Walter J. Curran

80 papers B 24Journal 6Unranked 50
YearRankTypeTitle / Venue / Authors
2021 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Tonghe Wang, Yang Lei, Zhen Tian, Matt Giles, Jeffrey D. Bradley, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Yabo Fu, Yang Lei, Tonghe Wang, Pretesh Patel, Ashesh B. Jani, Hui Mao, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Image-Guided Procedures
Yabo Fu, Yang Lei, Tonghe Wang, Jun Zhou, Pretesh Patel, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 J jnl
CoRR
Mingquan Lin, Jacob F. Wynne, Yang Lei, Tonghe Wang, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 J jnl
Medical Image Anal.
Yabo Fu, Yang Lei, Tonghe Wang, Pretesh Patel, Ashesh B. Jani, Hui Mao, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Image-Guided Procedures
Shadab Momin, Yang Lei, Tonghe Wang, Yabo Fu, Pretesh Patel, Ashesh B. Jani, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 B conf
Image Processing
Richard L. J. Qiu, Yang Lei, Aparna H. Kesarwala, Kristin Higgins, Jeffrey D. Bradley, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Tonghe Wang, Yang Lei, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 B conf
Image Processing
Yabo Fu, Yang Lei, Tonghe Wang, Sibo Tian, Pretesh Patel, Ashesh B. Jani, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Computer-Aided Diagnosis
Xianjin Dai, Yang Lei, Tonghe Wang, Jun Zhou, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 B conf
Image Processing
Yang Lei, Zhen Tian, Tonghe Wang, Justin Roper, Kristin Higgins, Jeffrey D. Bradley, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Computer-Aided Diagnosis
Shadab Momin, Yang Lei, Tonghe Wang, Yabo Fu, Pretesh Patel, Ashesh B. Jani, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 B conf
Image Processing
Huiqiao Xie, Yang Lei, Tonghe Wang, Yabo Fu, Xiangyang Tang, Walter J. Curran, Pretesh Patel, Tian Liu, Xiaofeng Yang
2021 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Yang Lei, Bing Ji, Tian Liu, Walter J. Curran, Hui Mao, Xiaofeng Yang
2021 conf
Image-Guided Procedures
Xianjin Dai, Yang Lei, Yupei Zhang, Tonghe Wang, Walter J. Curran, Pretesh Patel, Tian Liu, Xiaofeng Yang
2021 conf
Image-Guided Procedures
Xianjin Dai, Yang Lei, Zhen Tian, Tonghe Wang, Tian Liu, Walter J. Curran, Xiaofeng Yang
2021 conf
Computer-Aided Diagnosis
Yabo Fu, Yang Lei, Tonghe Wang, Jun Zhou, Walter J. Curran, Pretesh Patel, Tian Liu, Xiaofeng Yang
2021 conf
Computer-Aided Diagnosis
Mingquan Lin, Shadab Momin, Boran Zhou, Katherine Tang, Yang Lei, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 B conf
Image Processing
Tonghe Wang, Yang Lei, Sibo Tian, Tian Liu, Walter J. Curran, Kristin Higgins, Xiaofeng Yang
2021 conf
Computer-Aided Diagnosis
Tonghe Wang, Yang Lei, Olayinka A. Abiodun Ojo, Oladunni A. Akin-Akintayo, Akinyemi A. Akintayo, Walter J. Curran, Tian Liu, David M. Schuster, Xiaofeng Yang
2021 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Yang Lei, Zhen Tian, Tonghe Wang, Justin Roper, Kristin Higgins, Jeffrey D. Bradley, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Image-Guided Procedures
