Ethereum Smart Contract Vulnerability Detection Method and System Based on Pre-trained Model

Through the pre-trained model-based method, the objective function fragments and AST structured information of the smart contract are extracted, combined with data flow and control flow analysis, and the characteristics are fusionized using the CodeBert model, the problem of high accuracy and cost in smart contract vulnerability detection is solved, and efficient vulnerability detection is achieved.

CN114817932BActive Publication Date: 2025-05-27HOHAI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210444092.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-26
Publication Date
2025-05-27
Estimated Expiration
2042-04-26

AI Technical Summary

Technical Problem

The existing smart contract vulnerability detection methods have problems with low accuracy, high missed rate and false alarm rate, and the cost of manual detection is high, making it difficult to cope with the rapid growth of the number of smart contracts on the Ethereum platform.

Method used

Using a pre-trained model-based method, the target function fragments and AST structured information in the smart contract are extracted, combined with data flow and control flow analysis, and the CodeBert model is used to fuse different code characterization features to realize the detection of smart contract vulnerabilities.

Benefits of technology

It improves the accuracy and completeness of smart contract vulnerability detection, alleviates the problem of data collection and low data volume, and maximizes the vulnerability detection effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114817932B_ABST
    Figure CN114817932B_ABST
Patent Text Reader

Abstract

The present invention proposes a method and system for detecting vulnerabilities in Ethereum smart contracts based on a pre-trained model. In order to obtain more effective vulnerability semantic or syntactic information, the present invention is intended to be based on two different forms of code representation. Firstly, by analyzing information such as the data flow and control flow of the smart contract program, the program slicing technique is used to automatically extract the vulnerability code slices. Secondly, by analyzing the AST of the contract, the smart contract is compiled using a syntax parser, and the AST structured information is automatically obtained using a custom traversal method. At the same time, in order to achieve better detection effects, the present invention uses the pre-trained CodeBert model to fuse the two types of information, realize the fusion of features, and finally realize the detection of vulnerabilities with serious hazard levels in the current Ethereum smart contract environment. The present invention is targeted at smart contract developers, realizes the automatic detection of Ethereum smart contract vulnerabilities based on code fusion representation, and achieves the purpose of contract security guarantee.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an Ethereum smart contract vulnerability detection method and system based on a pre-training model, and belongs to the field of blockchain security and deep learning. Background Art

[0002] As one of the most successful applications of blockchain technology, smart contracts have attracted the attention of academia and industry. A smart contract is a computer program that runs on a blockchain platform, usually written in the Turing-complete high-level programming language Solidity. Ethereum, as an open source public blockchain platform, is also the blockchain platform with the largest number of smart contracts deployed so far. The security of smart contracts is usually determined by the blockchain, Ethereum, and its own programming language Solidity. In the past, the security issues of smart contracts have caused significant economic losses.

[0003] Smart contracts are extremely vulnerable to attacks. There are three main reasons why contracts are attacked by attackers: (1) Smart contracts usually process and manipulate transactions related to encrypted digital currencies. Attacking smart contracts can bring more economic benefits to attackers; (2) The application scenarios of smart contracts are complex and varied. The current programming language of smart contracts is still novel and rough. In actual scenarios, it may be difficult for contract developers to test, which may cause asset security issues in smart contracts; (3) Unlike traditional languages, smart contracts cannot be modified once deployed. The existence of smart contract security vulnerabilities will cause the contract to behave unexpectedly, which violates the original intention of creating fair and trustworthy contracts.

[0004] Smart contract vulnerability detection is an important topic in smart contract security research. First of all, due to the security and privacy protection of the Ethereum chain, 98% of smart contracts are not open source. So far, there is a lack of an open, sufficiently large vulnerability dataset in smart contract vulnerability detection, which hinders the use of source code for vulnerability detection.

