arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

超越检测:智能合约的代理攻击合成与模拟

Beyond Detection: Agentic Attack Synthesis and Simulation for Smart Contracts

Xianhao Zhang, Jing Sun, Zijian Zhang, Ye Liu, Zhe Hou, Jiaqi Gao, Yuqiang Sun

arXiv 2607.15673首次发表:更新:

AI 中文总结

研究智能合约漏洞利用验证问题,提出KASS多智能体框架,将自动利用生成分解为多阶段并集成多种机制,在多类智能合约上评估,能成功生成可执行利用及结构化攻击计划,验证效果优于其他工具。

AI 中文摘要

智能合约漏洞带来严重金融风险,现有安全工具多止于漏洞检测,对解释漏洞是否可利用、攻击如何展开及造成何种损害支持有限。为此提出KASS框架用于智能合约漏洞利用验证。它将自动利用生成分解为规划、生成和测试阶段,集成三种互补机制。在104个智能合约上评估,结果显示KASS为94.23%测试合约成功生成可执行利用,高于其他工具。在11个真实世界合约上成功验证9例。KASS还能生成结构化攻击计划。

英文摘要

Smart contract vulnerabilities pose severe financial risks, yet existing security tools largely stop at vulnerability detection, offering limited support for explaining whether reported flaws are exploitable, how attacks unfold, and what concrete damage they cause. To bridge this gap, we propose KASS (Knowledge-Augmented Attack Synthesis and Simulation), a multi-agent framework for executable smart contract exploit verification. KASS decomposes automated exploit generation into planning, generation, and testing stages, and integrates three complementary mechanisms: retrieval-augmented planning over real-world audit knowledge, formal generation and validation constraints that bind attack plans to executable proof-of-concept tests, and a hierarchical dual-loop refinement process that repairs code-level errors while triggering strategy-level replanning when attack assumptions fail. We evaluate KASS on 104 SmartBugs-Curated contracts across four vulnerability categories. Experimental results show that KASS successfully generates executable exploits for 94.23% of tested contracts; this rate is higher than previously reported results for REX and AdvSCanner on comparable SmartBugs-Curated subsets, and higher than our reproduced Claude Code baseline under the same evaluation protocol. On 11 real-world CVE-tagged contracts, KASS successfully validates 9 cases. Beyond exploit generation, KASS produces structured attack plans that document exploitation flows, quantify potential asset losses, and serve as semantic false positive filters for static analysis tools.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