A fine-grained vulnerability detection method, system, device and storage medium for smart contracts

By generating a collection of code control flows for smart contracts and inputting prompt templates and residual networks, the complexity and fine-grained positioning problems of existing smart contract vulnerability detection methods are solved, efficient vulnerability scoring and sorting are achieved, and vulnerability detection and repair processes are simplified.

CN119598475BActive Publication Date: 2025-05-16NANJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510140022.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-16
Estimated Expiration
2045-02-08

AI Technical Summary

Technical Problem

The existing smart contract vulnerability detection methods require pre-set complex graph feature extraction rules and cannot be positioned to specific code fragments in a fine-grained manner, resulting in cumbersome detection and inconvenient repair.

Method used

By obtaining smart contract code data, generating a code control flow set, and inputting it to the prompt template and residual network, a reparameterized embedding sequence is obtained. Then, the sequence is input into the pre-trained fine-grained vulnerability detection model to perform vulnerability scoring and sorting to achieve fine-grained vulnerability detection.

Benefits of technology

It solves the cumbersome problem of complex graph feature extraction rules, realizes fine-grained detection of smart contract vulnerabilities, and can quantify the severity of code control flow vulnerabilities and sort it, which is convenient for developers to handle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119598475B_ABST
    Figure CN119598475B_ABST
Patent Text Reader

Abstract

The present invention discloses a fine-grained vulnerability detection method, system, device and storage medium for smart contracts, and belongs to the technical field of smart contract vulnerability detection. The method includes obtaining code data of a smart contract to be detected including several statements; traversing the code data of the smart contract to be detected according to the node type of the statement to generate a code control flow set; inputting the code control flow set into a prompt template to obtain a prompt text embedding sequence corresponding to each code control flow; inputting the prompt text embedding sequence corresponding to each code control flow into a residual network, and converting it into a reparameterized embedding sequence through a residual reparameterization operation; inputting the reparameterized embedding sequence into a fine-grained vulnerability detection model to obtain a vulnerability set of the smart contract to be detected, and scoring and calculating the vulnerabilities corresponding to each code control flow, and sorting them according to the scoring calculation results to obtain a fine-grained vulnerability detection result. The present invention realizes the detection of code control flows with vulnerabilities and obtains fine-grained vulnerability detection results.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of smart contract vulnerability detection, and specifically relates to a fine-grained vulnerability detection method, system, device and storage medium for smart contracts. Background Art

[0002] Smart contracts are executable programs written in code based on the blockchain platform and are widely used in fields such as finance and healthcare. The source code of smart contracts is similar to other programming languages. There are risks of vulnerabilities that cannot be ignored due to programmers' lack of development experience or lax project code review. The reasons why smart contracts are vulnerable to security vulnerabilities mainly include the following aspects: first, the programming language and tools of smart contracts are not mature enough, which makes smart contracts written with these new tools more difficult to test; second, smart contract developers may not be able to fully grasp the basic logic of programming languages ​​and tools, causing them to write smart contracts with security flaws or vulnerable to attacks; finally, because digital currencies on the blockchain are managed by smart contracts, smart contracts have become an attractive target for attackers. Many malicious attackers try to exploit vulnerabilities in smart contracts through various means to steal funds or destroy blockchain networks. Therefore, it is crucial to detect vulnerabilities in smart contracts.

[0003] Existing smart contract vulnerability detection methods can be roughly divided into formal verification methods, symbolic execution methods, and deep learning methods. Among them, deep learning methods usually extract graph neural network features of smart contract source code or bytecode, and convert the source code into pre-designed nodes and edges to capture specific vulnerability patterns. However, detection methods based on graph neural networks often require pre-designed complex node and edge extraction rules, which greatly increases the cumbersomeness of vulnerability detection. At the same time, most of the existing deep learning methods cannot locate the specific code snippets containing vulnerabilities in a fine-grained manner, which brings inconvenience to researchers in fixing smart contract vulnerabilities. Summary of the invention

[0004] The purpose of the present invention is to overcome the deficiencies in the prior art and to provide a fine-grained vulnerability detection method, system, device and storage medium for smart contracts, which solves the problem of needing to pre-set complex graph feature extraction rules and being unable to locate specific code snippets in a fine-grained manner.

