image.png

Reimagined taint analysis system built upon deductive reasoning, counterintuitive philosophy, and human heuristics in real-world vulnerability research. We propose brand new dataflow analysis concepts ("State-recovery theory", "Parameter-first heuristic search", "Definition and Reference is All You Need"...), and tell a story how deductive reasoning - human's greatest cognition tool - played a role both in conceptualizing a bespoke dataflow system for Transformers, and enabling AIs in autonomous black-box taint analysis in binaries.