AI 中文总结
针对智能合约修复中线性推理导致的错误累积问题,提出思维树框架,结合文档解析、静态分析与Tree of Thoughts推理,在50个真实漏洞上测试,性能优于ContractTinker。
AI 中文摘要
智能合约为去中心化金融(DeFi)、非同质化代币(NFT)等区块链应用提供支持,但一旦部署便无法修改,哪怕是微小的漏洞也可能造成重大经济损失。当前基于人工智能的修复方法依赖线性推理,会导致错误累积,生成的补丁不可靠。本文提出的方法结合了文档解析、静态分析与思维树(Tree of Thoughts)推理:首先将审计报告转换为结构化数据,再使用Slither定位确切的易受攻击代码;该三步框架可同时探索多条修复路径、评估选项并排除不佳选择,最后通过编译和人工检查验证补丁。我们在Code4Rena的50个真实漏洞上测试了该方法,其单次成功率达62%、前3名成功率达84%,分别比ContractTinker高出12和6个百分点;同时将完全有效补丁的比例提升至44%,将有缺陷补丁从38%降至22%,无效补丁从10%降至4%。该方法克服了线性推理的局限,使智能合约修复更准确、实用。
英文摘要
Smart contracts power blockchain applications such as DeFi and NFTs. However, once deployed, they cannot be modified. Even minor bugs can result in significant financial losses. Current AI-based repair methods rely on linear reasoning, which leads to the accumulation of errors and unreliable patches. Our method combines document parsing, static analysis, and Tree of Thoughts reasoning. We first convert audit reports into structured data. Then we use Slither to locate the exact vulnerable code. Our three-step framework explores multiple repair paths simultaneously, evaluates options, and eliminates poor choices. Finally, we verify patches through compilation and manual checks. We test our method on 50 real vulnerabilities from Code4Rena. Our method achieves a 62% single success rate and an 84% top-3 success rate, outperforming ContractTinker by 12 and 6 percentage points, respectively. We also increase the proportion of fully effective patches to 44%, while reducing defective patches from 38% to 22% and invalid patches from 10% to 4%. This approach overcomes the limitations of linear reasoning and makes smart contract repair more accurate and practical.