🤖 AI Summary
This work addresses the vulnerability of smart contracts to diverse security threats stemming from their immutability and the limited generalizability and automation of existing detection approaches. To overcome these limitations, the authors propose a tailored vulnerability detection framework leveraging large language models (LLMs), which incorporates vulnerability-specific prompting strategies for thirteen common vulnerability types. The framework integrates abstract syntax tree (AST) context extraction and is trained on a large-scale, real-world annotated dataset, thereby circumventing the constraints of traditional rule-based methods. Experimental results demonstrate that the proposed approach achieves an average true positive recall of 0.92 and a true negative recall of 0.85 across all thirteen vulnerability categories, significantly enhancing both detection accuracy and scalability.
📝 Abstract
Smart contracts on blockchains are prone to diverse security vulnerabilities that can lead to significant financial losses due to their immutable nature. Existing detection approaches often lack flexibility across vulnerability types and rely heavily on manually crafted expert rules. In this paper, we present an LLM-based framework for practical smart contract vulnerability detection. We construct and release a large-scale dataset comprising 31,165 professionally annotated vulnerability instances collected from over 3,200 real-world projects across 15 major blockchain platforms. Our approach leverages precise AST-based context extraction and vulnerability-specific prompt design to instantiate customized detectors for 13 prevalent vulnerability categories. Experimental results demonstrate strong effectiveness, achieving an average positive recall of 0.92 and an average negative recall of 0.85, highlighting the potential of carefully engineered contextual prompting for scalable and high-precision smart contract security analysis.