Wei Huang

46 papers A* 3A 2B 1Misc 1Journal 35Unranked 4
YearRankTypeTitle / Venue / Authors
2026 J jnl
Knowl. Based Syst.
Xinyuan Miao, Mingqi Qiao, Wei Huang, Jiayu Du, Fan Zhang, Jing Zhao, Guangjiao Zhou
2026 J jnl
CoRR
Gaojie Jin, Xinping Yi, Wei Huang, Sven Schewe, Xiaowei Huang
2025 J jnl
Neural Networks
Chenyu Zhou, Yabin Peng, Wei Huang, Xinyuan Miao, Yi Cao, Xinghao Wang, Xianglong Kong
2025 J jnl
CoRR
Sihao Wu, Gaojie Jin, Wei Huang, Jianhong Wang, Xiaowei Huang
2025 J jnl
Complex Intell. Syst.
Zijie Zhang, Xinyuan Miao, Chenyu Zhou, Chenming Shang, Xi Chen, Xianglong Kong, Wei Huang, Yi Cao
2025 J jnl
J. Syst. Archit.
Luo Cheng, Hanwei Zhang, Qisong He, Wei Huang, Renjue Li, Xiaowei Huang, Holger Hermanns, Lijun Zhang
2025 J jnl
Knowl. Based Syst.
Chenyu Zhou, Wei Huang, Xinyuan Miao, Yabin Peng, Xianglong Kong, Yi Cao, Xi Chen
2025 A* conf
AAAI
Kaiwen Cai, Chris Xiaoxuan Lu, Xingyu Zhao, Wei Huang, Xiaowei Huang
2025 J jnl
IEEE Trans. Pattern Anal. Mach. Intell.
Gaojie Jin, Xinping Yi, Wei Huang, Sven Schewe, Xiaowei Huang
2024 J jnl
Comput. Secur.
Xinwei Yuan, Shu Han, Wei Huang, Hongliang Ye, Xianglong Kong, Fan Zhang
2024 J jnl
Artif. Intell. Rev.
Xiaowei Huang, Wenjie Ruan, Wei Huang, Gaojie Jin, Yi Dong, Changshun Wu, Saddek Bensalem, Ronghui Mu, Yi Qi, Xingyu Zhao, Kaiwen Cai, Yanghao Zhang, Sihao Wu, Peipei Xu, Dengyu Wu, André Freitas, Mustafa A. Mustafa
2024 J jnl
Mach. Vis. Appl.
Xi Chen, Wei Huang, Wei Guo, Fan Zhang, Jiayu Du, Zhizhong Zhou
2024 J jnl
Comput. Secur.
Xi Chen, Wei Huang, Ziwen Peng, Wei Guo, Fan Zhang
2024 Misc conf
SETTA
Hanwei Zhang, Luo Cheng, Qisong He, Wei Huang, Renjue Li, Ronan Sicre, Xiaowei Huang, Holger Hermanns, Lijun Zhang
2024 J jnl
CoRR
Hanwei Zhang, Luo Cheng, Qisong He, Wei Huang, Renjue Li, Ronan Sicre, Xiaowei Huang, Holger Hermanns, Lijun Zhang
2024 B conf
IJCNN
Kaikang Zhao, Xi Chen, Wei Huang, Liuxin Ding, Xianglong Kong, Fan Zhang
2024 J jnl
CoRR
Kaikang Zhao, Xi Chen, Wei Huang, Liuxin Ding, Xianglong Kong, Fan Zhang
2024 J jnl
Neurocomputing
Wei Huang, Yifan Zhou, Gaojie Jin, Youcheng Sun, Jie Meng, Fan Zhang, Xiaowei Huang
2024 J jnl
Secur. Saf.
Fan Zhang, Xi Chen, Wei Huang, Jiangxing Wu, Zijie Zhang, Chenyu Zhou, Jianpeng Li, Ziwen Peng, Wei Guo, Guangze Yang, Xinyuan Miao, Ruiyang Huang, Jiayu Du
2024 J jnl
ACM Trans. Softw. Eng. Methodol.
Wei Huang, Xingyu Zhao, Alec Banks, Victoria Cox, Xiaowei Huang
2023 J jnl
CoRR
Xinwei Yuan, Shu Han, Wei Huang, Hongliang Ye, Xianglong Kong, Fan Zhang
2023 J jnl
CoRR
