EvoPatch-IoT: Evolution-Aware Cross-Architecture Vulnerability Retrieval and Patch-State Profiling for BusyBox-Based IoT Firmware

BusyBox is widely reused in Linux-based Internet-of-Things (IoT) firmware, but stripped symbols, heterogeneous instruction sets, uncertain component versions, and selective patch backports make N-day vulnerability localization difficult. We propose EvoPatch-IoT, an evolution-aware retrieval framework whose novelty lies not in another standalone encoder, but in coupling target-local geometric localization, architecture-normalized anonymous multi-view evidence, and a version-causal historical prototype memory for reference-guided retrieval. We also release an original benchmark constructed by collecting official BusyBox releases and compiling each selected version separately for AArch64, ARM, MIPS, MIPSEL, and x86_64 in both stripped and unstripped forms. It contains 57 compiled versions and 555 binaries, together with 155,845 high-confidence stripped-to-unstripped anchors; the dataset is available in the public record. On the original symmetric 57-version benchmark (1020 directed architecture pairs), EvoPatch-IoT obtains 34.56% Hit@1 and 56.24% Hit@10. Relative to the actual strongest baseline, the in-house geometry-only ShapeStat control, these are gains of 8.00% and 5.50%, rather than gains over a weaker literature-inspired control. A stricter historical-only evaluation on 15 chronologically held-out recent versions gives 28.76% Hit@1 and 49.93% Hit@10 versus 26.55% and 47.83% for geometry alone; paired tests over 300 architecture pairs yield p < 1.6 × 10−16, with version-block 95% confidence intervals excluding zero. Direct ablations show that geometry and historical prototypes provide most of the gain, while fusion mainly improves first-rank precision and MRR. A single-CVE patch-state study is retained as supporting, not general, evidence.

Authors

Publication Details

Journal
Pragmatic Cybersecurity
Published
2026-09-30
DOI
https://doi.org/10.53941/pc.2026.100019
Primary Topic
Security and Verification in Computing
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

EvoPatch-IoT: Evolution-Aware Cross-Architecture Vulnerability Retrieval and Patch-State Profiling for BusyBox-Based IoT Firmware

Yongluo Shen, Yinhao Xiao, Huixi Li
Pragmatic Cybersecurity
Security and Verification in Computing
article

EvoPatch-IoT: Evolution-Aware Cross-Architecture Vulnerability Retrieval and Patch-State Profiling for BusyBox-Based IoT Firmware

Yongluo Shen, Yinhao Xiao, Huixi Li
article en

Abstract

BusyBox is widely reused in Linux-based Internet-of-Things (IoT) firmware, but stripped symbols, heterogeneous instruction sets, uncertain component versions, and selective patch backports make N-day vulnerability localization difficult. We propose EvoPatch-IoT, an evolution-aware retrieval framework whose novelty lies not in another standalone encoder, but in coupling target-local geometric localization, architecture-normalized anonymous multi-view evidence, and a version-causal historical prototype memory for reference-guided retrieval. We also release an original benchmark constructed by collecting official BusyBox releases and compiling each selected version separately for AArch64, ARM, MIPS, MIPSEL, and x86_64 in both stripped and unstripped forms. It contains 57 compiled versions and 555 binaries, together with 155,845 high-confidence stripped-to-unstripped anchors; the dataset is available in the public record. On the original symmetric 57-version benchmark (1020 directed architecture pairs), EvoPatch-IoT obtains 34.56% Hit@1 and 56.24% Hit@10. Relative to the actual strongest baseline, the in-house geometry-only ShapeStat control, these are gains of 8.00% and 5.50%, rather than gains over a weaker literature-inspired control. A stricter historical-only evaluation on 15 chronologically held-out recent versions gives 28.76% Hit@1 and 49.93% Hit@10 versus 26.55% and 47.83% for geometry alone; paired tests over 300 architecture pairs yield p < 1.6 × 10−16, with version-block 95% confidence intervals excluding zero. Direct ablations show that geometry and historical prototypes provide most of the gain, while fusion mainly improves first-rank precision and MRR. A single-CVE patch-state study is retained as supporting, not general, evidence.

Pragmatic CybersecurityVol. 1(3)
Openalex Percentile: Top 9%
Security and Verification in Computing
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

EvoPatch-IoT: Evolution-Aware Cross-Architecture Vulnerability Retrieval and Patch-State Profiling for BusyBox-Based IoT Firmware — Yongluo Shen, Yinhao Xiao, et al. · Pragmatic Cybersecurity (2026) | TGRS Research Map | TGRS