Vulnerability Detection Method, Device, Equipment and Medium for Smart Contracts
By generating a directed graph of smart contracts and using feature extraction models and neural network identification vulnerabilities, the problem of smart contract vulnerability detection accuracy and low efficiency is solved, and efficient and accurate vulnerability detection is achieved.
Patent Information
- Application Number
- CN202410547779.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-06
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2044-05-06
AI Technical Summary
The existing smart contract vulnerability detection methods have problems such as low detection accuracy, low efficiency, low automation, and loss of grammar and semantics, making it difficult to effectively improve the accuracy and efficiency of smart contract vulnerability detection.
By obtaining the target smart contract, generating its directed graph, using the pre-trained feature extraction model to extract node feature vectors, combining the adjacency matrix of the directed graph, and using the graph neural network and multi-layer perceptron network to identify the vulnerability detection results of the smart contract.
It improves the accuracy and efficiency of smart contract vulnerability detection, can automatically and accurately identify vulnerabilities in smart contracts, and reduces the false positive rate and the consumption of computing resources.
Smart Images

Figure CN118536119B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to a method, apparatus, device, and medium for detecting vulnerabilities in smart contracts. Background Art
[0002] A smart contract is code written on a blockchain. Once an event triggers the terms in the smart contract, the code will execute automatically. It is necessary to detect vulnerabilities in the smart contract before it is released.
[0003] Currently, traditional smart contract vulnerability detection methods include formal verification, fuzz testing, machine learning, etc. Formal verification highly depends on the hard logic rules predefined by experts during vulnerability detection. As the structure of smart contracts becomes more complex, the rules defined by experts cannot keep up with the speed of smart contract vulnerability updates, and the logic rules defined by experts may lead to a high false positive rate. Therefore, the detection method of formal verification has the problem of low detection accuracy.
[0004] Although the method based on fuzz testing can discover potential vulnerabilities in smart contracts to a certain extent by inputting a large amount of random or abnormal data, fuzz testing usually requires a large amount of computing resources and time, and has problems of low efficiency and low automation.
[0005] Although the vulnerability detection method based on machine learning improves the detection efficiency, most of them detect after converting the smart contract source code into bytecode, and there will be a situation where the syntax and semantics of the smart contract are lost during the conversion process, resulting in low accuracy of vulnerability detection.
[0006] Therefore, how to improve the accuracy and efficiency of smart contract vulnerability detection has become a technical problem that needs to be solved urgently by those skilled in the art. Summary of the Invention
[0007] In view of the above, this application provides a method, apparatus, device, and medium for detecting vulnerabilities in smart contracts, aiming to solve the above technical problems.
[0008] In a first aspect, this application provides a method for detecting vulnerabilities in a smart contract, the method including:
[0009] Obtain a target smart contract to be detected;
[0010] Generate a directed graph of the target smart contract;
[0011] Use a pre-trained feature extraction model to extract the node feature vectors of the directed graph;
[0012] Based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph, identify the vulnerability detection result of the target smart contract.
[0013] Preferably, generating the directed graph of the target smart contract includes:
[0014] Analyze the call relationship between the functions of the target smart contract;
[0015] Using the functions of the target smart contract as nodes and the call relationship as edges, generate the directed graph of the target smart contract.
[0016] Preferably, using the pre-trained feature extraction model to extract the node feature vectors of the directed graph includes:
[0017] Use regular expressions to determine the start position and end position of the function corresponding to each node in the directed graph;
[0018] Generate the target text corresponding to each function according to the start position and the end position;
[0019] Input the target text into the feature extraction model, and extract the features of the target text as the node feature vectors of the directed graph.
[0020] Preferably, the feature extraction model is trained based on the LLM model, and the training process of the feature extraction model includes:
[0021] Obtain the code files of a preset number of sample smart contracts;
[0022] Concatenate the code files of all sample smart contracts to obtain a target text file;
[0023] Use the target text file as the input of the LLM model to perform unsupervised training operations to obtain the feature extraction model.