Yang Lei, Tonghe Wang, Sibo Tian, Yabo Fu, Pretesh Patel, Ashesh B. Jani, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 B conf
Image Processing
Tonghe Wang, Yang Lei, Mark McDonald, Jonathan J. Beitler, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Jiwoong Jason Jeong, Yang Lei, Karen Xu, Tian Liu, Hyunsuk Shim, Walter J. Curran, Hui-Kuo Shu, Xiaofeng Yang
2021 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Tonghe Wang, Yang Lei, Oladunni O. Akin-Akintayo, Olayinka A. Abiodun Ojo, Akinyemi A. Akintayo, Walter J. Curran, Tian Liu, David M. Schuster, Xiaofeng Yang
2021 B conf
Image Processing
Yang Lei, Yabo Fu, Tonghe Wang, Walter J. Curran, Tian Liu, Pretesh Patel, Xiaofeng Yang
2021 conf
Image-Guided Procedures
Shadab Momin, Yang Lei, Tonghe Wang, Yabo Fu, Pretesh Patel, Ashesh B. Jani, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Computer-Aided Diagnosis
Yupei Zhang, Yang Lei, Mingquan Lin, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Image-Guided Procedures
Xianjin Dai, Yang Lei, James Janopaul-Naylor, Tonghe Wang, Justin Roper, Tian Liu, Walter J. Curran, Pretesh Patel, Xiaofeng Yang
2021 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Xianjin Dai, Yang Lei, Tonghe Wang, Jun Zhou, Justin Roper, Mark McDonald, Jonathan J. Beitler, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 B conf
Image Processing
Xianjin Dai, Yang Lei, James Janopaul-Naylor, Tonghe Wang, Justin Roper, Jun Zhou, Walter J. Curran, Tian Liu, Pretesh Patel, Xiaofeng Yang
2021 conf
Image-Guided Procedures
Xianjin Dai, Yang Lei, Tonghe Wang, Jun Zhou, Walter J. Curran, Tian Liu, Xiaofeng Yang
2021 conf
Image-Guided Procedures
Yupei Zhang, Yang Lei, Xiuxiu He, Zhen Tian, Jiwoong Jason Jeong, Tonghe Wang, Qiulan Zeng, Ashesh B. Jani, Walter J. Curran, Pretesh Patel, Tian Liu, Xiaofeng Yang
2020 conf
Computer-Aided Diagnosis
Xiuxiu He, Bangjun Guo, Yang Lei, Yingzi Liu, Tonghe Wang, Walter J. Curran, Longjiang Zhang, Tian Liu, Xiaofeng Yang
2020 B conf
Image Processing
Yabo Fu, Yang Lei, Tonghe Wang, Kristin Higgins, Jeffrey D. Bradley, Walter J. Curran, Tian Liu, Xiaofeng Yang
2020 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Yang Lei, Tonghe Wang, Xue Dong, Kristin Higgins, Tian Liu, Walter J. Curran, Hui Mao, Jonathon A. Nye, Xiaofeng Yang
2020 conf
Computer-Aided Diagnosis
Yabo Fu, Yang Lei, Tonghe Wang, XiaoJun Jiang, Walter J. Curran, Tian Liu, Hui-Kuo Shu, Xiaofeng Yang
2020 conf
Computer-Aided Diagnosis
Yang Lei, Zhen Tian, Shannon Kahn, Walter J. Curran, Tian Liu, Xiaofeng Yang
2020 B conf
Image Processing
Xiuxiu He, Bangjun Guo, Yang Lei, Tonghe Wang, Tian Liu, Walter J. Curran, Longjiang Zhang, Xiaofeng Yang
2020 conf
Computer-Aided Diagnosis
Bangjun Guo, Xiuxiu He, Tonghe Wang, Yang Lei, Walter J. Curran, Tian Liu, Longjiang Zhang, Xiaofeng Yang
2020 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Jiwoong Jason Jeong, Yang Lei, Hui-Kuo Shu, Tian Liu, Liya Wang, Walter J. Curran, Hui Mao, Xiaofeng Yang
2020 B conf
