arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

当已验证源码成为攻击输入:防御智能合约免受基于大语言模型(LLM)的漏洞扫描

When Verified Source Becomes Attack Input: Defending Smart Contracts Against LLM-Based Vulnerability Scanning

Mingyuan Huang, Zimo Ji, Yifan Mo, Shuai Wang

arXiv 2608.28400首次发表:更新:

AI 中文总结

本文提出DeLLMGuard框架,通过分离源码与运行时执行并验证相关信息,在保留公开源码披露和授权审计的同时,降低LLM智能体对智能合约漏洞扫描的准确性,防御恶意扫描。

AI 中文摘要

智能合约是部署在区块链上用于管理数字资产的金融程序。为了建立用户和投资者的信任,智能合约项目通常会在区块链浏览器上发布其源码,并将其与部署后的字节码进行验证,使得链上程序可通过人类可读的实现形式访问。然而,大语言模型(LLM)智能体正在改变这种披露机制的威胁模型。通过利用公开披露的源码,近期的智能体工作流使得大规模扫描合约漏洞以实施攻击变得愈发可行。在本文中,我们提出DeLLMGuard,这是一种智能合约部署框架,可在保留公开源码披露和授权审计的同时,防御基于LLM的恶意漏洞扫描。DeLLMGuard可在真实区块链环境中通过多个合约地址将披露的源码与运行时执行分离,因此LLM智能体在进行漏洞分析前必须先恢复额外的代理(proxy)、委托(delegate)和工厂(factory)关系。内置的验证层会检查部署关系、运行时字节码、源码和状态变化,以确保转换过程保留原始业务实现。我们在源自SCONE-bench的环境中,使用三个LLM智能体对387个真实存在漏洞的合约评估DeLLMGuard。DeLLMGuard将整体根本原因正确性从23.5%降至6.6%,且在主要非代理合约集上优于闭源字节码基线。追踪和消融分析进一步显示,智能体常能恢复下游合约,但仍无法识别漏洞,这表明跨合约恢复仍是自动化LLM扫描面临的主要挑战。

英文摘要

Smart contracts are financial programs deployed on blockchains to manage digital assets. To build trust with users and investors, smart contract projects typically publish their source code on blockchain explorers and verify it against the deployed bytecode, making the on-chain program accessible through a human-readable implementation. However, LLM agents are changing the threat model of this disclosure mechanism. By leveraging publicly disclosed source code, recent agent workflows make it increasingly practical to scan contract vulnerabilities for exploits at large scale. In this paper, we propose DeLLMGuard, a smart contract deployment framework that defends against malicious LLM-based vulnerability scanning while preserving public source disclosure and authorized auditing. DeLLMGuard can separate disclosed source code from runtime execution through multiple contract addresses in a real-world blockchain environment. LLM agents must therefore recover additional proxy, delegate, and factory relations before vulnerability analysis. A built-in Verification Layer checks deployment relations, runtime bytecode, source code, and state changes to ensure that the transformation preserves the original business implementation. We evaluate DeLLMGuard on 387 real-world vulnerable contracts with three LLM agents in an environment derived from SCONE-bench. DeLLMGuard reduces overall root-cause correctness from 23.5% to 6.6% and outperforms the closed-source bytecode baseline on the primary non-proxy set. Trace and ablation analyses further show that agents often recover downstream contracts but still fail to identify the vulnerability, indicating that cross-contract recovery remains a major challenge for automated LLM scanning.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