PSCVFinder: A Prompt-Tuning Based Framework for Smart Contract Vulnerability Detection

计算机科学 脆弱性(计算) 利用 智能合约 依赖关系(UML) 程序切片 计算机安全 适应性 编码(集合论) 脆弱性评估 基线(sea) 人工智能 程序设计语言 软件 心理学 生态学 海洋学 集合(抽象数据类型) 心理弹性 块链 心理治疗师 生物 地质学
作者
Lei Yu,Junyi Lu,Xianglong Liu,Yang Li,Fengjun Zhang,Jiajia Ma
标识
DOI:10.1109/issre59848.2023.00030
摘要

With the increasing security issues in the blockchain, smart contract vulnerability detection has gradually become the focus of research. Recently, many approaches have been proposed to detect smart contract vulnerabilities. Despite promising results, these approaches still have three drawbacks: 1) Symbolic execution and static analysis methods are constrained by predefined rules, which limits their adaptability to different vulnerabilities. 2) Most smart contract code contains abundant irrelevant information which is useless for vulnerability detection. 3) Pre-trained models fail to bridge the gap between pre-training and detecting smart contract vulnerabilities.To solve these problems, we propose an approach named PSCVFinder for detecting reentrancy vulnerability and times-tamp dependency vulnerability, which are two severe vulnerabilities in smart contract. To better detect these vulnerabilities, we propose CSCV which is a smart contract slicing method to reduce the irrelevant code. Unlike existing approaches, our model first learns the representation of programming language through the pre-training model, then fully exploits the capacity of large language model with prompt-tuning to precisely detect smart contract vulnerability. We conduct experiments on real-world dataset and the results reflect that PSCVFinder scores 93.83% and 93.49% on two kinds of vulnerabilities in F1-score, surpassing the state-of-the-art baseline by 1.14% and 4.02%, respectively.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
刚刚
刚刚
彭于晏应助上善若水采纳,获得10
1秒前
1秒前
善学以致用应助学术脑袋采纳,获得10
1秒前
yar完成签到 ,获得积分10
2秒前
3秒前
3秒前
Johnny完成签到,获得积分10
4秒前
可爱的函函应助阿方采纳,获得10
4秒前
认真沅完成签到,获得积分10
5秒前
Ava应助Redde采纳,获得10
6秒前
秃然发布了新的文献求助10
6秒前
7秒前
花薇Liv完成签到 ,获得积分10
7秒前
7秒前
7秒前
7秒前
所所应助小龙虾仙女采纳,获得10
8秒前
静静在学呢完成签到,获得积分10
9秒前
dxk发布了新的文献求助10
10秒前
在水一方应助科研采纳,获得10
11秒前
天才幸运鱼完成签到,获得积分10
12秒前
goodgoodstudy发布了新的文献求助10
12秒前
sqq发布了新的文献求助10
12秒前
受伤书文发布了新的文献求助10
13秒前
13秒前
英俊的铭应助西西采纳,获得10
14秒前
666发布了新的文献求助10
15秒前
正直的小馒头完成签到,获得积分10
15秒前
wAnDou完成签到,获得积分10
16秒前
16秒前
学术脑袋发布了新的文献求助10
17秒前
wxgggg发布了新的文献求助10
21秒前
22秒前
23秒前
23秒前
PeterLin完成签到,获得积分10
25秒前
26秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
PowerCascade: A Synthetic Dataset for Cascading Failure Analysis in Power Systems 2000
Picture this! Including first nations fiction picture books in school library collections 1000
Signals, Systems, and Signal Processing 610
Unlocking Chemical Thinking: Reimagining Chemistry Teaching and Learning 555
Photodetectors: From Ultraviolet to Infrared 500
信任代码:AI 时代的传播重构 450
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6357722
求助须知:如何正确求助?哪些是违规求助? 8172278
关于积分的说明 17207451
捐赠科研通 5413235
什么是DOI,文献DOI怎么找? 2864968
邀请新用户注册赠送积分活动 1842489
关于科研通互助平台的介绍 1690595