[0005] The present invention provides the following technical solutions:

[0006] In a first aspect, a fine-grained vulnerability detection method for a smart contract is provided, comprising: obtaining code data of a smart contract to be detected including several statements; traversing the code data of the smart contract to be detected according to the node type of the statement to generate a code control flow set; inputting the code control flow set into a pre-acquired prompt template to obtain a prompt text embedding sequence corresponding to each code control flow; inputting the prompt text embedding sequence corresponding to each code control flow into a residual network, and converting it into a reparameterized embedding sequence through a residual reparameterization operation; inputting the reparameterized embedding sequence into a pre-trained fine-grained vulnerability detection model to obtain a vulnerability set of the smart contract to be detected, scoring and calculating the vulnerabilities corresponding to each code control flow in the vulnerability set, and sorting them according to the results of the scoring calculation to obtain a fine-grained vulnerability detection result.

[0007] As an optional technical solution of the present invention, the code data of the smart contract to be detected is traversed according to the node type of the statement to generate a code control flow set, including:

[0008] The node types of the statement include regular nodes, conditional judgment nodes, loop judgment nodes, entry nodes and exit nodes;

[0009] Traverse the code data of the smart contract to be tested, expressed as:

[0010] ;

[0011] in, A set of statements representing the smart contract code data to be tested. Indicates the first, second, ..., A statement, Indicates the total number of statements;

[0012] A set of statements for the smart contract code data to be tested Any entry node , add it to the corresponding code control flow , and the corresponding code control flow As the current code control flow, determine the entry node The current follow-up statement The node type, ;

[0013] If the current follow-up statement If it is a regular node, the current subsequent statement Join the current code control flow , and continue to traverse the next statement; if the current subsequent statement For conditional judgment nodes, create a control flow with the current code Same first synchronization code control flow , the current subsequent statement and the success statement to judge success Join the current code control flow , the current subsequent statement And the failure statement to judge failure Add the first synchronous code control flow, and traverse the subsequent statements of the successful statement and the failed statement respectively; if the current subsequent statement For loop judgment nodes, create a control flow with the current code The same second synchronization code controls the flow , the current subsequent statement And the loop statement to judge success Join the current code control flow , the current subsequent statement And non-loop statements that jump out of the loop when the judgment fails Adding a second synchronous code control flow , traverse the subsequent statements of loop statements and non-loop statements respectively; if the current subsequent statement If it is an exit node, the current subsequent statement Join the current code control flow Then end the current traversal;

[0014] After traversing all the entry nodes in the smart contract code data to be detected, the code control flow set is obtained, which is expressed as:

[0015] ;

[0016] in, Represents a collection of code control flows, Indicates the first, second, ..., The code controls the flow. Represents the total number of code control flows, which is equal to the number of entry nodes.

[0017] As an optional technical solution of the present invention, after the code control flow set is generated, each code control flow in the code control flow set is converted into a tag embedding sequence, including:

[0018] For any code control flow in the code control flow set , convert it into a tag sequence, represented as:

[0019] ;

[0020] in, represents a tag sequence, Indicates the first, second, ..., Marks, Indicates the total number of markers;

[0021] Mark any tag in the sequence Converted to an embedding vector, represented as:

[0022] ;

[0023] in, Indicates the mark The corresponding embedding vector, represents the word embedding matrix, represents the type embedding matrix, Indicates the number of markers, Indicates the number of tag types. represents the dimension of the embedding vector;

[0024] The tag embedding sequence includes a tag word embedding sequence and a tag type embedding sequence, which is expressed as:

[0025] ;

[0026] in, Represents any code control flow The tag embedding sequence is Indicates the first, second, ..., The embedding vector corresponding to each tag.

[0027] As an optional technical solution of the present invention, a set of code control flows is input into a pre-acquired prompt template to obtain a prompt text embedding sequence corresponding to each code control flow, including:

[0028] Any code control flow in the code control flow set Add the prompt template and get the prompt text, expressed as;

[0029] ;

[0030] in, Represents any code control flow The corresponding prompt text, A mask mark indicating the beginning of the prompt template. The mask tokens representing the predicted label vocabulary, A mask token representing a segment of text, Represents the natural language template text in the prompt text;

[0031] The prompt text Control flow of code The outer part is converted into a tag sequence, and then through the word embedding matrix After converting the token sequence into the corresponding embedding sequence, After concatenation, we get the hint text embedding sequence, expressed as:

[0032] ;

[0033] in, Represents a sequence of hint text embeddings, Indicates mask mark The corresponding embedding sequence is Indicates mask mark The corresponding embedding sequence is Indicates mask mark The corresponding embedding sequence is Represents the embedding sequence of the natural language template text in the prompt text.

