Xiaohui Bei

91 papers A* 29A 8B 1Misc 1Journal 47Unranked 4
YearRankTypeTitle / Venue / Authors
2026 J jnl
Discret. Appl. Math.
Xiaohui Bei, Alexander Lam, Xinhang Lu, Warut Suksompong
2025 J jnl
SIAM J. Discret. Math.
Xiaohui Bei, Edith Elkind, Erel Segal-Halevi, Warut Suksompong
2025 J jnl
Games Econ. Behav.
Xiaohui Bei, Shengxin Liu, Xinhang Lu
2025 J jnl
CoRR
Xiaohui Bei, Yuda Feng, Yang Hu, Shi Li, Ruilong Zhang
2025 A* conf
AAAI
Xiaohui Bei, Pinyan Lu, Zhiqi Wang, Tao Xiao, Xiang Yan
2025 J jnl
Artif. Intell.
Xiaohui Bei, Biaoshuai Tao, Jiajun Wu, Mingwei Yang
2025 J jnl
Soc. Choice Welf.
Xiaohui Bei, Xinhang Lu, Warut Suksompong
2024 J jnl
Soc. Choice Welf.
Xinhang Lu, Jannik Peters, Haris Aziz, Xiaohui Bei, Warut Suksompong
2024 J jnl
Soc. Choice Welf.
Xinhang Lu, Jannik Peters, Haris Aziz, Xiaohui Bei, Warut Suksompong
2024 A* conf
IJCAI
Xiaohui Bei, Alexander Lam, Xinhang Lu, Warut Suksompong
2024 J jnl
CoRR
Xiaohui Bei, Alexander Lam, Xinhang Lu, Warut Suksompong
2023 A* conf
AAAI
Xinhang Lu, Jannik Peters, Haris Aziz, Xiaohui Bei, Warut Suksompong
2023 conf
WINE
Hongtao Lv, Xiaohui Bei, Zhenzhe Zheng, Fan Wu
2023 J jnl
CoRR
Hongtao Lv, Xiaohui Bei, Zhenzhe Zheng, Fan Wu
2023 A* conf
SODA
Xiaohui Bei, Nick Gravin, Pinyan Lu, Zhihao Gavin Tang
2023 J jnl
CoRR
Xiaohui Bei, Shengxin Liu, Xinhang Lu
2023 J jnl
CoRR
Xiaohui Bei, Biaoshuai Tao, Jiajun Wu, Mingwei Yang
2022 J jnl
CoRR
Xinhang Lu, Jannik Peters, Haris Aziz, Xiaohui Bei, Warut Suksompong
2022 J jnl
CoRR
Xiaohui Bei, Nick Gravin, Pinyan Lu, Zhihao Gavin Tang
2022 J jnl
Auton. Agents Multi Agent Syst.
Xiaohui Bei, Shengxin Liu, Chung Keung Poon, Hongao Wang
2022 J jnl
CoRR
Xiaohui Bei, Zihao Li, Junjie Luo
2022 conf
WINE
Xiaohui Bei, Zihao Li, Junjie Luo
2022 Misc conf
CSR
Yifen Li, Xiaohui Bei, Youming Qiao, Dacheng Tao, Zhiya Chen
2022 A conf
UAI
Zihao Li, Xiaohui Bei, Zhenzhen Yan
2022 A* conf
AAAI
Hao Wang, Xiaohui Bei
2022 J jnl
SIAM J. Discret. Math.
Xiaohui Bei, Ayumi Igarashi, Xinhang Lu, Warut Suksompong
2022 A* conf
AAAI
Xiaohui Bei, Shengyu Zhang
2022 A* conf
AAAI
Xiaohui Bei, Xinhang Lu, Warut Suksompong
2021 A* conf
AAAI
Xiaohui Bei, Warut Suksompong
2021 J jnl
Artif. Intell.
Xiaohui Bei, Zihao Li, Jinyan Liu, Shengxin Liu, Xinhang Lu
2021 J jnl
SIAM J. Comput.
Xiaohui Bei, Shiteng Chen, Ji Guan, Youming Qiao, Xiaoming Sun
2021 A* conf
ICML
Chunxue Yang, Xiaohui Bei
2021 J jnl
CoRR
Sijun Tan, Jibang Wu, Xiaohui Bei, Haifeng Xu
2021 A* conf
NeurIPS
Sijun Tan, Jibang Wu, Xiaohui Bei, Haifeng Xu
2021 A* conf
AAAI
Xiaohui Bei, Shengxin Liu, Xinhang Lu, Hongao Wang
2021 J jnl
Auton. Agents Multi Agent Syst.
Xiaohui Bei, Shengxin Liu, Xinhang Lu, Hongao Wang
2021 A* conf
AAAI
Xiaohui Bei, Ayumi Igarashi, Xinhang Lu, Warut Suksompong
2021 J jnl
Theory Comput. Syst.
Xiaohui Bei, Xinhang Lu, Pasin Manurangsi, Warut Suksompong
2021 J jnl
CoRR
Xiaohui Bei, Xinhang Lu, Warut Suksompong
2020 A* conf
SODA
Xiaohui Bei, Xiaoming Sun, Hao Wu, Jialin Zhang, Zhijie Zhang, Wei Zi
2020 A conf
AAMAS
Xiaohui Bei, Shengxin Liu, Chung Keung Poon, Hongao Wang
2020 A* conf
AAAI
Xiaohui Bei, Zihao Li, Jinyan Liu, Shengxin Liu, Xinhang Lu
2020 A conf
ITCS
Xiaohui Bei, Shiteng Chen, Ji Guan, Youming Qiao, Xiaoming Sun
2020 J jnl
CoRR
Xiaohui Bei, Shengxin Liu, Xinhang Lu, Hongao Wang
2020 J jnl
Soc. Choice Welf.