[0024] Preferably, based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph, identifying the vulnerability detection result of the target smart contract includes:
[0025] Divide the directed graph into N multi-hop subgraphs, where N represents the number of nodes in the directed graph;
[0026] Input the node feature vector corresponding to each node, the multi-hop subgraph and the adjacency matrix of the directed graph into a graph neural network to obtain the local feature of each node;
[0027] Based on the local features of each node, obtain the target feature of the directed graph;
[0028] Input the target feature of the directed graph into a multi-layer perceptron network to obtain the vulnerability detection result of the target smart contract.
[0029] Preferably, obtaining the target feature of the directed graph based on the local features of each node includes:
[0030] Inputting the local features of each node into a self-attention mechanism network to obtain the global feature of each node;
[0031] Adding the global features of each node to obtain an addition result;
[0032] Dividing the addition result by the number of nodes to obtain the target feature of the directed graph.
[0033] Preferably, the method further includes:
[0034] Sending the vulnerability detection result of the target smart contract to a preset terminal.
[0035] In a second aspect, the present application provides a vulnerability detection device for a smart contract, and the device includes:
[0036] An acquisition module: used to acquire a target smart contract to be detected;
[0037] A generation module: used to generate a directed graph of the target smart contract;
[0038] An extraction module: used to extract the node feature vectors of the directed graph by using a pre-trained feature extraction model;
[0039] A detection module: used to identify the vulnerability detection result of the target smart contract based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph.
[0040] In a third aspect, the present application provides an electronic device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus;
[0041] The memory is used to store a computer program;
[0042] The processor is used to implement the vulnerability detection method for the smart contract according to any one of the embodiments in the first aspect when executing the program stored in the memory.
[0043] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, it implements the vulnerability detection method for the smart contract according to any one of the embodiments in the first aspect.
[0044] The above technical solutions provided by the embodiments of the present application have the following advantages compared with the prior art:
[0045] This application obtains the target smart contract to be detected, generates a directed graph of the target smart contract, which can represent the relationship between the codes of the target smart contract, extracts the node feature vectors of the directed graph using a pre-trained feature extraction model. Since the node feature vectors of the directed graph can represent not only the characteristic information of the node but also the importance of the node in the directed graph, and the adjacency matrix of the directed graph can represent the connection relationship between each node in the directed graph, based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph, it is possible to automatically and accurately identify whether there are vulnerabilities in the target smart contract, thereby improving the vulnerability detection accuracy and efficiency of the target smart contract. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.
[0047] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0048] Figure 1 It is a schematic flowchart of an embodiment of the method for detecting vulnerabilities in the smart contract of this application;
[0049] Figure 2 It is a schematic block diagram of an embodiment of the device for detecting vulnerabilities in the smart contract of this application;
[0050] Figure 3 It is a schematic diagram of an embodiment of the electronic device of this application;
[0051] The realization of the purpose of this application, functional features and advantages will be further described in conjunction with the embodiments with reference to the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0052] To make the purposes, technical solutions and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are some but not all of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of this application without creative efforts belong to the scope of protection of this application.
[0053] The following disclosure provides many different embodiments or examples for implementing different structures of the present application. To simplify the disclosure of the present application, the components and settings of specific examples are described below. Of course, they are only examples and are not intended to limit the present application. In addition, the present application may repeat reference numerals and / or letters in different examples. This repetition is for the purpose of simplification and clarity and does not itself indicate the relationship between the various embodiments and / or settings discussed.
[0054] The present application provides a method for detecting vulnerabilities in smart contracts. Referring to Figure 1 as shown, it is a schematic flowchart of the method of the embodiment of the method for detecting vulnerabilities in smart contracts of the present application. This method can be executed by an electronic device, and the electronic device can be implemented by software and / or hardware. The method for detecting vulnerabilities in smart contracts includes:
[0055] Step S10: Obtain a target smart contract to be detected;
[0056] Step S20: Generate a directed graph of the target smart contract;
[0057] Step S30: Use a pre-trained feature extraction model to extract the node feature vectors of the directed graph;
[0058] Step S40: Based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph, identify the vulnerability detection result of the target smart contract.