[0034] As an optional technical solution of the present invention, the prompt text embedding sequence corresponding to each code control flow is input into the residual network, and converted into a reparameterized embedding sequence through a residual reparameterization operation, including:

[0035] For the hint text embedding sequence Any embedding sequence in , perform residual reparameterization operation, expressed as:

[0036] ;

[0037] ;

[0038] in, represents the reparameterization result, represents the residual reparameterization operation, represents the dimension reduction matrix, represents a dimension-raising matrix, represents a nonlinear activation function;

[0039] The reparameterized embedding sequence is obtained, expressed as:

[0040] ;

[0041] in, represents the reparameterized embedding sequence, Indicates mask mark The corresponding embedding sequence The reparameterization result of Represents a tag embedding sequence The reparameterization result of Indicates mask mark The corresponding embedding sequence The reparameterization result of Represents the embedding sequence of the natural language template text in the prompt text The reparameterization result of Indicates mask mark The corresponding embedding sequence The reparameterization result of .

[0042] As an optional technical solution of the present invention, the re-parameterized embedding sequence is input into a pre-trained fine-grained vulnerability detection model to obtain a vulnerability set of the smart contract to be detected, including:

[0043] Obtain a label vocabulary set including security words and vulnerability words;

[0044] The predicted probability of each label word is calculated according to the reparameterized embedding sequence, which is expressed as:

[0045] ;

[0046] in, Indicates The predicted probability of the label words, Indicates the prediction Tag vocabulary, represents the reparameterized embedding sequence, It means to find the conditional probability;

[0047] The probability distribution vector of each label vocabulary is calculated through the head neural network in the fine-grained vulnerability detection model, which is expressed as:

[0048] ;

[0049] in, Represents the probability distribution vector of each label vocabulary, represents the head neural network;

[0050] According to the probability distribution vector of each label vocabulary Calculate the predicted probability value of each label word and get the label word with the maximum predicted probability , expressed as:

[0051] ;

[0052] in, Represents a function. When the function value is the largest, take the parameter , Indicates the total number of label words;

[0053] The maximum predicted probability label word As the final predicted label word, if the final predicted label word belongs to a safe word, it indicates that the current code control flow is safe; if the final predicted label word belongs to a vulnerability word, it indicates that there is a vulnerability in the current code control flow, and it is added to the vulnerability set.

[0054] As an optional technical solution of the present invention, the vulnerabilities corresponding to each code control flow in the vulnerability set are scored and calculated, and the scores are sorted according to the score calculation results to obtain fine-grained vulnerability detection results, including:

[0055] Based on the maximum predicted probability label word of each code control flow in the vulnerability set , the vulnerabilities corresponding to each code control flow are scored and calculated, expressed as:

[0056] ;

[0057] in, Represents any code control flow score;

[0058] According to the size of the score, the code control flows in the vulnerability set are sorted from high to low to obtain fine-grained vulnerability detection results.

[0059] In a second aspect, a fine-grained vulnerability detection system for smart contracts is provided, including: a data acquisition module, used to acquire code data of a smart contract to be detected including a plurality of statements;

[0060] A traversal module, used to traverse the smart contract code data to be detected according to the node type of the statement, and generate a code control flow set;

[0061] A prompt text module is used to input the code control flow set into the pre-acquired prompt template to obtain the prompt text embedding sequence corresponding to each code control flow;

[0062] The residual module is used to input the prompt text embedding sequence corresponding to each code control flow into the residual network, and convert it into a reparameterized embedding sequence through the residual reparameterization operation;

[0063] The detection module is used to input the re-parameterized embedding sequence into a pre-trained fine-grained vulnerability detection model to obtain a vulnerability set of the smart contract to be detected, score the vulnerabilities corresponding to each code control flow in the vulnerability set, and sort them according to the results of the score calculation to obtain a fine-grained vulnerability detection result.

[0064] In a third aspect, a fine-grained vulnerability detection device for a smart contract is provided, comprising a processor and a storage medium; the storage medium is used to store instructions; the processor is used to operate according to the instructions to execute the steps of the fine-grained vulnerability detection method for the smart contract described in the first aspect.

[0065] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the steps of the fine-grained vulnerability detection method for smart contracts described in the first aspect.

[0066] Compared with the prior art, the present invention has the following beneficial effects:

[0067] The present invention provides a fine-grained vulnerability detection method for smart contracts. The method obtains a re-parameterized embedding sequence through a prompt template and a residual network, thereby solving the problem of needing to pre-set complex graph feature extraction rules and improving the simplicity of vulnerability detection. The method accurately captures the calling relationship between statements in the smart contract through the node type of the statement, and fine-grains the detection object from the entire smart contract into a code control flow, thereby realizing fine-grained detection of smart contract vulnerabilities. At the same time, the vulnerabilities corresponding to each code control flow in the vulnerability set are scored and calculated, and the severity of the code control flow vulnerabilities is quantified and ranked, which helps developers to handle them according to vulnerability priority. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] Figure 1 is a flow chart of a fine-grained vulnerability detection method for a smart contract in an embodiment of the present invention;

[0069] Figure 2 It is a schematic diagram of generating a code control flow set in an embodiment of the present invention. DETAILED DESCRIPTION

[0070] The present invention will be further described below in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and cannot be used to limit the protection scope of the present invention.

