Solidity 遇上 LLM:一种基于 Transformer 的智能合约漏洞检测方法
Solidity Meets LLMs: A Transformer-Based Approach to Smart Contract Vulnerability Detection
浏览论文内容
中文总结 AI 辅助
本文提出基于 Transformer 的智能合约漏洞检测方法,利用预训练 LLM 微调 BERT 模型,在 Solidity 代码片段上实现 92% 的 F1 分数,有效增强合约安全性。
中文摘要 AI 辅助
区块链技术的日益普及,特别是以太坊平台,凸显了智能合约在去中心化应用中的关键作用。然而,这些合约日益增长的复杂性和财务价值使其成为网络攻击的主要目标。在这项工作中,我们提出了一种基于 Transformer 的方法,用于检测以 Solidity 编写的智能合约片段中的漏洞。利用预训练大型语言模型(LLM)的表示能力,我们构建了一个稳健的流水线,包括定义真实数据集,将代码片段标记为易受攻击或安全。然后,我们在此数据集上微调一个基于 BERT 的架构,使模型能够捕获 Solidity 代码特有的句法和语义模式。我们微调后的模型表现出强大的性能,F1 分数达到 92%,凸显了 LLM 适配在通过深度上下文理解增强智能合约安全性方面的有效性。
英文摘要
The growing adoption of blockchain technologies, particularly the Ethereum platform, has amplified the critical role of smart contracts in decentralized applications. However, the increasing complexity and financial value of these contracts make them prime targets for cyber attacks. In this work, we present a transformer-based approach for the detection of vulnerabilities in smart contract fragments written in Solidity. Leveraging the representational power of pre-trained Large Language Models (LLMs), we construct a robust pipeline that includes the definition of a ground truth dataset, labeling code fragments as vulnerable or safe. We then fine-tune a BERT-based architecture on this dataset, enabling the model to capture the syntactic and semantic patterns specific to Solidity code. Our fine-tuned model demonstrates strong performance, achieving an F1 score of 92%, and highlighting the effectiveness of LLM adaptation in enhancing smart contract security through deep contextual understanding.
发表机构
- University of Oum El Bouaghi(乌姆布阿格大学)
- Laval University(拉瓦尔大学)
机构由 AI 辅助整理,请以论文原文为准。