[0005] Currently, most research work on vulnerability detection uses traditional methods, that is, based on the characteristics of existing vulnerabilities, human experts manually define and summarize vulnerability rules to match the contract to be tested, thereby detecting contract vulnerabilities. Traditional detection of smart contract vulnerabilities has the following two main limitations: (1) Research on traditional vulnerability analysis scenarios is often done by experts or some automated algorithms to generate vulnerability rules. Although traditional methods have achieved certain results in detecting vulnerabilities, they still have low accuracy and high rates of missed reports and false positives. In addition, some detection tools take a long time to detect, and the detection effect is not satisfactory. (2) The number of smart contracts deployed on the Ethereum platform is increasing every year, and the cost of manual vulnerability detection is increasing.

[0006] Compared with traditional smart contract vulnerability detection methods, smart contract vulnerability detection based on deep learning has higher accuracy and completeness. Related deep learning-based detection method research mainly uses deep learning methods to learn and analyze information such as code lexical, grammatical, control flow and data flow. Generally speaking, different code intermediate representations have different representation effects. However, current research is usually based on a single code intermediate representation form, such as code tokens, abstract syntax trees, control flow graphs, etc., which may result in not containing enough rich code vulnerability syntax or semantic information during vulnerability detection. Summary of the invention

[0007] Purpose of the invention: In view of the problems existing in the prior art, the purpose of the present invention is to provide an Ethereum smart contract vulnerability detection method and system based on a pre-trained model, by extracting smart contract vulnerability slice information and AST structured information, and using a pre-trained model for feature fusion, ultimately achieving the detection of contract vulnerabilities with serious hazard levels in the current Ethereum smart contract environment.

[0008] Technical solution: To achieve the above-mentioned invention object, the present invention provides an Ethereum smart contract vulnerability detection method based on a pre-training model, comprising the following steps:

[0009] Step 1: Collect smart contract data sets, extract target function fragments in smart contracts according to the standard features of vulnerable contracts, and form a sample set with the target function fragment set of smart contracts and contract vulnerability labels; the target function fragment set includes one or more target function fragments;

[0010] Step 2: According to the vulnerability criteria, find the relevant variables or statements in the smart contract target function fragment set, and obtain the smart contract program slice information set after data flow and control flow analysis;

[0011] Step 3: Call the parser to compile each target function fragment in the smart contract target function fragment set, and traverse the generated AST of each target function fragment to obtain the smart contract AST structured information set;

[0012] Step 4: Normalize, segment and encode the smart contract program slice information set and AST structured information set;

[0013] Step 5: Use two network models to train two types of code representation information, and use the pre-trained model CodeBert to splice different code representations to detect smart contract vulnerabilities based on the fused features.

[0014] Preferably, the method for extracting the target function fragment in the smart contract in step 1 comprises the following steps:

[0015] Step 11: According to the original contract version in the smart contract source code, call the corresponding compiler Solc version to compile the contract;

[0016] Step 12: For the contract compiled successfully by Solc, generate the corresponding contract abstract syntax tree file;

[0017] Step 13: Use Slither to generate a global function call graph, and obtain the global function call relationship based on the contract global function call path;

[0018] Step 14: Use Slither to generate a control flow graph inside a single function and obtain the control dependency and data dependency of the variables inside the function;

[0019] Step 15: According to step 13 and step 14, the global control flow graph of the contract is spliced ​​together to obtain the complete control flow and data flow information of a contract;

[0020] Step 16: Based on the global control flow graph in step 15, for the smart contract dataset, analyze the variable relationship and extract the corresponding function fragments according to the standards and patterns of the vulnerability types.

[0021] Preferably, the method for obtaining the smart contract program slice information set in step 2 comprises the following steps:

[0022] Step 21: According to the vulnerability classification framework or vulnerability criteria, for one or more target functions in the target function fragment set of the smart contract, determine a related variable set or statement set;

[0023] Step 22: Perform data dependency analysis on variables or statements based on the global control flow graph, extract all variables or statements with relevant data dependencies, and generate a candidate data dependency set for the target function fragment set;

[0024] Step 23: According to the global control flow graph, perform control dependency analysis on variables or statements, extract all relevant control-dependent variables or statements, and generate a candidate control dependency set for the target function fragment set;

[0025] Step 24: Merge all candidate data dependency sets and candidate control dependency sets in the order of the codes in the original contract to generate a smart contract program slice information set.

