Intelligent contract vulnerability data set construction method and device, equipment and medium
By obtaining and preprocessing the alliance chain contract code, determining the vulnerability type, and using a large language model to generate contract code with vulnerabilities, the problem of insufficient contract samples in the alliance chain is solved, and a high-quality vulnerability data set is built, which improves the security of the alliance chain.
Patent Information
- Application Number
- CN202510077392.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-05-16
AI Technical Summary
In the alliance chain, due to the extremely limited number of open contracts, it is difficult to collect sufficient contract samples, resulting in the challenge of building vulnerable data sets, which in turn affects the security of the alliance chain.
By obtaining the original contract code, preprocessing, determining the vulnerability type and definition, designing model prompt words, and using large language models to generate contract codes with vulnerabilities to build a smart contract vulnerability data set.
It realizes the construction of high-quality smart contract vulnerability data sets, improves the security of the alliance chain, and provides an effective evaluation and optimization benchmark for vulnerability detection models.
Smart Images

Figure CN120012104A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of smart contract security technology, and more specifically to a method, device, equipment and medium for constructing a smart contract vulnerability dataset. Background Art
[0002] Smart contracts, as the core component of blockchain technology, play a key role in automatically executing contract terms. Once the preset conditions are met, they can trigger the execution process autonomously. However, in the context of consortium chains, due to strict considerations for security and privacy protection, the number of public contracts is extremely limited and difficult to obtain. This situation directly leads to the difficulty in collecting sufficient contract samples, which poses a considerable challenge to building a vulnerability dataset. The vulnerability dataset, as an accelerator for the development and optimization of vulnerability detection models, plays an indispensable role in improving the security of consortium chains. It can not only provide a solid benchmark for the effectiveness evaluation of vulnerability detection tools, but also build a solid line of defense for the security protection of consortium chains. Summary of the invention
[0003] In view of the above problems, the present disclosure provides a method, device, equipment and medium for constructing a smart contract vulnerability dataset.
[0004] According to a first aspect of the present disclosure, a method for constructing a smart contract vulnerability dataset is provided, including: obtaining original contract code; preprocessing the original contract code to obtain preprocessed contract code; investigating and determining vulnerability types and corresponding vulnerability definitions; designing model prompt words for each vulnerability type based on the vulnerability type and vulnerability definition; and generating contract codes with vulnerabilities using a large language model based on the model prompt words, the preprocessed contract code, and the number of vulnerabilities to obtain a smart contract vulnerability dataset, wherein the large language model has rich language knowledge and code patterns by being pre-trained on large-scale text data, and can generate high-quality text and code.
[0005] In some exemplary embodiments, the method further includes: performing quality verification on the contract code with vulnerabilities to obtain a target smart contract vulnerability data set.
[0006] In some exemplary embodiments, preprocessing the original contract code includes: using a hash algorithm to deduplicate the original contract code content to obtain deduplicated contract code; using a syntax analysis tool to check syntax errors in the deduplicated contract code to exclude invalid contract code and obtain valid contract code; and using custom rules to filter and test the valid contract code to obtain preprocessed contract code.
[0007] In some exemplary embodiments, vulnerability types include random number generation, system timestamp, materialized variable address, global variables, field declaration, program concurrency, data structure iteration, external file access, external library call, network service, system command execution, unencrypted sensitive data, unused privacy data management mechanism, cross-channel chaincode call, range risk query, and write-before-read.
[0008] In some exemplary embodiments, generating contract code with vulnerabilities using a large language model includes: selecting a first preset number of preprocessed contract codes from preprocessed contract codes; adding a first preset number of vulnerability types to each selected preprocessed contract code using the large language model; and repeating the above steps until all types of vulnerabilities are added to the contract code.
[0009] In some exemplary embodiments, using a large language model to generate contract code with vulnerabilities also includes: repeatedly executing the above steps of generating contract code with vulnerabilities to ensure the scale and diversity of the data; randomly selecting contract codes with no less than the number of vulnerability types from the preprocessed contract codes; using the large language model to add one of the vulnerabilities to the selected contract codes in turn to ensure that labels of all vulnerability types exist in the data set.
[0010] In some exemplary embodiments, quality verification of contract codes with vulnerabilities includes: using a hash algorithm to deduplicate the contract codes with vulnerabilities to obtain deduplicated contract codes with vulnerabilities; using a syntax analysis tool to check syntax errors in the deduplicated contract codes with vulnerabilities to exclude invalid contract codes and obtain valid contract codes with vulnerabilities; and manually proofreading the contract codes with vulnerabilities according to preset vulnerability rules to obtain a target smart contract vulnerability data set.
