Sep 2026· ACM Transactions on Software Engineering and Methodology· 0 citations· 8 references
TL;DR
A unified framework combining a novel Hierarchical Cross-Attention Subgraph Neural Network for detection with Large Language Models for explanation form a comprehensive framework that significantly enhances both the technical accuracy and operational usability of smart contract analysis.
Abstract
Smart contracts enable decentralized applications, yet their immutability makes security vulnerabilities catastrophic, often leading to irrecoverable financial losses and systemic risks. Existing machine learning approaches typically operate at the coarse contract level, failing to localize issues to specific functions or provide interpretable remediation guidance for developers. To address these persistent limitations, we introduce a unified framework combining a novel Hierarchical Cross-Attention Subgraph Neural Network (HCA-SGNN) for detection with Large Language Models (LLMs) for explanation. For detection, HCA-SGNN processes functions as subgraphs, explicitly modeling control- and data-flow dependencies while capturing cross-function interactions to pinpoint localized risks. To enable robust training, we develop an AST-driven injection system that generates stealthy, context-aware vulnerabilities through template-based synthesis. Uniquely, this system ensures collision-free variable naming and version-specific compatibility, producing a comprehensive, function-level annotated dataset covering diverse classes such as reentrancy, integer overflows, and access control flaws. Complementing detection, we generate structured, human-readable justifications using synthetic data and chain-of-thought prompting. These explanations detail the vulnerability type, affected area, root cause, and actionable mitigation strategies, effectively bridging the gap between automated detection and practical insight. Together, these components form a comprehensive framework that significantly enhances both the technical accuracy and operational usability of smart contract analysis.
Results indicate that integrating semantic richness and structural awareness within a Contextual Encoding Network architecture enhances both detection reliability and generalization capability, making the framework suitable for practical smart contract security analysis.
R. S, Mahantesh Mathapati· Journal of Artificial Intell...· 0 citations
Detecting vulnerabilities in software development is crucial yet challenging. Deep learning-based approaches have shown promise in automatically learning features for vulnerable function detection. In practice, human analysts need to correlate the behavioral logic of multiple functions to confirm the occurrence of vuln...
Hong-Jun Huang, Fu-Tai Zou, Jia-Ping Gui et al.· ACM Transactions on Software...· 0 citations
The growing adoption of blockchain technologies, particularly the Ethereum platform, has amplified the critical role of smart contracts in decentralized applications. However, the increasing complexity and financial value of these contracts make them prime targets for cyber attacks. In this work, we present a transform...
Djamel Eddine Hakim Ghorab, Farid Mokhati, Mostafa Anouar Ghorab· International Joint Conferen...· 0 citations
Large Language Models (LLMs) are increasingly being deployed for smart contract security, yet a fundamental question remains unresolved for practitioners: when confronted with the realistic, multi-label setting where a single contract may harbor several concurrent vulnerabilities, which deployment strategy is more effe...
Badaruddin Chachar, J. Ferreira, M. Cavazza et al.· IEEE Access· 0 citations
A failure analysis of the representation layer underlying GNN-based smart contract vulnerability detectors finds one confirmed case of misclassification caused directly by a representation-layer failure; the prevalence of such failures in real-world contract populations remains an open empirical question.
Birindwa Prisca Hondi, Chinoso Philip Nwishienyi, Charity Wanja Mwaura et al.· 0 citations
Results show that LLM-based vulnerability injection is feasible, while exposing key limitations in scalability and diversity, and practical challenges including LLMs' non-determinism and the difficulty of preserving contract semantics are reported.
Luca Migliaccio, Roberto Natella, N. Ivaki et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.