发表机构
Tsinghua University; Beihang University; Beijing Normal University; Zhejiang Gongshang University; GoPlus Security; University of Oxford; East China Normal University(清华大学; 北京航空航天大学; 北京师范大学; 浙江工商大学; GoPlus安全; 牛津大学; 华东师范大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
EchoFuzz利用大型语言模型生成漏洞函数调用序列并迭代引导模糊测试,提升智能合约漏洞检测效率与覆盖率,实验显示分支覆盖率提高29%,漏洞检测增加62%。
AI 中文摘要
智能合约作为去中心化应用的基石,自主管理着数万亿美元的数字资产,因此成为攻击者的诱人目标。模糊测试已成为检测智能合约漏洞的一种有前景的技术,然而现有方法面临两大挑战。(1)状态转换中的逻辑缺口和组合冗余阻碍了在漏洞检测效率与状态空间探索成本之间进行有效权衡,导致关键执行路径被忽视。(2)基于规则的序列变异策略存在路径冗余和合约逻辑指导不足的问题,造成性能瓶颈,阻碍了面向深度漏洞路径的探索。为应对这些挑战,我们提出了EchoFuzz,一个由LLM引导的模糊测试框架,引入了漏洞函数调用序列(VFCS)——通过关键状态转换暴露漏洞的最小、行为保持的执行路径。EchoFuzz包含两个关键流程。首先,我们开发了一种链式引导的LLM方法,将静态分析与逻辑理解相结合,生成合约特定的VFCS候选,以消除组合冗余。其次,我们采用迭代模糊测试策略,利用具有实时反馈的LLM自适应地将模糊器引向未覆盖的分支。实验表明,EchoFuzz优于最先进的方法,实现了29%更高的分支覆盖率,并检测到62%更多的漏洞。它还在真实合约中发现了37个先前未知的漏洞,展示了强大的实用性。
英文摘要
Smart contracts, serving as the cornerstone of decentralized applications, autonomously manage trillion-dollar digital assets, making them attractive targets for attacks. Fuzzing has emerged as a promising technique for detecting vulnerabilities in smart contracts, yet existing methods face two main challenges. (1) The logical gap in state transitions and combinatorial redundancy hinders effective tradeoffs between bug detection efficiency and state space exploration cost, leading to critical execution paths to be overlooked. (2) Rule-based sequence mutation strategies suffer from path redundancy and inadequate guidance from contract logic, resulting in performance bottlenecks that stall the exploration of in-depth vulnerability-oriented paths. To tackle these challenges, we propose EchoFuzz, an LLM-guided fuzzing framework introducing Vulnerable Function Call Sequences (VFCS) - minimal, behavior-preserving execution paths that expose bugs through key state transitions. EchoFuzz consists of two key procedures. First, we develop a chain-guided LLM approach, that combines static analysis with logical understanding to generate contract-specific VFCS candidates that eliminate combinatorial redundancy. Second, we adopt an iterative fuzzing strategy that uses LLMs with real-time feedback to adaptively steer fuzzer toward uncovered branches. Experiments show EchoFuzz outperforms state-of-the-art methods, achieving 29\% higher branch coverage and detecting 62\% more vulnerabilities. It also found 37 previously unknown vulnerabilities in real contracts, showing strong practicality.
CommentsAccepted by ICSE'2026