Candace L. Sidner

81 papers A* 16A 10B 11Misc 4Journal 20Unranked 18
YearRankTypeTitle / Venue / Authors
2019 J jnl
Auton. Robots
Anahita Mohseni-Kabir, Changshuo Li, Victoria Wu, Daniel Miller, Benjamin Hylak, Sonia Chernova, Dmitry Berenson, Candace L. Sidner, Charles Rich
2019 J jnl
AI Mag.
Philip R. Cohen, Barbara J. Grosz, Candace L. Sidner, Liz Sonenberg, Matthew Johnson, Alonso Vera
2018 J jnl
ACM Trans. Interact. Intell. Syst.
Candace L. Sidner, Timothy W. Bickmore, Bahador Nooraie, Charles Rich, Lazlo Ring, Mahni Shayganfar, Laura Vardoulakis
2017 conf
HRI (Companion)
Anahita Mohseni-Kabir, Changshuo Li, Victoria Wu, Daniel Miller, Benjamin Hylak, Sonia Chernova, Dmitry Berenson, Candace L. Sidner, Charles Rich
2016 conf
AAAI Workshop: Symbiotic Cognitive Systems
Mahni Shayganfar, Charles Rich, Candace L. Sidner
2016 A conf
AAMAS
Mahni Shayganfar, Charles Rich, Candace L. Sidner
2016 A* conf
HRI
Mahni Shayganfar, Charles Rich, Candace L. Sidner
2015 conf
HRI (Extended Abstracts)
Candace L. Sidner, Charles Rich, Mohammad Shayganfar, Timothy W. Bickmore, Lazlo Ring, Zessie Zhang
2015 B conf
IVA
Timothy W. Bickmore, Dina Utami, Shuo Zhou, Candace L. Sidner, Lisa Quintiliani, Michael K. Paasche-Orlow
2015 A* conf
HRI
Anahita Mohseni-Kabir, Charles Rich, Sonia Chernova, Candace L. Sidner, Daniel Miller
2014 B ed.
IVA
Timothy W. Bickmore, Stacy Marsella, Candace L. Sidner
2014 B conf
IVA
Morteza Behrooz, Charles Rich, Candace L. Sidner
2014 conf
AAAI Fall Symposia
Candace L. Sidner, Charles Rich, Mohammad Shayganfar, Morteza Behrooz, Timothy W. Bickmore, Lazlo Ring, Zessie Zhang
2013 conf
SIGDIAL Conference
Candace L. Sidner, Timothy W. Bickmore, Charles Rich, Barbara Barry, Lazlo Ring, Morteza Behrooz, Mohammad Shayganfar
2012 A conf
IROS
Mohammad Shayganfar, Charles Rich, Candace L. Sidner
2012 B conf
IVA
Laura Pfeifer Vardoulakis, Lazlo Ring, Barbara Barry, Candace L. Sidner, Timothy W. Bickmore
2012 B conf
IVA
Charles Rich, Candace L. Sidner
2011 J jnl
J. Biomed. Informatics
Timothy W. Bickmore, Daniel Schulman, Candace L. Sidner
2011 conf
AIIDE
David Becroft, Jesse Bassett, Adrian Mejia, Charles Rich, Candace L. Sidner
2011 conf
AAAI Spring Symposium: AI and Health Communication
Daniel Schulman, Timothy W. Bickmore, Candace L. Sidner
2011 A* conf
HRI
Kevin O'Brien, Joel Sutherland, Charles Rich, Candace L. Sidner
2011 B conf
RO-MAN
Aaron Holroyd, Charles Rich, Candace L. Sidner, Brett Ponsleur
2010 conf
AAAI Fall Symposium: Dialog with Robots
Charles Rich, Candace L. Sidner
2010 A* conf
HRI
Charles Rich, Brett Ponsleur, Aaron Holroyd, Candace L. Sidner
2009 J jnl
AI Mag.
Charles Rich, Candace L. Sidner
2008 Misc conf
FLAIRS
Candace L. Sidner
2007 J jnl
AI Mag.
Charles Rich, Candace L. Sidner
2007 conf
AAAI Spring Symposium: Intentions in Intelligent Systems
Charles Rich, Candace L. Sidner
2007 J jnl
Artif. Intell.
Louis-Philippe Morency, Candace L. Sidner, Christopher Lee, Trevor Darrell
2007 ed.
HLT-NAACL
Candace L. Sidner, Tanja Schultz, Matthew Stone, ChengXiang Zhai
2007 J jnl
Knowl. Based Syst.
Cécile Paris, Candace L. Sidner
2006 J jnl
Pers. Ubiquitous Comput.
Charles Rich, Candace L. Sidner, Neal Lesh, Andrew Garland, Shane Booth, Markus Chimani
2006 A* conf
AAAI
Charles Rich, Candace L. Sidner
2006 A ed.
IUI
Cécile Paris, Candace L. Sidner
2006 A* conf
AAAI
Louis-Philippe Morency, Candace L. Sidner, Christopher Lee, Trevor Darrell
2006 A* conf
HRI
Candace L. Sidner, Christopher Lee, Louis-Philippe Morency, Clifton Forlines
2006 conf
AAAI Spring Symposium: Argumentation for Consumers of Healthcare
Timothy W. Bickmore, Candace L. Sidner
2005 conf
AAAI Fall Symposium: Caring Machines