Xiaohui Bei, Guangda Huzhang, Warut Suksompong
2019 J jnl
ACM Trans. Algorithms
Xiaohui Bei, Jugal Garg, Martin Hoefer
2019 A* conf
NeurIPS
Nixie S. Lesmana, Xuan Zhang, Xiaohui Bei
2019 J jnl
CoRR
Xiaohui Bei, Xiaoming Sun, Hao Wu, Jialin Zhang, Zhijie Zhang, Wei Zi
2019 J jnl
CoRR
Xiaohui Bei, Ayumi Igarashi, Xinhang Lu, Warut Suksompong
2019 A* conf
SODA
Xiaohui Bei, Nick Gravin, Pinyan Lu, Zhihao Gavin Tang
2019 J jnl
CoRR
Xiaohui Bei, Warut Suksompong
2019 A conf
UAI
Taoan Huang, Bohui Fang, Xiaohui Bei, Fei Fang
2019 J jnl
CoRR
Taoan Huang, Bohui Fang, Xiaohui Bei, Fei Fang
2019 J jnl
ACM Trans. Economics and Comput.
Xiaohui Bei, Jugal Garg, Martin Hoefer, Kurt Mehlhorn
2019 J jnl
CoRR
Xiaohui Bei, Zihao Li, Jinyan Liu, Shengxin Liu, Xinhang Lu
2019 J jnl
CoRR
Xiaohui Bei, Shiteng Chen, Ji Guan, Youming Qiao, Xiaoming Sun
2019 A conf
AAMAS
Taoan Huang, Bohui Fang, Hoon Oh, Xiaohui Bei, Fei Fang
2019 A* conf
IJCAI
Xiaohui Bei, Xinhang Lu, Pasin Manurangsi, Warut Suksompong
2019 J jnl
CoRR
Xiaohui Bei, Xinhang Lu, Pasin Manurangsi, Warut Suksompong
2018 A* conf
AAAI
Xiaohui Bei, Shengyu Zhang
2018 conf
PRICAI (1)
Chaoli Zhang, Fan Wu, Xiaohui Bei
2018 A conf
AAMAS
Chaoli Zhang, Xiang Wang, Fan Wu, Xiaohui Bei
2018 A* conf
IJCAI
Xiaohui Bei, Guangda Huzhang, Warut Suksompong
2018 J jnl
CoRR
Xiaohui Bei, Guangda Huzhang, Warut Suksompong
2017 A* conf
IJCAI
Xiaohui Bei, Ning Chen, Guangda Huzhang, Biaoshuai Tao, Jiajun Wu
2017 B conf
SAGT
Xiaohui Bei, Jugal Garg, Martin Hoefer, Kurt Mehlhorn
2017 A* conf
IJCAI
Xiaohui Bei, Youming Qiao, Shengyu Zhang
2017 J jnl
CoRR
Xiaohui Bei, Youming Qiao, Shengyu Zhang
2017 A* conf
IJCAI
Guangda Huzhang, Xin Huang, Shengyu Zhang, Xiaohui Bei
2017 J jnl
SIAM J. Comput.
Xiaohui Bei, Ning Chen, Nick Gravin, Pinyan Lu
2016 A* conf
EC
Xiaohui Bei, Jugal Garg, Martin Hoefer
2016 A conf
ESA
Xiaohui Bei, Jugal Garg, Martin Hoefer, Kurt Mehlhorn
2016 J jnl
CoRR
Xiaohui Bei, Jugal Garg, Martin Hoefer, Kurt Mehlhorn
2016 A* conf
AAAI
Xiaohui Bei, Wei Chen, Jugal Garg, Martin Hoefer, Xiaoming Sun
2016 ch.
Encyclopedia of Algorithms
Xiaohui Bei, Ning Chen, Shengyu Zhang
2015 conf
ICALP (1)
Xiaohui Bei, Ning Chen, Shengyu Zhang
2015 J jnl
CoRR
Xiaohui Bei, Jugal Garg, Martin Hoefer
2013 A* conf
STOC
Xiaohui Bei, Ning Chen, Shengyu Zhang
2013 J jnl
CoRR
Xiaohui Bei, Ning Chen, Shengyu Zhang
2013 A* conf
KDD
Xiaohui Bei, Ning Chen, Liyu Dou, Xiangru Huang, Ruixin Qiang
2012 J jnl
CoRR
Xiaohui Bei, Ning Chen, Nick Gravin, Pinyan Lu
2012 A* conf
STOC
Xiaohui Bei, Ning Chen, Nick Gravin, Pinyan Lu
2012 J jnl
CoRR
Xiaohui Bei, Wei Chen, Jialin Zhang
2012 J jnl
CoRR
Xiaohui Bei, Ning Chen, Shengyu Zhang
2012 J jnl
Electron. Colloquium Comput. Complex.
Xiaohui Bei, Ning Chen, Shengyu Zhang
2012 A* conf
AAAI
Xiaohui Bei, Ning Chen, Xia Hua, Biaoshuai Tao, Endong Yang
2011 A* conf
SODA
Xiaohui Bei, Zhiyi Huang
2011 J jnl
Theor. Comput. Sci.
Xiaohui Bei, Wei Chen, Shang-Hua Teng, Jialin Zhang, Jiajie Zhu
2011 J jnl
CoRR
Xiaohui Bei, Ning Chen, Nick Gravin, Pinyan Lu
2010 J jnl
CoRR
Xiaohui Bei, Zhiyi Huang
2009 A conf
ESA
Xiaohui Bei, Wei Chen, Shang-Hua Teng, Jialin Zhang, Jiajie Zhu
redb/extractors/apk_extractors/apk_resources.py
← Index redb/extractors/apk_extractors/apk_resources.py python
import hashlib
import inspect
import os
from datetime import datetime, timezone
from typing import Any

