Xiangshui Miao

59 papers A* 2A 1C 3Journal 36Unranked 17
YearRankTypeTitle / Venue / Authors
2026 J jnl
Microelectron. J.
Sheng Hu, Huajun Sun, Jun Zhou, Qiong Zhan, Peng Sun, Beibei Sheng, Peng Zhu, Changtian Cao, Daohong Yang, Xiangshui Miao
2026 conf
ASP-DAC
Yingjie Yu, Houji Zhou, Jiancong Li, Tong Hu, Jia Chen, Yi Li, Xiangshui Miao
2026 J jnl
IEEE Trans. Circuits Syst. I Regul. Pap.
Junming Zhang, Zheyuan Sheng, Huajun Sun, Chuanbo Zhu, Liangyu Chen, Zhenyu Hu, Xiangshui Miao
2026 conf
ASP-DAC
Zhiwei Zhou, Tong Hu, Han Bao, Houji Zhou, Yuyang Fu, Jiancong Li, Jia Chen, Yi Li, Xiangshui Miao
2026 J jnl
CoRR
Junming Zhang, Qinyan Zhang, Huajun Sun, Feiyang Gao, Sheng Hu, Rui Nie, Xiangshui Miao
2025 J jnl
Sci. China Inf. Sci.
Yingjie Yu, Shengguang Ren, Ling Yang, Yi Li, Xiangshui Miao
2025 C conf
ISCAS
Zhouchao Gan, Yifeng Xiong, Fan Yang, Mengjie Li, Xiangshui Miao, Xingsheng Wang
2025 C conf
ICCD
Zijian Xiong, Xiangrui Yang, Yuhang Zhang, Yue Zhou, Jianguo Yang, Yaoyu Tao, Xiangshui Miao, Yuhui He
2025 J jnl
IEEE Trans. Circuits Syst. I Regul. Pap.
Zhiwei Zhou, Jiancong Li, Han Jia, Ling Yang, Houji Zhou, Han Bao, Yuyang Fu, Yi Li, Xiangshui Miao
2025 J jnl
Nat. Comput. Sci.
Meng Xu, Shaocong Wang, Yangu He, Yi Li, Woyu Zhang, Ming Yang, Xiaojuan Qi, Zhongrui Wang, Ming Xu, Dashan Shang, Qi Liu, Xiangshui Miao, Ming Liu
2025 J jnl
IEEE Trans. Very Large Scale Integr. Syst.
Fan Yang, Nan Li, Letian Wang, Pinfeng Jiang, Xiangshui Miao, Xingsheng Wang
2025 J jnl
CoRR
Houji Zhou, Ling Yang, Zhiwei Zhou, Yi Li, Xiangshui Miao
2025 conf
IRPS
Dejiang Mu, Pan Liu, Zijian Zhou, Zifei Cai, Jian Zhang, Kanhao Xue, Zhigang Ji, Xiangshui Miao, Xingsheng Wang
2025 J jnl
Sci. China Inf. Sci.
Pinfeng Jiang, Danzhe Song, Menghua Huang, Fan Yang, Letian Wang, Pan Liu, Xiangshui Miao, Xingsheng Wang
2025 C conf
ISCAS
Pinfeng Jiang, Letian Wang, Yilong Fang, Yi Wang, Mingde Zhu, Xiangshui Miao, Xingsheng Wang
2025 A* conf
DAC
Yuyang Fu, Jiancong Li, Jia Chen, Zhiwei Zhou, Houji Zhou, Wenlong Peng, Yi Li, Xiangshui Miao
2025 A conf
ICCAD
Pinfeng Jiang, Letian Wang, Yilong Fang, Yi Wang, Mingde Zhu, Xiangshui Miao, Xingsheng Wang
2024 J jnl
Sci. China Inf. Sci.
Jinyu Wen, Lun Wang, Jiangxi Chen, Hao Tong, Xiangshui Miao
2024 conf
ICTA
Fan Yang, Nan Li, Juncheng Huang, Qingjie Wang, Xiangshui Miao, Xingsheng Wang
2024 J jnl
Sensors
Peng Cheng, Candong Zhao, Qinjie Pan, Zijian Xiong, Qi Chen, Xiangshui Miao, Yuhui He