Edward M. Riseman, Allen R. Hanson, Roderic A. Grupen, Phebe Sessions, Julie Abramson, Mary Olson, Candace L. Sidner
2005 B conf
ICMI
Louis-Philippe Morency, Candace L. Sidner, Christopher Lee, Trevor Darrell
2005 A* conf
AAAI
Charles Rich, Candace L. Sidner, Neal Lesh, Andrew Garland, Shane Booth, Markus Chimani
2005 J jnl
CoRR
Candace L. Sidner, Christopher Lee, Cory D. Kidd, Neal Lesh, Charles Rich
2005 J jnl
Artif. Intell.
Candace L. Sidner, Christopher Lee, Cory D. Kidd, Neal Lesh, Charles Rich
2005 J jnl
Interactions
Candace L. Sidner, Christopher Lee
2004 J jnl
IEICE Trans. Inf. Syst.
Neal Lesh, Joe Marks, Charles Rich, Candace L. Sidner
2004 conf
AH
Candace L. Sidner
2004 Misc conf
FLAIRS
David DeVault, Charles Rich, Candace L. Sidner
2004 conf
CHI Extended Abstracts
Christopher Lee, Neal Lesh, Candace L. Sidner, Louis-Philippe Morency, Ashish Kapoor, Trevor Darrell
2004 A conf
IUI
Candace L. Sidner, Cory D. Kidd, Christopher Lee, Neal Lesh
2004 B conf
Intelligent Tutoring Systems
Claude Frasson, Kaska Porayska-Pomsta, Cristina Conati, Guy Gouardères, W. Lewis Johnson, Helen Pain, Elisabeth André, Timothy W. Bickmore, Paul Brna, Isabel Fernández de Castro, Stefano A. Cerri, Cleide Jane Costa, James C. Lester, Christine L. Lisetti, Stacy Marsella, Jack Mostow, Roger Nkambou, Magalie Ochs, Ana Paiva, Fábio Paraguaçu, Natalie K. Person, Rosalind W. Picard, Candace L. Sidner, Angel de Vicente
2003 B conf
SMC
Candace L. Sidner, Christopher Lee
2002 Misc conf
NordiCHI
Olle Bälter, Candace L. Sidner
2002 B conf
Intelligent Tutoring Systems
Jeff Rickel, Neal Lesh, Charles Rich, Candace L. Sidner, Abigail S. Gertner
2002 A conf
IUI
Candace L. Sidner, Myroslava O. Dzikovska
2002 B conf
ICMI
Candace L. Sidner, Myroslava O. Dzikovska
2002 A conf
INTERSPEECH
Candace L. Sidner, Clifton Forlines
2001 J jnl
AI Mag.
Charles Rich, Candace L. Sidner, Neal Lesh
2001 conf
User Modeling
Neal Lesh, Charles Rich, Candace L. Sidner
2001 Misc conf
HCI
Charles Rich, Candace L. Sidner, Neal Lesh
2001 A conf
IUI
Jim R. Davies, Abigail S. Gertner, Neal Lesh, Charles Rich, Candace L. Sidner, Jeff Rickel
2001 A* conf
ACL
Justine Cassell, Yukiko I. Nakano, Timothy W. Bickmore, Candace L. Sidner, Charles Rich
1999 A conf
IUI
Candace L. Sidner, Daniel M. Coffman
1998 J jnl
User Model. User Adapt. Interact.
Charles Rich, Candace L. Sidner
1998 A conf
IUI
Candace L. Sidner, Alex Acero, Janet E. Cahn, Julia Hirschberg, Robert Moore, Salim Roukos
1997 conf
Agents
Charles Rich, Candace L. Sidner
1997 A conf
IUI
Charles Rich, Candace L. Sidner
1997 J jnl
ACM Trans. Comput. Hum. Interact.
Steve Whittaker, Jerry Swanson, Jakov Kucan, Candace L. Sidner
1996 A* conf
ACM Symposium on User Interface Software and Technology
Charles Rich, Candace L. Sidner
1996 A* conf
CHI
Steve Whittaker, Candace L. Sidner
1994 A* conf
AAAI
Candace L. Sidner
1994 J jnl
Knowl. Based Syst.
Candace L. Sidner
1990 A* conf
AAAI
Karen E. Lochbaum, Barbara J. Grosz, Candace L. Sidner
1986 J jnl
Comput. Linguistics
Barbara J. Grosz, Candace L. Sidner
1985 A* conf
IJCAI
Barbara J. Grosz, Candace L. Sidner
1985 J jnl
Comput. Intell.
Candace L. Sidner
1982 conf
ECICS
Madeleine Bates, Candace L. Sidner
1982 conf
ECICS
Candace L. Sidner, John Vittal
1981 J jnl
Am. J. Comput. Linguistics
Candace L. Sidner
1981 A* conf
IJCAI
Candace L. Sidner, David J. Israel
1979 A* conf
ACL
Candace L. Sidner
1979
Candace L. Sidner
1978 conf
TINLAP
Candace L. Sidner
redb/extractors/apk_extractors/apk_resources.py
← Index redb/extractors/apk_extractors/apk_resources.py python
import hashlib
import inspect
import os
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.apk_extractor import APKExtractor
from redb.models.dataclasses import APKResource


