, vol 14, pp. 25515 - 25536, 2026. DOI: 10.1109/ACCESS.2026.3662238.
Z. Hou, C. Dong and Y. Shang, "HermHD: Enhancing smart contract security based on code obfuscation", ICIT '23: Proceedings of the 2023 11th International Conference on Information Technology: IoT and Smart City, 2024. DOI: 10.1145/3638985.3639001.
T. Forissier, "EVeilM: EVM Bytecode Obfuscation" (2024), Access time: 10/5/2026, https://github.com/tit0uanf/EVeilM.
P. Zhang, X. Wang, Y. Tong, H. Dong, Y. Xiao and S. Ji, "Bytecode Obfuscation for Smart Contracts via Structural and Semantic Perturbation", ACM Transactions on Software Engineering and Methodology, 2026. DOI: 10.1145/3809489.
P. D. Rosa, S. Queyrut, Y.D. Bromberg, P. Felber and V. Schiavoni, "PhishingHook: Catching Phishing Ethereum Smart Contracts leveraging EVM Opcodes", IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), 2025. DOI: 10.1109/DSN64029.2025.00033.
Jon-Becker, "Github", Access time: 10/5/2026, https://github.com/Jon-Becker/heimdall-rs.
Downloads
Published
How to Cite
Issue
Section
License
Open Access Policy
The Journal of Science and Technology on Information Security provides open access to its published articles to broaden opportunities for high-quality research findings to be available and widely disseminated free of charge, contributing to the greater exchange of knowledge.
Open access statement: CTUJoS permits everyone to read, download, copy, distribute, print, search, or link to the full texts of the published articles without registration, price barriers, or asking for permission from the Journal or the author.
Proposed Policy for Journals That Offer Delayed Open Access
Authors who publish with this journal agree to the following terms:
1. Authors retain copyright and grant the journal right of first publication, with the work [SPECIFY PERIOD OF TIME] after publication simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
2. Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
3. Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).