[0026] Preferably, the method for obtaining the smart contract AST structured information set in step 3 comprises the following steps:

[0027] Step 31: Use the grammar parser ANTLR to compile each target function fragment in the target function fragment set to generate a compiled AST fragment set;

[0028] Step 32: Use a depth-first traversal method to traverse the compiled AST fragment set and generate an AST structured information set.

[0029] Preferably, step 4 includes the following steps:

[0030] Step 41: Normalize vulnerability information: Use FUN{#} to replace the target function name in the contract, where # represents a number and takes values ​​according to the position before and after the target function; remove stop words and punctuation marks; replace single-character variables and constants with agreed fixed strings; split words in camel case named variables.

[0031] Step 42: Word segmentation: all texts in the program slice information set and the AST structured information set are word segmented, and a dic dictionary and an inv_dic dictionary are generated. Word is used to represent a word in the dictionary, and idx represents the position of the word in the dictionary. The key-value pair format of the dic dictionary is "word:idx", and the key-value pair format of the inv_dic dictionary is "idx:word".

[0032] Step 43: Encoding: Use the word2vec model to vectorize the words in the dataset and finally form a word embedding matrix.

[0033] Preferably, step 5 includes the following steps:

[0034] Step 51: respectively train two different code representations using a program slicing model and an AST structured information model;

[0035] Step 52: Use the pre-trained model CodeBert as the fusion model. The input of the fusion model is the concatenation of the code representation output by the program slicing model and the AST structured information model. The input is processed according to the structure of the pre-trained model CodeBert, and the input sequence I is converted into an input vector X 0 , the transformer layer generates the context representation X n =transformer n (X n-1 ), n∈[1,N], N is the number of transformer layers, and finally a linear classifier is added and the softMax function of the output prediction probability is used for prediction.

[0036] Step 53: After optimizing the model parameters based on the training set, save the parameters of the model with the best performance.

[0037] Preferably, the program slicing model and the AST structured information model both adopt the BLSTM model.

[0038] Based on the same inventive concept, the present invention provides an Ethereum smart contract vulnerability detection system based on a pre-trained model, comprising:

[0039] The target function extraction module is used to collect the smart contract data set, extract the target function fragments in the smart contract according to the standard features of the vulnerable contract, and form a sample set with the target function fragment set of the smart contract and the contract vulnerability label; the target function fragment set includes one or more target function fragments;

[0040] The program slice information acquisition module is used to find the relevant variables or statements in the smart contract target function fragment set according to the vulnerability standard, and obtain the smart contract program slice information set after data flow and control flow analysis;

[0041] The AST structured information acquisition module is used to call the syntax parser to compile each target function fragment in the smart contract target function fragment set, and traverse the AST of each generated target function fragment to obtain the smart contract AST structured information set;

[0042] The preprocessing module is used to normalize, segment and encode the smart contract program slice information set and AST structured information set;

[0043] And the vulnerability detection module is used to use two network models to train two types of code representation information, and use the pre-trained model CodeBert to splice different code representations to detect smart contract vulnerabilities based on the fused features.

[0044] Based on the same inventive concept, the present invention provides a computer system, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded into the processor, the method for detecting Ethereum smart contract vulnerabilities based on a pre-trained model is implemented.

[0045] Based on the same inventive concept, the present invention provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the Ethereum smart contract vulnerability detection method based on the pre-trained model.

[0046] Beneficial effects: The present invention provides an Ethereum smart contract vulnerability detection method and system based on a pre-trained model. According to the standard features of the vulnerable contract, the target function fragments in the smart contract are extracted, and the smart contract vulnerability related information is extracted at the function level; in the part of extracting the vulnerability program slice information, the contract data flow and control flow information are analyzed, the target program code is extracted, and the slices are composed; in the part of extracting the vulnerability AST structured information, based on the function level, the contract is compiled using a syntax parser, and then the AST is traversed using a custom traversal method to generate the corresponding AST structured information. In the training and detection part of the model, the pre-trained CodeBert model is used to fuse the two types of information to achieve feature fusion, training and vulnerability detection. The present invention makes full use of the smart contract code vulnerability syntax or semantic information, and at the same time introduces a pre-trained model for information fusion, which can alleviate the problems of difficult data collection and small data volume, and achieve the goal of maximizing the vulnerability detection effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 is an overall step diagram of an embodiment of the present invention;

[0048] Figure 2 The figure is a flow chart of a method according to a specific example of the present invention. DETAILED DESCRIPTION

[0049] The present invention is further explained below in conjunction with specific embodiments. It should be understood that these embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention. After reading the present invention, various equivalent forms of modifications to the present invention by those skilled in the art all fall within the scope defined by the claims attached to this application.