# ─── Suspicious file types ──────────────────────────────────────────────
# File types that are suspicious when found inside res/ or assets/.
# Excludes javascript/html (extremely common in legitimate hybrid apps)
# and common media/font types that are normal APK content.
SUSPICIOUS_TYPES = {
    # Executables — no legitimate reason in assets/res
    "elf", "pebin", "macho", "dex", "apk",
    # Java containers — DexClassLoader target
    "jar",
    # Archives — rare in legitimate assets (~135:1 malware-to-benign ratio)
    "zip", "gzip", "7z", "xz", "tar", "bzip2", "rar", "7zip", "lzma",
    # Scripts with system execution capability
    "shell", "python", "powershell", "batch",
}

# ─── Entropy thresholds ─────────────────────────────────────────────────
# For unrecognized/unknown types: encrypted payloads typically land > 7.0
ENTROPY_HIGH_UNKNOWN = 7.0
# For recognized-but-non-image types: stricter threshold
ENTROPY_EXTREME = 7.85

# ─── Android-specific binary format magic bytes ─────────────────────────
# These formats are common in legitimate APKs but unknown to Magika,
# causing misclassification (e.g., AXML → "gzip", profm → "unknown").
AXML_MAGIC = b'\x03\x00\x08\x00'       # Android Binary XML (compiled res/*.xml)
ARSC_MAGIC = b'\x02\x00\x0c\x00'       # Android compiled resource table
ART_PROF_MAGIC = b'pro\x00'            # ART baseline profile
ART_PROFM_MAGIC = b'prm\x00'           # ART baseline profile metadata

# ─── Allowlisted paths ──────────────────────────────────────────────────
# Fixed, hardcoded paths in the Android build system that are always benign.
# ART profiles at these exact paths are shipped by Jetpack ProfileInstaller.
ALLOWLISTED_PATHS = {
    "assets/dexopt/baseline.prof",
    "assets/dexopt/baseline.profm",
}

