Ralph Hertwig

32 papers B 15Journal 14Unranked 3
YearRankTypeTitle / Venue / Authors
2026 conf
IUI Companion
Antonela Tommasel, Markus Schedl, Ralph Hertwig
2025 J jnl
CoRR
Julian Berger, Jason W. Burton, Ralph Hertwig, Thomas Kosch, Ralf H. J. M. Kurvers, Benito Kurzenberger, Christopher Lazik, Linda Onnasch, Tobias Rieger, Anna Isabel Thoma, Dirk U. Wulff, Stefan M. Herzog
2025 J jnl
CoRR
Xinyi Zhao, Anna Isabel Thoma, Ralph Hertwig, Dirk U. Wulff
2025 J jnl
Comput. Hum. Behav. Artif. Humans
Arend Hintze, Charu Bisht, Jory Schossau, Ralph Hertwig
2025 J jnl
CoRR
Xinyi Zhao, Ralph Hertwig, Dirk U. Wulff
2024 B conf
CogSci
Francesca Bonalumi, Ralph Hertwig, Azzurra Ruggeri
2024 B conf
CogSci
Yujia Yang, Anna Isabel Thoma, Ralph Hertwig, Dirk U. Wulff
2023 J jnl
CoRR
Nils C. Köbis, Philipp Lorenz-Spreen, Tamer Ajaj, Jean-François Bonnefon, Ralph Hertwig, Iyad Rahwan
2022 J jnl
PLoS Comput. Biol.
Stefan Appelhoff, Ralph Hertwig, Bernhard Spitzer
2022 J jnl
Top. Cogn. Sci.
Ralph Hertwig, Christina Leuker, Thorsten Pachur, Leonidas Spiliopoulos, Timothy J. Pleskac
2021 B conf
CogSci
Lou Marie Haux, Jan Engelmann, Esther Herrmann, Ralph Hertwig
2021 J jnl
Synth.
Anastasia Kozyreva, Ralph Hertwig
2020 B conf
CogSci
Shahar Hechtlinger, Christina Leuker, Ralph Hertwig
2019 J jnl
Top. Cogn. Sci.
Gerhard Schurz, Ralph Hertwig
2019 B conf
CogSci
Emmanuel M. Pothos, Jerome R. Busemeyer, Timothy J. Pleskac, James M. Yearsley, Josh Tenenbaum, Noah D. Goodman, Michael Henry Tessler, Tom Griffiths, Falk Lieder, Ralph Hertwig, Thorsten Pachur, Christina Leuker, Richard M. Shiffrin
2017 B conf
CogSci
Job Schepens, Ralph Hertwig, Wouter van den Bos
2017 B conf
CogSci
Christin Schulze, Thorsten Pachur, Ralph Hertwig
2017 B conf
CogSci
Christina Leuker, Timothy J. Pleskac, Thorsten Pachur, Ralph Hertwig
2017 B conf
CogSci
Nadine Fleischhut, Stefan M. Herzog, Ralph Hertwig
2017 J jnl
CoRR
Mehdi Moussaïd, Stefan M. Herzog, Juliane E. Kämmer, Ralph Hertwig
2016 J jnl
Minds Mach.
Ralph Hertwig, Arthur Paul Pedersen
2016 B conf
CogSci
Ying Li, Thomas T. Hills, Ralph Hertwig
2016 J jnl
Minds Mach.
Till Grüne-Yanoff, Ralph Hertwig
2015 B conf
CogSci
Douglas Markant, Timothy J. Pleskac, Adele Diederich, Thorsten Pachur, Ralph Hertwig
2014 B conf
CogSci
Nadine Fleischhut, Florian Artinger, Sebastian Olschewski, Kirsten G. Volz, Ralph Hertwig
2013 B conf
CogSci
Renata Suter, Thorsten Pachur, Ralph Hertwig
2013 J jnl
CoRR
Arend Hintze, Randal S. Olson, Christoph Adami, Ralph Hertwig
2013 B conf
CogSci
Dirk U. Wulff, Thomas T. Hills, Ralph Hertwig
2012 B conf
CogSci
Dirk U. Wulff, Thomas T. Hills, Ralph Hertwig
2012 conf
ICANN (2)
Jan K. Woike, Ulrich Hoffrage, Ralph Hertwig
2012 J jnl
Synth.
Ralph Hertwig
2004 conf
ICCM
Lael Schooler, Ralph Hertwig
redb/extractors/decompiler/_archive/GhidraDecompilerScript-latest.java
← Index redb/extractors/decompiler/_archive/GhidraDecompilerScript-latest.java java
import ghidra.app.script.GhidraScript;
import ghidra.program.model.listing.*;
import ghidra.app.decompiler.*;
import ghidra.program.model.block.*;
import ghidra.program.model.symbol.*;
import ghidra.program.model.pcode.*;
import ghidra.program.model.address.*;
import org.json.JSONObject;
import org.json.JSONArray;
import java.security.MessageDigest;
import java.nio.charset.StandardCharsets;

