arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ContractLens:用于恶意智能合约检测的潜在安全知识

ContractLens: Latent Security Knowledge for Malicious Smart Contract Detection

Shuyi Miao, Xinyi Huang, Wangjie Qiu, Fei Shen, Jinchun He, Zhiming Zheng, Tat-Seng Chua

arXiv 2610.04992首次发表:更新:

发表机构

Beihang University; Beijing University of Posts and Telecommunications; National University of Singapore(北京航空航天大学; 北京邮电大学; 新加坡国立大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

ContractLens通过定位预训练大模型中的潜在安全知识,利用线性探针与三因素重要性评分选出关键神经元,实现可解释且高精度的恶意智能合约检测。

AI 中文摘要

检测恶意智能合约对于保障Web3.0生态系统的安全至关重要。然而,现有的基于大型语言模型(LLM)的审计方法在很大程度上依赖于提示工程或针对特定攻击的微调,而支撑恶意逻辑检测的内部表示仍缺乏清晰的刻画。为弥补这一空白,我们提出了ContractLens,一个在预训练LLM中定位并利用潜在安全知识以实现可解释的恶意智能合约检测的框架。具体而言,我们首先使用逐层线性探针来识别能够区分恶意合约与良性合约的候选层,然后根据这些层对恶意逻辑移除的敏感性以及在行为保持的表面修改下的稳定性来选择关键层。接下来,在这些关键层内,我们将激活对比、恶意逻辑特异性以及探针权重结合为一个三因素重要性评分,并利用排序评分曲线的拐点自适应地选择恶意合约判别单元(MCDU)。最后,我们将所选单元的激活拼接成一个紧凑表示,并训练一个轻量级分类器进行检测,整个过程保持预训练模型冻结。神经元掩蔽实验表明,掩蔽MCDU导致的检测性能下降幅度大于掩蔽随机选择的神经元或按激活幅度匹配的神经元。ContractLens在所有三个预训练模型上的平均检测准确率均高于所评估的方法。进一步的评估展示了其对未见恶意意图的泛化能力,并表明在固定所识别的MCDU的情况下,仅使用少量标注样本训练的分类器仍能实现较强的检测性能。

英文摘要

Detecting malicious smart contracts is essential to safeguarding the Web3.0 ecosystem. However, existing auditing methods based on large language models (LLMs) largely rely on prompt engineering or attack-specific fine-tuning, while the internal representations that support malicious logic detection remain poorly characterized. To address this gap, we propose ContractLens, a framework that localizes and uses latent security knowledge in pretrained LLMs for interpretable malicious smart contract detection. Specifically, we first use layerwise linear probes to identify candidate layers that distinguish malicious from benign contracts, then select critical layers based on their sensitivity to malicious logic removal and stability under behaviour-preserving surface modifications. Next, within these critical layers, we combine activation contrast, malicious-logic specificity, and probe weights into a tri-factor importance score and adaptively select malicious contract-discriminative units (MCDUs) using the knee point of the ranked score curve. Finally, we concatenate the selected units' activations into a compact representation and train a lightweight classifier for detection, keeping the pretrained model frozen throughout. Neuron masking experiments show that masking MCDUs causes larger drops in detection performance than masking randomly selected neurons or neurons matched in activation magnitude. ContractLens achieves higher average detection accuracy than the evaluated methods on all three pretrained models. Further evaluations demonstrate generalization to unseen malicious intents and show that, with the identified MCDUs fixed, a classifier trained on few labelled samples can still achieve strong detection performance.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