Image Processing
Yabo Fu, Yang Lei, Yingzi Liu, Tonghe Wang, Walter J. Curran, Tian Liu, Pretesh Patel, Xiaofeng Yang
2020 J jnl
CoRR
Yang Lei, Yabo Fu, Tonghe Wang, Richard L. J. Qiu, Walter J. Curran, Tian Liu, Xiaofeng Yang
2020 B conf
Image Processing
Yang Lei, Xue Dong, Tonghe Wang, Kristin Higgins, Tian Liu, Walter J. Curran, Hui Mao, Jonathan A. Nye, Xiaofeng Yang
2020 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Xianjin Dai, Yang Lei, Yingzi Liu, Tonghe Wang, Walter J. Curran, Pretesh Patel, Tian Liu, Xiaofeng Yang
2020 B conf
Image Processing
Yingzi Liu, Yang Lei, Tonghe Wang, Jun Zhou, Liyong Lin, Tian Liu, Pretesh Patel, Walter J. Curran, Lei Ren, Xiaofeng Yang
2020 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Yang Lei, Xue Dong, Tonghe Wang, Kristin Higgins, Tian Liu, Walter J. Curran, Jonathan A. Nye, Hui Mao, Xiaofeng Yang
2020 J jnl
CoRR
Tonghe Wang, Yang Lei, Yabo Fu, Walter J. Curran, Tian Liu, Xiaofeng Yang
2020 conf
Computer-Aided Diagnosis
Yabo Fu, Bangjun Guo, Yang Lei, Tonghe Wang, Tian Liu, Walter J. Curran, Longjiang Zhang, Xiaofeng Yang
2020 J jnl
IEEE Trans. Medical Imaging
Yupei Zhang, Xiuxiu He, Zhen Tian, Jiwoong Jason Jeong, Yang Lei, Tonghe Wang, Qiulan Zeng, Ashesh B. Jani, Walter J. Curran, Pretesh Patel, Tian Liu, Xiaofeng Yang
2020 B conf
Image Processing
Yang Lei, Yabo Fu, Hui Mao, Walter J. Curran, Tian Liu, Xiaofeng Yang
2020 B conf
Image Processing
Yang Lei, Jun Zhou, Xue Dong, Tonghe Wang, Hui Mao, Mark McDonald, Walter J. Curran, Tian Liu, Xiaofeng Yang
2020 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Yang Lei, Xue Dong, Sibo Tian, Tonghe Wang, Pretesh Patel, Walter J. Curran, Ashesh B. Jani, Tian Liu, Xiaofeng Yang
2020 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Tonghe Wang, Matt Giles, Robert H. Press, Xianjin Dai, Ashesh B. Jani, Peter Rossi, Yang Lei, Walter J. Curran, Pretesh Patel, Tian Liu, Xiaofeng Yang
2020 B conf
Image Processing
Yabo Fu, Yang Lei, Jun Zhou, Tonghe Wang, Ashesh B. Jani, Pretesh Patel, Hui Mao, Walter J. Curran, Tian Liu, Xiaofeng Yang
2020 conf
Computer-Aided Diagnosis
Yang Lei, Joseph Harms, Xue Dong, Tonghe Wang, Xiangyang Tang, David S. Yu, Jonathan J. Beitler, Walter J. Curran, Tian Liu, Xiaofeng Yang
2020 B conf
Image Processing
Xiuxiu He, Yang Lei, Yabo Fu, Hui Mao, Walter J. Curran, Tian Liu, Xiaofeng Yang
2020 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Yabo Fu, Yang Lei, Jun Zhou, Tonghe Wang, David S. Yu, Jonathan J. Beitler, Walter J. Curran, Tian Liu, Xiaofeng Yang
2020 B conf
Image Processing
Yang Lei, Sibo Tian, Yabo Fu, Xue Dong, Tonghe Wang, Ashesh B. Jani, David M. Schuster, Walter J. Curran, Pretesh Patel, Tian Liu, Xiaofeng Yang
2020 B conf
Image Processing
Qiulan Zeng, Yabo Fu, Jiwoong Jason Jeong, Yang Lei, Tonghe Wang, Hui Mao, Ashesh B. Jani, Pretesh Patel, Walter J. Curran, Tian Liu, Xiaofeng Yang
2019 conf
AIRT@MICCAI
Yang Lei, Yabo Fu, Joseph Harms, Tonghe Wang, Walter J. Curran, Tian Liu, Kristin Higgins, Xiaofeng Yang
