arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.13004cs.CR

IntentFuzz:一种面向意图型跨链桥的协议感知模糊测试器,用于自动检测不变量违反

IntentFuzz: A Protocol-Aware Fuzzer for Automated Invariant Violation Detection in Intent-Based Cross-Chain Bridges

André Augusto, Christof Ferreira Torres, André Vasconcelos, Miguel Correia

首次发表
浏览论文内容

中文总结 AI 辅助

针对意图型跨链桥,提出协议感知模糊测试器IntentFuzz,自动恢复意图结构并合成多步序列,检测不变量违反,在真实部署中确认22个漏洞。

中文摘要 AI 辅助

跨链桥在不同区块链之间转移价值。意图型桥是其中一种变体,由求解器(solver)完成用户声明的结果,链下结算层(settlement layer)随后将完成情况与存款进行对账。现有的智能合约模糊测试器和静态分析器只能标记已知的坏代码模式,或需要针对特定协议手工编写的断言。本工作形式化了一个分类体系,将不变量违反(合约必须在本地强制执行的安全属性)与合法委托给链下结算层的结算风险区分开来,并提出了IntentFuzz:一种协议感知的模糊测试器,它直接从无注释的Solidity源码中恢复桥的意图结构和存款/完成函数角色,然后使用基于LLM的回退机制合成多步模糊测试序列,以帮助构建调用参数。IntentFuzz在9/9个基准协议中恢复了正确的意图结构,并以100%的召回率和82%的综合精确率对存款和完成函数进行分类;在77个手动标注合约的语料库中,它达到了79.5%的桥分类精确率和97.2%的召回率,在已确认的桥中,结构选择达到88.6%的精确率和召回率,而存款和完成分类各达到100%的召回率。在23个植入错误的突变体上,IntentFuzz达到了100%的召回率和100%的精确率,执行了273个模板(每个模板中位数为14毫秒,共507笔交易)。在24个真实部署中,它在仅启发式输入生成下确认了17个真实的不变量违反,启用其LLM辅助层后上升到22个,跨越8个易受攻击的GitHub仓库,每个发现都可针对公开部署的字节码复现。

英文摘要

Cross-chain bridges move value between blockchains. Intent-based bridges are a variant where a solver fulfills a user's declared outcome and an off-chain settlement layer later reconciles the fill against the deposit. Existing smart-contract fuzzers and static analyzers only flag known-bad code patterns or require protocol-specific hand-written assertions. This work formalizes a taxonomy separating invariant violations, safety properties a contract must enforce locally, from settlement exposures legitimately delegated to the off-chain settlement layer, and proposes IntentFuzz: a protocol-aware fuzzer that recovers a bridge's intent structure and deposit/fill function roles directly from unannotated Solidity source, then synthesizes multi-step fuzz sequences using an LLM-based fallback to help build call arguments. IntentFuzz recovers the correct intent structure in 9/9 benchmark protocols and classifies deposit and fill functions with 100% recall and 82% combined precision; across a corpus of 77 manually labeled contracts, it reaches 79.5% bridge-classification precision and 97.2% recall, and among confirmed bridges, struct selection reaches 88.6% precision and recall while deposit and fill classification each reach 100% recall. On 23 planted-bug mutants, IntentFuzz attains 100% recall and 100% precision, executing 273 templates (507 transactions in a median of 14ms per template). Across 24 real-world deployments, it confirms 17 genuine invariant violations under heuristic-only input generation, rising to 22 with its LLM-assisted tier enabled, spanning eight vulnerable GitHub repositories, each finding reproducible against public, deployed bytecode.

发表机构

  • INESC-ID & IST, University of Lisbon(里斯本大学信息与通信系统研究所及理工学院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