# ─── Image handling ─────────────────────────────────────────────────────
# Magika-confirmed image types: high entropy is expected (lossy codecs
# like VP8/JPEG arithmetic-code toward entropy ~7.95-8.0 by design).
IMAGE_MAGIKA_TYPES = {"png", "webp", "jpeg", "gif", "bmp", "tiff", "ico"}
IMAGE_EXTENSIONS = {".png", ".webp", ".jpg", ".jpeg", ".gif", ".bmp", ".tiff", ".ico"}

# ─── Types Magika assigns when it can't identify the content ────────────
UNRECOGNIZED_MAGIKA_TYPES = {"unknown", "empty"}

# ─── Resource scan limits ───────────────────────────────────────────────
MAX_RESOURCE_FILES = 5000


class APKResourceExtractor(APKExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False,
        apk=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, apk,
        )
        self.resources = []
        self.suspicious_files = []
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.APK_RESOURCES.value

    # ─── Core classification logic ──────────────────────────────────────

    def _identify_android_format(self, header: bytes) -> str | None:
        """
        Identify Android-specific binary formats that Magika doesn't know.
        Returns a corrected type label, or None to fall through to Magika.
        """
        if len(header) < 4:
            return None

        magic4 = header[:4]

        # Android Binary XML — all res/*.xml in a compiled APK.
        # Magika often misclassifies this as "gzip".
        if magic4 == AXML_MAGIC:
            return "android_binary_xml"

        # Android compiled resource table (resources.arsc chunks)
        if magic4 == ARSC_MAGIC:
            return "android_resource_table"

        # ART baseline profiles — high entropy (zlib inside) but benign.
        # The format is inert (method reference bitmaps/metadata, not
        # executable code) and some build configs place them at varying paths.
        if magic4 == ART_PROF_MAGIC:
            return "android_art_profile"
        if magic4 == ART_PROFM_MAGIC:
            return "android_art_profile_metadata"

        return None

    def _is_suspicious_resource(
        self, path: str, magika_type: str, entropy: float,
        android_type: str | None,
    ) -> bool:
        """
        Determine if a resource file is suspicious.

        Detection layers:
        1. Allowlisted paths → always benign
        2. Android-specific format override → reclassify Magika mislabels
        3. Image extension vs Magika type mismatch → encrypted blob detection
        4. Magika-confirmed images → benign regardless of entropy
        5. Suspicious type match → flag known-dangerous types
        6. High-entropy unknown blobs → likely encrypted payloads
        """

        # ── Layer 1: Allowlisted paths (hardcoded Android build artifacts) ──
        if path in ALLOWLISTED_PATHS:
            return False

        # ── Layer 2: Android-specific format detection ──────────────────────
        # Override Magika's label for formats it doesn't recognize.
        # All Android-specific formats (AXML, ARSC, ART profiles) are
        # legitimate build artifacts — never suspicious.
        if android_type is not None:
            return False

        # ── Layer 3: Image extension / Magika type mismatch ─────────────────
        # If the file extension claims "image" but Magika's content analysis
        # disagrees, this is a strong signal for an encrypted payload with
        # a fake image extension (e.g., ErrorFather's "rbyypivsnw.png").
        ext = os.path.splitext(path)[1].lower()
        if ext in IMAGE_EXTENSIONS and magika_type not in IMAGE_MAGIKA_TYPES:
            # Exception: Magika might label a valid image as "unknown" if
            # the file is very small (< ~16 bytes). Don't flag tiny files.
            if entropy > 5.0:
                return True

        # ── Layer 4: Magika-confirmed images → benign ───────────────────────
        # Lossy codecs (VP8, JPEG) produce entropy up to ~8.0 by design.
        # If Magika confirms image structure, high entropy is expected.
        if magika_type in IMAGE_MAGIKA_TYPES:
            return False

        # ── Layer 5: Known suspicious file types ────────────────────────────
        if magika_type in SUSPICIOUS_TYPES:
            return True