[0059] A smart contract is code written on a blockchain. Once an event triggers the terms in the smart contract, the code will be automatically executed. That is, the code is executed when the conditions are met without manual control. Smart contracts are written in high-level programming languages (for example, Solidity language), then compiled into virtual machine bytecodes that support a Turing-complete instruction set, and published to a system that supports the running of smart contracts. Once a smart contract is successfully published, its code cannot be modified or its execution blocked, that is, smart contracts are irreversible. Like traditional software programs, the code of smart contracts may also have vulnerability problems. Due to the huge digital assets associated with smart contracts and their irreversibility, the vulnerabilities in their code are easily attacked. Therefore, after the smart contract is written or before the smart contract is published, it is necessary to detect whether there are vulnerabilities in the code of the smart contract.
[0060] In this embodiment, when receiving a request to detect whether there are vulnerabilities in a smart contract, the electronic device obtains a target smart contract to be detected. Among them, the request may include the target smart contract to be detected or the storage path of the target smart contract. That is, the target smart contract can be uploaded by the user when submitting the detection request, or can be obtained by the user from the storage address specified in the request after submitting the request.
[0061] After obtaining the target smart contract to be detected, a directed graph of the target smart contract is generated. A directed graph is a data structure composed of a set of nodes and the relationships between the nodes. The directed graph can represent the relationships between the codes of the target smart contract. Among them, the nodes of the directed graph represent the functions of the target smart contract, and the edges of the directed graph represent the call relationships between the functions. Specifically, generating the directed graph of the target smart contract includes:
[0062] Analyze the call relationships between the functions of the target smart contract;
[0063] Using the functions of the target smart contract as nodes and the call relationships as edges, generate the directed graph of the target smart contract.
[0064] Input the code of the target smart contract into the Slither tool. By using the Slither tool to analyze the call relationships between the functions of the target smart contract, a call relationship graph of the target smart contract functions can be obtained. The call relationship graph can clearly express the dependency relationships between the functions in the target smart contract. Using the functions of the target smart contract as nodes and the call relationships as edges, thus generating the directed graph of the target smart contract. For example, a directed edge from node A to node B in the directed graph indicates that function A in the target smart contract calls function B. Among them, Slither is a static analysis framework for smart contracts, providing functions such as automated vulnerability detection and code understanding.
[0065] After generating the directed graph of the target smart contract, it is necessary to extract the node feature vectors of the directed graph to identify and detect the directed graph through the node feature vectors. Specifically, a feature extraction model can be pre-trained through a large language model (LLM), and the feature extraction model is used to extract the node feature vectors of the directed graph. Among them, using the pre-trained feature extraction model to extract the node feature vectors of the directed graph includes:
[0066] Use regular expressions to determine the start position and end position of the function corresponding to each node in the directed graph;
[0067] Generate the target text corresponding to each function according to the start position and the end position;
[0068] Input the target text into the feature extraction model, and extract the features of the target text as the node feature vectors of the directed graph.
[0069] Since each node in the directed graph represents a function in the target smart contract, it is necessary to first obtain the text of the function. Using pre-configured regular expressions, the starting and ending positions of the function code corresponding to each node are determined. After obtaining the starting and ending positions, the content of the function can be output in the format of a text file, thereby obtaining the text corresponding to each function (denoted as the target text). The target text is input into the feature extraction model, and the feature extraction model can extract and output the feature vector corresponding to each function. The feature vector corresponding to the function is the node feature vector corresponding to the function, thereby obtaining the node feature vector of each node in the directed graph. It can be understood that a regular expression is a logical formula for string operations, which consists of some predefined specific characters and combinations of these specific characters to form a rule string, and this rule string is used to express a filtering or screening logic for strings.
[0070] Among them, the feature extraction model is trained based on the LLM model, and the training process of the feature extraction model includes:
[0071] Obtain the code files of a preset number of sample smart contracts;
[0072] Concatenate the code files of all sample smart contracts to obtain a target text file;
[0073] Use the target text file as the input of the LLM model to perform unsupervised training operations to obtain the feature extraction model.
