Wei Cheng

76 papers A* 1A 4B 10C 4Misc 2Journal 46Unranked 8
YearRankTypeTitle / Venue / Authors
2026 J jnl
Des. Codes Cryptogr.
Jihao Fan, Wei Cheng, Yongbin Zhou, Sylvain Guilley
2026 J jnl
IACR Cryptol. ePrint Arch.
Yuhan Zhao, Wei Cheng, Zehua Qiao, Yuejun Liu, Yongbin Zhou
2026 J jnl
IACR Trans. Cryptogr. Hardw. Embed. Syst.
Julien Béguinot, Olivier Rioul, Loïc Masure, François-Xavier Standaert, Wei Cheng, Sylvain Guilley
2026 J jnl
IEEE Trans. Computers
Qianmei Wu, Chengdong Xie, Wei Cheng, Fan Zhang
2025 J jnl
IACR Cryptol. ePrint Arch.
Qianmei Wu, Sayandeep Saha, Wei Cheng, Fan Zhang, Shivam Bhasin
2025 Misc conf
VTS
Hasin Ishraq Reefat, Hossein Pourmehrani, Wei Cheng, Claude Carlet, Abderrahman Daif, Cédric Tavernier, Sylvain Guilley, Naghmeh Karimi
2025 J jnl
IEEE Trans. Inf. Forensics Secur.
Chong Xiao, Ming Tang, Sengim Karayalcin, Wei Cheng
2025 conf
CASCADE
Neelam Nasir, Julien Béguinot, Wei Cheng, Ulrich Kühne, Jean-Luc Danger
2025 J jnl
IACR Cryptol. ePrint Arch.
Julien Béguinot, Olivier Rioul, Loïc Masure, François-Xavier Standaert, Wei Cheng, Sylvain Guilley
2025 J jnl
IACR Cryptol. ePrint Arch.
Jiangshan Long, Changhai Ou, Yukun Cheng, Kexin Qiao, Wei Cheng, Fan Zhang
2025 J jnl
IEEE Trans. Inf. Forensics Secur.
Qianmei Wu, Wei Cheng, Fan Zhang, Sylvain Guilley
2025 J jnl
IEEE Trans. Computers
Peng Chen, Jinnuo Li, Wei Cheng, Chi Cheng
2024 B conf
TrustCom
Zelong Zhang, Wei Cheng, Yongbin Zhou, Zehua Qiao, Yuhan Zhao, Jian Weng
2024 J jnl
Microprocess. Microsystems
Julien Béguinot, Wei Cheng, Sylvain Guilley, Olivier Rioul
2024 conf
CRYPTO (6)
Julien Béguinot, Wei Cheng, Sylvain Guilley, Olivier Rioul
2024 J jnl
IACR Cryptol. ePrint Arch.
Julien Béguinot, Wei Cheng, Sylvain Guilley, Olivier Rioul
2024 conf
SecureComm (1)
Ziyue Shen, Yiwen Gao, Wei Cheng, Jiabei Wang, Yongbin Zhou
2024 J jnl
J. Electron. Test.
Md Toufiq Hasan Anik, Hasin Ishraq Reefat, Wei Cheng, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
2024 J jnl
IEEE Trans. Computers
Wei Cheng, Jingdian Ming, Sylvain Guilley, Jean-Luc Danger
2024 J jnl
J. Cryptogr. Eng.
Wei Cheng, Yi Liu, Sylvain Guilley, Olivier Rioul
2024 B conf
TrustCom
Xiaoran Huang, Yiwen Gao, Wei Cheng, Yuejun Liu, Jingdian Ming, Yongbin Zhou, Jian Weng
2024 B conf
TrustCom
Yuming Liu, Wei Cheng, Jihao Fan, Yongbin Zhou
2023 J jnl
Entropy
Om Prakash, Ashutosh Singh, Ram Krishna Verma, Patrick Solé, Wei Cheng
2023 B conf
ITW
Yi Liu, Julien Béguinot, Wei Cheng, Sylvain Guilley, Loïc Masure, Olivier Rioul, François-Xavier Standaert