from redb.extractors.enum import Tag
from redb.extractors.apk_extractor import APKExtractor
from redb.models.dataclasses import APKResource


# ─── Suspicious file types ──────────────────────────────────────────────
# File types that are suspicious when found inside res/ or assets/.
# Excludes javascript/html (extremely common in legitimate hybrid apps)
# and common media/font types that are normal APK content.
SUSPICIOUS_TYPES = {
    # Executables — no legitimate reason in assets/res
    "elf", "pebin", "macho", "dex", "apk",
    # Java containers — DexClassLoader target
    "jar",
    # Archives — rare in legitimate assets (~135:1 malware-to-benign ratio)
    "zip", "gzip", "7z", "xz", "tar", "bzip2", "rar", "7zip", "lzma",
    # Scripts with system execution capability
    "shell", "python", "powershell", "batch",
}

# ─── Entropy thresholds ─────────────────────────────────────────────────
# For unrecognized/unknown types: encrypted payloads typically land > 7.0
ENTROPY_HIGH_UNKNOWN = 7.0
# For recognized-but-non-image types: stricter threshold
ENTROPY_EXTREME = 7.85

# ─── Android-specific binary format magic bytes ─────────────────────────
# These formats are common in legitimate APKs but unknown to Magika,
# causing misclassification (e.g., AXML → "gzip", profm → "unknown").
AXML_MAGIC = b'\x03\x00\x08\x00'       # Android Binary XML (compiled res/*.xml)
ARSC_MAGIC = b'\x02\x00\x0c\x00'       # Android compiled resource table
ART_PROF_MAGIC = b'pro\x00'            # ART baseline profile
ART_PROFM_MAGIC = b'prm\x00'           # ART baseline profile metadata