[0071] Example 1

[0072] This embodiment provides a fine-grained vulnerability detection method for smart contracts. Figure 1 As shown, the specific steps include:

[0073] Step 1: Obtain the smart contract code data to be tested, including several statements.

[0074] like Figure 2 As shown, the statements of the smart contract to be tested include functions (accumulate funds), function (Deposit), Function (Withdrawal) and function (Equal amounts).

[0075] Step 2: Traverse the smart contract code data to be tested according to the node type of the statement and generate a code control flow set.

[0076] In this embodiment, the node types of the statement include regular nodes, conditional judgment nodes, loop judgment nodes, entry nodes and exit nodes. Among them, regular nodes include placeholders, variable assignments and operation statements; conditional judgment nodes include conditional judgment statements; loop judgment nodes include loop judgment statements; entry nodes include function start statements; and exit nodes include function end statements.

[0077] Step 2.1: Traverse the smart contract code data to be tested, expressed as:

[0078] ;

[0079] in, A set of statements representing the smart contract code data to be tested. Indicates the first, second, ..., A statement, Indicates the total number of statements.

[0080] Step 2.2: Statement set for the smart contract code data to be tested Any entry node , add it to the corresponding code control flow , and the corresponding code control flow As the current code control flow, determine the entry node The current follow-up statement The node type, .

[0081] Specifically, if the current follow-up statement If it is a regular node, the current subsequent statement Join the current code control flow , and continue to traverse the next statement; if the current subsequent statement For conditional judgment nodes, create a control flow with the current code Same first synchronization code control flow , the current subsequent statement and the success statement to judge success Join the current code control flow , the current subsequent statement And the failure statement to judge failure Add the first synchronous code control flow, and traverse the subsequent statements of the successful statement and the failed statement respectively; if the current subsequent statement For loop judgment nodes, create a control flow with the current code The same second synchronization code controls the flow , the current subsequent statement And the loop statement to judge success Join the current code control flow , the current subsequent statement And non-loop statements that jump out of the loop when the judgment fails Adding a second synchronous code control flow , traverse the subsequent statements of loop statements and non-loop statements respectively; if the current subsequent statement If it is an exit node, the current subsequent statement Join the current code control flow Then end the current traversal.

[0082] Step 2.3: After traversing all entry nodes in the smart contract code data to be detected, the code control flow set is obtained, which is expressed as:

[0083] ;

[0084] in, Represents a collection of code control flows, Indicates the first, second, ..., The code controls the flow. Represents the total number of code control flows, which is equal to the number of entry nodes.

[0085] like Figure 2 As shown in the figure, the smart contract code data to be tested includes 4 function statements, and the code control flow of each function statement is traversed separately. The corresponding code control flow is ,function The corresponding code control flow is ,function The corresponding code control flow is ,function The corresponding code control flow is , where the number represents the line number of the code statement. Figure 2 In the code control flow set, the red part indicates the code control flow with vulnerabilities, and the green part indicates the safe code control flow.

[0086] Step 3: After the code control flow set is generated, each code control flow in the code control flow set is converted into a tag embedding sequence.

[0087] Step 3.1: For any code control flow in the code control flow set , convert it into a tag sequence, represented as:

[0088] ;

[0089] in, represents a tag sequence, Indicates the first, second, ..., Marks, Indicates the total number of tags.

[0090] Step 3.2, then add the tag type for each code element corresponding to the tag, including keywords, variable names, operators and separators. Converted to an embedding vector, represented as:

[0091] ;

[0092] in, Indicates the mark The corresponding embedding vector, represents the word embedding matrix, represents the type embedding matrix, Indicates the number of markers, Indicates the number of tag types. Represents the dimension of the embedding vector. In this embodiment .

[0093] Step 3.3, the tag embedding sequence includes a tag word embedding sequence and a tag type embedding sequence, which is expressed as:

[0094] ;

[0095] in, Represents any code control flow The tag embedding sequence is Indicates the first, second, ..., The embedding vector corresponding to each tag.

[0096] Step 4: Input the code control flow set into the pre-acquired prompt template to obtain the prompt text embedding sequence corresponding to each code control flow.

