Xiangbing Zhou

33 papers C 1Journal 28Unranked 4
YearRankTypeTitle / Venue / Authors
2025 J jnl
Inf. Sci.
Chen Huang, Yingjie Song, Hongjiang Ma, Xiangbing Zhou, Wu Deng
2025 J jnl
IEEE Trans. Syst. Man Cybern. Syst.
Yan-Xue Wu, Min Wang, Fan Min, Qi Wang, Zhi-Heng Zhang, Haoyu Zhang, Xiangbing Zhou
2025 J jnl
IEEE Trans. Intell. Transp. Syst.
Wu Deng, Shifan Shang, Lirong Zhang, Yi Lin, Chen Huang, Huimin Zhao, Xiaojuan Ran, Xiangbing Zhou, Huiling Chen
2025 J jnl
IEEE Trans. Consumer Electron.
Wu Deng, Haotian Xu, Zheng Guan, Yuzhu Sun, Xiaojuan Ran, Hongjiang Ma, Xiangbing Zhou, Huimin Zhao
2025 J jnl
Int. J. Mach. Learn. Cybern.
Jiamiao Wang, Ling Chen, Zhiheng Zhang, Jin He, Xiangbing Zhou
2025 J jnl
IEEE Trans. Geosci. Remote. Sens.
Ziwei Wang, Ji Zhou, Wenbin Tang, Xiangbing Zhou, Bohan Zhou, Frank-Michael Göttsche, Shaomin Liu
2024 J jnl
Eng. Appl. Artif. Intell.
Xiaojuan Ran, Naret Suyaroj, Worawit Tepsan, Jianghong Ma, Xiangbing Zhou, Wu Deng
2024 J jnl
Inf. Sci.
Zhuoning Zhu, Xiang Li, Huayue Chen, Xiangbing Zhou, Wu Deng
2024 J jnl
Appl. Soft Comput.
Chen Huang, Daqing Wu, Xiangbing Zhou, Yingjie Song, Huiling Chen, Wu Deng
2024 J jnl
IEEE Trans. Intell. Transp. Syst.
Wu Deng, Xing Cai, Daqing Wu, Yingjie Song, Huiling Chen, Xiaojuan Ran, Xiangbing Zhou, Huimin Zhao
2024 J jnl
IEEE Trans. Geosci. Remote. Sens.
Huayue Chen, Haoyu Long, Tao Chen, Yingjie Song, Huiling Chen, Xiangbing Zhou, Wu Deng
2024 J jnl
Eng. Appl. Artif. Intell.
Haoyu Long, Tao Chen, Huayue Chen, Xiangbing Zhou, Wu Deng
2024 J jnl
Knowl. Based Syst.
Yan-Xue Wu, Fan Min, Gong-Suo Chen, Shaopeng Shen, Zuo-Cheng Wen, Xiangbing Zhou
2023 J jnl
Eng. Appl. Artif. Intell.
Chen Huang, Xiangbing Zhou, Xiaojuan Ran, Jiamiao Wang, Huayue Chen, Wu Deng
2023 J jnl
Inf. Sci.
Chen Huang, Xiangbing Zhou, Xiaojuan Ran, Yi Liu, Wuquan Deng, Wu Deng
2023 J jnl
Expert Syst. Appl.
Yingjie Song, Xing Cai, Xiangbing Zhou, Bin Zhang, Huiling Chen, Yuangang Li, Wuquan Deng, Wu Deng
2023 J jnl
Inf. Sci.
Xiangbing Zhou, Xing Cai, Hua Zhang, Zhiheng Zhang, Ting Jin, Huayue Chen, Wu Deng
2022 C conf
IGARSS
Jin Ma, Xiaojie Yang, Xiangbing Zhou, Ji Zhou
2022 J jnl
Inf. Sci.
Wu Deng, Xiaoxiao Zhang, Yongquan Zhou, Yi Liu, Xiangbing Zhou, Huiling Chen, Huimin Zhao
2022 J jnl
Inf. Sci.
Wu Deng, Lirong Zhang, Xiangbing Zhou, Yongquan Zhou, Yuzhu Sun, Weihong Zhu, Huayue Chen, Wuquan Deng, Huiling Chen, Huimin Zhao
2022 J jnl
Eng. Appl. Artif. Intell.
Xiangbing Zhou, Hongjiang Ma, Jianggang Gu, Huiling Chen, Wu Deng
2021 J jnl
Complex.
Yingjie Song, Daqing Wu, Ali Wagdy Mohamed, Xiangbing Zhou, Bin Zhang, Wu Deng
2020 J jnl
Concurr. Comput. Pract. Exp.
Ling Li, Xiangbing Zhou, Yiping Li, Jiangang Gu, Shaopeng Shen
2019 J jnl
Intell. Data Anal.
Hongjiang Ma, Xiangbing Zhou
2018 J jnl
ISPRS Int. J. Geo Inf.
Xiangbing Zhou, Fang Miao, Hongjiang Ma, Hua Zhang, Huaming Gong
2018 J jnl
Inf.
Xiangbing Zhou, Fang Miao, Hongjiang Ma
2017 J jnl
ISPRS Int. J. Geo Inf.
Xiangbing Zhou, Jianggang Gu, Shaopeng Shen, Hongjiang Ma, Fang Miao, Hua Zhang, Huaming Gong
2014 J jnl
Neurocomputing
Xiangbing Zhou, Junkang Tian, Hongjiang Ma, Shouming Zhong
2013 conf
ICSOC Workshops
Xiangbing Zhou, Hongjiang Ma, Fang Miao
2012 conf
AICI
Xiangbing Zhou, Hongjiang Ma, Fang Miao
2012 conf
ICICA (2)
Xiangbing Zhou, Hongjiang Ma, Fang Mao
2010 J jnl
Expert Syst. Appl.
Junkang Tian, Xiangbing Zhou
2009 conf
WKDD
Xiaoping Yang, Xiangbing Zhou
redb/extractors/decompiler/apk/smali_normalization.py
← Index redb/extractors/decompiler/apk/smali_normalization.py python
"""Semantic normalization of Dalvik/smali instructions.

