DexShield

The open-source, auditable Android code obfuscation & app-protection framework — a clean-room DexGuard alternative, built and measured for the age of LLM-assisted reverse engineering.

Full DEX + manifest + resource obfuscation, DEX string encryption and a native RASP — with a reproducible LLM-resistance benchmark (0.67, 0% cross-build transfer) that the commercial incumbents don't publish. Why it matters →

CI status License Apache 2.0 Kotlin

What is DexShield?

DexShield is a free, open-source Android code obfuscation and application-protection framework. It is a clean-room, modular and documented reimplementation of the protection techniques used by commercial tools such as DexGuard. It works on two levels: a JVM bytecode pipeline built on ASM, and a DEX backend (built on dexlib2) that rewrites the final classes.dex, binary AndroidManifest.xml and resources.arsc of an already-built APK — plus a native C++ RASP. Driven by a typed, human-readable YAML config. Apache-2.0 licensed, created by Ivan Garibay.

Features

Every DEX-level transform below is verified installing and running real APKs on real Android devices.

Full name obfuscation

Renames classes, private/static members and virtual methods (override-consistent) on the final DEX, plus Activity/Service components in both the DEX and the binary manifest. ReTrace-compatible mapping.txt.

DEX string encryption

AES-256 encryption of string literals in the final DEX with an auto-injected decrypt runtime — covers code already shipped as Dalvik, not just your pre-D8 bytecode.

Resource obfuscation

Shortens resource names in resources.arsc while keeping resource IDs intact, so code and compiled XML keep resolving. Strip-debug, control-flow and asset/class encryption included.

Native RASP (.so)

C++/JNI detectors: anti-debug (TracerPid), anti-Frida, and un-hookable signature verification reading the APK v2 signing block in native code. A re-signed/repackaged APK aborts at startup.

Native library encryption

Encrypts the app's own .so (AES-256, per-build seed) into assets, strips the plaintext, and rewrites System.loadLibrary → an injected NativeLoader that decrypts and loads at runtime. Verified end-to-end on a real Verifone T650p.

Reflection/JNI-aware keep

Automatically preserves classes and members referenced by name (Class.forName, getMethod, native), so aggressive obfuscation doesn't break real apps. On by default.

Config-driven CLI & Gradle

One dexshield.yml + protect-apk drives the whole pipeline. Plus the com.dexshield Gradle plugins and a programmatic Kotlin API.

Quick start

Protect a built APK (DEX backend)

dexshield protect-apk --input app.apk --output app-protected.apk \
    --config dexshield.yml --mapping mapping.txt

# then re-sign with your own key (DexShield never handles keystores):
zipalign -p -f 4 app-protected.apk aligned.apk
apksigner sign --ks release.jks aligned.apk

JVM pipeline (JAR / library)

dexshield protect --config dexshield.yml --input app.jar --output app-protected.jar

Gradle plugin

plugins { id("com.dexshield") }

dexshield {
    configFile.set(file("dexshield.yml"))
    inputJar.set(tasks.named<Jar>("jar").flatMap { it.archiveFile })
    outputJar.set(layout.buildDirectory.file("protected/app-protected.jar"))
}

Full documentation and an executable example are in the GitHub repository.

Why an open-source DexGuard alternative?

Commercial Android hardening tools are powerful but proprietary and expensive. DexShield brings the core ideas — name obfuscation, string encryption and RASP — into an auditable, extensible, Apache-2.0 codebase that teams can read, trust and adapt. Every transformation is a Transform that a shared Pipeline executes in order over a mutable class pool, so you can add your own protections by implementing a single interface.

👉 See the detailed DexShield vs DexGuard comparison, or why DexShield — the market gaps it fills in the LLM era.

PhaseContentStatus
1Name + string obfuscation, CLI, Gradle plugin✅ Done
2RASP + native .so (anti-debug, anti-Frida, signature verification)✅ Done, verified on hardware
3Control-flow, class/asset encryption, white-box AES✅ Done
4DEX backend: names, components, resources, strings, strip-debug, reflection-aware keep, config-driven protect-apk✅ Done, verified on real Android devices
5Method virtualization: full ISA (int/long/arrays/control-flow/calls/fields), R8-compatible via bytecode dispatcher✅ Done, verified on a real Verifone T650p
6Polish: integrated re-signing, native AAR, more detectors, plugin SDK, releases, live-Frida detection✅ Done
7Native library encryption: encrypt the app's own .so, strip plaintext, inject NativeLoader + rewrite System.loadLibrary✅ Done, verified end-to-end on a real Verifone T650p

Research

DexShield is also a reproducible research platform. Two contributions set it apart from a plain DexGuard reimplementation:

Per-build diversification

Every build produces a different name scheme and a different string-encryption key, so analysis of one build does not transfer to another — defeating pattern/signature-based deobfuscation. A fixed seed makes builds reproducible. Verified on real Android devices.

LLM-resistance benchmark

A reproducible benchmark that measures how well a large language model can reverse-engineer protected vs. plain code — a threat existing evaluations ignore. In a pilot, an assistant's recovery dropped from 1.00 (plain) to 0.33 (protected).

👉 See all measured numbers — size & speed overhead, string removal and reverse-engineering resistance — on the DexShield benchmarks page.

A draft paper — "DexShield: An Open, Diversified and LLM-Measured Android Application Protection Platform" — and the benchmark are in the repository. The individual techniques are not claimed as novel; the contribution is the open, diversified, measurable integration, and the evaluation is stated as preliminary.

Author

DexShield was created and is maintained by Ivan Garibay — an Android developer and application-security engineer, specialized in reverse engineering of SDKs and mobile app hardening.

🔗 github.com/garibayivan