[0074] For example, obtain 100,000 sample smart contract code files without label information from a predetermined data source, and use the sample smart contract code files as training samples to train the model. The code files can be source code files. Before training, it is necessary to process the code files of the sample smart contracts and concatenate all the code files of the sample smart contracts into a text file (denoted as the target text file), that is, the target text file contains the code information of all training samples. Use the target text file as the input of the LLM model (for example, the Llama model), and by repeatedly masking a random segment of text in the target text file and asking the Llama model to complete it, the understanding of the semantics of the smart contract code by the Llama model can be enhanced, ensuring that after the smart contract code is used as the text input of the Llama, the output feature vector can accurately express the semantics of the smart contract code.
[0075] After extracting the node feature vectors of the directed graph using the feature extraction model, the vulnerability detection result of the target smart contract is identified based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph. The adjacency matrix of the directed graph is a two-dimensional matrix with N rows and N columns, which is used to represent the connection relationship between each node in the directed graph, where N represents the number of nodes in the directed graph. Specifically, based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph, identifying the vulnerability detection result of the target smart contract includes:
[0076] Dividing the directed graph into N multi-hop subgraphs, where N represents the number of nodes in the directed graph;
[0077] Inputting the node feature vector corresponding to each node, the multi-hop subgraph, and the adjacency matrix of the directed graph into a graph neural network to obtain the local feature of each node;
[0078] Based on the local features of each node, obtaining the target feature of the directed graph;
[0079] Inputting the target feature of the directed graph into a multi-layer perceptron network to obtain the vulnerability detection result of the target smart contract.
[0080] Assume that there are 50 nodes in a directed graph. Then the directed graph is sliced into 50 multi-hop subgraphs. In a directed graph, an edge from a node i to another node j is a first-degree edge of node i. If node j has a first-degree edge pointing to node k, then the edge from node i to node j and then to node k is a second-degree edge of node i. The set of all M-degree edges of node i is called the multi-hop subgraph of node i. A graph neural network can learn the relationships between nodes and represent the nodes with weights. The graph neural network represents the importance of each node through the connection relationships between nodes, that is, the weight value of a node represents the importance of the node in the directed graph. The larger the weight value, the more important the node. Inputting the node feature vector corresponding to each node, the multi-hop subgraph, and the adjacency matrix of the directed graph into the graph neural network together can obtain the local feature of the node. After obtaining the local features of each node, a network using the self-attention mechanism can obtain the target feature of the directed graph. Inputting the target feature of the directed graph into a multi-layer perceptron network can obtain the vulnerability detection result of the target smart contract. For example, an output vulnerability detection result of 1 indicates that the target smart contract has a vulnerability, and a vulnerability detection result of 0 indicates that the target smart contract has no vulnerability. Through the attention mechanism, the information of the entire directed graph can be comprehensively considered to generate a global feature with global information. A multi-layer perceptron network is a feedforward neural network model composed of multiple neuron layers. Each neuron layer is connected to all neurons in the previous layer and realizes non-linear mapping through the combination of weights and activation functions. By stacking multiple hidden layers, the multi-layer perceptron can learn more complex feature representations, thereby improving the accuracy of target smart contract vulnerability detection.
[0081] Further, obtaining the target feature of the directed graph based on the local feature of each node includes:
[0082] Inputting the local feature of each node into a self-attention mechanism network to obtain the global feature of each node;
[0083] Adding the global features of each node to obtain an addition result;
[0084] Dividing the addition result by the number of nodes to obtain the target feature of the directed graph.
[0085] Since the self-attention mechanism network can dynamically adjust the representation of nodes according to the relationships between nodes, by learning the relationships between a node and other nodes, it can capture the information transmission and influence between nodes, thereby generating a global feature representation. Therefore, by inputting the local features of all nodes into the self-attention mechanism network, the global features of each node can be obtained. The sum of the global features of all nodes is calculated to obtain a summation result, that is, the superimposed features. The feature obtained by dividing the summation result by the number of nodes N is used as the target feature of the directed graph, enabling the target feature to accurately represent the association information of the nodes in the directed graph.