[0097] Step 4.1: any code control flow in the code control flow set Add the prompt template and get the prompt text, expressed as;

[0098] ;

[0099] in, Represents any code control flow The corresponding prompt text, A mask mark indicating the beginning of the prompt template. The mask tokens representing the predicted label vocabulary, A mask token representing a segment of text, Represents the natural language template text in the prompt text.

[0100] Step 4.2: Change the prompt text Control flow of code The outer part is converted into a tag sequence, and then through the word embedding matrix After converting the token sequence into the corresponding embedding sequence, After concatenation, we get the hint text embedding sequence, expressed as:

[0101] ;

[0102] in, Represents a sequence of hint text embeddings, Indicates mask mark The corresponding embedding sequence is Indicates mask mark The corresponding embedding sequence is Indicates mask mark The corresponding embedding sequence is Represents the embedding sequence of the natural language template text in the prompt text.

[0103] Step 5: Input the prompt text embedding sequence corresponding to each code control flow into the residual network and convert it into a reparameterized embedding sequence through the residual reparameterization operation.

[0104] For the hint text embedding sequence Any embedding sequence in , perform residual reparameterization operation, expressed as:

[0105] ;

[0106] ;

[0107] in, represents the reparameterization result, represents the residual reparameterization operation, represents the dimension reduction matrix, represents a dimension-raising matrix, represents a non-linear activation function.

[0108] The reparameterized embedding sequence is obtained, expressed as:

[0109] ;

[0110] in, represents the reparameterized embedding sequence, Indicates mask mark The corresponding embedding sequence The reparameterization result of Represents a tag embedding sequence The reparameterization result of Indicates mask mark The corresponding embedding sequence The reparameterization result of Represents the embedding sequence of the natural language template text in the prompt text The reparameterization result of Indicates mask mark The corresponding embedding sequence The reparameterization result of .

[0111] Step 6: Input the re-parameterized embedding sequence into a pre-trained fine-grained vulnerability detection model to obtain a vulnerability set of the smart contract to be detected, score the vulnerabilities corresponding to each code control flow in the vulnerability set, and sort them according to the score calculation results to obtain fine-grained vulnerability detection results.

[0112] Step 6.1: Obtain a label vocabulary set including security words and vulnerability words.

[0113] In this embodiment, the tag vocabulary set is represented as:

[0114] ;

[0115] in, represents the label vocabulary, , label space , Indicates that there is a vulnerability. Indicates safety, and Represent the sets of vulnerability words and security words respectively.

[0116] Step 6.2: Calculate the predicted probability of each label word according to the reparameterized embedding sequence, expressed as:

[0117] ;

[0118] in, Indicates The predicted probability of the label words, Indicates the prediction Tag vocabulary, represents the reparameterized embedding sequence, It means conditional probability.

[0119] Step 6.3, calculate the probability distribution vector of each label word through the head neural network in the fine-grained vulnerability detection model, expressed as:

[0120] ;

[0121] in, Represents the probability distribution vector of each label vocabulary, Represents the head neural network.

[0122] Step 6.4: Based on the probability distribution vector of each label vocabulary Calculate the predicted probability value of each label word and get the label word with the maximum predicted probability , expressed as:

[0123] ;

[0124] in, Represents a function. When the function value is the largest, take the parameter , Indicates the total number of label words.

[0125] Step 6.5: label the word with the maximum predicted probability As the final predicted label word, if the final predicted label word belongs to a safe word, it indicates that the current code control flow is safe; if the final predicted label word belongs to a vulnerability word, it indicates that there is a vulnerability in the current code control flow, and it is added to the vulnerability set.

[0126] Step 6.6: label words with the maximum predicted probability of each code control flow in the vulnerability set , evaluate the vulnerabilities corresponding to each code control flow, expressed as:

[0127] ;

[0128] in, Represents any code control flow score.

[0129] In this embodiment, the function The corresponding code control flow score is expressed as:

[0130] .

[0131] Step 6.7: Sort the code control flows in the vulnerability set from high to low according to the scores to obtain fine-grained vulnerability detection results.

[0132] Example 2

[0133] This embodiment provides a brief description of the training process of the fine-grained vulnerability detection model based on Embodiment 1. The details are as follows:

[0134] Step 1: Obtain a real smart contract code dataset and its real label set, and preprocess the real smart contract code data to obtain a labeled embedding sequence.

[0135] The real smart contract code dataset is represented as:

[0136] ;

[0137] in, represents a dataset of real smart contract codes, Indicates the first, second, ..., Real smart contract code data.

[0138] The true label set is expressed as:

[0139] ;

[0140] in, represents the true label set, Indicates the first, second, ..., The real labels, , Indicates that there is a vulnerability. Indicates safety.