2023 B conf
ISIT
Julien Béguinot, Yi Liu, Olivier Rioul, Wei Cheng, Sylvain Guilley
2023 J jnl
CoRR
Julien Béguinot, Yi Liu, Olivier Rioul, Wei Cheng, Sylvain Guilley
2023 Misc conf
IWSEC
Julien Béguinot, Wei Cheng, Jean-Luc Danger, Sylvain Guilley, Olivier Rioul, Ville Yli-Mäyry
2023 conf
COSADE
Julien Béguinot, Wei Cheng, Sylvain Guilley, Yi Liu, Loïc Masure, Olivier Rioul, François-Xavier Standaert
2023 J jnl
J. Syst. Sci. Complex.
Minjia Shi, Yaya Li, Wei Cheng, Dean Crnkovic, Denis S. Krotov, Patrick Solé
2023 J jnl
Des. Codes Cryptogr.
Minjia Shi, Yaya Li, Wei Cheng, Dean Crnkovic, Denis S. Krotov, Patrick Solé
2023 A conf
DATE
Jingdian Ming, Yongbin Zhou, Wei Cheng, Huizhong Li
2022 J jnl
IEEE Trans. Very Large Scale Integr. Syst.
Trevor Kroeger, Wei Cheng, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi
2022 B conf
ISIT
Wei Cheng, Yi Liu, Sylvain Guilley, Olivier Rioul
2022 C conf
DSD
Julien Béguinot, Wei Cheng, Sylvain Guilley, Olivier Rioul
2022 J jnl
J. Electron. Test.
Trevor Kroeger, Wei Cheng, Jean-Luc Danger, Sylvain Guilley, Naghmeh Karimi
2022 J jnl
IEEE Trans. Inf. Forensics Secur.
Wei Cheng, Sylvain Guilley, Jean-Luc Danger
2022 J jnl
IACR Cryptol. ePrint Arch.
Wei Cheng, Sylvain Guilley, Jean-Luc Danger
2022 J jnl
IACR Trans. Cryptogr. Hardw. Embed. Syst.
Qianmei Wu, Wei Cheng, Sylvain Guilley, Fan Zhang, Wei Fu
2022 J jnl
IEEE Trans. Inf. Forensics Secur.
Jingdian Ming, Yongbin Zhou, Wei Cheng, Huizhong Li
2022 J jnl
IACR Cryptol. ePrint Arch.
Julien Béguinot, Wei Cheng, Sylvain Guilley, Yi Liu, Loïc Masure, Olivier Rioul, François-Xavier Standaert
2022 J jnl
CoRR
Minjia Shi, Yaya Li, Wei Cheng, Dean S. Crnkovic, Denis S. Krotov, Patrick Solé
2022 J jnl
IACR Trans. Cryptogr. Hardw. Embed. Syst.
Julien Béguinot, Wei Cheng, Sylvain Guilley, Olivier Rioul
2022 conf
CWIT
Wei Cheng, Olivier Rioul, Yi Liu, Julien Béguinot, Sylvain Guilley
2021 C conf
ICCD
Jingdian Ming, Wei Cheng, Yongbin Zhou, Huizhong Li
2021 J jnl
CoRR
Wei Cheng, Yi Liu, Sylvain Guilley, Olivier Rioul
2021 B conf
ISIT
Patrick Solé, Wei Cheng, Sylvain Guilley, Olivier Rioul
2021 J jnl
Cryptogr. Commun.
Wei Cheng, Sylvain Guilley, Jean-Luc Danger
2021 B conf
ISIT
Olivier Rioul, Wei Cheng, Sylvain Guilley
2021 J jnl
CoRR
Olivier Rioul, Wei Cheng, Sylvain Guilley
2021 J jnl
J. Cryptogr. Eng.
Wei Cheng, Claude Carlet, Kouassi Goli, Jean-Luc Danger, Sylvain Guilley
2021 conf
COSADE
Trevor Kroeger, Wei Cheng, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi
2021 J jnl
IACR Cryptol. ePrint Arch.
Wei Cheng, Sylvain Guilley, Claude Carlet, Jean-Luc Danger, Sihem Mesnager
2021 J jnl
IACR Trans. Cryptogr. Hardw. Embed. Syst.
Wei Cheng, Sylvain Guilley, Claude Carlet, Jean-Luc Danger, Sihem Mesnager
2021 B conf
ITW
Patrick Solé, Yi Liu, Wei Cheng, Sylvain Guilley, Olivier Rioul
2021 A conf
DATE
Trevor Kroeger, Wei Cheng, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi
2021 B conf
ITW
Yi Liu, Wei Cheng, Sylvain Guilley, Olivier Rioul
2021 J jnl
CoRR
Yi Liu, Wei Cheng, Sylvain Guilley, Olivier Rioul
2021 J jnl
IEEE Trans. Inf. Forensics Secur.
Wei Cheng, Sylvain Guilley, Claude Carlet, Sihem Mesnager, Jean-Luc Danger
2021 J jnl
IACR Trans. Cryptogr. Hardw. Embed. Syst.
Jingdian Ming, Huizhong Li, Yongbin Zhou, Wei Cheng, Zehua Qiao
2021
Wei Cheng
2020 A conf
ITC
Trevor Kroeger, Wei Cheng, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi
2020 A conf
DATE
Trevor Kroeger, Wei Cheng, Sylvain Guilley, Jean-Luc Danger, Naghmeh Karimi
2020 J jnl
Cybersecur.
Yiwen Gao, Yongbin Zhou, Wei Cheng
2020 J jnl
IEEE Trans. Inf. Forensics Secur.
Jingdian Ming, Yongbin Zhou, Wei Cheng, Huizhong Li, Guang Yang, Qian Zhang
2020 J jnl
IACR Cryptol. ePrint Arch.
Wei Cheng, Sylvain Guilley, Claude Carlet, Sihem Mesnager, Jean-Luc Danger
2019 J jnl
IACR Cryptol. ePrint Arch.
Wei Cheng, Claude Carlet, Kouassi Goli, Sylvain Guilley, Jean-Luc Danger
2019 conf
PROOFS
Wei Cheng, Claude Carlet, Kouassi Goli, Jean-Luc Danger, Sylvain Guilley
2018 C conf
ICCD
Qian Zhang, Yongbin Zhou, Shuang Qiu, Wei Cheng, Jingdian Ming, Rui Zhang
2018 J jnl
IACR Cryptol. ePrint Arch.
Jingdian Ming, Wei Cheng, Huizhong Li, Guang Yang, Yongbin Zhou, Qian Zhang
2018 conf
TrustCom/BigDataSE
Yiwen Gao, Wei Cheng, Hailong Zhang, Yongbin Zhou
2018 A* conf
DAC
Yiwen Gao, Hailong Zhang, Wei Cheng, Yongbin Zhou, Yuchen Cao
2018 J jnl
IACR Cryptol. ePrint Arch.
Yiwen Gao, Yongbin Zhou, Wei Cheng
2017 J jnl
IACR Cryptol. ePrint Arch.
Shuang Qiu, Rui Zhang, Yongbin Zhou, Wei Cheng
2017 J jnl
IACR Cryptol. ePrint Arch.
Wei Cheng, Chao Zheng, Yuchen Cao, Yongbin Zhou, Hailong Zhang, Sylvain Guilley, Laurent Sauvage
2017 J jnl
IACR Cryptol. ePrint Arch.
Changhai Ou, Degang Sun, Zhu Wang, Xinping Zhou, Wei Cheng
2016 C conf
ICICS
Wei Cheng, Yongbin Zhou, Laurent Sauvage
redb/extractors/decompiler/bninja/analysis/cfg-old.py
← Index redb/extractors/decompiler/bninja/analysis/cfg-old.py python
from collections import deque
from enum import Enum