# ─── Allowlisted paths ──────────────────────────────────────────────────
# Fixed, hardcoded paths in the Android build system that are always benign.
# ART profiles at these exact paths are shipped by Jetpack ProfileInstaller.
ALLOWLISTED_PATHS = {
    "assets/dexopt/baseline.prof",
    "assets/dexopt/baseline.profm",
}

# ─── Image handling ─────────────────────────────────────────────────────
# Magika-confirmed image types: high entropy is expected (lossy codecs
# like VP8/JPEG arithmetic-code toward entropy ~7.95-8.0 by design).
IMAGE_MAGIKA_TYPES = {"png", "webp", "jpeg", "gif", "bmp", "tiff", "ico"}
IMAGE_EXTENSIONS = {".png", ".webp", ".jpg", ".jpeg", ".gif", ".bmp", ".tiff", ".ico"}

# ─── Types Magika assigns when it can't identify the content ────────────
UNRECOGNIZED_MAGIKA_TYPES = {"unknown", "empty"}

# ─── Resource scan limits ───────────────────────────────────────────────
MAX_RESOURCE_FILES = 5000


class APKResourceExtractor(APKExtractor):

    def __init__(
        self, filepath, log, exporters=None, index_prefix=None,
        known_benign=False, known_malicious=False,
        apk=None,
    ):
        super().__init__(
            filepath, log, exporters, index_prefix,
            known_benign, known_malicious, apk,
        )
        self.resources = []
        self.suspicious_files = []
        self.log.debug(inspect.currentframe().f_code.co_name)

    def tag(self):
        return Tag.APK_RESOURCES.value

    # ─── Core classification logic ──────────────────────────────────────

    def _identify_android_format(self, header: bytes) -> str | None:
        """
        Identify Android-specific binary formats that Magika doesn't know.
        Returns a corrected type label, or None to fall through to Magika.
        """
        if len(header) < 4:
            return None

        magic4 = header[:4]

        # Android Binary XML — all res/*.xml in a compiled APK.
        # Magika often misclassifies this as "gzip".
        if magic4 == AXML_MAGIC:
            return "android_binary_xml"

        # Android compiled resource table (resources.arsc chunks)
        if magic4 == ARSC_MAGIC:
            return "android_resource_table"

        # ART baseline profiles — high entropy (zlib inside) but benign.
        # The format is inert (method reference bitmaps/metadata, not
        # executable code) and some build configs place them at varying paths.
        if magic4 == ART_PROF_MAGIC:
            return "android_art_profile"
        if magic4 == ART_PROFM_MAGIC:
            return "android_art_profile_metadata"

        return None

    def _is_suspicious_resource(
        self, path: str, magika_type: str, entropy: float,
        android_type: str | None,
    ) -> bool:
        """
        Determine if a resource file is suspicious.

        Detection layers:
        1. Allowlisted paths → always benign
        2. Android-specific format override → reclassify Magika mislabels
        3. Image extension vs Magika type mismatch → encrypted blob detection
        4. Magika-confirmed images → benign regardless of entropy
        5. Suspicious type match → flag known-dangerous types
        6. High-entropy unknown blobs → likely encrypted payloads
        """

        # ── Layer 1: Allowlisted paths (hardcoded Android build artifacts) ──
        if path in ALLOWLISTED_PATHS:
            return False

        # ── Layer 2: Android-specific format detection ──────────────────────
        # Override Magika's label for formats it doesn't recognize.
        # All Android-specific formats (AXML, ARSC, ART profiles) are
        # legitimate build artifacts — never suspicious.
        if android_type is not None:
            return False

        # ── Layer 3: Image extension / Magika type mismatch ─────────────────
        # If the file extension claims "image" but Magika's content analysis
        # disagrees, this is a strong signal for an encrypted payload with
        # a fake image extension (e.g., ErrorFather's "rbyypivsnw.png").
        ext = os.path.splitext(path)[1].lower()
        if ext in IMAGE_EXTENSIONS and magika_type not in IMAGE_MAGIKA_TYPES:
            # Exception: Magika might label a valid image as "unknown" if
            # the file is very small (< ~16 bytes). Don't flag tiny files.
            if entropy > 5.0:
                return True

        # ── Layer 4: Magika-confirmed images → benign ───────────────────────
        # Lossy codecs (VP8, JPEG) produce entropy up to ~8.0 by design.
        # If Magika confirms image structure, high entropy is expected.
        if magika_type in IMAGE_MAGIKA_TYPES:
            return False

        # ── Layer 5: Known suspicious file types ────────────────────────────
        if magika_type in SUSPICIOUS_TYPES:
            return True