[0141] Referring to step 3 of Example 1, the real smart contract code dataset Code samples in Convert to a sequence of tokens , and then through the word embedding matrix and type embedding matrix Mark the sequence The tokens in are converted into embedding vectors , and finally the real smart contract code dataset Convert to a token embedding sequence including a token word embedding sequence and a token type embedding sequence .

[0142] Step 2: Enter the real smart contract code dataset into the prompt template to get the prompt text.

[0143] The smart contract vulnerability detection task is converted into mask modeling through the prompt template. Code samples in Add the prompt template, and the resulting prompt text is expressed as:

[0144] ;

[0145] in, Represents code sample The prompt text.

[0146] Step 3: Convert the prompt text into a re-parameterized embedding vector through the residual network.

[0147] Referring to step 4.2 in Example 1, based on the prompt text Get hint text embedding sequence Referring to step 5 in Example 1, the prompt text is embedded in the sequence Input the residual network to get the reparameterized embedding sequence .

[0148] The prompt text is converted into a re-parameterized embedding vector through the residual network, and the model only needs to optimize the parameters of the incremental part to reduce the overhead of model training and inference.

[0149] Step 4: Input the re-parameterized embedding vector into the pre-acquired CodeBERT model to obtain a prediction result.

[0150] This example uses the CodeBERT model for training. Refer to steps 6.1 to 6.5 of Example 1 to obtain the maximum predicted probability label word , and the maximum predicted probability label word Mapping to the final predicted label , and get the prediction result.

[0151] Step 5: Based on the prediction results, update the parameters of the residual network and CodeBERT model by minimizing the loss function to obtain a fine-grained vulnerability detection model.

[0152] The loss function is expressed as:

[0153] ;

[0154] in, represents the minimization of the cross entropy loss function, and are respectively the prompt text embedding sequence and residual reparameterization operation Parameters.

[0155] After back-propagation optimization of various parameters, a fine-grained vulnerability detection model is obtained. The fine-grained vulnerability detection model obtained through the above pre-training uses the residual network to fix some model parameters, and only updates the weight parameters related to the model and the task, reducing the model's overhead in the training and reasoning stages. Through the prompt template, the smart contract vulnerability detection task is converted into a mask word prediction task for the prompt text. The residual network incremental parameters of the model are optimized by minimizing the cross-entropy loss function to ensure that the model can learn from the training data and adapt to specific vulnerability detection tasks.

[0156] Example 3

[0157] This embodiment provides a fine-grained vulnerability detection system for smart contracts, including:

[0158] A data acquisition module, used to acquire the code data of the smart contract to be tested, including several statements;

[0159] A traversal module, used to traverse the smart contract code data to be detected according to the node type of the statement, and generate a code control flow set;

[0160] A prompt text module is used to input the code control flow set into the pre-acquired prompt template to obtain the prompt text embedding sequence corresponding to each code control flow;

[0161] The residual module is used to input the prompt text embedding sequence corresponding to each code control flow into the residual network, and convert it into a reparameterized embedding sequence through the residual reparameterization operation;

[0162] The detection module is used to input the re-parameterized embedding sequence into a pre-trained fine-grained vulnerability detection model to obtain a vulnerability set of the smart contract to be detected, score the vulnerabilities corresponding to each code control flow in the vulnerability set, and sort them according to the results of the score calculation to obtain a fine-grained vulnerability detection result.

[0163] Example 4

[0164] This embodiment provides a fine-grained vulnerability detection device for a smart contract, including a processor and a storage medium; the storage medium is used to store instructions; the processor is used to operate according to the instructions to execute the steps of the fine-grained vulnerability detection method for the smart contract described in Example 1.

[0165] Example 5

[0166] This embodiment provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the steps of the fine-grained vulnerability detection method for smart contracts described in Example 1 are implemented.