from binaryninja.enums import (
    BranchType,
    InstructionTextTokenType,
)

# Support both package and standalone imports
try:
    from ..utils.hashes import calculate_md5, calculate_sha256
except ImportError:
    # Fallback to absolute imports (for multiprocessing spawned processes)
    from redb.extractors.decompiler.bninja.utils.hashes import calculate_md5, calculate_sha256


class CFGAnalysis:
    def __init__(self, function):
        self.function = function

    def determine_block_type(self, block) -> str:
        """Determine the type of a basic block."""
        # Check if it's a thunk function (usually just a jump or call)
        if len(block.disassembly_text) <= 2 and any(
            "jmp" in line.tokens[0].text.lower() for line in block.disassembly_text
        ):
            return "THUNK"

        # Check if it contains only data (no valid instructions)
        if all(not line.tokens for line in block.disassembly_text):
            return "DATA"

        # Default to code
        return "CODE"

    def extract_cyclomatic_complexity(self):
        """
        Cyclomatic complexity (McCabe’s metric) measures the number of linearly independent paths
        through a function’s control flow graph (CFG).
        The standard formula is:

            M = E - N + 2

        where:
            - E = number of edges in the CFG
            - N = number of nodes (basic blocks)
            - 2 accounts for the entry and exit nodes of a single connected graph
        """
        if self.function is None:
            return 0

        # number of basic blocks
        num_blocks = len(self.function.basic_blocks)
        # number of edges in the graph
        num_edges = sum(
            len(basic_block.outgoing_edges)
            for basic_block in self.function.basic_blocks
        )
        return num_edges - num_blocks + 2

    def extract_function_cfg(self):
        """Extract information about a function CFG and return it as a dictionary."""

        function = self.function
        function_data = {
            "function_address": self.function.start,
            "blocks": [],
            "measures": {
                "cyclomatic_complexity": self.extract_cyclomatic_complexity(),
            },
        }

        if self.function is None:
            return function_data

        # Get the map of the depth associated to every block
        depths = self.get_map_depth()

        # Get the map of the positions associated to every block
        id_maps = self.get_block_id_map()

        # Extract block data with graph structure information
        for block in function.basic_blocks:
            # dominators per every block translated
            dominators = sorted(self.extract_dominators(block, id_maps))

            # post dominators
            post_dominators = sorted(self.extract_post_dominators(block, id_maps))

            # Build block instructions string
            block_instructions = "\n".join(str(line) for line in block.disassembly_text)

            # Determine block type
            block_type = self.determine_block_type(block)

            # Extract successors directly from basic block
            successor_blocks = [edge.target.start for edge in block.outgoing_edges]
            # We ensure a canonical order and we sort the edges
            successor_blocks.sort()

            # Extract predecessors directly from basic block
            predecessor_blocks = [edge.source.start for edge in block.incoming_edges]
            # We ensure a canonical order and we sort the edges
            predecessor_blocks.sort()

            # Determine branch type from outgoing edges
            branch_type = self.determine_branch_type(block)

            instructions_count = len(block.disassembly_text)

            # Create block record
            block_json = {
                "function_address": self.function.start,
                "block_start_address": block.start,
                "block_end_address": block.end,
                "block_size": block.end - block.start,
                "instructions_count": instructions_count,
                "block_instructions_hash": calculate_sha256(block_instructions),
                "predecessor_blocks": predecessor_blocks,
                "successor_blocks": successor_blocks,
                "depth": depths[block.start],
                "position": id_maps[block.start],
                "branch_type": branch_type,
                "block_type": block_type,
                "flags": self.extract_block_flags(block),
                "dominators": dominators,
                "post_dominators": post_dominators,
            }
            function_data["blocks"].append(block_json)

        return function_data

    def extract_dominators(self, bb, id_maps):
        """Extract the dominators normalized"""
        dom_idx = [id_maps[d.start] for d in bb.dominators]
        return dom_idx

    def extract_post_dominators(self, bb, id_maps):
        """Extract the post-dominators normalized"""
        post_dom_idx = [id_maps[d.start] for d in bb.post_dominators]
        return post_dom_idx

    def determine_branch_type(self, block):
        """
        Determine the type of branch at the end of a basic block.
        This combines edge type information with instruction analysis.
        """
        # If no outgoing edges, it might be a return or terminal block
        if not block.outgoing_edges:
            # Check if the last instruction is a return
            for line in reversed(list(block.disassembly_text)):
                if line.tokens and any(
                    token.text.lower() in ["ret", "retn"] for token in line.tokens
                ):
                    return "RETURN"
            return "UNKNOWN"

