What is DexShield?
DexShield is a free, open-source Android code obfuscation and application-protection framework. It is a clean-room, modular and documented reimplementation of the protection techniques used by commercial tools such as DexGuard. It works on two levels: a JVM bytecode pipeline built on ASM, and a DEX backend (built on dexlib2) that rewrites the final classes.dex, binary AndroidManifest.xml and resources.arsc of an already-built APK — plus a native C++ RASP. Driven by a typed, human-readable YAML config. Apache-2.0 licensed, created by Ivan Garibay.
Features
Every DEX-level transform below is verified installing and running real APKs on real Android devices.
Full name obfuscation
Renames classes, private/static members and virtual methods (override-consistent) on the final DEX, plus Activity/Service components in both the DEX and the binary manifest. ReTrace-compatible mapping.txt.
DEX string encryption
AES-256 encryption of string literals in the final DEX with an auto-injected decrypt runtime — covers code already shipped as Dalvik, not just your pre-D8 bytecode.
Resource obfuscation
Shortens resource names in resources.arsc while keeping resource IDs intact, so code and compiled XML keep resolving. Strip-debug, control-flow and asset/class encryption included.
Native RASP (.so)
C++/JNI detectors: anti-debug (TracerPid), anti-Frida, and un-hookable signature verification reading the APK v2 signing block in native code. A re-signed/repackaged APK aborts at startup.
Native library encryption
Encrypts the app's own .so (AES-256, per-build seed) into assets, strips the plaintext, and rewrites System.loadLibrary → an injected NativeLoader that decrypts and loads at runtime. Verified end-to-end on a real Verifone T650p.
Reflection/JNI-aware keep
Automatically preserves classes and members referenced by name (Class.forName, getMethod, native), so aggressive obfuscation doesn't break real apps. On by default.
Config-driven CLI & Gradle
One dexshield.yml + protect-apk drives the whole pipeline. Plus the com.dexshield Gradle plugins and a programmatic Kotlin API.
Quick start
Protect a built APK (DEX backend)
dexshield protect-apk --input app.apk --output app-protected.apk \
--config dexshield.yml --mapping mapping.txt
# then re-sign with your own key (DexShield never handles keystores):
zipalign -p -f 4 app-protected.apk aligned.apk
apksigner sign --ks release.jks aligned.apk
JVM pipeline (JAR / library)
dexshield protect --config dexshield.yml --input app.jar --output app-protected.jar
Gradle plugin
plugins { id("com.dexshield") }
dexshield {
configFile.set(file("dexshield.yml"))
inputJar.set(tasks.named<Jar>("jar").flatMap { it.archiveFile })
outputJar.set(layout.buildDirectory.file("protected/app-protected.jar"))
}
Full documentation and an executable example are in the GitHub repository.
Why an open-source DexGuard alternative?
Commercial Android hardening tools are powerful but proprietary and expensive. DexShield brings the core ideas — name obfuscation, string encryption and RASP — into an auditable, extensible, Apache-2.0 codebase that teams can read, trust and adapt. Every transformation is a Transform that a shared Pipeline executes in order over a mutable class pool, so you can add your own protections by implementing a single interface.
👉 See the detailed DexShield vs DexGuard comparison, or why DexShield — the market gaps it fills in the LLM era.
| Phase | Content | Status |
|---|---|---|
| 1 | Name + string obfuscation, CLI, Gradle plugin | ✅ Done |
| 2 | RASP + native .so (anti-debug, anti-Frida, signature verification) | ✅ Done, verified on hardware |
| 3 | Control-flow, class/asset encryption, white-box AES | ✅ Done |
| 4 | DEX backend: names, components, resources, strings, strip-debug, reflection-aware keep, config-driven protect-apk | ✅ Done, verified on real Android devices |
| 5 | Method virtualization: full ISA (int/long/arrays/control-flow/calls/fields), R8-compatible via bytecode dispatcher | ✅ Done, verified on a real Verifone T650p |
| 6 | Polish: integrated re-signing, native AAR, more detectors, plugin SDK, releases, live-Frida detection | ✅ Done |
| 7 | Native library encryption: encrypt the app's own .so, strip plaintext, inject NativeLoader + rewrite System.loadLibrary | ✅ Done, verified end-to-end on a real Verifone T650p |
Research
DexShield is also a reproducible research platform. Two contributions set it apart from a plain DexGuard reimplementation:
Per-build diversification
Every build produces a different name scheme and a different string-encryption key, so analysis of one build does not transfer to another — defeating pattern/signature-based deobfuscation. A fixed seed makes builds reproducible. Verified on real Android devices.
LLM-resistance benchmark
A reproducible benchmark that measures how well a large language model can reverse-engineer protected vs. plain code — a threat existing evaluations ignore. In a pilot, an assistant's recovery dropped from 1.00 (plain) to 0.33 (protected).
👉 See all measured numbers — size & speed overhead, string removal and reverse-engineering resistance — on the DexShield benchmarks page.
A draft paper — "DexShield: An Open, Diversified and LLM-Measured Android Application Protection Platform" — and the benchmark are in the repository. The individual techniques are not claimed as novel; the contribution is the open, diversified, measurable integration, and the evaluation is stated as preliminary.