[0050] like Figure 1 As shown, an Ethereum smart contract vulnerability detection method based on a pre-training model disclosed in an embodiment of the present invention mainly includes the following steps:

[0051] Collect smart contract data sets, extract target function fragments in smart contracts according to standard features of vulnerable contracts, and form a sample set with a set of target function fragments of smart contracts and contract vulnerability labels; the target function fragment set includes one or more target function fragments;

[0052] According to the vulnerability criteria, find the relevant variables or statements in the smart contract target function fragment set, and obtain the smart contract program slice information set after data flow and control flow analysis;

[0053] Call the parser to compile each target function fragment in the smart contract target function fragment set, and traverse the generated AST of each target function fragment to obtain the smart contract AST structured information set;

[0054] Normalize, segment and encode the smart contract program slice information set and AST structured information set;

[0055] Two network models are used to train two types of code representation information, and the pre-trained model CodeBert is used to splice different code representations, and the detection of smart contract vulnerabilities is realized based on the fused features.

[0056] like Figure 2 As shown, taking the detection of reentrancy vulnerabilities in smart contracts as an example, the detailed steps of a method for detecting vulnerabilities in Ethereum smart contracts based on a pre-trained model disclosed in an embodiment of the present invention are described as follows:

[0057] Step 1: Collect a certain number and types of smart contract data sets (including vulnerable contracts and non-vulnerable contracts), extract the target function fragments in the smart contract according to the standard characteristics of the vulnerable contract, and form a sample set with the target function fragment set of the smart contract and the contract vulnerability label. The type refers to the type of vulnerability with a more serious or most serious hazard level in the current Ethereum environment. In this embodiment, the reentrancy vulnerability is used as an example for detailed description.

[0058] The data set collection mainly includes two aspects:

[0059] a. Dataset crawling and collection. Use keyword search (smart contract vulnerability, re-entrancy vulnerability) on Github and use Kral (https: / / github.com / cleanunicorn / / karl) to monitor Ethereum in real time;

[0060] b. Data labeling. The collected data is labeled with traditional tools and manually audited to form a labeled reentrancy vulnerability dataset SCR = {SCR 1 ,SCR 2 ,SCR 3 ,…,SCR N}, where N is the number of contracts in the dataset.

[0061] According to the reentrancy vulnerability standard, the target function fragment set of the smart contract is obtained. The specific process is as follows:

[0062] Step 11: According to the original contract version in the contract source code, call the corresponding compiler Solc version to compile the contract;

[0063] Step 12: For the contract compiled successfully by Solc, generate the corresponding contract abstract syntax tree ast_json file.

[0064] Step 13: Use Slither to generate a global function call graph, and obtain the global function call relationship based on the contract global function call path.

[0065] Step 14: Use Slither to generate a control flow graph inside a single function and obtain the control dependency and data dependency of the variables inside the function.

[0066] Step 15: According to step 13 and step 14, assemble the global control flow graph of the contract to obtain the complete control flow and data flow information of a contract.

[0067] Step 16: Based on the global control flow graph in step 15, for the vulnerability dataset SCR, according to the standards and patterns of the vulnerability types, analyze the variable relationships and extract the corresponding function fragments. k For reentrancy vulnerabilities, we analyze the global control flow graph to locate the function path containing the call-statement, and then extract the corresponding function according to the path to form the target function fragment set of the contract. Where n is a contract SCR k The number of objective function fragments in ,.