Xiaowei Huang, Wenjie Ruan, Wei Huang, Gaojie Jin, Yi Dong, Changshun Wu, Saddek Bensalem, Ronghui Mu, Yi Qi, Xingyu Zhao, Kaiwen Cai, Yanghao Zhang, Sihao Wu, Peipei Xu, Dengyu Wu, André Freitas, Mustafa A. Mustafa
2023 J jnl
ACM Trans. Embed. Comput. Syst.
Yi Dong, Wei Huang, Vibhav Bharti, Victoria Cox, Alec Banks, Sen Wang, Xingyu Zhao, Sven Schewe, Xiaowei Huang
2023 A* conf
ICCV
Wei Huang, Xingyu Zhao, Gaojie Jin, Xiaowei Huang
2023 J jnl
CoRR
Saddek Bensalem, Chih-Hong Cheng, Wei Huang, Xiaowei Huang, Changshun Wu, Xingyu Zhao
2023 conf
AISoLA
Saddek Bensalem, Chih-Hong Cheng, Wei Huang, Xiaowei Huang, Changshun Wu, Xingyu Zhao
2022 conf
AISafety@IJCAI
Yi Qi, Philippa Ryan Conmy, Wei Huang, Xingyu Zhao, Xiaowei Huang
2022 J jnl
CoRR
Yi Qi, Philippa Ryan Conmy, Wei Huang, Xingyu Zhao, Xiaowei Huang
2022 J jnl
IEEE Trans. Reliab.
Wei Huang, Youcheng Sun, Xingyu Zhao, James Sharp, Wenjie Ruan, Jie Meng, Xiaowei Huang
2022 J jnl
Mach. Learn.
Wei Huang, Xingyu Zhao, Xiaowei Huang
2022 A* conf
CVPR
Gaojie Jin, Xinping Yi, Wei Huang, Sven Schewe, Xiaowei Huang
2022 J jnl
CoRR
Gaojie Jin, Xinping Yi, Wei Huang, Sven Schewe, Xiaowei Huang
2022 J jnl
CoRR
Wei Huang, Xingyu Zhao, Alec Banks, Victoria Cox, Xiaowei Huang
2022 J jnl
CoRR
Wei Huang, Xingyu Zhao, Gaojie Jin, Xiaowei Huang
2021 conf
AISafety@IJCAI
Xingyu Zhao, Wei Huang, Alec Banks, Victoria Cox, David Flynn, Sven Schewe, Xiaowei Huang
2021 J jnl
CoRR
Xingyu Zhao, Wei Huang, Alec Banks, Victoria Cox, David Flynn, Sven Schewe, Xiaowei Huang
2021 A conf
UAI
Xingyu Zhao, Wei Huang, Xiaowei Huang, Valentin Robu, David Flynn
2021 conf
DSN (Supplements)
Xingyu Zhao, Wei Huang, Sven Schewe, Yi Dong, Xiaowei Huang
2021 J jnl
CoRR
Xingyu Zhao, Wei Huang, Sven Schewe, Yi Dong, Xiaowei Huang
2021 J jnl
CoRR
Xingyu Zhao, Wei Huang, Vibhav Bharti, Yi Dong, Victoria Cox, Alec Banks, Sen Wang, Sven Schewe, Xiaowei Huang
2021 J jnl
CoRR
Nicolas Berthier, Youcheng Sun, Wei Huang, Yanghao Zhang, Wenjie Ruan, Xiaowei Huang
2020 J jnl
CoRR
Wei Huang, Xingyu Zhao, Xiaowei Huang
2020 J jnl
CoRR
Wei Huang, Yifan Zhou, Youcheng Sun, Alec Banks, Jie Meng, James Sharp, Simon Maskell, Xiaowei Huang
2020 A conf
IROS
Wei Huang, Yifan Zhou, Youcheng Sun, James Sharp, Simon Maskell, Xiaowei Huang
2019 J jnl
CoRR
Wei Huang, Youcheng Sun, James Sharp, Xiaowei Huang
2019 J jnl
CoRR
Wei Huang, Youcheng Sun, Xiaowei Huang, James Sharp
redb/extractors/js_extractor.py
← Index redb/extractors/js_extractor.py python
import logging
import re
from abc import ABCMeta, abstractmethod