Analogous to Binary Ninja's LLIL normalization: strips register allocation
noise and instruction encoding variants while preserving semantic operations.

Three normalization levels (most aggressive to most detailed):
  - 'category':    semantic category only (MOV, ALU, CALL, ...)
  - 'opcode':      base opcode, width-invariant (add, sub, invoke, ...)
  - 'opcode_api':  opcode category + API method/field references for
                   invoke/field/alloc instructions (default for MinHash)

References:
  - Smali+ 12-category reduction (Canfora et al.)
  - MOSDroid opcode family grouping
  - DroidSIFT/DroidSim API-sensitive similarity
"""

import re
from typing import List

# ---------------------------------------------------------------------------
# Dalvik opcode -> semantic category mapping
# ---------------------------------------------------------------------------
# Prefix-matched against instruction opcodes. Order matters for overlapping
# prefixes (longer/more-specific prefixes should come first in iteration,
# but since we use startswith and break on first match, we order by
# specificity within the list).

OPCODE_CATEGORIES = {
    # Arithmetic/logic
    "add": "ALU", "sub": "ALU", "mul": "ALU", "div": "ALU",
    "rem": "ALU", "and": "ALU", "or": "ALU", "xor": "ALU",
    "shl": "ALU", "shr": "ALU", "ushr": "ALU", "neg": "ALU",
    "not": "ALU",
    # Data movement
    "move": "MOV", "const": "CONST",
    # Memory access (field/array)
    "iget": "LOAD", "sget": "LOAD", "aget": "LOAD",
    "iput": "STORE", "sput": "STORE", "aput": "STORE",
    # Invocations
    "invoke": "CALL",
    # Control flow
    "if": "BRANCH", "goto": "JMP",
    "switch": "SWITCH",
    "return": "RET",
    # Object/type
    "new": "ALLOC", "check": "TYPE", "instance": "TYPE",
    # Array
    "fill": "ARR", "array": "ARR",
    # Comparison
    "cmpl": "CMP", "cmpg": "CMP", "cmp": "CMP",
    # Exception / synchronization
    "throw": "EXC", "monitor": "SYNC",
    # Conversion (int-to-long, float-to-int, etc.)
    "int-to": "CONV", "long-to": "CONV", "float-to": "CONV",
    "double-to": "CONV",
}

# Pre-compiled regexes for operand extraction
_METHOD_REF_RE = re.compile(r"(L[\w/$]+;->[\w<>]+\(.*?\)[\w/$;\[]*)")
_FIELD_REF_RE = re.compile(r"(L[\w/$]+;->[\w]+:[\w/$;\[]+)")
_CLASS_REF_RE = re.compile(r"(L[\w/$]+;)")
_CONST_STRING_RE = re.compile(r'^const-string(?:/jumbo)?\s')


def categorize_opcode(opcode: str) -> str:
    """Map a Dalvik opcode to its semantic category.