[0068] Step 2: According to the corresponding reentrancy vulnerability standard, find the relevant variables (such as address type) or statements (such as call-statement statements), and obtain the smart contract program slice information set after data flow and control flow analysis. The specific steps are as follows:

[0069] Step 21: Determine the target set. According to the vulnerability classification framework or reentrancy vulnerability criteria, for the contract target function fragment set SFR k , determine the relevant variable set in the function fragment set (such as a variable of type address) or a statement collection (such as call-statement); where m is the target function fragment set SFR k The number of variables in , l is the set of objective function fragments SFR k The number of sentences in

[0070] Step 22: Data flow analysis. According to the global control flow graph generated in step 15, perform data dependency analysis on variables or statements, extract all variables or statements with relevant data dependencies, and generate the target function fragment set SFR. k Candidate data dependency set Where p is the set of objective function fragments SFR k The number of data-dependent statements in

[0071] Step 23: Control flow analysis. According to the global control flow graph generated in step 15, perform control dependency analysis on variables or statements, extract all relevant control-dependent variables or statements, and generate the target function fragment set SFR. t Candidate control dependency set

[0072] Where q is the set of objective function fragments SFR k Control the number of dependent statements in

[0073] Step 24: Get program slices. For contract SCR k , according to the order of the code in the original contract, merge the data dependency and control dependency sets to generate a program slice information set (assuming q≤p)

[0074]

[0075] Step 3: Given a reentrancy vulnerability contract, use the syntax parser to compile the contract AST and obtain the AST structured information set. The specific steps are:

[0076] Step 31: Compile the target function fragment. The target function fragment set SFR generated according to step 16 k , use the grammar parser ANTLR to compile the function fragment and generate a collection of compiled AST fragments

[0077] Step 32: Customize the traversal sequence. Use depth-first traversal to traverse the AST fragment set ASTSF compiled in step 41 k , generate AST structured information set

[0078] Step 4: Preprocess the program slice information and AST structure information to remove information irrelevant to the vulnerability information. The specific steps are as follows:

[0079] Step 41: Contract normalization. Use FUN{#} (where # can be 1, 2, 3...) to replace the functions in the contract. For example, according to the vulnerability rules, 3 target functions related to the reentrancy vulnerability can be extracted from a contract. According to the front and back positions of the functions, the function names are changed to FUN1, FUN2, and FUN3. The remaining normalization operations include stop word removal; single-character variables, such as "a", "b", "i", "j", "k", etc., are replaced by "SimpleVar"; punctuation removal (such as "," ,";", etc.); constant replacement (according to the type of constants, we unify them into "StringLiteral", "DecimalNumber", "HexNumber" and "HexLiteral"); camel case named variable splitting ("myContractValue" becomes "my", "Contract", "Value", etc.);

[0080] Step 42: Contract segmentation. Set the program segmentation information into PSR k and AST structured information set ASIR k All texts in the dictionary are segmented and dic dictionary and inv_dic dictionary are generated. Word represents the word in the dictionary, and idx represents the position of word in the dictionary. The key-value pair format of dic dictionary is "word:idx", and the key-value pair format of inv_dic dictionary is "idx:word".

[0081] Step 43: Contract word vector encoding. The word2vec model is used to vectorize the words in the above dataset and finally form a word embedding matrix.

[0082] Step 5: Train the two code representation information according to the input design model, and design a pre-training model to splice different code representations. The specific steps are as follows:

[0083] Step 51: After the above steps, the vulnerability dataset SCR = {SCR 1 ,SCR 2 ,SCR 3 ,…,SCR N}, each smart contract extracts two information sets, namely, program slice information set PSR = {PSR 1 ,PSR 2 ,PSR 3 ,…,PSR n} and AST structured information set ASIR = {ASIR 1 ,ASIR 2 ,ASIR 3 ,…,ACIR n}, the program slicing model and AST structured information model are used to train the two types of information respectively. These two models use the RNNs family model (such as BLSTM), and the model structure is implemented using the standard BLSTM. The two models have the same model structure with the same number of layers. During the model training process, since each contract can extract one or more target functions, the sequence length corresponding to a contract is different. Here, we count the number of word segmentations in the target function fragment in each contract, take the average, truncate the excess, and fill in 0 if it is insufficient, to ensure the consistency of the length of the input sequence, and then use the word vector matrix encoded with the two types of information as input. Here we use the two models as feature extractors, calculate the loss of the model's actual output and expected output, and reversely update the parameters. The output MPSR of a layer i of these two models i and MASIR i As the learned vulnerability feature representation.