[0011] A second aspect of the present disclosure provides a device for constructing a smart contract vulnerability dataset, including: an acquisition module for acquiring original contract code; a preprocessing module for preprocessing the original contract code to obtain preprocessed contract code; a vulnerability determination module for investigating and determining vulnerability types and corresponding vulnerability definitions; a first generation module for designing model prompt words for each vulnerability type based on the vulnerability type and vulnerability definition; and a second generation module for generating contract codes with vulnerabilities using a large language model based on the model prompt words, the preprocessed contract code, and the number of vulnerabilities to obtain a smart contract vulnerability dataset, wherein the large language model has rich language knowledge and code patterns by being pre-trained on large-scale text data, and can generate high-quality text and code.
[0012] A third aspect of the present disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.
[0013] The fourth aspect of the present disclosure further provides a computer-readable storage medium having a computer program or instructions stored thereon, which implements the steps of the above method when the above computer program or instructions are executed by a processor. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0015] Figure 1 A flowchart of a method for constructing a smart contract vulnerability dataset according to an embodiment of the present disclosure is schematically shown;
[0016] Figure 2 A block diagram schematically shows a structure of a device for constructing a smart contract vulnerability dataset according to an embodiment of the present disclosure; and
[0017] Figure 3 A block diagram of an electronic device suitable for a method for constructing a smart contract vulnerability dataset according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0018] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.
[0019] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise", "include", etc. used herein indicate the existence of features, steps, operations and / or components, but do not exclude the existence or addition of one or more other features, steps, operations or components.
[0020] All terms (including technical and scientific terms) used herein have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0021] When using expressions such as "at least one of A, B, and C, etc.", they should generally be interpreted according to the meaning of the expression commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0022] In the technical solution of the present disclosure, the user information (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0023] In the scenario of using personal information for automated decision-making, the methods, devices, and systems provided by the embodiments of the present disclosure provide users with corresponding operation portals for users to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered. The expression "automated decision-making" here refers to the activity of automatically analyzing and evaluating a person's behavioral habits, interests and hobbies, or economic, health, credit status, etc. through computer programs, and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by people who specialize in a certain field, have specialized experience, knowledge and skills, and have reached a certain level of professionalism.
[0024] Figure 1 The figure schematically shows a flow chart of a method for constructing a smart contract vulnerability dataset according to an embodiment of the present disclosure.
[0025] like Figure 1 As shown, the smart contract vulnerability dataset construction method of this embodiment includes operations S110 to S150.
[0026] In operation S110, the original contract code is obtained.
[0027] In some exemplary embodiments, obtaining the original contract code includes collecting the original contract code from a code repository of an open source source code management platform. For example, in order to ensure that the collected contract code is related to the Go language smart contract, the embodiment of the present invention sets smart contract keywords and verifies them through word frequency analysis. The keywords required for contract initialization, calling, etc. such as "github.com / hyperledger / fabric", "Init", "Invoke", "chainmaker", "InitContract", "Upgrade-Contract" and the Go language are used as search conditions to obtain the contract code of the relevant project.
[0028] In operation S120, the original contract code is preprocessed to obtain a preprocessed contract code.
[0029] In some exemplary embodiments, a hash algorithm is used to deduplicate the original contract code content to ensure the uniqueness of each contract code and obtain deduplicated contract code; a syntax analysis tool is used to check syntax errors in the deduplicated contract code to exclude invalid contract code and obtain valid contract code; and custom rules are used to filter and test valid contract code to obtain preprocessed contract code, such as a file containing / test / in the path and _test.go in the file name, to ensure the purity of the data set.
[0030] In operation S130 , the vulnerability type and the corresponding vulnerability definition are investigated and determined.
[0031] In the disclosed embodiment, in order to construct a multi-label smart contract vulnerability dataset, the present invention investigates and summarizes 16 smart contract vulnerabilities, including random number generation, system timestamp, concrete variable address, global variable, field declaration, program concurrency, data structure iteration, external file access, external library call, network service, system command execution, unencrypted sensitive data, unused privacy data management mechanism, cross-channel chain code call, range risk query and write-before-read, etc. For each vulnerability, a clear definition and feature description are given. Table 1 schematically shows the definition of smart contract vulnerabilities.
[0032] Table 1 Smart contract vulnerability definition
[0033]
[0034] In operation S140 , a model prompt word for each vulnerability type is designed based on the vulnerability type and the vulnerability definition.
[0035] For example, for a random number generation vulnerability, the model prompt may include "Please generate a smart contract code that contains a random number generation vulnerability that allows an attacker to predict the random number results."
[0036] In operation S150, based on the model prompt words, the preprocessed contract code and the number of vulnerabilities, the large language model is used to generate contract code with vulnerabilities to obtain a smart contract vulnerability dataset. The large language model is pre-trained on large-scale text data, has rich language knowledge and code patterns, and can generate high-quality text and code.
