Han Xu

12 papers A* 2C 1Journal 5Unranked 4
YearRankTypeTitle / Venue / Authors
2023 J jnl
Nat.
Yitong Chen, Maimaiti Nazhamaiti, Han Xu, Yao Meng, Tiankuang Zhou, Guangpu Li, Jingtao Fan, Qi Wei, Jiamin Wu, Fei Qiao, Lu Fang, Qionghai Dai
2022 conf
ASP-DAC
Ziwei Li, Han Xu, Zheyu Liu, Li Luo, Qi Wei, Fei Qiao
2022 A* conf
DAC
Maimaiti Nazhamaiti, Haijin Su, Han Xu, Zheyu Liu, Fei Qiao, Qi Wei, Zidong Du, Xinghua Yang, Li Luo
2022 J jnl
IEEE Trans. Circuits Syst. I Regul. Pap.
Han Xu, Ningchao Lin, Li Luo, Qi Wei, Runsheng Wang, Cheng Zhuo, Xunzhao Yin, Fei Qiao, Huazhong Yang
2021 conf
A-SSCC
Han Xu, Zheyu Liu, Ziwei Li, Erxiang Ren, Maimaiti Nazhamati, Fei Qiao, Li Luo, Qi Wei, Xinjun Liu, Huazhong Yang
2021 C conf
ISCAS
Ziwei Li, Han Xu, Li Luo, Qi Wei, Fei Qiao
2021 J jnl
IEEE Trans. Circuits Syst. II Express Briefs
Han Xu, Ziru Li, Ningchao Lin, Qi Wei, Fei Qiao, Xunzhao Yin, Huazhong Yang
2021 J jnl
IEEE Trans. Circuits Syst. II Express Briefs
Maimaiti Nazhamaiti, Han Xu, Zheyu Liu, Yixuan Chen, Qi Wei, Xing Wu, Fei Qiao
2021 J jnl
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.
Han Xu, Ziwei Li, Ziru Li, Deliang Fan, Fei Qiao, Qi Wei, Li Luo, Xinjun Liu, Huazhong Yang
2020 conf
ISQED
Han Xu, Ziru Li, Fei Qiao, Qi Wei, Xinjun Liu, Huazhong Yang
2020 A* conf
DAC
Han Xu, Maimaiti Nazhamaiti, Yidong Liu, Fei Qiao, Qi Wei, Xinjun Liu, Huazhong Yang
2018 conf
SoCC
Han Xu, Fei Qiao, Zhe Chen, Qi Wei, Xinjun Liu, Huazhong Yang
tests/unit/test_decompile_scores.py
← Index tests/unit/test_decompile_scores.py python
"""Unit tests for bninja/analysis/scores.py — ObfuscationScores."""
import sys
import pytest
from unittest.mock import MagicMock

# Install binaryninja stubs before importing
from tests.unit.conftest_binja_stubs import (
    install_binja_stubs,
    HighLevelILOperation,
)
bn_mock = install_binja_stubs()

from redb.extractors.decompiler.bninja.analysis.scores import (
    ObfuscationScores,
    get_dominated_by,
    uses_mba,
)
import binaryninja.highlevelil as hlil_mod


# ============================================================================
# Helper: Mock HLIL instruction
# ============================================================================

class MockHLILInstruction(hlil_mod.HighLevelILInstruction):
    """Mock HLIL instruction with operation and operands."""
    def __init__(self, operation, operands=None):
        self.operation = operation
        self.operands = operands or []


class MockHLILBasicBlock:
    """Mock HLIL basic block for flattened score testing."""
    def __init__(self, incoming_edges=None, dominator_tree_children=None):
        self.incoming_edges = incoming_edges or []
        self.dominator_tree_children = dominator_tree_children or []


# ============================================================================
# 5a. ObfuscationScores
# ============================================================================


class TestFlattenedScore:
    def test_flattened_score_no_back_edges(self):
        """Linear CFG with no back edges -> score 0.0."""
        block = MockHLILBasicBlock(incoming_edges=[], dominator_tree_children=[])
        func = MagicMock()
        func.basic_blocks = [block]
        scores = ObfuscationScores(func)
        assert scores.flattened_score() == 0.0

    def test_flattened_score_with_loop(self):
        """CFG with a back edge -> score > 0.0."""
        block = MockHLILBasicBlock(dominator_tree_children=[])
        # Create a back edge: an incoming edge whose source is in the dominated set
        edge = MagicMock()
        edge.source = block  # source IS the dominator -> back edge
        block.incoming_edges = [edge]
        func = MagicMock()
        func.basic_blocks = [block]
        scores = ObfuscationScores(func)
        assert scores.flattened_score() > 0.0

    def test_flattened_score_fully_flat(self):
        """Flattened CFG: one block dominates all -> ratio close to 1.0."""
        children = [MockHLILBasicBlock() for _ in range(4)]
        root = MockHLILBasicBlock(dominator_tree_children=children)
        # Back edge from root incoming
        edge = MagicMock()
        edge.source = root
        root.incoming_edges = [edge]
        all_blocks = [root] + children
        func = MagicMock()
        func.basic_blocks = all_blocks
        scores = ObfuscationScores(func)
        assert scores.flattened_score() == pytest.approx(1.0)


class TestMBAScore:
    def test_mba_score_no_mixed_ops(self):
        """Instructions with only arithmetic -> score 0.0."""
        instr = MockHLILInstruction(HighLevelILOperation.HLIL_ADD, operands=[])
        func = MagicMock()
        func.instructions = [instr]
        scores = ObfuscationScores(func)
        assert scores.MBA_score() == 0.0

    def test_mba_score_mixed_ops(self):
        """Instructions with arithmetic + logic -> score > 0.0."""
        inner_logic = MockHLILInstruction(HighLevelILOperation.HLIL_XOR, operands=[])
        outer_arith = MockHLILInstruction(
            HighLevelILOperation.HLIL_ADD, operands=[inner_logic]
        )
        func = MagicMock()
        func.instructions = [outer_arith]
        scores = ObfuscationScores(func)
        assert scores.MBA_score() > 0.0

    def test_mba_score_all_mixed(self):
        """Every instruction has both -> score 1.0."""
        inner_logic = MockHLILInstruction(HighLevelILOperation.HLIL_NOT, operands=[])
        outer_arith = MockHLILInstruction(
            HighLevelILOperation.HLIL_SUB, operands=[inner_logic]
        )
        func = MagicMock()
        func.instructions = [outer_arith]
        scores = ObfuscationScores(func)
        assert scores.MBA_score() == 1.0


class TestGetDominatedBy:
    def test_get_dominated_by(self):
        child1 = MockHLILBasicBlock(dominator_tree_children=[])
        child2 = MockHLILBasicBlock(dominator_tree_children=[])
        root = MockHLILBasicBlock(dominator_tree_children=[child1, child2])
        result = get_dominated_by(root)
        assert root in result
        assert child1 in result
        assert child2 in result
        assert len(result) == 3


class TestUsesMBA:
    def test_uses_mba_arithmetic_only(self):
        instr = MockHLILInstruction(HighLevelILOperation.HLIL_ADD, operands=[])
        assert uses_mba(instr) is False

    def test_uses_mba_logic_only(self):
        instr = MockHLILInstruction(HighLevelILOperation.HLIL_XOR, operands=[])
        assert uses_mba(instr) is False

    def test_uses_mba_mixed(self):
        inner = MockHLILInstruction(HighLevelILOperation.HLIL_AND, operands=[])
        outer = MockHLILInstruction(HighLevelILOperation.HLIL_ADD, operands=[inner])
        assert uses_mba(outer) is True