[0084] Step 52: Set the input of the fusion model. The input I of the model is set to the concatenation of two segmented data, that is, I = {[CLS], MPSR, [SEP], MASIR}, where [CLS] is a special marker at the starting position, [SEP] is the segmentation program slice set MPSR = {MPSR 1 ,MPSR 2 ,MPSR 3 ,…,MPSR M ) and AST structured information set MASIR = {MASIR 1 ,MASIR 2 ,MASIR 3 ,…,MASIR M ), where M is the number of layers of the defined model.

[0085] Step 53: Build the model structure. Process the input according to the structure of the pre-trained model CodeBert, and the input sequence I is converted into an input vector X 0 , the transformer layer generates the context representation X n =transformer n (X n-1 ), n∈[1,N]. Finally, a linear classifier is added and a softMax function is used to output the predicted probability for prediction.

[0086] Step 54: Model tuning and saving. After performing appropriate parameter tuning based on the training set, update the parameters in reverse order and save the parameters of the model with the best performance.

[0087] Those skilled in the art can understand that the above specific implementation process takes the detection of reentrancy vulnerabilities as an example, but the solution of the present invention is not only applicable to the detection of this specific type of vulnerability, but can also be applied to the detection of other currently known vulnerability types, or to the detection of multiple vulnerability types at the same time. For a contract, the corresponding target function fragment set can be extracted according to the standard features of different types of vulnerabilities, and the target function fragment set and the corresponding vulnerability type label can constitute a learning sample.

[0088] Based on the same inventive concept, an Ethereum smart contract vulnerability detection system based on a pre-trained model provided by an embodiment of the present invention includes: a target function extraction module, which is used to collect a smart contract data set, extract target function fragments in the smart contract according to the standard features of the vulnerable contract, and form a sample set with a target function fragment set of the smart contract and a contract vulnerability label; the target function fragment set includes one or more target function fragments; a program slice information acquisition module, which is used to find relevant variables or statements in the smart contract target function fragment set according to the vulnerability standard, and obtain the smart contract program slice information set after data flow and control flow analysis; an AST structured information acquisition module, which is used to call a syntax parser to compile each target function fragment in the smart contract target function fragment set, and traverse the generated AST of each target function fragment to obtain the smart contract AST structured information set; a preprocessing module, which is used to normalize, segment and encode the smart contract program slice information set and the AST structured information set; and a vulnerability detection module, which is used to use two network models to train two types of code representation information, and use the pre-trained model CodeBert to splice different code representations, and realize the detection of smart contract vulnerabilities based on the fused features.

[0089] Based on the same inventive concept, an embodiment of the present invention provides a computer system, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded into the processor, the method for detecting Ethereum smart contract vulnerabilities based on a pre-trained model is implemented.

[0090] Based on the same inventive concept, an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the Ethereum smart contract vulnerability detection method based on the pre-trained model is implemented.