[0037] In some exemplary embodiments, generating contract codes with vulnerabilities using a large language model includes: selecting a first preset number of preprocessed contract codes from the preprocessed contract codes; adding a first preset number of vulnerability types to each selected preprocessed contract code using a large language model; repeating the above steps until all types of vulnerabilities are added to the contract code. To ensure the scale and diversity of the data, the above steps can be repeated twice. To ensure that labels of all vulnerability types exist in the data set, it can also include randomly selecting contract codes of no less than the number of vulnerability types from the preprocessed contract codes; and using the large language model to add one of the vulnerabilities in the selected contract code in turn.
[0038] In the embodiment of the present invention, the large language model understands the logical structure of the contract based on the input prompt words and contract source code, and introduces vulnerabilities at appropriate locations. In this process, the large language model not only generates contract code with vulnerabilities, but also retains most of the functions and logic of the original contract.
[0039] For example, step 1: randomly select 200 contracts from the preprocessed contract code, and use the large language model to randomly add 2 types of vulnerabilities to each contract. This step aims to initially build a dataset and verify the ability of the large language model to generate vulnerability codes.
[0040] Step 2: Randomly select 200 contracts again and randomly add 3 vulnerabilities. Repeat this process until 16 vulnerabilities are added to the contracts. This step aims to gradually increase the complexity and diversity of the dataset to ensure that the dataset covers all vulnerability types investigated.
[0041] Step 3: Repeat steps 1 and 2 twice to ensure the scale and diversity of the data. By repeatedly generating multiple datasets, the scale of the dataset can be further increased and the generalization ability of the model can be improved.
[0042] Step 4: Each time, 200 contracts are randomly selected from the original contracts, and one of the vulnerabilities is added in turn using the large language model. This step is to ensure that all 16 vulnerability labels exist in the dataset to avoid missing certain vulnerability types in the dataset.
[0043] In some exemplary embodiments, after generating a contract code with vulnerabilities, quality verification is required to obtain a target smart contract vulnerability dataset.
[0044] For example, a hash algorithm is used to deduplicate contract codes with vulnerabilities to obtain deduplicated contract codes with vulnerabilities; a syntax analysis tool is used to check syntax errors in the deduplicated contract codes with vulnerabilities to eliminate invalid contract codes and obtain valid contract codes with vulnerabilities; and according to preset vulnerability rules, the contract codes with vulnerabilities are manually proofread to obtain the target smart contract vulnerability data set.
[0045] This disclosed embodiment innovatively proposes a method for constructing a multi-label consortium chain smart contract vulnerability dataset. In view of the current problem that the number of consortium chain smart contracts is small and the research in related security fields is limited, a method for constructing a Go language smart contract vulnerability dataset based on a large model is proposed to accelerate the development and optimization of vulnerability detection models.
[0046] Based on the above-mentioned smart contract vulnerability dataset construction method, the present disclosure also provides a smart contract vulnerability dataset construction device. Figure 2 The device is described in detail.
[0047] Figure 2 The structural block diagram of the smart contract vulnerability dataset construction device according to an embodiment of the present disclosure is schematically shown.
[0048] like Figure 2 As shown, the smart contract vulnerability dataset construction device 800 of this embodiment includes an acquisition module 810, a preprocessing module 820, a vulnerability determination module 830, a first generation module 840 and a second generation module 850.
[0049] The acquisition module 810 is used to acquire the original contract code.
[0050] The preprocessing module 820 is used to preprocess the original contract code to obtain a preprocessed contract code.
[0051] The vulnerability determination module 830 is used to investigate and determine the vulnerability type and the corresponding vulnerability definition.
[0052] The first generating module 840 is used to design a model prompt word for each vulnerability type based on the vulnerability type and the vulnerability definition.
[0053] The second generation module 850 is used to generate contract codes with vulnerabilities using a large language model based on model prompt words, preprocessed contract codes, and the number of vulnerabilities to obtain a smart contract vulnerability dataset, wherein the large language model has rich language knowledge and code patterns through pre-training on large-scale text data, and can generate high-quality text and code.
[0054] According to an embodiment of the present disclosure, any multiple modules of the acquisition module 810, the preprocessing module 820, the vulnerability determination module 830, the first generation module 840, and the second generation module 850 can be combined in one module for implementation, or any one of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the acquisition module 810, the preprocessing module 820, the vulnerability determination module 830, the first generation module 840, and the second generation module 850 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or can be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware, and firmware, or in any appropriate combination of any of them. Alternatively, at least one of the acquisition module 810, the preprocessing module 820, the vulnerability determination module 830, the first generation module 840 and the second generation module 850 can be at least partially implemented as a computer program module, which can perform corresponding functions when executed.
[0055] Figure 3 A block diagram of an electronic device suitable for implementing a method for constructing a smart contract vulnerability dataset according to an embodiment of the present disclosure is schematically shown.
