Skip to Content
New release 12 available 🎉

Performance

Value and Array Encryption trades a small amount of runtime cost for keeping your constants and array data out of the decompiled code.

  • Per-access decryption. Each encrypted constant is fetched through a decryption call instead of being loaded directly, so a value read costs more than a plain ldc. For the overwhelming majority of code this is imperceptible, but it can add up when a hot loop repeatedly reads encrypted constants millions of times.
  • Array rebuild on first use. An encrypted inline array is reconstructed from its decrypted data the first time it is initialized.

Because the cost is proportional to how often encrypted values are read, apply encryption where it protects something worth protecting rather than to every literal in the assembly. If a specific tight loop shows measurable overhead, consider hoisting the constant into a variable outside the loop, or enabling encryption only for the data types that actually carry sensitive data (see Configuration).

As with any protection setting, run your test suite and, if relevant, your performance benchmarks against the obfuscated assembly to confirm the trade-off is acceptable for your application.

Last updated on