Wei Ye

62 papers A* 14B 3Journal 36Unranked 8
YearRankTypeTitle / Venue / Authors
2026 J jnl
ACM Comput. Surv.
Xiaofeng Cao, Mingwei Xu, Xin Yu, Jiangchao Yao, Wei Ye, Sheng-Jun Huang, Min-Ling Zhang, Ivor W. Tsang, Yew-Soon Ong, James T. Kwok, Heng Tao Shen
2026 J jnl
IEEE Trans. Multim.
Wengang Guo, Wei Ye, Chunchun Chen, Xin Sun, Christian Böhm, Claudia Plant, Susanto Rahardja
2026 A* conf
AAAI
Chunchun Chen, Xing Wei, Jiayi Yang, Chenrun Wang, Yiwei Fu, Yuxing Zhang, Xin Sun, Rui Fan, Wei Ye
2026 J jnl
Pattern Recognit.
Jiayi Yang, Wei Ye, Xin Sun, Rui Fan, Jungong Han
2026 J jnl
Mach. Learn.
Yucheng Jiang, Jiateng Li, Yuan Tian, Jiangchao Yao, Xin Yu, Wei Ye, Xiaofeng Cao
2026 J jnl
CoRR
Zizhan Guo, Yi Feng, Mengtan Zhang, Haoran Zhang, Wei Ye, Rui Fan
2026 J jnl
CoRR
Yue Niu, Zhaokai Sun, Jiayi Yang, Xiaofeng Cao, Rui Fan, Xin Sun, Hanli Wang, Wei Ye
2026 J jnl
CoRR
Guanfeng Tang, Hongbo Zhao, Ziwei Long, Jiayao Li, Bohong Xiao, Wei Ye, Hanli Wang, Rui Fan
2025 J jnl
CoRR
Xiaofeng Cao, Mingwei Xu, Xin Yu, Jiangchao Yao, Wei Ye, Shengjun Huang, Minling Zhang, Ivor W. Tsang, Yew Soon Ong, James T. Kwok, Heng Tao Shen
2025 J jnl
IEEE Trans. Artif. Intell.
Wei Ye, Shuhao Tang, Hao Tian, Qijun Chen
2025 J jnl
CoRR
Wengang Guo, Wei Ye, Chunchun Chen, Xin Sun, Christian Böhm, Claudia Plant, Susanto Rahardja
2025 A* conf
AAAI
Yuxiao Lee, Xiaofeng Cao, Jingcai Guo, Wei Ye, Qing Guo, Yi Chang
2025 J jnl
IEEE Trans. Knowl. Data Eng.
Wei Ye, Wengang Guo, Shuhao Tang, Hao Tian, Xin Sun, Xiaofeng Cao, Heng Tao Shen
2025 J jnl
IEEE Trans Autom. Sci. Eng.
Zhiwei Huang, Jiaqi Li, Hongbo Zhao, Xiao Ma, Ping Zhong, Xiao-Hu Zhou, Wei Ye, Rui Fan
2025 J jnl
CoRR
Xing Wei, Chunchun Chen, Rui Fan, Xiaofeng Cao, Sourav Medya, Wei Ye
2025 J jnl
IEEE Trans. Instrum. Meas.
Ming-Ju Lee, Zhiyuan Wu, Chengju Liu, Wei Ye, Sergey Vityazev, Qijun Chen, Rui Fan
2025 J jnl
IEEE Trans Autom. Sci. Eng.
Guanfeng Tang, Zhiyuan Wu, Jiahang Li, Ping Zhong, Wei Ye, Xieyuanli Chen, Huimin Lu, Rui Fan
2024 A* conf
AAAI
Hao Tian, Sourav Medya, Wei Ye
2024 J jnl
IEEE Trans. Instrum. Meas.
Linchuan Zhang, Huilin Yin, Wei Ye, Johannes Betz
2024 A* conf
IJCAI
Shuhao Tang, Hao Tian, Xiaofeng Cao, Wei Ye
2024 J jnl
CoRR
Shuhao Tang, Hao Tian, Xiaofeng Cao, Wei Ye
2024 B conf
SMC
Wengang Guo, Wei Ye
2024 J jnl
CoRR
Wengang Guo, Wei Ye
2024 conf
ECML/PKDD (8)
Wei Ye, Hao Tian, Shuhao Tang, Xin Sun
2024 A* conf
NeurIPS
Yadong Sun, Xiaofeng Cao, Yu Wang, Wei Ye, Jingcai Guo, Qing Guo
2024 B conf
SMC
Jiayi Yang, Sourav Medya, Wei Ye
2024 J jnl
IEEE Trans. Veh. Technol.
Linchuan Zhang, Wei Ye, Jun Yan, Hao Zhang, Johannes Betz, Huilin Yin
2024 J jnl
IEEE Trans. Artif. Intell.