[0056] like Figure 3 As shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage part 908 to a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a dedicated microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include an onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0057] In RAM 903, various programs and data required for the operation of electronic device 900 are stored. Processor 901, ROM 902 and RAM 903 are connected to each other via bus 904. Processor 901 performs various operations of the method flow according to the embodiment of the present disclosure by executing the program in ROM 902 and / or RAM 903. It should be noted that the program can also be stored in one or more memories other than ROM 902 and RAM 903. Processor 901 can also perform various operations of the method flow according to the embodiment of the present disclosure by executing the program stored in one or more memories.
[0058] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the input / output (I / O) interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the input / output (I / O) interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed, so that a computer program read therefrom is installed into the storage portion 908 as needed.
[0059] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist independently without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiment of the present disclosure is implemented.
[0060] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, an apparatus or a device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the ROM 902 and / or RAM 903 described above and / or one or more memories other than ROM 902 and RAM 903.
[0061] It will be appreciated by those skilled in the art that the features described in the various embodiments of the present disclosure may be combined and / or combined in a variety of ways, even if such combinations or combinations are not explicitly described in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features described in the various embodiments of the present disclosure may be combined and / or combined in a variety of ways. All of these combinations and / or combinations fall within the scope of the present disclosure.
Claims
1. A method for constructing a smart contract vulnerability dataset, characterized in that: The method comprises: Get the original contract code; Preprocessing the original contract code to obtain a preprocessed contract code; Research and determine vulnerability types and corresponding vulnerability definitions; Designing model prompt words for each vulnerability type based on the vulnerability type and vulnerability definition; and Based on the model prompt words, preprocessed contract code and the number of vulnerabilities, a large language model is used to generate contract code with vulnerabilities to obtain a smart contract vulnerability dataset. The large language model is pre-trained on large-scale text data, has rich language knowledge and code patterns, and can generate high-quality text and code.
2. The method according to claim 1, characterized in that The method further comprises: The quality of the contract code with vulnerabilities is verified to obtain a target smart contract vulnerability data set.
3. The method according to claim 1, characterized in that The preprocessing of the original contract code includes: Use the hash algorithm to remove duplicates from the original contract code content to obtain the deduplicated contract code; Using a syntax analysis tool to check syntax errors in the deduplicated contract code to eliminate invalid contract codes and obtain valid contract codes; and The valid contract code is filtered and tested using custom rules to obtain the preprocessed contract code.
4. The method according to claim 1, characterized in that: The vulnerability types include random number generation, system timestamp, concrete variable address, global variables, field declaration, program concurrency, data structure iteration, external file access, external library call, network service, system command execution, unencrypted sensitive data, unused privacy data management mechanism, cross-channel chain code call, range risk query and write-before-read.
5. The method according to claim 1, characterized in that The method of using a large language model to generate contract code with vulnerabilities includes: Selecting a first preset number of preprocessed contract codes from the preprocessed contract codes; Using the large language model, adding a first preset number of vulnerability types to each selected preprocessed contract code; Repeat the above steps until all types of vulnerabilities are added to the contract code.
6. The method according to claim 5, characterized in that The method of using a large language model to generate contract code with vulnerabilities also includes: Repeating the steps of claim 5 twice to ensure the scale and diversity of the data; Randomly select contract codes with a number no less than the number of vulnerability types from the preprocessed contract codes; Use the large language model to add one type of vulnerability to the selected contract code one by one to ensure that labels of all vulnerability types exist in the dataset.
7. The method according to claim 1, characterized in that The quality verification of the contract code with vulnerabilities includes: Deduplication of the contract code with the vulnerability is performed using a hash algorithm to obtain deduplicated contract code with the vulnerability; Using a syntax analysis tool to check syntax errors in the deduplicated contract code with vulnerabilities to eliminate invalid contract codes and obtain valid contract codes with vulnerabilities; and According to the preset vulnerability rules, the contract code with vulnerabilities is manually proofread to obtain the target smart contract vulnerability data set.
8. A device for constructing a smart contract vulnerability dataset, characterized in that: The device comprises: Acquisition module, used to obtain the original contract code; A preprocessing module, used to preprocess the original contract code to obtain a preprocessed contract code; Vulnerability determination module, used to investigate and determine vulnerability types and corresponding vulnerability definitions; A first generating module is used to design a model prompt word for each vulnerability type based on the vulnerability type and the vulnerability definition; and The second generation module is used to generate contract codes with vulnerabilities using a large language model based on the model prompt words, the preprocessed contract codes, and the number of vulnerabilities to obtain a smart contract vulnerability dataset. The large language model is pre-trained on large-scale text data, has rich language knowledge and code patterns, and can generate high-quality text and code.
9. An electronic device, comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.