2024 J jnl
Sci. China Inf. Sci.
Zhouchao Gan, Dongdong Zhang, Chenyu Zhang, Yinghao Ma, Xiangshui Miao, Xingsheng Wang
2024 J jnl
IEEE Trans. Circuits Syst. I Regul. Pap.
Han Bao, Pengyu Ren, Kehong Xu, Ling Yang, Houji Zhou, Jiancong Li, Yi Li, Xiangshui Miao
2024 conf
ICTA
Yi-Bai Xue, Shengguang Ren, Yu Zhang, Wen-Bin Zuo, Yi Li, Xiangshui Miao
2024 J jnl
IEEE Trans. Ind. Electron.
Ziqi Chen, Xin Li, Xun Zhu, Haoyuan Liu, Hao Tong, Xiangshui Miao
2024 conf
IMW
Jun Yu, Jiawei Fu, Candong Zhao, Fuwei Zhuge, Qi Chen, Yuhui He, Xiangshui Miao
2024 conf
ICTA
Jing Tian, Huai-Zhi Pei, Shengguang Ren, Han Bao, Ling Yang, Yi Li, Xiangshui Miao
2024 J jnl
IEEE Trans. Very Large Scale Integr. Syst.
Yajuan Hui, Qingzhen Li, Leimin Wang, Cheng Liu, Deming Zhang, Xiangshui Miao
2024 J jnl
IEEE Trans. Circuits Syst. II Express Briefs
Yajuan Hui, Qingzhen Li, Cheng Liu, Deming Zhang, Xiangshui Miao
2024 J jnl
Sci. China Inf. Sci.
Ninghua Li, Wang Cai, Jun Xiang, Hao Tong, Weiming Cheng, Xiangshui Miao
2024 A* conf
DAC
Zifei Cai, Anaoxue Huang, Yifeng Xiong, Dejiang Mu, Xiangshui Miao, Xingsheng Wang
2023 conf
VLSI Technology and Circuits
Yaxin Ding, Jianguo Yang, Yu Liu, Jianfeng Gao, Yuan Wang, Pengfei Jiang, Shuxian Lv, Yuting Chen, Boping Wang, Wei Wei, Tiancheng Gong, Kanhao Xue, Qing Luo, Xiangshui Miao, Ming Liu
2023 J jnl
Sci. China Inf. Sci.
Haowen Luo, Ruihan Li, Xiangshui Miao, Xingsheng Wang
2023 J jnl
Sci. China Inf. Sci.
Jiancong Li, Houji Zhou, Yi Li, Xiangshui Miao
2023 J jnl
Sci. China Inf. Sci.
Xiaojie Wang, Zeyang Feng, Jingwei Cai, Hao Tong, Xiangshui Miao
2023 conf
ICTA
Fei-Xiong Lu, Yi Li, Jian-Cong Li, Yi-Bai Xue, Zhiwei Zhou, Xiangshui Miao
2023 conf
NANOARCH
Houji Zhou, Zhiwei Zhou, Shengguang Ren, Jia Chen, Yi Li, Xiangshui Miao
2023 J jnl
Adv. Intell. Syst.
Yingjie Yu, Ling Yang, Houji Zhou, Ruizhe Zhao, Yi Li, Hao Tong, Xiangshui Miao
2023 conf
ICTA
Zhouchao Gan, Dongdong Zhang, Yinghao Ma, Chenyu Zhang, Xiangshui Miao, Xingsheng Wang
2023 J jnl
Adv. Intell. Syst.
Houji Zhou, Ling Yang, Han Bao, Jiancong Li, Yi Li, Xiangshui Miao
2023 J jnl
Sci. China Inf. Sci.
Chengxu Wang, Hao Yu, Yichen Wang, Zichong Zhang, Xiangshui Miao, Xingsheng Wang
2023 J jnl
Sensors
Runqing Zhang, Rui Su, Chenglin Shen, Ruizi Xiao, Weiming Cheng, Xiangshui Miao
2023 J jnl
Sci. China Inf. Sci.
Zhuiri Peng, Runfeng Lin, Zheng Li, Langlang Xu, Xiangxiang Yu, Xinyu Huang, Wenhao Shi, Xiao He, Xiaohan Meng, Lei Tong, Xiangshui Miao, Lei Ye
