A lightweight method for generating fuzz test cases under bytecode-level static guidance, and results indicate that static guidance, directed seed generation, and vulnerability-specific oracles each contribute to the final performance.
Abstract
The effectiveness of smart contract fuzzing depends strongly on whether generated transactions reach deep, state-dependent execution paths. Existing fuzzers often generate highly random call sequences, wasting executions on semantically invalid or low-value states and leaving vulnerabilities that require specific invocation orders unexplored. We present a lightweight method for generating fuzz test cases under bytecode-level static guidance. We construct an Ethereum virtual machine control-flow graph, extract paths containing vulnerability-relevant instructions, recover function selectors, and order externally callable functions according to storage read-write dependencies. A coverage-guided evolutionary strategy then generates, evaluates, recombines, and mutates executable seeds. Five dedicated runtime oracles target reentrancy, integer overflow or underflow, block-state dependence, unsafe delegate calls, and frozen Ether. The evaluation uses deployed Ethereum contracts, including labelled vulnerable contracts. SAEFUZZ detects most labelled vulnerable contracts, yielding 98.50% accuracy, 90.00% precision, and 81.82% recall. It also achieves 84.07% mean instruction coverage, with valid test cases accounting for 93.48% of generated cases. Ablation results indicate that static guidance, directed seed generation, and vulnerability-specific oracles each contribute to the final performance.
Results show that LLM-based vulnerability injection is feasible, while exposing key limitations in scalability and diversity, and practical challenges including LLMs' non-determinism and the difficulty of preserving contract semantics are reported.
Luca Migliaccio, Roberto Natella, N. Ivaki et al.· 0 citations
Prototype pollution is a critical class of taint-style vulnerabilities in JavaScript programs, enabling attackers to tamper with object prototypes and thereby alter program behavior in unexpected and often dangerous ways. Despite its severity, existing detection techniques struggle with excessive false positives and po...
De-Zhen Kong, Pei-Sen Yao, Jia-Kun Liu et al.· ACM Transactions on Software...· 0 citations
Advances in large language models (LLMs) fuel the quest for scalable methods to assess the security of generated and security-sensitive software. Static analysis is widely adopted as a scalable, reproducible, and inexpensive security gate, but cannot directly observe runtime exploit behaviour. Vulnerabilities dependent...
Jessica Pourleyli, Maitreyee Das Urmi, Glaucia Melo· 0 citations
SE4SC-LLM, an LLM-augmented symbolic execution framework for smart contracts that achieves 95.1% average CFG coverage, a 6.5 percentage point improvement over the strongest baseline, and detects 11.2% more vulnerabilities.
Tian-Huan Miao, Yang Liu· International Conference on...· 0 citations
This paper proposes SVACS, a bytecode-based analysis framework to identify multiple co-existing vulnerabilities based on SWC registry to align with industry-standard security guidelines and assist security reviewers to ensure smart contract security.
Ankur Jain, Abhishar Anand, S. Tripathy· IEEE Access· 0 citations
Smart contracts, which are fundamental to DeFi financial systems, are vulnerable to exploitable bugs that can cause substantial monetary losses. A recent study shows that over 80% of these exploitable bugs, primarily functional bugs, evade detection by existing tools. Automatically identifying functional bugs in smart...
Xing-Shuang Lin, Bin-Bin Zhao, Qin-Ge Xie et al.· ACM Transactions on Software...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.