[0167] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0168] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0169] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0170] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0171] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A fine-grained vulnerability detection method for smart contracts, characterized in that: include: Obtaining the smart contract code data to be tested including several statements; Traverse the smart contract code data to be detected according to the node type of the statement, and generate a code control flow set; Input the code control flow set into the pre-acquired prompt template to obtain the prompt text embedding sequence corresponding to each code control flow; The prompt text embedding sequence corresponding to each code control flow is input into the residual network and converted into a reparameterized embedding sequence through the residual reparameterization operation; Input the re-parameterized embedding sequence into a pre-trained fine-grained vulnerability detection model to obtain a vulnerability set of the smart contract to be detected, score the vulnerabilities corresponding to each code control flow in the vulnerability set, and sort them according to the score calculation results to obtain a fine-grained vulnerability detection result; Among them, the code data of the smart contract to be detected is traversed according to the node type of the statement to generate a code control flow set, including: The node types of the statement include regular nodes, conditional judgment nodes, loop judgment nodes, entry nodes and exit nodes; Traverse the code data of the smart contract to be tested, expressed as: ; in, A set of statements representing the smart contract code data to be tested. Indicates the first, second, ..., A statement, Indicates the total number of statements; A set of statements for the smart contract code data to be tested Any entry node , add it to the corresponding code control flow , and the corresponding code control flow As the current code control flow, determine the entry node The current follow-up statement The node type, ; If the current follow-up statement If it is a regular node, the current subsequent statement Join the current code control flow , and continue to traverse the next statement; if the current subsequent statement For conditional judgment nodes, create a control flow with the current code Same first synchronization code control flow , the current subsequent statement and the success statement to judge success Join the current code control flow , the current subsequent statement And the failure statement to judge failure Add the first synchronous code control flow, and traverse the subsequent statements of the successful statement and the failed statement respectively; if the current subsequent statement For loop judgment nodes, create a control flow with the current code The same second synchronization code controls the flow , the current subsequent statement And the loop statement to judge success Join the current code control flow , the current subsequent statement And non-loop statements that jump out of the loop when the judgment fails Adding a second synchronous code control flow , traverse the subsequent statements of loop statements and non-loop statements respectively; if the current subsequent statement If it is an exit node, the current subsequent statement Join the current code control flow Then end the current traversal; After traversing all the entry nodes in the smart contract code data to be detected, the code control flow set is obtained, which is expressed as: ; in, Represents a collection of code control flows, Indicates the first, second, ..., The code controls the flow. Represents the total number of code control flows, which is equal to the number of entry nodes.

2. The fine-grained vulnerability detection method for smart contracts according to claim 1 is characterized in that: After the code control flow set is generated, each code control flow in the code control flow set is converted into a tag embedding sequence, including: For any code control flow in the code control flow set , convert it into a tag sequence, represented as: ; in, represents a tag sequence, Indicates the first, second, ..., Marks, Indicates the total number of markers; Mark any tag in the sequence Converted to an embedding vector, represented as: ; in, Indicates the mark The corresponding embedding vector, represents the word embedding matrix, represents the type embedding matrix, Indicates the number of markers, Indicates the number of tag types. represents the dimension of the embedding vector; The tag embedding sequence includes a tag word embedding sequence and a tag type embedding sequence, which is expressed as: ; in, Represents any code control flow The tag embedding sequence is Indicates the first, second, ..., The embedding vector corresponding to each tag.

3. The fine-grained vulnerability detection method for smart contracts according to claim 2 is characterized in that: Input the code control flow set into the pre-acquired prompt template to obtain the prompt text embedding sequence corresponding to each code control flow, including: Any code control flow in the code control flow set Add the prompt template and get the prompt text, expressed as; ; in, Represents any code control flow The corresponding prompt text, A mask mark indicating the beginning of the prompt template. The mask tokens representing the predicted label vocabulary, A mask token representing a segment of text, Represents the natural language template text in the prompt text; The prompt text Control flow of code The outer part is converted into a tag sequence, and then through the word embedding matrix After converting the token sequence into the corresponding embedding sequence, After concatenation, we get the hint text embedding sequence, expressed as: ; in, Represents a sequence of hint text embeddings, Indicates mask mark The corresponding embedding sequence is Indicates mask mark The corresponding embedding sequence is Indicates mask mark The corresponding embedding sequence is Represents the embedding sequence of the natural language template text in the prompt text.

4. The fine-grained vulnerability detection method for smart contracts according to claim 3 is characterized in that: The prompt text embedding sequence corresponding to each code control flow is input into the residual network and converted into a reparameterized embedding sequence through the residual reparameterization operation, including: For the hint text embedding sequence Any embedding sequence in , perform residual reparameterization operation, expressed as: ; ; in, represents the reparameterization result, represents the residual reparameterization operation, represents the dimension reduction matrix, represents a dimension-raising matrix, represents a nonlinear activation function; The reparameterized embedding sequence is obtained, expressed as: ; in, represents the reparameterized embedding sequence, Indicates mask mark The corresponding embedding sequence The reparameterization result of Represents a tag embedding sequence The reparameterization result of Indicates mask mark The corresponding embedding sequence The reparameterization result of Represents the embedding sequence of the natural language template text in the prompt text The reparameterization result of Indicates mask mark The corresponding embedding sequence The reparameterization result of .