2022 J jnl
Neuromorph. Comput. Eng.
Qing Wan, Changjin Wan, Huaqiang Wu, Yuchao Yang, Xiaohe Huang, Peng Zhou, Lin Chen, Tian-Yu Wang, Yi Li, Kanhao Xue, Yu-Hui He, Xiangshui Miao, Xi Li, Chenchen Xie, Houpeng Chen, Zhitang Song, Hong Wang, Yue Hao, Junyao Zhang, Jia Huang, Zheng Yu Ren, Li Qiang Zhu, Jianyu Du, Chen Ge, Yang Liu, Guanglong Ding, Ye Zhou, Su-Ting Han, Guosheng Wang, Xiao Yu, Bing Chen, Zhufei Chu, Lunyao Wang, Yinshui Xia, Chen Mu, Feng Lin, Chixiao Chen, Bojun Cheng, Yannan Xing, Weitao Zeng, Hong Chen, Lei Yu, Giacomo Indiveri, Ning Qiao
2022 J jnl
Adv. Intell. Syst.
Yichun Xu, Sen Gao, Zhiyuan Li, Rui Yang, Xiangshui Miao
2022 J jnl
IEEE Trans. Neural Networks Learn. Syst.
Yue Zhou, Nuo Xu, Bin Gao, Fuwei Zhuge, Zijian Tang, Xinchen Deng, Yi Li, Yuhui He, Xiangshui Miao
2022 J jnl
Sci. China Inf. Sci.
Houji Zhou, Yi Li, Xiangshui Miao
2022 J jnl
Microelectron. J.
Li Li, Zuopai Zhou, Na Bai, Tao Wang, Kanhao Xue, Huajun Sun, Qiang He, Weiming Cheng, Xiangshui Miao
2021 J jnl
Adv. Intell. Syst.
Houji Zhou, Jia Chen, Yinan Wang, Sen Liu, Yi Li, Qingjiang Li, Qi Liu, Zhongrui Wang, Yuhui He, Hui Xu, Xiangshui Miao
2021 J jnl
Adv. Intell. Syst.
Houji Zhou, Jia Chen, Yinan Wang, Sen Liu, Yi Li, Qingjiang Li, Qi Liu, Zhongrui Wang, Yuhui He, Hui Xu, Xiangshui Miao
2021 J jnl
IEEE Trans. Neural Networks Learn. Syst.
Yin Sheng, Tingwen Huang, Zhigang Zeng, Xiangshui Miao
2021 conf
ICTA
Shengguang Ren, Run Ni, Xiaodi Huang, Yi Li, Xiangshui Miao
2020 conf
ICTA
Hao Yu, Chengxu Wang, Xiangshui Miao, Xingsheng Wang
2020 conf
ICTA
Han Bao, Xiaodi Huang, Jia Chen, Yi Li, Xiangshui Miao
2020 conf
ICTA
Jia Chen, Wen-Qian Pan, Yi Li, Ting-Chang Chang, Xiangshui Miao
2020 conf
ICTA
Chengxu Wang, Hao Yu, Xiangshui Miao, Xingsheng Wang
2020 J jnl
Adv. Intell. Syst.
Yifan Qin, Han Bao, Feng Wang, Jia Chen, Yi Li, Xiangshui Miao
2020 J jnl
Adv. Intell. Syst.
Yifan Qin, Han Bao, Feng Wang, Jia Chen, Yi Li, Xiangshui Miao
2018 J jnl
Sci. China Inf. Sci.
Yi Li, Yaxiong Zhou, Zhuorui Wang, Xiangshui Miao
2012 conf
NEMS
Wenhao Zhao, Wenli Zhou, Xiangshui Miao
redb/extractors/apk_extractors/apk_inconsistency_tests.py
← Index redb/extractors/apk_extractors/apk_inconsistency_tests.py python
import inspect
import re
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.apk_extractor import APKExtractor
from redb.models.dataclasses import APKInconsistencyTests