        # ── Layer 6: High-entropy unrecognized blobs ────────────────────────
        # Files Magika can't identify with high entropy are likely encrypted
        # payloads. Most Android malware packers store encrypted DEX/SO
        # payloads as opaque blobs with random names and no valid magic.
        if magika_type in UNRECOGNIZED_MAGIKA_TYPES and entropy > ENTROPY_HIGH_UNKNOWN:
            return True

        # ── Layer 7: Extreme entropy on any non-image recognized type ───────
        # Catches edge cases where Magika assigns a benign label (e.g.,
        # "xml", "txt") but the entropy is impossibly high for that format.
        if magika_type not in IMAGE_MAGIKA_TYPES and entropy > ENTROPY_EXTREME:
            return True

        return False

    # ─── Extraction pipeline ────────────────────────────────────────────

    def extract(self):
        if not self._is_valid_apk():
            self.log.error(f"Invalid APK for {self.hash.sha256}")
            return None

        try:
            from magika import Magika
            magika = Magika()
        except Exception as e:
            self.log.error(f"Failed to initialize Magika for {self.hash.sha256}: {e}")
            magika = None

        self.resources = []
        self.suspicious_files = []
        scanned = 0

        zf = self._get_zip_file()
        if not zf:
            return None

        with zf:
            for info in zf.infolist():
                if info.is_dir():
                    continue
                if not (info.filename.startswith("res/") or
                        info.filename.startswith("assets/")):
                    continue

                if scanned >= MAX_RESOURCE_FILES:
                    self.log.warning(
                        f"Resource scan limit reached ({MAX_RESOURCE_FILES}), "
                        f"stopping resource enumeration"
                    )
                    break
                scanned += 1

                try:
                    data = zf.read(info.filename)
                except Exception as e:
                    self.log.warning(
                        f"Error reading resource {info.filename}: {e}"
                    )
                    continue

                try:
                    file_sha256 = hashlib.sha256(data).hexdigest()
                    file_entropy = round(self.calculate_entropy(data), 3)

                    # Read first bytes for Android-specific format detection
                    header = data[:16] if len(data) >= 16 else data

                    if magika:
                        try:
                            filetype = magika.identify_bytes(data).output.label
                        except Exception:
                            filetype = "unknown"
                    else:
                        filetype = "unknown"

                    # Identify Android-specific formats once, reuse for
                    # both stored type and suspicion classification
                    android_type = self._identify_android_format(header)
                    stored_type = android_type if android_type else filetype

                    suspicious = self._is_suspicious_resource(
                        path=info.filename,
                        magika_type=filetype,
                        entropy=file_entropy,
                        android_type=android_type,
                    )

                    resource = APKResource(
                        path=info.filename,
                        size=info.file_size,
                        sha256=file_sha256,
                        filetype_magika=stored_type,
                        entropy=file_entropy,
                    )

                    if suspicious:
                        resource.is_suspicious = True
                        self.suspicious_files.append(resource)

                    self.resources.append(resource)
                except Exception as e:
                    self.log.warning(
                        f"Error processing resource {info.filename}: {e}"
                    )
                    continue

        if not self.resources:
            return None

        return {
            "total_resource_count": len(self.resources),
            "total_resource_size": sum(r.size for r in self.resources),
            "suspicious_file_count": len(self.suspicious_files),
            "resources": self.resources,
            "suspicious_files": self.suspicious_files,
        }

    # ─── Export ──────────────────────────────────────────────────────────

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.resources:
                return None

            current_time = datetime.now(timezone.utc)
            data = []
            for res in self.resources:
                data.append([
                    self.sha256,
                    res.path,
                    res.size,
                    res.sha256,
                    res.filetype_magika,
                    res.entropy,
                    int(res.is_suspicious),
                    current_time,
                ])

            column_names = [
                'sha256', 'resource_path', 'resource_size',
                'resource_sha256', 'resource_magika', 'resource_entropy',
                'is_suspicious', 'analysis_date',
            ]

            column_type_names = [
                'FixedString(64)', 'String', 'UInt64',
                'FixedString(64)', 'LowCardinality(String)', 'Float32',
                'UInt8', "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_apk_resources"