Wei Ye, Hao Tian, Qijun Chen
2024 A* conf
AAAI
Wengang Guo, Jiayi Yang, Huilin Yin, Qijun Chen, Wei Ye
2024 A* conf
ICRA
Zhiyuan Wu, Jiaqi Li, Yi Feng, Chengju Liu, Wei Ye, Qijun Chen, Rui Fan
2023 J jnl
CoRR
Hao Tian, Sourav Medya, Wei Ye
2023 A* conf
ICDE
Wei Ye, Dominik Mautz, Christian Böhm, Ambuj K. Singh, Claudia Plant
2023 A* conf
ICDE
Wei Ye, Omid Askarisichani, Alex T. Jones, Ambuj K. Singh
2023 J jnl
CoRR
Wengang Guo, Jiayi Yang, Huilin Yin, Qijun Chen, Wei Ye
2023 conf
ICDM (Workshops)
Yunqi Hong, Wei Ye
2022 J jnl
CoRR
Wei Ye, Hao Tian, Qijun Chen
2022 J jnl
CoRR
Wei Ye, Zexi Huang, Yunqi Hong, Ambuj K. Singh
2022 J jnl
CoRR
Wei Ye, Jiayi Yang, Sourav Medya, Ambuj K. Singh
2022 J jnl
IEEE Trans. Knowl. Data Eng.
Wei Ye, Omid Askarisichani, Alex T. Jones, Ambuj K. Singh
2022 J jnl
CoRR
Wei Ye, Francesco Bullo, Noah E. Friedkin, Ambuj K. Singh
2021 conf
ICDM (Workshops)
Wengang Guo, Kaiyan Lin, Wei Ye
2021 J jnl
CoRR
Wengang Guo, Kaiyan Lin, Wei Ye
2021 J jnl
IEEE Trans. Knowl. Data Eng.
Wei Ye, Dominik Mautz, Christian Böhm, Ambuj K. Singh, Claudia Plant
2021 J jnl
IEEE Trans. Knowl. Data Eng.
Wei Ye, Zhen Wang, Rachel Redberg, Ambuj K. Singh
2020 J jnl
CoRR
Wei Ye, Omid Askarisichani, Alex T. Jones, Ambuj K. Singh
2020 J jnl
CoRR
Wei Ye, Dominik Mautz, Christian Böhm, Ambuj K. Singh, Claudia Plant
2020 J jnl
ACM Trans. Knowl. Discov. Data
Dominik Mautz, Wei Ye, Claudia Plant, Christian Böhm
2020 J jnl
CoRR
Wei Ye, Zhen Wang, Rachel Redberg, Ambuj K. Singh
2019 conf
GI-Jahrestagung
Dominik Mautz, Wei Ye, Claudia Plant, Christian Böhm
2018
Wei Ye
2018 A* conf
KDD
Dominik Mautz, Wei Ye, Claudia Plant, Christian Böhm
2017 conf
ECML/PKDD (1)
Wei Ye, Linfei Zhou, Xin Sun, Claudia Plant, Christian Böhm
2017 conf
DEXA (2)
Linfei Zhou, Wei Ye, Zhen Wang, Claudia Plant, Christian Böhm
2017 B conf
DaWaK
Linfei Zhou, Wei Ye, Claudia Plant, Christian Böhm
2017 A* conf
KDD
Wei Ye, Linfei Zhou, Dominik Mautz, Claudia Plant, Christian Böhm
2017 conf
DEXA (2)
Linfei Zhou, Wei Ye, Bianca Wackersreuther, Claudia Plant, Christian Böhm
2017 A* conf
KDD
Dominik Mautz, Wei Ye, Claudia Plant, Christian Böhm
2016 A* conf
KDD
Wei Ye, Sebastian Goebl, Claudia Plant, Christian Böhm
2016 A* conf
ICDM
Wei Ye, Samuel Maurus, Nina C. Hubig, Claudia Plant
2015 J jnl
Appl. Soft Comput.
Ling Wang, Ruixin Yang, Haoqi Ni, Wei Ye, Minrui Fei, Panos M. Pardalos
2012 J jnl
Comput. Sci. Inf. Syst.
Ling Wang, Wei Ye, Haikuan Wang, Xiping Fu, Minrui Fei, Muhammad Ilyas Menhas
2011 conf
ICSI (2)
Ling Wang, Wei Ye, Xiping Fu, Muhammad Ilyas Menhas
CLAUDE.md
← Index CLAUDE.md markdown
# CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

