Haim Schweitzer

59 papers A* 31B 4Journal 16Unranked 8
YearRankTypeTitle / Venue / Authors
2025 A* conf
AAAI
Guihong Wan, Ninghui Hao, Crystal Maung, Haim Schweitzer, Chen Zhao, Kun-Hsing Yu, Yevgeniy R. Semenov
2024 A* conf
AAAI
Guihong Wan, Wei Mao, Yevgeniy R. Semenov, Haim Schweitzer
2024 A* conf
AAAI
Wei Mao, Guihong Wan, Haim Schweitzer
2024 A* conf
AAAI
Boshen Yan, Guihong Wan, Haim Schweitzer, Zoltan Maliga, Sara Khattab, Kun-Hsing Yu, Peter K. Sorger, Yevgeniy R. Semenov
2024 J jnl
Int. J. Data Sci. Anal.
Guihong Wan, Haim Schweitzer
2024 J jnl
Data Min. Knowl. Discov.
Guihong Wan, Baokun He, Haim Schweitzer
2023 A* conf
AAAI
Guihong Wan, Meng Jiao, Xinglong Ju, Yu Zhang, Haim Schweitzer, Feng Liu
2021 conf
PAKDD (3)
Guihong Wan, Haim Schweitzer
2021 A* conf
ICDM
Guihong Wan, Haim Schweitzer
2021 A* conf
AAAI
Guihong Wan, Haim Schweitzer
2021 A* conf
AAAI
Guihong Wan, Haim Schweitzer
2021 A* conf
ICDE
Guihong Wan, Haim Schweitzer
2021 A* conf
IJCAI
Guihong Wan, Haim Schweitzer
2020 A* conf
AAAI
Baokun He, Guihong Wan, Haim Schweitzer
2020 A* conf
ICDM
Guihong Wan, Crystal Maung, Chenxu Zhang, Haim Schweitzer
2019 J jnl
CoRR
Baokun He, Guihong Wan, Haim Schweitzer
2019 A* conf
AAAI
Baokun He, Swair Shah, Crystal Maung, Gordon Arnold, Guihong Wan, Haim Schweitzer
2019 B conf
ICTAI
Guihong Wan, Crystal Maung, Haim Schweitzer
2019 J jnl
CoRR
Guihong Wan, Crystal Maung, Haim Schweitzer
2018 J jnl
Int. J. Artif. Intell. Tools
Swair Shah, Baokun He, Crystal Maung, Haim Schweitzer
2018 A* conf
AAAI
Swair Shah, Baokun He, Ke Xu, Crystal Maung, Haim Schweitzer
2018 J jnl
Int. J. Artif. Intell. Tools
Ke Xu, Crystal Maung, Hiromasa Arai, Haim Schweitzer
2017 A* conf
AAAI
Ke Xu, Tongyi Cao, Swair Shah, Crystal Maung, Haim Schweitzer
2017 B conf
ICTAI
Swair Shah, Baokun He, Crystal Maung, Haim Schweitzer
2017 A* conf
AAAI
Ke Xu, Swair Shah, Tongyi Cao, Crystal Maung, Haim Schweitzer
2017 B conf
ICTAI
Ke Xu, Hiromasa Arai, Crystal Maung, Haim Schweitzer
2016 A* conf
AAAI
Hiromasa Arai, Crystal Maung, Ke Xu, Haim Schweitzer
2016 A* conf
AAAI
Hiromasa Arai, Ke Xu, Crystal Maung, Haim Schweitzer
2015 J jnl
IEEE Trans. Knowl. Data Eng.
Crystal Maung, Haim Schweitzer
2015 A* conf
AAAI
Hiromasa Arai, Crystal Maung, Haim Schweitzer
2013 conf
NIPS
Crystal Maung, Haim Schweitzer
2011 J jnl
IEEE Trans. Pattern Anal. Mach. Intell.
Haim Schweitzer, Rui A. Deng, Robert Finis Anderson
2009 A* conf
ICCV
Haim Schweitzer, Robert Finis Anderson, Rui A. Deng
2009 B conf
SMC
Robert Finis Anderson, Haim Schweitzer
2005 conf
CVPR Workshops
Feng Wu, Haim Schweitzer
2005 conf
VISION
Feng Wu, Haim Schweitzer
2004 conf
Multimedia Information Retrieval
Tomohiro Yoshizawa, Haim Schweitzer
2002 conf
ECCV (4)
Haim Schweitzer
2002 conf
ECCV (4)
Haim Schweitzer, J. W. Bell, Feng Wu
2001 A* conf
ICCV
Haim Schweitzer
1999 A* conf
CVPR
Haim Schweitzer
1999 J jnl
Image Vis. Comput.
Haim Schweitzer
1999 J jnl
J. Exp. Theor. Artif. Intell.
Haim Schweitzer
1999 A* conf
ICCV
Haim Schweitzer
1998 J jnl
Int. J. Intell. Syst.
Haim Schweitzer, Sanjeev R. Kulkarni
1998 A* conf
ICCV
Haim Schweitzer
1998 A* conf
ICCV
Haim Schweitzer
1998 J jnl
Comput. Intell.
Haim Schweitzer, Janell Straach
1997 J jnl
Data Min. Knowl. Discov.
Haim Schweitzer
1997 conf
AAAI/IAAI
Haim Schweitzer
1996 A* conf
CVPR
Haim Schweitzer, Radha Krishnan
1995 J jnl
IEEE Trans. Pattern Anal. Mach. Intell.
Haim Schweitzer
1995 A* conf
IJCAI (1)
Haim Schweitzer, Janell Straach
1993 A* conf
CVPR
Haim Schweitzer
1993 A* conf
ICCV
Haim Schweitzer
1991 J jnl
J. Algorithms
James R. Bergen, Haim Schweitzer
1990 J jnl
Mach. Learn.
Haim Schweitzer
1990 A* conf
AAAI
Haim Schweitzer
1988 A* conf
COLT
Haim Schweitzer
redb/extractors/decompiler/apk/smali_normalization.py
← Index redb/extractors/decompiler/apk/smali_normalization.py python
"""Semantic normalization of Dalvik/smali instructions.

