AI 中文总结
研究智能合约因业务路径关系不一致产生的漏洞,提出手性分析,将配对路径视为隐式规范,形式化关系并推导义务。通过ChiralDetector实现,经初步评估能减少候选对、产生去重结果,揭示难用单功能规则表达的漏洞类并控制成本与精度。
AI 中文摘要
智能合约漏洞常源于业务路径间的不一致,如单批入口点、直接与基于适配器的流程等。现有分析器对局部语法和数据流模式有效,但对关系型漏洞支持有限。本文引入手性分析,将配对业务路径视为相互的隐式规范。形式化手性关系为变质关系的静态类似物,推导相关义务,违反且有安全影响时报告漏洞。在ChiralDetector中实现,提取业务路径,用静态事实排序候选对,应用基于大语言模型的语义过滤和检测,验证并去重结果。在Phi协议的初步评估中,减少候选对,产生去重结果组,保留严格验证器确定的有效独特问题,结果表明手性分析可揭示难以用单功能规则表达的业务逻辑漏洞类,还能控制大语言模型成本和验证器精度。
英文摘要
Smart-contract vulnerabilities often arise from inconsistencies between business paths that should correspond to one another, such as single and batch entry points, direct and adapter-based flows, quote and execution paths, or inverse operations such as buy and sell. Existing analyzers are effective for many local syntactic and data-flow patterns, but they provide limited support for bugs whose oracle is relational: whether two semantically paired paths preserve compatible guards, state transitions, value flows, and failure behavior. This paper introduces chiral analysis, a relational model that treats paired business paths as implicit specifications for each other. We formalize chiral relations as static analogues of metamorphic relations, derive obligations over guards, actors, state, value, ordering, failure behavior, and external interactions, and report a vulnerability when a violated obligation has security impact. We implement this idea in ChiralDetector, a Solidity prototype that extracts business paths, ranks candidate pairs with static facts, applies LLM-based semantic filtering and detection, and validates and deduplicates findings. In a preliminary evaluation on the Phi protocol, ChiralDetector reduced 3,217 statically ranked path pairs to 1,643 semantic candidates, produced 101 deduplicated finding groups, and retained 44 strict-validator positives that manually collapsed to 13 effective unique issues. These include cross-art Merkle proof reuse, fee unit mismatches, public state-tracking helpers, and refund propagation gaps. The results suggest that chiral analysis can expose business-logic bug classes that are difficult to express as single-function rules while providing a structured way to control LLM cost and validator precision.