        # ── Layer 6: High-entropy unrecognized blobs ────────────────────────
        # Files Magika can't identify with high entropy are likely encrypted
        # payloads. Most Android malware packers store encrypted DEX/SO
        # payloads as opaque blobs with random names and no valid magic.
        if magika_type in UNRECOGNIZED_MAGIKA_TYPES and entropy > ENTROPY_HIGH_UNKNOWN:
            return True

        # ── Layer 7: Extreme entropy on any non-image recognized type ───────
        # Catches edge cases where Magika assigns a benign label (e.g.,
        # "xml", "txt") but the entropy is impossibly high for that format.
        if magika_type not in IMAGE_MAGIKA_TYPES and entropy > ENTROPY_EXTREME:
            return True

        return False

    # ─── Extraction pipeline ────────────────────────────────────────────

    def extract(self):
        if not self._is_valid_apk():
            self.log.error(f"Invalid APK for {self.hash.sha256}")
            return None

        try:
            from magika import Magika
            magika = Magika()
        except Exception as e:
            self.log.error(f"Failed to initialize Magika for {self.hash.sha256}: {e}")
            magika = None

        self.resources = []
        self.suspicious_files = []
        scanned = 0

        zf = self._get_zip_file()
        if not zf:
            return None

        with zf:
            for info in zf.infolist():
                if info.is_dir():
                    continue
                if not (info.filename.startswith("res/") or
                        info.filename.startswith("assets/")):
                    continue

                if scanned >= MAX_RESOURCE_FILES:
                    self.log.warning(
                        f"Resource scan limit reached ({MAX_RESOURCE_FILES}), "
                        f"stopping resource enumeration"
                    )
                    break
                scanned += 1

                try:
                    data = zf.read(info.filename)
                except Exception as e:
                    self.log.warning(
                        f"Error reading resource {info.filename}: {e}"
                    )
                    continue

                try:
                    file_sha256 = hashlib.sha256(data).hexdigest()
                    file_entropy = round(self.calculate_entropy(data), 3)

                    # Read first bytes for Android-specific format detection
                    header = data[:16] if len(data) >= 16 else data

                    if magika:
                        try:
                            filetype = magika.identify_bytes(data).output.label
                        except Exception:
                            filetype = "unknown"
                    else:
                        filetype = "unknown"

                    # Identify Android-specific formats once, reuse for
                    # both stored type and suspicion classification
                    android_type = self._identify_android_format(header)
                    stored_type = android_type if android_type else filetype

                    suspicious = self._is_suspicious_resource(
                        path=info.filename,
                        magika_type=filetype,
                        entropy=file_entropy,
                        android_type=android_type,
                    )

                    resource = APKResource(
                        path=info.filename,
                        size=info.file_size,
                        sha256=file_sha256,
                        filetype_magika=stored_type,
                        entropy=file_entropy,
                    )

                    if suspicious:
                        resource.is_suspicious = True
                        self.suspicious_files.append(resource)

                    self.resources.append(resource)
                except Exception as e:
                    self.log.warning(
                        f"Error processing resource {info.filename}: {e}"
                    )
                    continue

        if not self.resources:
            return None

        return {
            "total_resource_count": len(self.resources),
            "total_resource_size": sum(r.size for r in self.resources),
            "suspicious_file_count": len(self.suspicious_files),
            "resources": self.resources,
            "suspicious_files": self.suspicious_files,
        }

    # ─── Export ──────────────────────────────────────────────────────────

    def prepare_export_data(self, exporter_type: str) -> Any:
        if exporter_type == "ClickHouseExporter":
            if not self.resources:
                return None

            current_time = datetime.now(timezone.utc)
            data = []
            for res in self.resources:
                data.append([
                    self.sha256,
                    res.path,
                    res.size,
                    res.sha256,
                    res.filetype_magika,
                    res.entropy,
                    int(res.is_suspicious),
                    current_time,
                ])

            column_names = [
                'sha256', 'resource_path', 'resource_size',
                'resource_sha256', 'resource_magika', 'resource_entropy',
                'is_suspicious', 'analysis_date',
            ]

            column_type_names = [
                'FixedString(64)', 'String', 'UInt64',
                'FixedString(64)', 'LowCardinality(String)', 'Float32',
                'UInt8', "DateTime64(3, 'UTC')",
            ]

            return (data, column_names, column_type_names)

    def get_clickhouse_table(self) -> str:
        return "redb_apk_resources"