2019 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Tonghe Wang, Yang Lei, Haipeng Tang, Joseph Harms, Cheng Wang, Tian Liu, Walter J. Curran, Weihua Zhou, Dianfu Li, Xiaofeng Yang
2019 B conf
Image Processing
Bo Wang, Yang Lei, Tonghe Wang, Xue Dong, Sibo Tian, XiaoJun Jiang, Ashesh B. Jani, Tian Liu, Walter J. Curran, Pretesh Patel, Xiaofeng Yang
2019 conf
Computer-Aided Diagnosis
Bo Wang, Yang Lei, Jiwoong Jason Jeong, Tonghe Wang, Yingzi Liu, Sibo Tian, Pretesh Patel, XiaoJun Jiang, Ashesh B. Jani, Hui Mao, Walter J. Curran, Tian Liu, Xiaofeng Yang
2019 conf
Computer-Aided Diagnosis
Yang Lei, Yingzi Liu, Xue Dong, Sibo Tian, Tonghe Wang, XiaoJun Jiang, Kristin Higgins, Jonathan J. Beitler, David S. Yu, Tian Liu, Walter J. Curran, Yi Fang, Xiaofeng Yang
2019 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Yang Lei, Yingzi Liu, Tonghe Wang, Sibo Tian, Xue Dong, XiaoJun Jiang, Tian Liu, Hui Mao, Walter J. Curran, Hui-Kuo Shu, Xiaofeng Yang
2019 conf
AIRT@MICCAI
Yang Lei, Tonghe Wang, Joseph Harms, Yabo Fu, Xue Dong, Walter J. Curran, Tian Liu, Xiaofeng Yang
2019 J jnl
CoRR
Yabo Fu, Yang Lei, Tonghe Wang, Walter J. Curran, Tian Liu, Xiaofeng Yang
2019 conf
Computer-Aided Diagnosis
Tonghe Wang, Yang Lei, Ghazal Shafai-Erfani, XiaoJun Jiang, Xue Dong, Jun Zhou, Tian Liu, Walter J. Curran, Xiaofeng Yang, Hui-Kuo Shu
2019 B conf
Image Processing
Yang Lei, Tonghe Wang, Yingzi Liu, Kristin Higgins, Sibo Tian, Tian Liu, Hui Mao, Hyunsuk Shim, Walter J. Curran, Hui-Kuo Shu, Xiaofeng Yang
2019 conf
Biomedical Applications in Molecular, Structural, and Functional Imaging
Jiwoong Jason Jeong, Bing Ji, Yang Lei, Liya Wang, Tian Liu, Arif Ali, Walter J. Curran, Hui Mao, Xiaofeng Yang
2019 conf
Computer-Aided Diagnosis
Ge Cui, Jiwoong Jason Jeong, Yang Lei, Tonghe Wang, Tian Liu, Walter J. Curran, Hui Mao, Xiaofeng Yang
2018 conf
EMBC
Yang Lei, Hui-Kuo Shu, Sibo Tian, Tonghe Wang, Tian Liu, Hui Mao, Hyunsuk Shim, Walter J. Curran, Xiaofeng Yang
2017 B conf
Image Processing
Xiaofeng Yang, Yang Lei, Hui-Kuo Shu, Peter Rossi, Hui Mao, Hyunsuk Shim, Walter J. Curran, Tian Liu
2016 B conf
Image Processing
Xiaofeng Yang, Peter Rossi, Ashesh B. Jani, Hui Mao, Walter J. Curran, Tian Liu
2016 conf
Image-Guided Procedures
Xiaofeng Yang, Ashesh B. Jani, Peter J. Rossi, Hui Mao, Walter J. Curran, Tian Liu
2016 conf
Image-Guided Procedures
Xiaofeng Yang, Ashesh B. Jani, Peter J. Rossi, Hui Mao, Walter J. Curran, Tian Liu
2015 B conf
Image Processing
Xiaofeng Yang, Peter Rossi, Ashesh B. Jani, Hui Mao, Tomi Ogunleye, Walter J. Curran, Tian Liu
2015 conf
Image-Guided Procedures
Xiaofeng Yang, Peter Rossi, Hui Mao, Ashesh B. Jani, Tomi Ogunleye, Walter J. Curran, Tian Liu
2014 conf
Image-Guided Procedures
Xiaofeng Yang, Peter Rossi, Tomi Ogunleye, Ashesh B. Jani, Walter J. Curran, Tian Liu
redb/extractors/apk_extractors/apk_resources.py
← Index redb/extractors/apk_extractors/apk_resources.py python
import hashlib
import inspect
import os
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.apk_extractor import APKExtractor
from redb.models.dataclasses import APKResource