# Emulator detection indicator strings
EMULATOR_INDICATORS = {
    "generic", "sdk", "google_sdk", "Emulator",
    "goldfish", "ranchu", "Andy", "Genymotion",
    "BlueStacks", "nox", "ttVM_Hdragon",
}

# Root detection indicator strings
ROOT_INDICATORS = {
    "/system/app/Superuser.apk",
    "/system/xbin/su",
    "/system/bin/su",
    "com.noshufou.android.su",
    "com.thirdparty.superuser",
    "eu.chainfire.supersu",
    "com.koushikdutta.superuser",
    "com.topjohnwu.magisk",
}

# Standard DEX filename pattern
STANDARD_DEX_PATTERN = re.compile(r"^classes\d*\.dex$")


class APKInconsistencyTestsExtractor(APKExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False,
        apk=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, apk,
        )
        self.test_results = None
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.APK_INCONSISTENCY_TESTS.value

    def _test_zip_bomb(self):
        """Check if any ZIP entry has compression ratio > 100:1."""
        try:
            zf = self._get_zip_file()
            if not zf:
                return None
            with zf:
                for info in zf.infolist():
                    if info.compress_size > 0:
                        ratio = info.file_size / info.compress_size
                        if ratio > 100:
                            return True
            return False
        except Exception as e:
            self.log.warning(f"Error in zip bomb test: {e}")
            return None

    def _test_zip_duplicate_entries(self):
        """Check for duplicate filenames in ZIP directory."""
        try:
            zf = self._get_zip_file()
            if not zf:
                return None
            with zf:
                names = [info.filename for info in zf.infolist()]
                return len(names) != len(set(names))
        except Exception as e:
            self.log.warning(f"Error in duplicate entries test: {e}")
            return None

    def _test_zip_path_traversal(self):
        """Check for path traversal (../) in ZIP entry names."""
        try:
            for f in self._list_files():
                if ".." in f or f.startswith("/"):
                    return True
            return False
        except Exception as e:
            self.log.warning(f"Error in path traversal test: {e}")
            return None

    def _test_zip_suspicious_timestamps(self):
        """Check for timestamps at epoch (1980) or in the future."""
        try:
            zf = self._get_zip_file()
            if not zf:
                return None
            now = datetime.now()
            with zf:
                for info in zf.infolist():
                    try:
                        dt = datetime(*info.date_time)
                        if dt.year <= 1980 or dt > now:
                            return True
                    except (ValueError, TypeError):
                        continue
            return False
        except Exception as e:
            self.log.warning(f"Error in suspicious timestamps test: {e}")
            return None

    def _test_hidden_dex_files(self):
        """Check for DEX files not matching classes*.dex pattern."""
        try:
            for f in self._list_files():
                if f.endswith(".dex"):
                    basename = f.split("/")[-1]
                    if not STANDARD_DEX_PATTERN.match(basename):
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in hidden DEX files test: {e}")
            return None

    def _test_manifest_component_mismatch(self):
        """Check for declared components that don't exist in DEX."""
        try:
            if not self._is_valid_apk():
                return None

            # Get all class names from DEX
            dex_classes = set()
            try:
                from androguard.core.dex import DEX
                for dex_data in (self.apk.get_all_dex() or []):
                    try:
                        d = DEX(dex_data)
                        for cls in d.get_classes():
                            name = cls.get_name()
                            if name:
                                # Convert "Lcom/example/Foo;" to "com.example.Foo"
                                dex_classes.add(
                                    name[1:-1].replace("/", ".") if name.startswith("L") else name
                                )
                    except Exception:
                        continue
            except Exception:
                return None

            if not dex_classes:
                return None

            # Check manifest components against DEX classes
            components = []
            try:
                components.extend(self.apk.get_activities() or [])
                components.extend(self.apk.get_services() or [])
                components.extend(self.apk.get_receivers() or [])
                components.extend(self.apk.get_providers() or [])
            except Exception:
                return None

            for comp in components:
                if comp and comp not in dex_classes:
                    # Component might use a shorthand; check with package prefix
                    package = self.apk.get_package() or ""
                    full_name = package + comp if comp.startswith(".") else comp
                    if full_name not in dex_classes:
                        return True

            return False
        except Exception as e:
            self.log.warning(f"Error in manifest component mismatch test: {e}")
            return None

    def _test_debuggable_release(self):
        """Check android:debuggable=true combined with a release signature."""
        try:
            if not self._is_valid_apk():
                return None

            is_debuggable = self.apk.get_attribute_value(
                "application", "debuggable"
            ) == "true"