## Project Overview

REDB (RationalEdge Samples DB) is a malware analysis framework that extracts features from PE (Portable Executable) files and stores them in ClickHouse database for analysis. It provides a comprehensive set of extractors for analyzing binary samples including PE headers, imports, resources, signatures, and decompiled code.

## Common Commands

### Development Setup
```bash
source venv/bin/activate

# Install dependencies
pip install -r requirements.txt

# Run the main application
python start.py --path /path/to/samples --repo sample_repo --index_prefix redb
```

### Analysis Commands
```bash
# Process a single file
python start.py --path /path/to/binary --repo test --index_prefix redb

# Process from S3 storage
python start.py --s3 --repo malpedia --index_prefix redb

# Process from S3 storage but only a subset of a specific repository
python start.py --s3 --repo "vx-itw" --s3-notes "ITW.0138" --index_prefix redb

# Run only decompilation
python start.py --path /path/to/binary --repo test --index_prefix redb --decompile

# Run specific modules
python start.py --path /path/to/binary --repo test --index_prefix redb --modules "BasicPropertiesExtractor,PEFeaturesExtractor"

# Run as Nomad job (for containerized deployment)
python start.py --nomad-job
```

### Testing
There are no formal unit tests. Testing is done by running the extractors on sample files in the `test_files/` directory.

## Architecture Overview

### Core Components

1. **Ingestor (`redb/ingestor.py`)**: Main orchestrator that handles file processing, multiprocessing, and coordinates extractors
2. **Extractors (`redb/extractors/`)**: Modular analysis components that extract specific features
3. **Database Exporters (`redb/extractors/database_exporters.py`)**: Handle data export to ClickHouse
4. **Settings (`redb/settings/`)**: Configuration management for database connections

### Extractor Architecture

All extractors inherit from the base `Extractor` class and implement:
- `extract()`: Main analysis logic
- `prepare_export_data()`: Format data for database export
- `get_clickhouse_table()`: Return target table name

Available extractors:
- **General**: BasicPropertiesExtractor, HashExtractor, DIEExtractor, CAPAExtractor
- **PE-specific**: PEFeaturesExtractor, PEImportExtractor, PEResourceExtractor, PEOverlayExtractor, PESectionExtractor, PESignatureExtractor, PEDotNetExtractor, PEInconstistencyTestsExtractor, PEExtraFindings
- **ELF**: ELFFeaturesExtractor, ELFSegmentExtractor, ELFSectionExtractor, ELFDependencyExtractor, ELFSymbolExtractor, ELFImportExtractor, ELFExportExtractor, ELFRelocationExtractor, ELFNotesExtractor
- **Mach-O**: MachOFeaturesExtractor, MachOSegmentExtractor, MachOImportExtractor, MachOExportExtractor, MachODylibExtractor, MachOSignatureExtractor
- **APK**: APKFeaturesExtractor, APKManifestExtractor, APKPermissionsExtractor, APKSignatureExtractor, APKDexExtractor, APKResourceExtractor, APKNativeLibExtractor, APKInconsistencyTestsExtractor
- **Decompilation**: DecompileBinja, DecompileAPK

### Database Schema

The project uses a comprehensive ClickHouse schema defined in `redb/redb_schema.yml` with tables for:
- Basic properties (`redb_basic_properties`)
- PE features (`redb_pe_features`, `redb_pe_imports`, `redb_pe_sections`, etc.)
- Decompiled code (`code_binja_decompiled_functions_content`, `code_binja_decompiled_functions_references`)
- CAPA analysis (`redb_capa`, `redb_capa_capabilities`)

Full schema documentation is available in `docs/database_schema.md`.

### Processing Modes

1. **Analysis Mode**: Extracts features using selected modules
2. **Decompile Mode**: Uses Binary Ninja for code decompilation
3. **S3 Mode**: Fetches samples from S3 storage based on catalog queries
4. **Nomad Job Mode**: Processes single jobs using environment variables for containerized deployment

### Configuration

Environment variables are used for configuration:
- Database connection: `CLICKHOUSE_HOST`, `CLICKHOUSE_PORT`, `CLICKHOUSE_USER`, `CLICKHOUSE_PASSWORD`
- S3 storage: `S3_ENDPOINT`, `S3_ACCESS_KEY`, `S3_SECRET_KEY`
- Processing: `BATCH_SIZE`, `REDB_TIMEOUT`, `DECOMPILE_WORKER_TIMEOUT`
- Nomad jobs: `JOB_ID`, `S3_KEY`, `S3_BUCKET`, `WORKER_TYPE`, `CALLBACK_URL`, `ANALYSIS_MODULES`

## Important Implementation Details

### Multiprocessing
- Uses `spawn` method for multiprocessing to avoid memory issues
- Worker processes have timeout handlers to prevent hanging
- Supports both batch processing and streaming processing modes

### Memory Management
- Implements aggressive garbage collection between batches
- Monitors swap usage and restarts worker pools when needed
- Kills stuck processes automatically

### Error Handling
- Comprehensive logging with per-file context
- Graceful handling of corrupted or unsupported files
- Automatic retry logic for database operations

### Security Context
This is a defensive security tool for malware analysis. It processes potentially malicious files in a controlled environment to extract features for detection and analysis purposes.

## Development Notes

- The codebase is optimized for processing large batches of malware samples
- Extractors are designed to be modular and can be run individually or in combination
- Database schema supports both normalized and denormalized views for different query patterns
- S3 integration allows for scalable processing of large malware repositories