# ─── Suspicious file types ──────────────────────────────────────────────
# File types that are suspicious when found inside res/ or assets/.
# Excludes javascript/html (extremely common in legitimate hybrid apps)
# and common media/font types that are normal APK content.
SUSPICIOUS_TYPES = {
    # Executables — no legitimate reason in assets/res
    "elf", "pebin", "macho", "dex", "apk",
    # Java containers — DexClassLoader target
    "jar",
    # Archives — rare in legitimate assets (~135:1 malware-to-benign ratio)
    "zip", "gzip", "7z", "xz", "tar", "bzip2", "rar", "7zip", "lzma",
    # Scripts with system execution capability
    "shell", "python", "powershell", "batch",
}

# ─── Entropy thresholds ─────────────────────────────────────────────────
# For unrecognized/unknown types: encrypted payloads typically land > 7.0
ENTROPY_HIGH_UNKNOWN = 7.0
# For recognized-but-non-image types: stricter threshold
ENTROPY_EXTREME = 7.85

# ─── Android-specific binary format magic bytes ─────────────────────────
# These formats are common in legitimate APKs but unknown to Magika,
# causing misclassification (e.g., AXML → "gzip", profm → "unknown").
AXML_MAGIC = b'\x03\x00\x08\x00'       # Android Binary XML (compiled res/*.xml)
ARSC_MAGIC = b'\x02\x00\x0c\x00'       # Android compiled resource table
ART_PROF_MAGIC = b'pro\x00'            # ART baseline profile
ART_PROFM_MAGIC = b'prm\x00'           # ART baseline profile metadata

# ─── Allowlisted paths ──────────────────────────────────────────────────
# Fixed, hardcoded paths in the Android build system that are always benign.
# ART profiles at these exact paths are shipped by Jetpack ProfileInstaller.
ALLOWLISTED_PATHS = {
    "assets/dexopt/baseline.prof",
    "assets/dexopt/baseline.profm",
}

# ─── Image handling ─────────────────────────────────────────────────────
# Magika-confirmed image types: high entropy is expected (lossy codecs
# like VP8/JPEG arithmetic-code toward entropy ~7.95-8.0 by design).
IMAGE_MAGIKA_TYPES = {"png", "webp", "jpeg", "gif", "bmp", "tiff", "ico"}
IMAGE_EXTENSIONS = {".png", ".webp", ".jpg", ".jpeg", ".gif", ".bmp", ".tiff", ".ico"}

# ─── Types Magika assigns when it can't identify the content ────────────
UNRECOGNIZED_MAGIKA_TYPES = {"unknown", "empty"}

# ─── Resource scan limits ───────────────────────────────────────────────
MAX_RESOURCE_FILES = 5000


class APKResourceExtractor(APKExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False,
        apk=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, apk,
        )
        self.resources = []
        self.suspicious_files = []
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.APK_RESOURCES.value

    # ─── Core classification logic ──────────────────────────────────────

    def _identify_android_format(self, header: bytes) -> str | None:
        """
        Identify Android-specific binary formats that Magika doesn't know.
        Returns a corrected type label, or None to fall through to Magika.
        """
        if len(header) < 4:
            return None

        magic4 = header[:4]

        # Android Binary XML — all res/*.xml in a compiled APK.
        # Magika often misclassifies this as "gzip".
        if magic4 == AXML_MAGIC:
            return "android_binary_xml"

        # Android compiled resource table (resources.arsc chunks)
        if magic4 == ARSC_MAGIC:
            return "android_resource_table"

        # ART baseline profiles — high entropy (zlib inside) but benign.
        # The format is inert (method reference bitmaps/metadata, not
        # executable code) and some build configs place them at varying paths.
        if magic4 == ART_PROF_MAGIC:
            return "android_art_profile"
        if magic4 == ART_PROFM_MAGIC:
            return "android_art_profile_metadata"

        return None

    def _is_suspicious_resource(
        self, path: str, magika_type: str, entropy: float,
        android_type: str | None,
    ) -> bool:
        """
        Determine if a resource file is suspicious.

        Detection layers:
        1. Allowlisted paths → always benign
        2. Android-specific format override → reclassify Magika mislabels
        3. Image extension vs Magika type mismatch → encrypted blob detection
        4. Magika-confirmed images → benign regardless of entropy
        5. Suspicious type match → flag known-dangerous types
        6. High-entropy unknown blobs → likely encrypted payloads
        """

        # ── Layer 1: Allowlisted paths (hardcoded Android build artifacts) ──
        if path in ALLOWLISTED_PATHS:
            return False

        # ── Layer 2: Android-specific format detection ──────────────────────
        # Override Magika's label for formats it doesn't recognize.
        # All Android-specific formats (AXML, ARSC, ART profiles) are
        # legitimate build artifacts — never suspicious.
        if android_type is not None:
            return False

        # ── Layer 3: Image extension / Magika type mismatch ─────────────────
        # If the file extension claims "image" but Magika's content analysis
        # disagrees, this is a strong signal for an encrypted payload with
        # a fake image extension (e.g., ErrorFather's "rbyypivsnw.png").
        ext = os.path.splitext(path)[1].lower()
        if ext in IMAGE_EXTENSIONS and magika_type not in IMAGE_MAGIKA_TYPES:
            # Exception: Magika might label a valid image as "unknown" if
            # the file is very small (< ~16 bytes). Don't flag tiny files.
            if entropy > 5.0:
                return True