        # Collect branch types from all outgoing edges
        branch_types = []
        for edge in block.outgoing_edges:
            edge_type = edge.type
            # Map edge type to our branch type enum
            if isinstance(edge_type, str):
                if edge_type == "IndirectCall":
                    branch_types.append("CALL")
                else:
                    branch_types.append("UNKNOWN")
            else:
                # Use our mapping for integer/enum values
                type_mapping = {
                    BranchType.UnconditionalBranch: "DIRECT",
                    BranchType.FalseBranch: "CONDITIONAL",
                    BranchType.TrueBranch: "CONDITIONAL",
                    BranchType.CallDestination: "CALL",
                    BranchType.FunctionReturn: "RETURN",
                    BranchType.SystemCall: "CALL",
                    BranchType.IndirectBranch: "INDIRECT",
                    BranchType.ExceptionBranch: "UNKNOWN",
                    BranchType.UnresolvedBranch: "UNKNOWN",
                    BranchType.UserDefinedBranch: "UNKNOWN",
                }
                branch_types.append(type_mapping.get(edge_type, "UNKNOWN"))

        # Determine overall branch type (prioritize CALL > RETURN > CONDITIONAL > DIRECT)
        if "CALL" in branch_types:
            return "CALL"
        elif "RETURN" in branch_types:
            return "RETURN"
        elif "CONDITIONAL" in branch_types:
            return "CONDITIONAL"
        elif "DIRECT" in branch_types:
            return "DIRECT"
        elif len(block.outgoing_edges) == 1:
            return "FALLTHROUGH"

        # If edge analysis was inconclusive, fall back to instruction analysis
        last_instr = None
        for line in reversed(list(block.disassembly_text)):
            if line.tokens:
                last_instr = line
                break

        if last_instr:
            mnemonic = None
            for token in last_instr.tokens:
                if token.type == InstructionTextTokenType.InstructionToken:
                    mnemonic = token.text.lower()
                    break

            if mnemonic:
                if mnemonic == "call":
                    return "CALL"
                elif mnemonic == "jmp":
                    return "DIRECT"
                elif mnemonic.startswith("j") and mnemonic != "jmp":
                    return "CONDITIONAL"
                elif mnemonic in ["ret", "retn"]:
                    return "RETURN"

        return "UNKNOWN"

    def get_map_depth(self):
        """
        Run a BFS on the basic blocks of the function to assign a depth to every block
        """

        depths = {}
        entry = self.function.get_basic_block_at(self.function.start)

        ### Simple BFS
        q = deque()
        q.append(entry)
        depths[entry.start] = 0

        while q:
            b = q.popleft()
            b_depth = depths[b.start]
            for edge in b.outgoing_edges:
                tgt = edge.target

                if tgt is None:
                    continue

                if tgt.start not in depths:
                    depths[tgt.start] = b_depth + 1
                    q.append(tgt)

        return depths

    def get_block_id_map(self):
        """
        Assign a unique, sequential ID to each basic block of the function using a BFS starting from the entry block.
        """

        id_map = {}
        entry = self.function.get_basic_block_at(self.function.start)

        q = deque()
        q.append(entry)

        current_id = 0
        id_map[entry.start] = current_id

        while q:
            b = q.popleft()
            for edge in b.outgoing_edges:
                tgt = edge.target

                if tgt is None:
                    continue

                if tgt.start not in id_map:
                    current_id += 1
                    id_map[tgt.start] = current_id
                    q.append(tgt)

        return id_map

    def extract_block_flags(self, block):
        """
        Get the flags for every basic block. Currently, we implemented these heuristics:
            - if a basic block is the entry node for a function
            - if a basic block is the exit block for a function
            - if a basic block is part of a natural loop
        """
        flags = []

        if block.start == self.function.start:
            flags.append(BlockFlags.EntryBlock.value)

        if any(edge.type == BranchType.FunctionReturn for edge in block.outgoing_edges):
            flags.append(BlockFlags.ExitBlock.value)

        # if this block is in its dominance frontier, then it's part of a natural loop
        if block in block.dominance_frontier:
            flags.append(BlockFlags.LoopBlock.value)

        return flags


class BlockFlags(Enum):
    # generally, the basic block identifying the entry point of the function
    EntryBlock = "EntryBlock"
    # any basic blocks that makes the control flow exiting from the current function
    ExitBlock = "ExitBlock"
    # any block is in a natural loop if it is in its own dominance frontier
    LoopBlock = "LoopBlock"


class BlockType(Enum):
    THUNK = "THUNK"
    DATA = "DATA"
    PADDING = "PADDING"
    CODE = "CODE"