VLDB 2026 Research / reviewers in the wild / expert
Eva-Maria C. Behner
dblp:320/3502
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2026
0000-0002-2832-0722ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | To GOTO or Not to GOTO: Measuring Structural Complexity of (Decompiled) CodeabstractGotos are prevalent in many programs and contexts. Although it is widely assumed that gotos reduce readability, empirical evidence is limited, and most code metrics either ignore them or fail to model their impact on program comprehension. The problem is especially noticeable in highly optimized code, automatically transformed or AI generated code, and decompiler output, where gotos are very common. Without a metric that measures the structural complexity of such code with gotos, it remains challenging to evaluate and improve approaches involving program comprehension. Steffen Enders, Eva-Maria C. Behner, Elmar Gerhards-Padilla |
ICPC | 2 |
| 2025 | SoK: No Goto, No Cry? The Fairy Tale of Flawless Control-Flow StructuringabstractDecompilers play a crucial role in the detailed analysis of malware or firmware, particularly because control-flow structuring allows the recovery of high-level code that is more readable to human analysts. Despite the ongoing debate over their usage of gotos to work around constraints during control-flow structuring, pattern-matching approaches remain prevalent among both commercial and open-source decompilers. With the emergence of pattern-independent restructuring techniques, various attempts have been made to overcome readability limitations, especially concerning the use of gotos. However, despite these advances, recent approaches often fail to thoroughly address several inherent challenges of control-flow structuring, thereby affecting output quality or practicality.In this paper, we systematize the intrinsic challenges of control-flow structuring that every approach must address. In addition, we review existing methods, comparing them, while highlighting both their advantages and limitations with respect to these challenges. Specifically, we emphasize the practicability issues of current pattern-independent restructuring techniques and discuss whether and how future methods might overcome them. Finally, we explore the theoretical potential to mitigate some of these challenges by suggesting methodology ideas for various aspects of control-flow structuring. Overall, this paper enables other researchers to make informed decisions when developing or enhancing control-flow structuring methods, thereby preventing negative side-effects arising from the interdependence of challenges. Eva-Maria C. Behner, Steffen Enders, Elmar Gerhards-Padilla |
EuroS&P | 1 |
| 2025 | A Jump-Table-Agnostic Switch Recovery on ASTsabstractRecovering high-level control-flow structures is a crucial part of modern reverse engineering, especially in fields like binary analysis. Here, analysts often use decompilers to convert functions of binary programs into a more humanreadable C -like representation. Among these control-flow structures, switch statements have unique significance because of their ability to represent complex decision-making and branching behavior in a concise and readable manner. Consequently, the successful recovery of switch statements during decompilation can greatly enhance the readability of the resulting output, making it a highly desired goal in the field of reverse engineering. In this paper, we present a new technique for identifying abstract syntax tree components that can be transformed into semantically equivalent switches, thus improving code readability. In contrast to other approaches, we do not rely on jump tables that have or have not been emitted during compilation. Instead, we identify clusters of comparisons involving the same expression but with varying constant values within the abstract syntax tree to be transformed into switch constructs. Because this approach is inherently linked to the semantic definition of a switch statements, it only generates meaningful switches by design. We evaluated our approach on the coreutils-9.3 dataset and compared it to the leading decompilers Ghidra and Hex-Rays, both of which attempt to recover switch statements as well. Our evaluation results indicate that our approach outperforms both Ghidra and Hex-Rays by successfully recovering more than twice as many switch constructs in the given dataset. Steffen Enders, Eva-Maria C. Behner, Elmar Gerhards-Padilla |
ICSME | 2 |