        # ── Layer 4: Magika-confirmed images → benign ───────────────────────
        # Lossy codecs (VP8, JPEG) produce entropy up to ~8.0 by design.
        # If Magika confirms image structure, high entropy is expected.
        if magika_type in IMAGE_MAGIKA_TYPES:
            return False

        # ── Layer 5: Known suspicious file types ────────────────────────────
        if magika_type in SUSPICIOUS_TYPES:
            return True

        # ── Layer 6: High-entropy unrecognized blobs ────────────────────────
        # Files Magika can't identify with high entropy are likely encrypted
        # payloads. Most Android malware packers store encrypted DEX/SO
        # payloads as opaque blobs with random names and no valid magic.
        if magika_type in UNRECOGNIZED_MAGIKA_TYPES and entropy > ENTROPY_HIGH_UNKNOWN:
            return True

        # ── Layer 7: Extreme entropy on any non-image recognized type ───────
        # Catches edge cases where Magika assigns a benign label (e.g.,
        # "xml", "txt") but the entropy is impossibly high for that format.
        if magika_type not in IMAGE_MAGIKA_TYPES and entropy > ENTROPY_EXTREME:
            return True

        return False

    # ─── Extraction pipeline ────────────────────────────────────────────

    def extract(self):
        if not self._is_valid_apk():
            self.log.error(f"Invalid APK for {self.hash.sha256}")
            return None

        try:
            from magika import Magika
            magika = Magika()
        except Exception as e:
            self.log.error(f"Failed to initialize Magika for {self.hash.sha256}: {e}")
            magika = None

        self.resources = []
        self.suspicious_files = []
        scanned = 0

        zf = self._get_zip_file()
        if not zf:
            return None

        with zf:
            for info in zf.infolist():
                if info.is_dir():
                    continue
                if not (info.filename.startswith("res/") or
                        info.filename.startswith("assets/")):
                    continue

                if scanned >= MAX_RESOURCE_FILES:
                    self.log.warning(
                        f"Resource scan limit reached ({MAX_RESOURCE_FILES}), "
                        f"stopping resource enumeration"
                    )
                    break
                scanned += 1

                try:
                    data = zf.read(info.filename)
                except Exception as e:
                    self.log.warning(
                        f"Error reading resource {info.filename}: {e}"
                    )
                    continue

                try:
                    file_sha256 = hashlib.sha256(data).hexdigest()
                    file_entropy = round(self.calculate_entropy(data), 3)

                    # Read first bytes for Android-specific format detection
                    header = data[:16] if len(data) >= 16 else data

                    if magika:
                        try:
                            filetype = magika.identify_bytes(data).output.label
                        except Exception:
                            filetype = "unknown"
                    else:
                        filetype = "unknown"

                    # Identify Android-specific formats once, reuse for
                    # both stored type and suspicion classification
                    android_type = self._identify_android_format(header)
                    stored_type = android_type if android_type else filetype

                    suspicious = self._is_suspicious_resource(
                        path=info.filename,
                        magika_type=filetype,
                        entropy=file_entropy,
                        android_type=android_type,
                    )

                    resource = APKResource(
                        path=info.filename,
                        size=info.file_size,
                        sha256=file_sha256,
                        filetype_magika=stored_type,
                        entropy=file_entropy,
                    )

                    if suspicious:
                        resource.is_suspicious = True
                        self.suspicious_files.append(resource)

                    self.resources.append(resource)
                except Exception as e:
                    self.log.warning(
                        f"Error processing resource {info.filename}: {e}"
                    )
                    continue

        if not self.resources:
            return None

        return {
            "total_resource_count": len(self.resources),
            "total_resource_size": sum(r.size for r in self.resources),
            "suspicious_file_count": len(self.suspicious_files),
            "resources": self.resources,
            "suspicious_files": self.suspicious_files,
        }

    # ─── Export ──────────────────────────────────────────────────────────

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.resources:
                return None

            current_time = datetime.now(timezone.utc)
            data = []
            for res in self.resources:
                data.append([
                    self.sha256,
                    res.path,
                    res.size,
                    res.sha256,
                    res.filetype_magika,
                    res.entropy,
                    int(res.is_suspicious),
                    current_time,
                ])

            column_names = [
                'sha256', 'resource_path', 'resource_size',
                'resource_sha256', 'resource_magika', 'resource_entropy',
                'is_suspicious', 'analysis_date',
            ]

            column_type_names = [
                'FixedString(64)', 'String', 'UInt64',
                'FixedString(64)', 'LowCardinality(String)', 'Float32',
                'UInt8', "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_apk_resources"