Claims

1. An Ethereum smart contract vulnerability detection method based on a pre-trained model, characterized in that, it includes the following steps: Step 1: Collect a smart contract dataset, extract target function fragments in the smart contract according to the standard features of vulnerable contracts, and form a sample set with the set of target function fragments of the smart contract and contract vulnerability labels; the set of target function fragments includes one or more target function fragments; Step 2: According to the vulnerability criteria, find relevant variables or statements in the set of target function fragments of the smart contract, and after data flow and control flow analysis, obtain a set of smart contract program slice information; Step 3: Call a syntax parser to compile each target function fragment in the set of target function fragments of the smart contract, and traverse the AST of each generated target function fragment to obtain a set of smart contract AST structured information; Step 4: Normalize, tokenize, and encode the set of smart contract program slice information and the set of AST structured information; Step 5: Use two network models to train two types of code representation information, and use the pre-trained model CodeBert to splice different code representations, and detect smart contract vulnerabilities based on the fused features; The method for extracting target function fragments in the smart contract in Step 1 includes the following steps: Step 11: According to the original contract version in the smart contract source code, call the corresponding compiler Solc version to compile the contract; Step 12: For the contract successfully compiled by Solc, generate a corresponding contract abstract syntax tree file; Step 13: Use Slither to generate a function global call graph, and obtain the global function call relationship according to the contract global function call path; Step 14: Use Slither to generate a control flow graph inside a single function, and obtain the control dependence relationship and data dependence relationship of variables inside the function; Step 15: According to Step 13 and Step 14, splice and compose the global control flow graph of the contract to obtain the complete control flow and data flow information of a contract; Step 16: Based on the global control flow graph in Step 15, for the smart contract dataset, analyze variable relationships according to the standards and patterns of vulnerability types, and extract corresponding function fragments; The method for obtaining the set of smart contract program slice information in Step 2 includes the following steps: Step 21: According to the vulnerability classification framework or vulnerability criteria, determine a set of relevant variables or a set of statements for one or more target functions in the set of target function fragments of the smart contract; Step 22: According to the global control flow graph, perform data dependence analysis on variables or statements, extract all variables or statements with relevant data dependence, and generate a candidate data dependence set for the set of target function fragments; Step 23: According to the global control flow graph, perform control dependence analysis on variables or statements, extract all variables or statements with relevant control dependence, and generate a candidate control dependence set for the set of target function fragments; Step 24: Merge all candidate data dependence sets and candidate control dependence sets in the order of the code in the original contract to generate a set of smart contract program slice information; The method for obtaining the intelligent contract AST structured information set in step 3 includes the following steps: Step 31: Use the grammar parser ANTLR to compile each target function fragment in the target function fragment set, and generate a compiled AST fragment set; Step 32: Traverse the compiled AST fragment set in a depth-first traversal manner to generate an AST structured information set; The said step 4 includes the following steps: Step 41: Normalize the vulnerability information: Replace the target function name in the contract with FUN{#}, where # represents a number and is taken according to the front and back positions of the target function; Remove stop words and punctuation marks; Replace single-character variables and constants with agreed fixed strings; Split the words in camel-case variables; Step 42: Tokenize: Tokenize all the text in the program slice information set and the AST structured information set, and generate a dic dictionary and an inv_dic dictionary. Use word to represent the words in the dictionary, and idx to represent the position of the word word in the dictionary. Then the key-value pair format of the dic dictionary is "word: idx", and the key-value pair format of the inv_dic dictionary is "idx: word"; Step 43: Encode: Use the word2vec model to vectorize the words in the dataset, and finally form a word embedding matrix; The said step 5 includes the following steps: Step 51: Train two different code representations using the program slice model and the AST structured information model respectively; Step 52: Use the pre-trained model CodeBert as the fusion model. The input of the fusion model is the concatenation of the code representations output by the program slicing model and the AST structured information model. Process the input according to the structure of the pre-trained model CodeBert, and the input sequence I is converted into the input vector X 0 , and the transformer layer generates the context representation X n = transformer n (X n-1 ), n ∈ [1, N], where N is the number of transformer layers. Finally, add a linear classifier and use the softMax function of the output prediction probability to predict; Step 53: After tuning the parameters of the model based on the training set, save the parameters of the model with the best performance.

2. According to the method for detecting Ethereum intelligent contract vulnerabilities based on a pre-trained model described in claim 1, characterized in that both the program slice model and the AST structured information model adopt the BLSTM model.

