发表机构
Università degli Studi di Napoli Federico II; Gran Sasso Science Institute (GSSI); University of Coimbra; College of Computing and Informatics, University of North Carolina at Charlotte(那不勒斯费德里科二世大学; 格兰萨索科学研究所; 科英布拉大学; 北卡罗来纳大学夏洛特分校计算与信息学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究针对智能合约漏洞检测数据集稀缺问题,提出用大语言模型自动注入漏洞的方法,生成32个有效漏洞合约,评估了静态分析器并验证了该方法的可行性与局限性。
AI 中文摘要
评估智能合约漏洞检测工具需要带有已知真实值的数据集,但此类数据集稀缺且难以手动构建。我们提出一种使用大语言模型(Large Language Models, LLMs)自动向Solidity智能合约注入漏洞的方法,并在针对OpenSCV的49种漏洞类型的案例研究中进行了验证。注入的合约通过多步骤流程进行验证,该流程检查编译、执行、业务逻辑以及预期漏洞的存在。将该方法应用于SmartBugs的真实合约,LLMs生成了近1000个候选变体;去重和验证后,共有32个确认存在漏洞的合约(涵盖25种漏洞类型)通过验证,存活率为16.58%。存活的合约集中在结构更简单的目标以及具有局部句法模式的漏洞类型中。我们报告了实际挑战,包括LLMs的非确定性以及保留合约语义的难度。随后,我们使用经过验证的合约评估了三个静态分析器,揭示了它们互补且不完整的覆盖范围特征。结果表明,基于LLM的漏洞注入是可行的,同时也暴露出其在可扩展性和多样性方面的关键限制。
英文摘要
Assessing vulnerability detection tools for smart contracts requires datasets with known ground truth, yet such datasets are scarce and difficult to build by hand. We propose an approach that uses Large Language Models (LLMs) to automatically inject vulnerabilities into Solidity smart contracts, and demonstrate it in a case study targeting 49 vulnerability types from OpenSCV. Injected contracts are validated through a multi-step pipeline checking compilation, execution, business logic, and the presence of the intended vulnerability. Applied to real-world contracts from SmartBugs, LLMs generate nearly 1,000 candidate variants; after deduplication and validation, 32 confirmed vulnerable contracts spanning 25 vulnerability types survive (a 16.58% survival rate). Surviving contracts concentrate in structurally simpler targets and vulnerability types with localized syntactic patterns. We report practical challenges including LLMs' non-determinism and the difficulty of preserving contract semantics. We then use the validated contracts to assess three static analyzers, revealing complementary and incomplete coverage profiles. Results show that LLM-based vulnerability injection is feasible, while exposing key limitations in scalability and diversity.