    Prefix-matched: 'add-int/2addr' matches 'add' -> 'ALU'.
    Returns 'OTHER' for unrecognized opcodes.
    """
    for prefix, cat in OPCODE_CATEGORIES.items():
        if opcode.startswith(prefix):
            return cat
    return "OTHER"


# Mapping from semantic categories to the ACFG feature vector indices
# used by Binary Ninja's build_block_features (cfg_features.py).
# This enables cross-platform ACFG feature comparison.
CATEGORY_TO_ACFG_INDEX = {
    "ALU": 0,       # CAT_ARITHMETIC
    "CONV": 0,      # arithmetic-adjacent
    "CMP": 4,       # CAT_COMPARISON
    "MOV": 2,       # CAT_TRANSFER
    "CONST": 2,     # transfer-adjacent (loading constants)
    "LOAD": 5,      # CAT_MEMORY
    "STORE": 5,     # CAT_MEMORY
    "CALL": 3,      # CAT_CALL
    "BRANCH": 1,    # CAT_LOGIC (conditional logic)
    "JMP": 1,       # CAT_LOGIC
    "SWITCH": 1,    # CAT_LOGIC
    "RET": 2,       # CAT_TRANSFER
    "ALLOC": 5,     # CAT_MEMORY (heap allocation)
    "TYPE": 6,      # CAT_OTHER
    "ARR": 5,       # CAT_MEMORY
    "EXC": 6,       # CAT_OTHER
    "SYNC": 6,      # CAT_OTHER
    "OTHER": 6,     # CAT_OTHER
}


def normalize_instruction(line: str, level: str = "opcode_api") -> str:
    """Normalize a single smali instruction line.

    Args:
        line: A single smali instruction (whitespace-stripped).
        level: Normalization level:
            'category'   - most aggressive: just semantic category
            'opcode'     - base opcode only, width/addressing-mode invariant
            'opcode_api' - category + API references for invoke/field/alloc
                          (default, best for MinHash similarity)

    Returns:
        Normalized instruction string, or empty string for non-instructions.
    """
    stripped = line.strip()
    if not stripped:
        return ""

    parts = stripped.split(None, 1)
    opcode = parts[0]
    operands = parts[1] if len(parts) > 1 else ""

    if level == "category":
        return categorize_opcode(opcode)

    if level == "opcode":
        # Strip type/width suffixes for invariance:
        # add-int, add-long, add-float -> 'add'
        # add-int/2addr -> 'add'
        base = re.split(r"[-/]", opcode)[0]
        return base

    if level == "opcode_api":
        # const-string: preserve string content (encrypted strings are a
        # key malware indicator)
        if _CONST_STRING_RE.match(stripped):
            # Extract the string literal
            str_match = re.search(r'"(.*)"', operands)
            if str_match:
                return f"CONST_STR \"{str_match.group(1)}\""
            return "CONST_STR"

        # invoke-*: preserve method reference
        if opcode.startswith("invoke"):
            ref = _METHOD_REF_RE.search(operands)
            if ref:
                return f"CALL {ref.group(1)}"
            return "CALL"

        # Field access: preserve field reference
        if opcode.startswith(("iget", "iput", "sget", "sput")):
            ref = _FIELD_REF_RE.search(operands)
            if ref:
                cat = "LOAD" if "get" in opcode else "STORE"
                return f"{cat} {ref.group(1)}"
            # Fallback: try space-separated format from androguard
            # e.g. "iget v0, p0, Lcom/Foo;->field Ljava/lang/String;"
            space_ref = re.search(
                r"(L[\w/$]+;->[\w]+)\s+([\w/$;\[]+)", operands
            )
            if space_ref:
                cat = "LOAD" if "get" in opcode else "STORE"
                return f"{cat} {space_ref.group(1)}:{space_ref.group(2)}"
            cat = "LOAD" if "get" in opcode else "STORE"
            return cat

        # new-instance: preserve allocated type
        if opcode.startswith("new-instance") or opcode == "new-array":
            ref = _CLASS_REF_RE.search(operands)
            if ref:
                return f"ALLOC {ref.group(1)}"
            return "ALLOC"

        # Everything else: just the category
        return categorize_opcode(opcode)

    # Unknown level: return raw opcode
    return opcode


def normalize_method_body(
    body: str, level: str = "opcode_api"
) -> List[str]:
    """Normalize all instructions in a smali method body.

    Filters out directives (.), labels (:), comments (#), and blank lines.
    Returns a list of normalized instruction strings.

    Args:
        body: Raw smali method body text.
        level: Normalization level (see normalize_instruction).

    Returns:
        List of normalized instruction strings (no empty strings).
    """
    normalized = []
    for line in body.split("\n"):
        stripped = line.strip()
        # Skip non-instructions
        if not stripped:
            continue
        if stripped.startswith((".",":", "#")):
            continue
        result = normalize_instruction(stripped, level)
        if result:
            normalized.append(result)
    return normalized