from redb.extractors.extractor import Extractor
from redb.extractors.js_extractors.js_context import JSContext, _text_entropy

logger = logging.getLogger(__name__)

# ESM is recognised by line-anchored `import ... from "..."` / bare side-effect
# `import "..."` / top-level `export ...`. Anchored at line start to avoid
# matching the substring inside string literals or comments.
_ESM_PATTERN = re.compile(
    r'(?m)^\s*(?:'
    r'import\s+[^;\n]*?\bfrom\s+[\'"]'
    r'|import\s+[\'"][^\'"]+[\'"]'
    r'|export\s+(?:default\b|\{|\*|const\b|let\b|var\b|function\b|class\b|async\b)'
    r')'
)


@abstractmethod
class JSExtractor(Extractor, metaclass=ABCMeta):
    """Base class for JavaScript file extractors.

    Every JSExtractor reads its raw materials (bytes / decoded source / line
    list / scan_source results / pyjsparser AST / text entropy) from a shared
    `JSContext`. When workers.py drives the JS pipeline it builds one context
    per sample and threads it into every extractor via `context=`. When tests
    or other callers instantiate an extractor directly, the constructor builds
    a fresh context from `(filepath, source=...)`.

    All historical instance attributes (`self.binary`, `self.js_source`,
    `self.lines`) and helpers (`self._decode_source`, `self._parse_ast`,
    `self._calculate_text_entropy`) are preserved as thin delegators so
    existing extractor code keeps working unchanged.
    """

    def __init__(
        self,
        filepath,
        log,
        exporters=None,
        index_prefix=None,
        known_benign=False,
        known_malicious=False,
        source=None,
        context=None,
    ):
        if context is None:
            context = JSContext.from_path(filepath, log=log, source=source)
        elif source is not None and context.source != source:
            log.warning(
                "JSExtractor received both `source=` and `context=` with "
                "differing source; ignoring source kwarg"
            )
        self._context = context

        super().__init__(
            filepath,
            log,
            exporters,
            index_prefix,
            known_benign=known_benign,
            known_malicious=known_malicious,
        )

    @property
    def binary(self):
        return self._context.raw_bytes

    @property
    def js_source(self):
        return self._context.source

    @property
    def lines(self):
        return self._context.lines

    def _decode_source(self):
        """Back-compat shim — the context already decoded once at construction.

        Kept so any external caller using the historical method name keeps
        working without touching the underlying bytes again.
        """
        return self._context.source

    def _parse_ast(self):
        """Return the shared pyjsparser AST (or None if unavailable)."""
        return self._context.ast

    def _calculate_text_entropy(self, text):
        """Shannon text entropy for `text`.

        When `text` is the context's own source we read the cached value;
        otherwise we compute fresh. JSStringsExtractor calls this on arbitrary
        decoded substrings, so the fresh-compute path must remain available.
        """
        if text is self._context.source:
            return self._context.text_entropy
        return _text_entropy(text)

    def _detect_environment(self):
        """Detect the target JS runtime environment."""
        src = self.js_source
        if not src:
            return "unknown"

        # WScript/WSH indicators
        wscript_patterns = [
            'WScript.', 'WSH.', 'ActiveXObject', 'Scripting.FileSystemObject',
            'WScript.Shell', 'ADODB.Stream',
        ]
        for p in wscript_patterns:
            if p in src:
                return "wscript"

        # Browser-extension APIs — checked before generic browser/worker because
        # `chrome.*` and `browser.runtime` are distinctive of MV2/MV3 extensions
        extension_patterns = [
            'chrome.runtime', 'chrome.tabs', 'chrome.storage',
            'chrome.webRequest', 'browser.runtime', 'browser.tabs',
        ]
        for p in extension_patterns:
            if p in src:
                return "browser_extension"

        # Service / Web Workers — worker-only APIs that don't appear in regular
        # browser pages (a generic browser script would use `window.` or
        # `document.`, never `self.importScripts` or `caches.match`)
        worker_patterns = [
            "self.addEventListener('fetch'", 'self.addEventListener("fetch"',
            'self.importScripts', 'self.skipWaiting',
            'caches.match', 'caches.open',
        ]
        for p in worker_patterns:
            if p in src:
                return "service_worker"

        # Deno runtime
        if 'Deno.' in src:
            return "deno"

        # Node.js indicators
        node_patterns = [
            'require(', 'module.exports', 'process.env', '__dirname',
            '__filename', 'Buffer.', 'child_process',
        ]
        for p in node_patterns:
            if p in src:
                return "node"

        # Browser indicators
        browser_patterns = [
            'document.', 'window.', 'navigator.', 'localStorage',
            'sessionStorage', 'XMLHttpRequest', 'addEventListener',
        ]
        for p in browser_patterns:
            if p in src:
                return "browser"

        return "unknown"

    def _detect_script_type(self):
        """Detect the script type/format."""
        src = self.js_source
        if not src:
            return "unknown"

        stripped = src.lstrip()

        # JScript.Encode payload — must be checked first since the encoded
        # body can't be classified any other way
        if stripped.startswith('#@~^'):
            return "jse"

        # WSF / HTA live in the first few KB of an HTML-ish wrapper
        head_lower = stripped[:4096].lower()

        # Windows Script File — XML wrapper around one or more <script> blocks
        if ('<job' in head_lower or '<package' in head_lower) and '<script' in head_lower:
            return "wsf"

        # HTML Application — distinct from generic embedded_html because HTAs
        # run under mshta.exe with full WSH/ActiveX access
        if '<hta:application' in head_lower or 'application/hta' in head_lower:
            return "hta"

        if stripped.startswith('<!') or stripped.startswith('<html') or '<script' in stripped[:2000]:
            return "embedded_html"

        if 'WScript.' in src or 'WSH.' in src:
            return "wscript"

        if _ESM_PATTERN.search(src):
            return "esm"

        if 'require(' in src or 'module.exports' in src:
            return "node_module"

        return "standalone"