AI 中文总结
研究针对DeFi安全风险检测覆盖有限的问题,提出DeFiScreener框架,通过构建函数调用树、利用大语言模型生成语义嵌入,经两级筛选识别潜在易受攻击的函数和调用序列,实验证明该框架在攻击预筛选中有高召回率和精确率。
AI 中文摘要
区块链及其杀手级应用,特别是去中心化金融(DeFi),正得到广泛采用,截至2026年1月,已有超过5200个DeFi项目部署在主流区块链上。与此同时,DeFi中的安全风险日益严重。现有DeFi检测工具通常仅涵盖特定攻击类型,检测覆盖范围极为有限。本文提出通过从大量智能合约函数和调用序列中预筛选易受攻击的实例来解决这一差距,这是受“危险时间不对称”现象启发。为此提出了DeFiScreener,首个使用历史攻击案例识别潜在易受攻击函数和调用序列的自动化预筛选框架。它构建函数调用树(FCTs),利用大语言模型生成函数语义嵌入,然后进行两级筛选:在函数级别将函数嵌入与历史攻击函数的攻击模式库匹配,在序列级别应用面向攻击模式的蒙特卡洛树搜索(APO-MCTS)筛选易受攻击的调用序列,最后将识别出的候选者传递给大语言模型进行进一步分析。通过对包含207个真实DeFi攻击事件的数据集进行实证评估,结果表明DeFiScreener在攻击预筛选中召回率达98.55%,精确率达84.30%。
英文摘要
Blockchain and its killer applications, particularly decentralized finance (DeFi), are gaining widespread adoption, with over 5,200 DeFi projects deployed on mainstream blockchains as of January 2026. At the same time, security risks in DeFi are becoming increasingly serious. However, existing DeFi detection tools usually cover only specific attack types, exhibiting severely limited detection coverage. In this paper, we argue that an effective way to address this gap is to pre-screen vulnerable instances from large volumes of smart contract functions and call sequences. This is motivated by a key phenomenon we term "perilous temporal asymmetry". Inspired by this, we propose DeFiScreener, the first automated pre-screening framework for DeFi attacks that uses historical exploit cases to identify potentially vulnerable functions and call sequences. Given the full source code of a target project, DeFiScreener builds Function Call Trees (FCTs) and generates semantic embeddings for each function using a large language model (LLM), allowing both program structure and function intent to be analyzed together. It then applies a dual-level screening process. At the function level, function embeddings are matched against an Attack Pattern Library of historically exploited functions. At the sequence level, the proposed Attack Pattern Oriented Monte Carlo Tree Search (APO-MCTS) efficiently explores the FCTs and screens vulnerable call sequences. The identified candidates are ultimately passed to an LLM for further interpretive and security analysis. We empirically evaluate the DeFiScreener over datasets comprising 207 real-world DeFi attack incidents. Experimental results demonstrate that DeFiScreener achieves a remarkable 98.55% recall and 84.30% precision in attack pre-screening.