public class GhidraDecompilerScript extends GhidraScript {
    private DecompInterface decompInterface;
    private BasicBlockModel basicBlockModel;
    
    @Override
    public void run() throws Exception {
        // Get binary hash and filepath from arguments
        String[] args = getScriptArgs();
        if (args.length < 2) {
            System.err.println("{\"error\": \"Both SHA256 and filepath arguments are required\"}");
            return;
        }
        String sha256 = args[0];
        String filepath = args[1];

        // Initialize analysis components
        setupDecompiler();
        basicBlockModel = new BasicBlockModel(currentProgram);

        // Create the main JSON object for output
        JSONObject output = new JSONObject();
        output.put("sha256", sha256);
        output.put("decompiled", new JSONArray());
        output.put("disassembled", new JSONArray());
        output.put("cfg", new JSONArray());

        // Process all functions
        FunctionIterator functions = currentProgram.getFunctionManager().getFunctions(true);
        for (Function function : functions) {
            processFunction(function, output);
        }

        // Output the final JSON to stdout
        System.out.println(output.toString());
    }

    private void setupDecompiler() {
        decompInterface = new DecompInterface();
        DecompileOptions options = new DecompileOptions();
        decompInterface.setOptions(options);
        decompInterface.openProgram(currentProgram);
    }

    private void processFunction(Function function, JSONObject output) {
        Address entry = function.getEntryPoint();
        String functionName = function.getName();
        String functionAddress = entry.toString();

        // Process decompiled code
        processDecompiledCode(function, output.getJSONArray("decompiled"), 
                            functionName, functionAddress);

        // Process disassembled code
        processDisassembledCode(function, output.getJSONArray("disassembled"), 
                              functionName, functionAddress);

        // Process CFG
        processCFG(function, output.getJSONArray("cfg"), functionAddress);
    }

    private void processDecompiledCode(Function function, JSONArray decompArray, 
                                     String functionName, String functionAddress) {
        DecompileResults results = decompInterface.decompileFunction(function, 30, monitor);
        if (results.decompileCompleted()) {
            String decompiledCode = results.getDecompiledFunction().getC();
            String contentHash = calculateHash(decompiledCode);

            JSONObject functionObj = new JSONObject();
            functionObj.put("decompiled_content_hash", contentHash);
            functionObj.put("decompiled_function_name", functionName);
            functionObj.put("decompiled_function_address", functionAddress);
            functionObj.put("decompiled_function", decompiledCode);
            
            decompArray.put(functionObj);
        }
    }

    private void processDisassembledCode(Function function, JSONArray disasmArray, 
                                       String functionName, String functionAddress) {
        try {
            StringBuilder disassembly = new StringBuilder();
            StringBuilder normalized = new StringBuilder();
            int instructionCount = 0;