3. An Ethereum intelligent contract vulnerability detection system based on a pre-trained model, characterized in that it includes: A target function extraction module, which is used to collect an intelligent contract dataset, extract target function fragments in the intelligent contract according to the standard features of the vulnerable contract, and form a sample set with the target function fragment set of the intelligent contract and the contract vulnerability label; One or more target function fragments are included in the target function fragment set; The method for extracting target function fragments in the intelligent contract includes the following steps: Step 11: According to the original contract version in the intelligent contract source code, call the corresponding compiler Solc version to compile the contract; Step 12: For the contract successfully compiled by Solc, generate a corresponding contract abstract syntax tree file; Step 13: Use Slither to generate a function global call graph, and obtain the global function call relationship according to the contract global function call path; Step 20: Use Slither to generate a control flow graph inside a single function, and obtain the control dependence relationship and data dependence relationship of the variables inside the function; Step 21: According to steps 13 and 14, splice and compose the global control flow graph of the contract to obtain the complete control flow and data flow information of a contract; Step 16: Based on the global control flow graph in Step 15, for the smart contract dataset, analyze the variable relationships according to the standards and patterns of vulnerability types, and extract the corresponding function fragments. The program slicing information acquisition module is used to find relevant variables or statements in the set of target function fragments of the smart contract according to the vulnerability criteria. After data flow and control flow analysis, a set of smart contract program slicing information is obtained. The method for obtaining the set of smart contract program slicing information includes the following steps: Step 21: According to the vulnerability classification framework or vulnerability criteria, for one or more target functions in the set of target function fragments of the smart contract, determine the relevant variable set or statement set. Step 22: According to the global control flow graph, perform data dependency analysis on variables or statements, extract all variables or statements with relevant data dependencies, and generate a candidate data dependency set for the set of target function fragments. Step 23: According to the global control flow graph, perform control dependency analysis on variables or statements, extract all variables or statements with relevant control dependencies, and generate a candidate control dependency set for the set of target function fragments. Step 24: In the order of the code in the original contract, merge all candidate data dependency sets and candidate control dependency sets to generate a set of smart contract program slicing information. The AST structured information acquisition module is used to call the syntax parser to compile each target function fragment in the set of target function fragments of the smart contract, and traverse the generated AST of each target function fragment to obtain a set of smart contract AST structured information. The method for obtaining the set of smart contract AST structured information includes the following steps: Step 31: Use the syntax parser ANTLR to compile each target function fragment in the set of target function fragments, and generate a set of compiled AST fragments. Step 32: Traverse the set of compiled AST fragments in a depth-first traversal manner to generate a set of AST structured information. The preprocessing module is used to normalize, tokenize, and encode the set of smart contract program slicing information and the set of AST structured information. Among them, normalization is: use FUN{#} to replace the target function name in the contract, where # represents a number and takes values according to the front and back positions of the target function; remove stop words and punctuation marks; replace single-character variables and constants with a predefined fixed string; split the words in camel-case variables. Tokenization is: tokenize all the text in the set of program slicing information and the set of AST structured information, and generate a dic dictionary and an inv_dic dictionary. Use word to represent the words in the dictionary, and idx to represent the position of the word word in the dictionary. Then the key-value pair format of the dic dictionary is "word: idx", and the key-value pair format of the inv_dic dictionary is "idx: word"; Encoding is: use the word2vec model to vectorize the words in the dataset and finally form a word embedding matrix. And a vulnerability detection module, which is used to train two types of code representation information by using two network models, and use the pre-trained model CodeBert to splice different code representations, and realize the detection of smart contract vulnerabilities based on the fused features; including: training two different code representations by using a program slicing model and an AST structured information model respectively; The pre-trained model CodeBert is used as the fusion model. The input of the fusion model is the concatenation of the code representations output by the program slicing model and the AST structured information model. The input is processed according to the structure of the pre-trained model CodeBert, and the input sequence I is converted into the input vector X 0 , and the transformer layer generates the context representation X n = transformer n (X n-1 ), where n ∈ [1, N] and N is the number of transformer layers. Finally, a linear classifier is added and the softMax function of the output prediction probability is used for prediction; after parameter searching and tuning of the model based on the training set, the parameters of the model with the best performance are saved.

4. A computer system, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, when the computer program is loaded into the processor, it implements the Ethereum smart contract vulnerability detection method based on the pre-trained model according to any one of claims 1-2.

5. A computer-readable storage medium, which stores a computer program, wherein, when the computer program is executed by the processor, it implements the Ethereum smart contract vulnerability detection method based on the pre-trained model according to any one of claims 1-2.