5. The fine-grained vulnerability detection method for smart contracts according to claim 1 is characterized in that: The re-parameterized embedding sequence is input into a pre-trained fine-grained vulnerability detection model to obtain a vulnerability set of the smart contract to be detected, including: Obtain a label vocabulary set including security words and vulnerability words; The predicted probability of each label word is calculated according to the reparameterized embedding sequence, which is expressed as: ; in, Indicates The predicted probability of the label words, Indicates the prediction Tag vocabulary, represents the reparameterized embedding sequence, It means to find the conditional probability; The probability distribution vector of each label vocabulary is calculated through the head neural network in the fine-grained vulnerability detection model, which is expressed as: ; in, Represents the probability distribution vector of each label vocabulary, represents the head neural network; According to the probability distribution vector of each label vocabulary Calculate the predicted probability value of each label word and get the label word with the maximum predicted probability , expressed as: ; in, Represents a function. When the function value is the largest, take the parameter , Indicates the total number of label words; The maximum predicted probability label word As the final predicted label word, if the final predicted label word belongs to a safe word, it indicates that the current code control flow is safe; if the final predicted label word belongs to a vulnerability word, it indicates that there is a vulnerability in the current code control flow, and it is added to the vulnerability set.

6. The fine-grained vulnerability detection method for smart contracts according to claim 5 is characterized in that: The vulnerabilities corresponding to each code control flow in the vulnerability set are scored and sorted according to the score calculation results to obtain fine-grained vulnerability detection results, including: According to the maximum predicted probability label word of each code control flow in the vulnerability set , the vulnerabilities corresponding to each code control flow are scored and calculated, expressed as: ; in, Represents any code control flow score; According to the size of the score, the code control flows in the vulnerability set are sorted from high to low to obtain fine-grained vulnerability detection results.

7. A fine-grained vulnerability detection system for smart contracts, characterized in that: include: A data acquisition module, used to acquire the code data of the smart contract to be tested, including several statements; A traversal module, used to traverse the smart contract code data to be detected according to the node type of the statement, and generate a code control flow set; A prompt text module is used to input the code control flow set into the pre-acquired prompt template to obtain the prompt text embedding sequence corresponding to each code control flow; The residual module is used to input the prompt text embedding sequence corresponding to each code control flow into the residual network, and convert it into a reparameterized embedding sequence through the residual reparameterization operation; A detection module, used to input the re-parameterized embedding sequence into a pre-trained fine-grained vulnerability detection model to obtain a vulnerability set of the smart contract to be detected, score the vulnerabilities corresponding to each code control flow in the vulnerability set, and sort them according to the score calculation results to obtain a fine-grained vulnerability detection result; Among them, the code data of the smart contract to be detected is traversed according to the node type of the statement to generate a code control flow set, including: The node types of the statement include regular nodes, conditional judgment nodes, loop judgment nodes, entry nodes and exit nodes; Traverse the code data of the smart contract to be tested, expressed as: ; in, A set of statements representing the smart contract code data to be tested. Indicates the first, second, ..., A statement, Indicates the total number of statements; A set of statements for the smart contract code data to be tested Any entry node , add it to the corresponding code control flow , and the corresponding code control flow As the current code control flow, determine the entry node The current follow-up statement The node type, ; If the current follow-up statement If it is a regular node, the current subsequent statement Join the current code control flow , and continue to traverse the next statement; if the current subsequent statement For conditional judgment nodes, create a control flow with the current code Same first synchronization code control flow , the current subsequent statement and the success statement to judge success Join the current code control flow , the current subsequent statement And the failure statement to judge failure Add the first synchronous code control flow, and traverse the subsequent statements of the successful statement and the failed statement respectively; if the current subsequent statement For loop judgment nodes, create a control flow with the current code The same second synchronization code controls the flow , the current subsequent statement And the loop statement to judge success Join the current code control flow , the current subsequent statement And non-loop statements that jump out of the loop when the judgment fails Adding a second synchronous code control flow , traverse the subsequent statements of loop statements and non-loop statements respectively; if the current subsequent statement If it is an exit node, the current subsequent statement Join the current code control flow Then end the current traversal; After traversing all the entry nodes in the smart contract code data to be detected, the code control flow set is obtained, which is expressed as: ; in, Represents a collection of code control flows, Indicates the first, second, ..., The code controls the flow. Represents the total number of code control flows, which is equal to the number of entry nodes.

8. A fine-grained vulnerability detection device for smart contracts, characterized in that: including processor and storage medium; The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the fine-grained vulnerability detection method for the smart contract according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the fine-grained vulnerability detection method for the smart contract described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • System and methods for unbiased transformer source code vulnerability learning with semantic code graph

    US20240354424A1

  • Smart contract vulnerability detection method and system, and electronic device

    WO2024131508A1