            Listing listing = currentProgram.getListing();
            AddressSetView functionBody = function.getBody();
            InstructionIterator instructions = listing.getInstructions(functionBody, true);

            while (instructions.hasNext()) {
                try {
                    Instruction instr = instructions.next();
                    String disasmLine = instr.toString();
                    disassembly.append(disasmLine).append("\n");
                    normalized.append(normalizeInstruction(disasmLine)).append("\n");
                    instructionCount++;
                } catch (Exception e) {
                    System.err.println("Error processing instruction in " + functionName + ": " + e.getMessage());
                }
            }

            String disassembledCode = disassembly.toString();
            String contentHash = calculateHash(disassembledCode);

            JSONObject functionObj = new JSONObject();
            functionObj.put("disassembled_content_hash", contentHash);
            functionObj.put("disassembled_function_name", functionName);
            functionObj.put("disassembled_function_address", functionAddress);
            functionObj.put("disassembled_function", disassembledCode);
            functionObj.put("normalized_disassembly", normalized.toString());
            functionObj.put("instruction_count", instructionCount);

            // Set similarity-related fields to null for now
            functionObj.put("minhash_signature", JSONObject.NULL);
            functionObj.put("opcode_frequency_vector", JSONObject.NULL);
            functionObj.put("api_calls_vector", JSONObject.NULL);
            functionObj.put("instruction_embedding", JSONObject.NULL);

            disasmArray.put(functionObj);
        } catch (Exception e) {
            System.err.println("Error processing disassembly for " + functionName + ": " + e.getMessage());
        }
    }

    private void processCFG(Function function, JSONArray cfgArray, String functionAddress) {
        try {
            CodeBlockIterator blocks = basicBlockModel.getCodeBlocksContaining(
                function.getBody(), monitor);

            while (blocks.hasNext()) {
                CodeBlock block = blocks.next();
                String blockInstructions = getBlockInstructions(block);
                String blockId = calculateHash(blockInstructions);

                JSONObject blockObj = new JSONObject();
                blockObj.put("block_id", blockId);
                blockObj.put("function_address", functionAddress);
                blockObj.put("block_instructions", blockInstructions);

                // Get successor blocks
                CodeBlockReferenceIterator successors = block.getDestinations(monitor);
                JSONArray successorAddresses = new JSONArray();
                while (successors.hasNext()) {
                    CodeBlockReference ref = successors.next();
                    successorAddresses.put(ref.getDestinationAddress().toString());
                }
                blockObj.put("successor_blocks", successorAddresses);

                cfgArray.put(blockObj);
            }
        } catch (Exception e) {
            System.err.println("{\"error\": \"Error processing CFG: " + 
                             e.getMessage().replace("\"", "'") + "\"}");
        }
    }

    private String normalizeInstruction(String instruction) {
        return instruction.replaceAll("0x[0-9a-fA-F]+", "IMM")
                        .replaceAll("\\b\\d+\\b", "NUM");
    }

    private String getBlockInstructions(CodeBlock block) {
        StringBuilder instructions = new StringBuilder();
        AddressIterator addresses = block.getAddresses(true);
        while (addresses.hasNext()) {
            Address addr = addresses.next();
            Instruction instr = currentProgram.getListing().getInstructionAt(addr);
            if (instr != null) {
                instructions.append(instr.toString()).append("\n");
            }
        }
        return instructions.toString();
    }

    private String calculateHash(String content) {
        try {
            MessageDigest digest = MessageDigest.getInstance("SHA-256");
            byte[] hash = digest.digest(content.getBytes(StandardCharsets.UTF_8));
            StringBuilder hexString = new StringBuilder();
            for (byte b : hash) {
                hexString.append(String.format("%02x", b));
            }
            return hexString.toString();
        } catch (Exception e) {
            System.err.println("{\"error\": \"Error calculating hash\"}");
            return "";
        }
    }
}