[0086] In one embodiment, the method further includes:
[0087] Sending the vulnerability detection result of the target smart contract to a preset terminal.
[0088] After identifying the vulnerability detection result of the target smart contract, the vulnerability detection result of the target smart contract is sent to a preset terminal (for example, the terminals of developers and testers). When it is identified that the target smart contract has vulnerabilities, relevant personnel can timely repair the vulnerabilities of the target smart contract.
[0089] Refer to Figure 2 As shown, it is a schematic diagram of the functional modules of the vulnerability detection device 100 for smart contracts of the present application.
[0090] The vulnerability detection device 100 for smart contracts of the present application can be installed in an electronic device. According to the functions implemented, the vulnerability detection device 100 for smart contracts can include an acquisition module 110, a generation module 120, an extraction module 130, and a detection module 140. The modules of the present application can also be referred to as units, which refer to a series of computer program segments that can be executed by a processor of an electronic device and can complete fixed functions, and are stored in the memory of the electronic device.
[0091] In this embodiment, the functions of each module / unit are as follows:
[0092] The acquisition module 110: is used to acquire the target smart contract to be detected;
[0093] The generation module 120: is used to generate a directed graph of the target smart contract;
[0094] The extraction module 130: is used to extract the node feature vectors of the directed graph by using a pre-trained feature extraction model;
[0095] The detection module 140: is used to identify the vulnerability detection result of the target smart contract based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph.
[0096] In one embodiment, generating the directed graph of the target smart contract includes:
[0097] Analyze the call relationship between functions of the target smart contract;
[0098] Using the functions of the target smart contract as nodes and the call relationship as edges, generate the directed graph of the target smart contract.
[0099] In one embodiment, using the pre-trained feature extraction model to extract the node feature vectors of the directed graph includes:
[0100] Use regular expressions to determine the start position and end position of the function corresponding to each node in the directed graph;
[0101] Generate the target text corresponding to each function according to the start position and the end position;
[0102] Input the target text into the feature extraction model, and extract the features of the target text as the node feature vectors of the directed graph.
[0103] In one embodiment, the feature extraction model is trained based on a large language model, and the training process of the feature extraction model includes:
[0104] Obtain the code files of a preset number of sample smart contracts;
[0105] Concatenate the code files of all sample smart contracts to obtain a target text file;
[0106] Use the target text file as the input of the large language model to perform unsupervised training operations to obtain the feature extraction model.
[0107] In one embodiment, based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph, identifying the vulnerability detection result of the target smart contract includes:
[0108] Divide the directed graph into N multi-hop subgraphs, where N represents the number of nodes in the directed graph;
[0109] Input the node feature vector corresponding to each node, the multi-hop subgraph, and the adjacency matrix of the directed graph into a graph neural network to obtain the local feature of each node;
[0110] Based on the local features of each node, obtain the target feature of the directed graph;
[0111] Input the target feature of the directed graph into a multi-layer perceptron network to obtain the vulnerability detection result of the target smart contract.
[0112] In one embodiment, obtaining the target feature of the directed graph based on the local features of each node includes:
[0113] Inputting the local features of each node into a self-attention mechanism network to obtain the global feature of each node;
[0114] Adding the global features of each node to obtain an addition result;
[0115] Dividing the addition result by the number of nodes to obtain the target feature of the directed graph.
[0116] In one embodiment, the vulnerability detection device 100 of the smart contract further includes a sending module, and the sending module is used to send the vulnerability detection result of the target smart contract to a preset terminal.
[0117] Refer to Figure 3 As shown, it is a schematic diagram of a preferred embodiment of the electronic device of the present application.
