October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

How to Configure Code Obfuscation Without Breaking Reflection or Serialization

Reflection and serializers depend on runtime contracts that shrinkers may not see. Map those dependencies, write narrow platform-specific rules, and test the transformed artifact.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To keep reflection and serialization working after obfuscation, identify what your runtime discovers dynamically, preserve only the classes, members, constructors, and metadata those paths require, and test the transformed release artifact. There is no universally safe ProGuard or R8 rule: the right configuration depends on the platform, obfuscator and mode, serializer, and their versions.

Start by identifying your exact stack

Before changing rules, record the target runtime and platform, obfuscator and mode, serializer and version, and whether libraries or dependencies provide consumer keep rules. The Android guidance below concerns R8; the .NET example concerns trimming and System.Text.Json on .NET 8. Those mechanisms and their configuration are not interchangeable.

Ask for those details before adopting a copy-paste rule. A rule that works for one combination may be redundant, too broad, or insufficient for another.

Map the runtime contracts that obfuscation can break

Static analysis can miss code that builds class or member names at runtime. A shrinker may then remove something that appears unused, while renaming can invalidate a string-based lookup. For every dynamic entry point, write down exactly what the caller requires:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Class or member existence: can the shrinker remove it?
  • Stable names: does code look up a class, field, or method by a string?
  • Constructors: does reflection instantiate the class, and which constructor does it call?
  • Annotations or metadata: does a framework scan annotations, generic signatures, parameter names, or other attributes?
  • Framework conventions: does a callback, plugin, JNI upcall, or other external code call into the application by convention?

Search for patterns such as Class.forName, reflective constructors, getDeclaredField, getDeclaredMethod, annotation scans, JSON model fields, generic type tokens, JNI upcalls, and convention-based callbacks. These searches are a starting point, not proof that every dynamic path has been found. Android’s keep-rules overview discusses cases including class-by-name lookup, annotation-based access, private reflected members, and Parcelable.

Choose the narrowest rule that preserves the contract

Keep directives have different scopes. In Android R8, -keep prevents removal and renaming for matched items, while -keepclassmembers preserves matched members on classes that remain. A broad rule can constrain shrinking and optimization beyond the dynamic path you need to protect; prefer a rule limited to the specific class and member whenever that is sufficient. See Android’s explanation of keep-rule behavior and guidance on adding keep rules.

For example, if code loads one named class and invokes its no-argument constructor, the contract is that class and constructor—not every application class. If classes are selected through a shared interface, a rule targeting matching implementations and their required constructors may be narrower than retaining all classes. When a literal name identifies a field or method, target the exact declaring class and member signature rather than keeping every member with a broad * pattern.

For each rule, check the same questions before expanding its scope:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Does it preserve the required item from removal?
  • Must the item’s name remain stable, or does the caller use a different identifier such as an explicit serialized name?
  • Can unrelated classes and members still be shrunk or optimized?
  • Does the framework need annotations, generic signatures, or other metadata in addition to the item itself?
  • Is the rule already supplied by the library or generated code?

Handle Gson and R8 according to their versions and features

Gson does not have one rule that fits every model and R8 configuration. Android’s current guidance says Gson 2.11 and later bundle rules for fields annotated with @SerializedName. Check the Gson version and the effective rules before adding app-level duplicates. With an explicit serialized name, do not assume the source field name must remain unchanged; verify the actual model and library behavior. Android documents the relevant patterns in its library dependency keep-rules guidance.

R8 full mode adds a separate metadata consideration: Android’s Gson TypeToken example requires retaining the generic Signature attribute. Add metadata preservation only when the runtime pattern needs it; retaining extra attributes without a reason obscures the actual contract. Check Android’s R8 full-mode guidance alongside the library version and bundled rules.

Do not apply Android keep syntax to .NET trimming

Obfuscation and trimming are related but distinct transformations. Microsoft’s compatibility note says that .NET 8 projects using PublishTrimmed turn off reflection-based System.Text.Json defaults, which can break reflection-based serialization. If reflection is required, the documented JsonSerializerIsReflectionEnabledByDefault project property restores the previous behavior. Evaluate source-generated serialization and the guidance for your target framework as alternatives; consult Microsoft’s .NET 8 PublishTrimmed compatibility note and current trimming guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check generated and dependency-provided rules

Before writing a manual rule, inspect what your dependencies and generated code already contribute. Android says @Parcelize generates rules automatically, while a manual Parcelable implementation may need its CREATOR field preserved. Confirm whether existing consumer rules cover the project rather than adding overlapping directives by default; see the Android keep-rules overview.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Validate the transformed release-like artifact

A successful debug build does not establish that dynamic paths still work after shrinking or obfuscation. Build with the same obfuscator settings as release and exercise the actual runtime contracts in the transformed artifact:

  1. Round-trip representative serialized data: serialize and deserialize it, including model fields, annotations, and generic type-token paths your application uses.
  2. Exercise reflective discovery and access: load classes, construct instances, and read or invoke the specific members used at runtime.
  3. Test optional dependencies, dynamic plugins, and framework callbacks that rely on naming conventions or runtime discovery.
  4. If something fails, inspect shrinker diagnostics and mapping or removal outputs to find the affected class, member, or metadata. Adjust the narrowest relevant rule, rebuild, and rerun the test.

These checks provide evidence for the app and configuration you exercised, not a guarantee for every possible runtime path. Keep tests aligned with the dynamic behavior your application actually uses.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.