Analogous to Binary Ninja's LLIL normalization: strips register allocation
noise and instruction encoding variants while preserving semantic operations.

Three normalization levels (most aggressive to most detailed):
  - 'category':    semantic category only (MOV, ALU, CALL, ...)
  - 'opcode':      base opcode, width-invariant (add, sub, invoke, ...)
  - 'opcode_api':  opcode category + API method/field references for
                   invoke/field/alloc instructions (default for MinHash)

References:
  - Smali+ 12-category reduction (Canfora et al.)
  - MOSDroid opcode family grouping
  - DroidSIFT/DroidSim API-sensitive similarity
"""

import re
from typing import List

# ---------------------------------------------------------------------------
# Dalvik opcode -> semantic category mapping
# ---------------------------------------------------------------------------
# Prefix-matched against instruction opcodes. Order matters for overlapping
# prefixes (longer/more-specific prefixes should come first in iteration,
# but since we use startswith and break on first match, we order by
# specificity within the list).

OPCODE_CATEGORIES = {
    # Arithmetic/logic
    "add": "ALU", "sub": "ALU", "mul": "ALU", "div": "ALU",
    "rem": "ALU", "and": "ALU", "or": "ALU", "xor": "ALU",
    "shl": "ALU", "shr": "ALU", "ushr": "ALU", "neg": "ALU",
    "not": "ALU",
    # Data movement
    "move": "MOV", "const": "CONST",
    # Memory access (field/array)
    "iget": "LOAD", "sget": "LOAD", "aget": "LOAD",
    "iput": "STORE", "sput": "STORE", "aput": "STORE",
    # Invocations
    "invoke": "CALL",
    # Control flow
    "if": "BRANCH", "goto": "JMP",
    "switch": "SWITCH",
    "return": "RET",
    # Object/type
    "new": "ALLOC", "check": "TYPE", "instance": "TYPE",
    # Array
    "fill": "ARR", "array": "ARR",
    # Comparison
    "cmpl": "CMP", "cmpg": "CMP", "cmp": "CMP",
    # Exception / synchronization
    "throw": "EXC", "monitor": "SYNC",
    # Conversion (int-to-long, float-to-int, etc.)
    "int-to": "CONV", "long-to": "CONV", "float-to": "CONV",
    "double-to": "CONV",
}

# Pre-compiled regexes for operand extraction
_METHOD_REF_RE = re.compile(r"(L[\w/$]+;->[\w<>]+\(.*?\)[\w/$;\[]*)")
_FIELD_REF_RE = re.compile(r"(L[\w/$]+;->[\w]+:[\w/$;\[]+)")
_CLASS_REF_RE = re.compile(r"(L[\w/$]+;)")
_CONST_STRING_RE = re.compile(r'^const-string(?:/jumbo)?\s')


def categorize_opcode(opcode: str) -> str:
    """Map a Dalvik opcode to its semantic category.