            if not is_debuggable:
                return False

            # Check if it has a signing certificate (release builds have certs)
            try:
                certs = self.apk.get_certificates()
                if certs and len(certs) > 0:
                    return True
            except Exception:
                pass

            return False
        except Exception as e:
            self.log.warning(f"Error in debuggable release test: {e}")
            return None

    def _get_dex_strings(self):
        """Get all string constants from DEX files."""
        all_strings = set()
        try:
            from androguard.core.dex import DEX
            for dex_data in (self.apk.get_all_dex() or []):
                try:
                    d = DEX(dex_data)
                    for s in d.get_strings():
                        if s:
                            all_strings.add(s)
                except Exception:
                    continue
        except Exception:
            pass
        return all_strings

    def _test_emulator_detection_strings(self):
        """Check for emulator detection patterns in DEX strings."""
        try:
            if not self._is_valid_apk():
                return None

            dex_strings = self._get_dex_strings()
            for indicator in EMULATOR_INDICATORS:
                for s in dex_strings:
                    if indicator in s:
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in emulator detection test: {e}")
            return None

    def _test_debugger_detection(self):
        """Check for debugger detection API calls in DEX."""
        try:
            if not self._is_valid_apk():
                return None

            dex_strings = self._get_dex_strings()
            debugger_patterns = {
                "isDebuggerConnected",
                "waitingForDebugger",
                "Debug.isDebuggerConnected",
            }
            for pattern in debugger_patterns:
                for s in dex_strings:
                    if pattern in s:
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in debugger detection test: {e}")
            return None

    def _test_root_detection(self):
        """Check for root detection patterns in DEX."""
        try:
            if not self._is_valid_apk():
                return None

            dex_strings = self._get_dex_strings()
            for indicator in ROOT_INDICATORS:
                for s in dex_strings:
                    if indicator in s:
                        return True
            return False
        except Exception as e:
            self.log.warning(f"Error in root detection test: {e}")
            return None

    def extract(self):
        if not self._is_valid_apk():
            self.log.error(f"Invalid APK for {self.hash.sha256}")
            return None

        self.test_results = APKInconsistencyTests(
            test_zip_bomb=self._test_zip_bomb(),
            test_zip_duplicate_entries=self._test_zip_duplicate_entries(),
            test_zip_path_traversal=self._test_zip_path_traversal(),
            test_zip_suspicious_timestamps=self._test_zip_suspicious_timestamps(),
            test_hidden_dex_files=self._test_hidden_dex_files(),
            test_manifest_component_mismatch=self._test_manifest_component_mismatch(),
            test_debuggable_release=self._test_debuggable_release(),
            test_emulator_detection_strings=self._test_emulator_detection_strings(),
            test_debugger_detection=self._test_debugger_detection(),
            test_root_detection=self._test_root_detection(),
        )
        return self.test_results

    def _bool_to_nullable(self, val):
        """Convert bool/None to ClickHouse Nullable(UInt8)."""
        if val is None:
            return None
        return int(val)

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.test_results:
                return None

            current_time = datetime.now(timezone.utc)
            t = self.test_results

            data = [[
                self.sha256,
                self._bool_to_nullable(t.test_zip_bomb),
                self._bool_to_nullable(t.test_zip_duplicate_entries),
                self._bool_to_nullable(t.test_zip_path_traversal),
                self._bool_to_nullable(t.test_zip_suspicious_timestamps),
                self._bool_to_nullable(t.test_hidden_dex_files),
                self._bool_to_nullable(t.test_manifest_component_mismatch),
                self._bool_to_nullable(t.test_debuggable_release),
                self._bool_to_nullable(t.test_emulator_detection_strings),
                self._bool_to_nullable(t.test_debugger_detection),
                self._bool_to_nullable(t.test_root_detection),
                current_time,
            ]]

            column_names = [
                'sha256',
                'test_zip_bomb', 'test_zip_duplicate_entries',
                'test_zip_path_traversal', 'test_zip_suspicious_timestamps',
                'test_hidden_dex_files', 'test_manifest_component_mismatch',
                'test_debuggable_release', 'test_emulator_detection_strings',
                'test_debugger_detection', 'test_root_detection',
                'analysis_date',
            ]

            column_type_names = [
                'FixedString(64)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                'Nullable(UInt8)', 'Nullable(UInt8)',
                "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_apk_inconsistency_tests"