arXiv:2411.19234cs.CRcs.AI2024-11被引 18

用大模型提升智能合约漏洞检测效率,自动集成新规则。

SmartLLMSentry: A Comprehensive LLM Based Smart Contract Vulnerability Detection Framework

  • 用ChatGPT+上下文学习实现漏洞规则自动生成
  • 在五类漏洞上达到91.1%的精准匹配准确率
  • 适合区块链安全研究者和智能合约开发者

智能合约是区块链网络中管理数字资产的核心,亟需高效的安全保障。本文提出SmartLLMSentry框架,利用大语言模型(如ChatGPT)进行上下文学习,推动智能合约漏洞检测。传统基于规则的框架在整合新规则时效率低下,而SmartLLMSentry通过大模型实现规则生成与集成的自动化。我们构建了一个包含五类随机选取漏洞的专用数据集用于模型训练与评估。实验显示,在充足数据条件下,该框架达到91.1%的精确匹配准确率;但相较GPT-3,GPT-4在规则生成方面表现下降。研究表明,该框架显著提升了漏洞检测的速度与精度,为区块链安全提供了新路径,有效应对此前未充分探索的智能合约漏洞问题。

原文摘要 · Abstract (English)

Smart contracts are essential for managing digital assets in blockchain networks, highlighting the need for effective security measures. This paper introduces SmartLLMSentry, a novel framework that leverages large language models (LLMs), specifically ChatGPT with in-context training, to advance smart contract vulnerability detection. Traditional rule-based frameworks have limitations in integrating new detection rules efficiently. In contrast, SmartLLMSentry utilizes LLMs to streamline this process. We created a specialized dataset of five randomly selected vulnerabilities for model training and evaluation. Our results show an exact match accuracy of 91.1% with sufficient data, although GPT-4 demonstrated reduced performance compared to GPT-3 in rule generation. This study illustrates that SmartLLMSentry significantly enhances the speed and accuracy of vulnerability detection through LLMdriven rule integration, offering a new approach to improving Blockchain security and addressing previously underexplored vulnerabilities in smart contracts.

智能合约漏洞检测大模型应用区块链安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。