    Prefix-matched: 'add-int/2addr' matches 'add' -> 'ALU'.
    Returns 'OTHER' for unrecognized opcodes.
    """
    for prefix, cat in OPCODE_CATEGORIES.items():
        if opcode.startswith(prefix):
            return cat
    return "OTHER"


# Mapping from semantic categories to the ACFG feature vector indices
# used by Binary Ninja's build_block_features (cfg_features.py).
# This enables cross-platform ACFG feature comparison.
CATEGORY_TO_ACFG_INDEX = {
    "ALU": 0,       # CAT_ARITHMETIC
    "CONV": 0,      # arithmetic-adjacent
    "CMP": 4,       # CAT_COMPARISON
    "MOV": 2,       # CAT_TRANSFER
    "CONST": 2,     # transfer-adjacent (loading constants)
    "LOAD": 5,      # CAT_MEMORY
    "STORE": 5,     # CAT_MEMORY
    "CALL": 3,      # CAT_CALL
    "BRANCH": 1,    # CAT_LOGIC (conditional logic)
    "JMP": 1,       # CAT_LOGIC
    "SWITCH": 1,    # CAT_LOGIC
    "RET": 2,       # CAT_TRANSFER
    "ALLOC": 5,     # CAT_MEMORY (heap allocation)
    "TYPE": 6,      # CAT_OTHER
    "ARR": 5,       # CAT_MEMORY
    "EXC": 6,       # CAT_OTHER
    "SYNC": 6,      # CAT_OTHER
    "OTHER": 6,     # CAT_OTHER
}


def normalize_instruction(line: str, level: str = "opcode_api") -> str:
    """Normalize a single smali instruction line.

    Args:
        line: A single smali instruction (whitespace-stripped).
        level: Normalization level:
            'category'   - most aggressive: just semantic category
            'opcode'     - base opcode only, width/addressing-mode invariant
            'opcode_api' - category + API references for invoke/field/alloc
                          (default, best for MinHash similarity)

    Returns:
        Normalized instruction string, or empty string for non-instructions.
    """
    stripped = line.strip()
    if not stripped:
        return ""

    parts = stripped.split(None, 1)
    opcode = parts[0]
    operands = parts[1] if len(parts) > 1 else ""

    if level == "category":
        return categorize_opcode(opcode)

    if level == "opcode":
        # Strip type/width suffixes for invariance:
        # add-int, add-long, add-float -> 'add'
        # add-int/2addr -> 'add'
        base = re.split(r"[-/]", opcode)[0]
        return base

    if level == "opcode_api":
        # const-string: preserve string content (encrypted strings are a
        # key malware indicator)
        if _CONST_STRING_RE.match(stripped):
            # Extract the string literal
            str_match = re.search(r'"(.*)"', operands)
            if str_match:
                return f"CONST_STR \"{str_match.group(1)}\""
            return "CONST_STR"

        # invoke-*: preserve method reference
        if opcode.startswith("invoke"):
            ref = _METHOD_REF_RE.search(operands)
            if ref:
                return f"CALL {ref.group(1)}"
            return "CALL"

        # Field access: preserve field reference
        if opcode.startswith(("iget", "iput", "sget", "sput")):
            ref = _FIELD_REF_RE.search(operands)
            if ref:
                cat = "LOAD" if "get" in opcode else "STORE"
                return f"{cat} {ref.group(1)}"
            # Fallback: try space-separated format from androguard
            # e.g. "iget v0, p0, Lcom/Foo;->field Ljava/lang/String;"
            space_ref = re.search(
                r"(L[\w/$]+;->[\w]+)\s+([\w/$;\[]+)", operands
            )
            if space_ref:
                cat = "LOAD" if "get" in opcode else "STORE"
                return f"{cat} {space_ref.group(1)}:{space_ref.group(2)}"
            cat = "LOAD" if "get" in opcode else "STORE"
            return cat

        # new-instance: preserve allocated type
        if opcode.startswith("new-instance") or opcode == "new-array":
            ref = _CLASS_REF_RE.search(operands)
            if ref:
                return f"ALLOC {ref.group(1)}"
            return "ALLOC"

        # Everything else: just the category
        return categorize_opcode(opcode)

    # Unknown level: return raw opcode
    return opcode


def normalize_method_body(
    body: str, level: str = "opcode_api"
) -> List[str]:
    """Normalize all instructions in a smali method body.

    Filters out directives (.), labels (:), comments (#), and blank lines.
    Returns a list of normalized instruction strings.

    Args:
        body: Raw smali method body text.
        level: Normalization level (see normalize_instruction).

    Returns:
        List of normalized instruction strings (no empty strings).
    """
    normalized = []
    for line in body.split("\n"):
        stripped = line.strip()
        # Skip non-instructions
        if not stripped:
            continue
        if stripped.startswith((".",":", "#")):
            continue
        result = normalize_instruction(stripped, level)
        if result:
            normalized.append(result)
    return normalized