[0118] The electronic device includes a processor 111, a communication interface 112, a memory 113, and a communication bus 114. Among them, the processor 111, the communication interface 112, and the memory 113 complete mutual communication through the communication bus 114;
[0119] The memory 113 is used to store computer programs, for example, the vulnerability detection program of the smart contract;
[0120] Among them, the processor 111 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips in some embodiments. The processor 111 is generally used to control the overall operation of the electronic device, for example, to execute control and processing related to data interaction or communication. In this embodiment, the processor 111 is used to run the program code stored in the memory 113 or process data, such as running the program code of the vulnerability detection program of the smart contract.
[0121] The communication interface 112 may optionally include a standard wired interface, a wireless interface (such as a WI-FI interface), and the communication interface 112 may also be used to establish a communication connection between the electronic device and other electronic devices.
[0122] The memory 113 includes at least one type of readable storage medium, which includes flash memory, hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 113 may be an internal storage unit of the electronic device, such as the hard disk or memory of the electronic device. In other embodiments, the memory 113 may also be an external storage device of the electronic device, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. equipped with the electronic device. Of course, the memory 113 may also include both the internal storage unit and the external storage device of the electronic device. In this embodiment, the memory 11 is generally used to store the operating system installed in the electronic device and various computer programs, such as the program code of the vulnerability detection program of the smart contract. In addition, the memory 113 may also be used to temporarily store various data that have been output or will be output.
[0123] Figure 3 Only the electronic device with components 111 - 114 is shown, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively.
[0124] In an embodiment of the present application, when the processor 111 executes the program stored on the memory 113, it implements the vulnerability detection method of the smart contract provided by any one of the foregoing method embodiments, including:
[0125] Obtain the target smart contract to be detected;
[0126] Generate a directed graph of the target smart contract;
[0127] Use a pre-trained feature extraction model to extract the node feature vectors of the directed graph;
[0128] Based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph, identify the vulnerability detection result of the target smart contract.
[0129] For a detailed introduction to the above steps, please refer to the above Figure 2 Regarding the functional module diagram of the vulnerability detection device 100 embodiment of the smart contract and Figure 1 Regarding the flowchart illustration of the vulnerability detection method embodiment of the smart contract.
[0130] In addition, an embodiment of the present application also provides a computer-readable storage medium, which can be non-volatile or volatile. The computer-readable storage medium includes a storage data area and a storage program area. The storage program area stores a vulnerability detection program for smart contracts. When the vulnerability detection program for smart contracts is executed by a processor, the following operations are implemented:
[0131] Obtain a target smart contract to be detected;
[0132] Generate a directed graph of the target smart contract;
[0133] Use a pre-trained feature extraction model to extract the node feature vectors of the directed graph;
[0134] Based on the node feature vectors of the directed graph and the adjacency matrix of the directed graph, identify the vulnerability detection result of the target smart contract.
[0135] The specific implementation manner of the computer-readable storage medium of the present application is substantially the same as that of the above-mentioned vulnerability detection method for smart contracts, and will not be elaborated here.
[0136] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0137] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the related technology, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0138] It should be noted that the descriptions involving "first", "second", etc. in this application are only for descriptive purposes and should not be construed as indicating or implying their relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one such feature. Additionally, the technical solutions between various embodiments may be combined with each other, but it must be based on the ability of those of ordinary skill in the art to implement. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by this application.
[0139] It should be understood that the terms used herein are for the purpose of describing particular example embodiments only and are not intended to be limiting. Unless the context clearly dictates otherwise, the singular forms "a", "an", and "the" as used herein may also include the plural forms. The terms "comprises", "comprising", "includes", and "having" are inclusive and thus specify the presence of the stated features, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not to be construed as necessarily requiring them to be performed in the particular order described or illustrated, unless the order of performance is explicitly stated. It should also be understood that alternative or additional steps may be used.
[0140] The above are only specific embodiments of this application, enabling those skilled in the art to understand or implement this application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to the embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features claimed herein.
