AI 中文总结
研究以太坊NFT智能合约漏洞检测,结合漏洞聚焦代码切片、ERC-721知识库及受限DeepSeek分析,正则表达式定位候选语句,提取代码切片分析,结果显示聚焦代码上下文和领域约束影响检测器输出,提升阳性标签率。
AI 中文摘要
以太坊非同质化代币(NFT)通过智能合约实现所有权、转移、授权和元数据操作,这使得合约漏洞成为数字资产的直接风险。现有静态分析器提供基于规则的高效筛选,但难以处理特定应用逻辑,而无约束的大语言模型分析可能会被无关代码干扰或产生不一致输出。我们提出一种漏洞检测方法,结合以漏洞为重点的代码切片、面向ERC-721的知识库和受限的DeepSeek分析。正则表达式模式定位重入、整数溢出或下溢以及时间戳依赖的候选语句,结构感知上下文窗口算法提取带行号的代码切片。DeepSeek使用明确的决策规则和固定输出模式分析每个切片,结果记录支持自动批处理。在450个NFT合约样本上,完整配置产生437个阳性标签,报告的阳性标签率为97.1%。去除外部知识库后,该率降至87.11%,而在没有知识库的情况下分析完整合约则降至73.78%。这些结果表明,聚焦的代码上下文和领域约束对检测器报告的输出有重大影响。
英文摘要
Ethereum non-fungible tokens (NFTs) implement ownership, transfer, authorization, and metadata operations through smart contracts, making contract vulnerabilities a direct risk to digital assets. Existing static analyzers provide efficient rule-based screening but can struggle with application-specific logic, whereas unconstrained large language model analysis may be distracted by irrelevant code or produce inconsistent outputs. We present a vulnerability-detection method that combines vulnerability-focused code slicing, an ERC-721-oriented knowledge base, and constrained DeepSeek analysis. Regular-expression patterns locate candidate statements for reentrancy, integer overflow or underflow, and timestamp dependence. A structure-aware context-window algorithm then extracts line-numbered code slices. DeepSeek analyzes each slice using explicit decision rules and a fixed output schema, and the resulting records support automated batch processing. On 450 NFT contract samples, the full configuration produced 437 positive labels, corresponding to a reported positive-label rate of 97.1%. Removing the external knowledge base reduced this rate to 87.11%, while analyzing complete contracts without the knowledge base reduced it to 73.78%. These results indicate that focused code context and domain constraints materially affect the detector's reported output.