Claims
1. A method for detecting vulnerabilities in smart contracts, characterized in that: The method comprises: Get the target smart contract to be tested; Generate a directed graph of the target smart contract, where the nodes of the directed graph represent functions of the target smart contract, and the edges of the directed graph represent call relationships between functions; Extracting node feature vectors of the directed graph using a pre-trained feature extraction model; Based on the node feature vector of the directed graph and the adjacency matrix of the directed graph, identifying the vulnerability detection result of the target smart contract; The identifying the vulnerability detection result of the target smart contract based on the node feature vector of the directed graph and the adjacency matrix of the directed graph includes: Divide the directed graph into N multi-hop subgraphs, where N represents the number of nodes in the directed graph; Inputting the node feature vector corresponding to each node, the multi-hop subgraph and the adjacency matrix of the directed graph into the graph neural network to obtain the local features of each node; Based on the local features of each node, obtaining the target features of the directed graph; Inputting the target features of the directed graph into a multi-layer perceptron network to obtain a vulnerability detection result of the target smart contract; The obtaining the target feature of the directed graph based on the local feature of each node includes: Inputting the local features of each node into the self-attention mechanism network to obtain the global features of each node; Adding the global features of each node to obtain an addition result; The added result is divided by the number of nodes to obtain the target feature of the directed graph.
2. The method for detecting a vulnerability in a smart contract according to claim 1, wherein: The generating the directed graph of the target smart contract comprises: Analyze the calling relationship between the functions of the target smart contract; A directed graph of the target smart contract is generated with the functions of the target smart contract as nodes and the call relationships as edges.
3. The method for detecting a vulnerability in a smart contract according to claim 1, wherein: The step of extracting the node feature vector of the directed graph by using a pre-trained feature extraction model includes: Determine the starting position and ending position of the function corresponding to each node in the directed graph by using a regular expression; Generate a target text corresponding to each function according to the starting position and the ending position; The target text is input into the feature extraction model, and the features of the target text are extracted as node feature vectors of the directed graph.
4. The method for detecting a vulnerability in a smart contract according to claim 1, wherein: The feature extraction model is obtained based on the training of the large language model. The training process of the feature extraction model includes: Get a preset number of sample smart contract code files; Concatenate the code files of all sample smart contracts to obtain the target text file; The target text file is used as an input of a large language model to perform an unsupervised training operation to obtain the feature extraction model.
5. The method for detecting a vulnerability in a smart contract according to any one of claims 1 to 4, characterized in that: The method further comprises: The vulnerability detection result of the target smart contract is sent to a preset terminal.
6. A smart contract vulnerability detection device, characterized in that: The device comprises: Acquisition module: used to obtain the target smart contract to be detected; Generation module: used to generate a directed graph of the target smart contract, where the nodes of the directed graph represent the functions of the target smart contract, and the edges of the directed graph represent the calling relationship between the functions; Extraction module: used to extract node feature vectors of the directed graph using a pre-trained feature extraction model; Detection module: used to identify the vulnerability detection result of the target smart contract based on the node feature vector of the directed graph and the adjacency matrix of the directed graph; The identifying the vulnerability detection result of the target smart contract based on the node feature vector of the directed graph and the adjacency matrix of the directed graph includes: Divide the directed graph into N multi-hop subgraphs, where N represents the number of nodes in the directed graph; Inputting the node feature vector corresponding to each node, the multi-hop subgraph and the adjacency matrix of the directed graph into the graph neural network to obtain the local features of each node; Based on the local features of each node, obtaining the target features of the directed graph; Inputting the target features of the directed graph into a multi-layer perceptron network to obtain a vulnerability detection result of the target smart contract; The obtaining the target feature of the directed graph based on the local feature of each node includes: Inputting the local features of each node into the self-attention mechanism network to obtain the global features of each node; Adding the global features of each node to obtain an addition result; The added result is divided by the number of nodes to obtain the target feature of the directed graph.
7. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, configured to implement the vulnerability detection method for a smart contract according to any one of claims 1 to 5 when executing a program stored in a memory.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the vulnerability detection method for the smart contract as described in any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Intelligent contract vulnerability detection method based on graph neural network
CN116383832A
Explanatable intelligent contract vulnerability detection and positioning method based on reinforcement learning
CN117272312A