Visual analysis method and device for block chain smart contract code vulnerability detection

By building a smart contract multi-label vulnerability detection model based on the CodeBERT model, and combining visualization technology to display the detection results from multiple dimensions, the problem of lack of intuitiveness of smart contract vulnerability detection in the existing technology is solved, and the analysis ability and model interpretability are improved.

CN120217388APending Publication Date: 2025-06-27XINJIANG TECH INST OF PHYSICS & CHEM CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510356704.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing smart contract code vulnerability detection methods lack intuitiveness, resulting in difficulty in analyzing and insufficient interpretation capabilities, making it difficult to effectively detect and repair vulnerabilities in blockchain smart contracts.

Method used

The multi-label vulnerability detection model for blockchain smart contracts is adopted, based on the CodeBERT model and the full connection layer, and combined with visualization technology, the vulnerability detection results are visually displayed from three dimensions: macro statistics, meso-analysis and microcode.

Benefits of technology

It realizes intuitive display of smart contract code, vulnerabilities, models and results, improves the analytical capabilities of vulnerability detection and the interpretability of deep learning models, and simplifies the challenges of users when analyzing and optimizing detection models and their results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217388A_ABST
    Figure CN120217388A_ABST
Patent Text Reader

Abstract

The invention provides a block chain smart contract code vulnerability detection-oriented visual analysis method and device, relates to the technical field of data visualization processing, and aims to realize visual display of smart contract codes, vulnerabilities, models and results. The method comprises the following steps: acquiring smart contract code vulnerability data, and preprocessing the smart contract code vulnerability data to generate a to-be-detected data set; according to the to-be-detected data set, vulnerability classification is carried out by using a pre-trained multi-label vulnerability detection model to obtain a classification result, and the multi-label vulnerability detection model is constructed based on pre-training models of a natural language and a programming language; according to the classification result, a visual analysis view is generated, and the visual analysis view is configured to be capable of visually displaying vulnerability detection of the smart contract from three dimensions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data visualization processing, and more specifically, to a visual analysis method and device for detecting vulnerabilities in blockchain smart contract code. Background Art

[0002] Blockchain is a distributed database that combines multiple technologies such as cryptography, consensus mechanism, and smart contracts. It has characteristics such as decentralization, immutability, and security and transparency, and has been widely used in fields such as finance, supply chain, healthcare, government affairs, and the Internet of Things. As one of the core technologies of blockchain, the security vulnerabilities of smart contracts are still a key issue that needs to be solved urgently. Due to problems such as the imperfections of programming languages and tools, and the mistakes of developers, it is easy to cause vulnerabilities in smart contract code. In addition, the immutability of blockchain also makes it difficult to stop losses and repair in time once there are vulnerabilities in the contract, which may lead to huge economic losses. Therefore, it has become crucial to further explore and discover the security vulnerability patterns and detection methods of smart contracts.

[0003] In recent years, with the progress of deep learning technology, more and more researchers have begun to explore deep learning-based methods for detecting vulnerabilities in smart contract code. By learning a large number of smart contracts, potential vulnerability patterns can be quickly identified, which can significantly improve the detection efficiency and accuracy, and has good generalization and scalability. Although there have been many studies on deep learning-based methods for detecting vulnerabilities in smart contract code, the existing studies mainly focus on the research of code vector representation and detection models. These methods often lack intuitiveness, resulting in difficulties in analyzing and insufficient interpretability of smart contract vulnerability detection, thus making it more challenging for users to analyze and optimize the detection model and its results. Therefore, there is an urgent need for a visual analysis technology for detecting vulnerabilities in blockchain smart contracts to achieve an intuitive display of smart contract code, vulnerabilities, models, and results. Summary of the Invention

[0004] In view of the above problems, the present disclosure provides a visual analysis method and device for detecting vulnerabilities in blockchain smart contract code, aiming to achieve an intuitive display of smart contract code, vulnerabilities, models, and results.

[0005] One aspect of the present disclosure provides a visual analysis method for detecting vulnerabilities in blockchain smart contract code, including: obtaining vulnerability data of smart contract code and preprocessing the vulnerability data of smart contract code to generate a dataset to be detected; according to the dataset to be detected, using a pre-trained multi-label vulnerability detection model to perform vulnerability classification to obtain a classification result, wherein the multi-label vulnerability detection model is constructed based on pre-trained models of natural language and programming languages; according to the classification result, generating a visual analysis view, and the visual analysis view is configured to be able to visually display the vulnerability detection of smart contracts from three dimensions; wherein, the first dimension is used to display the code sequence distribution, the number of vulnerability types and the vulnerability correlation, the second dimension is used to display the model performance, the sample distribution and the classification result, and the third dimension is used to display the function call relationship, the code structure and the code weight change.

[0006] According to an embodiment of the present disclosure, preprocessing the vulnerability data of smart contract code to generate a dataset to be detected includes: converting the vulnerability data of smart contract code into an abstract syntax tree structure; extracting the function sequence of the smart contract source code from the abstract syntax tree, and generating a dataset to be detected according to the function sequence.

[0007] According to an embodiment of the present disclosure, the structure of the multi-label vulnerability detection model includes: a CodeBERT model and a fully connected layer connected to the output end of the CodeBERT model; wherein, according to the dataset to be detected, using a pre-trained multi-label vulnerability detection model to perform vulnerability classification to obtain a classification result includes: using the CodeBERT model to convert the function sequence into a feature vector; based on the feature vector, using the fully connected layer to map the feature vector to the vulnerability classification space to generate a corresponding probability value for each vulnerability category; and according to a preset probability threshold, determining the vulnerability category to obtain a classification result.

[0008] According to an embodiment of the present disclosure, generating a visual analysis view according to the classification result includes: classifying and organizing the parameters, inputs and outputs of the multi-label vulnerability detection model to generate JSON data; according to the JSON data, using a visualization library to create visual analysis interfaces generated in the first dimension, the second dimension and the third dimension respectively.

[0009] According to an embodiment of the present disclosure, in the first dimension, a macro statistical view is generated, wherein the macro statistical view includes: a function length sub-view for displaying the distribution of the smart contract function code and sequence length; a vulnerability distribution sub-view for displaying the relative frequency and potential connection of various vulnerabilities based on a three-layer sunburst chart.

[0010] According to an embodiment of the present disclosure, in the second dimension, a meso-analysis view is generated, where the meso-analysis view includes: a loss change sub-view for showing the change trend of the loss function of the multi-label vulnerability detection model in different iteration rounds; a vulnerability threshold sub-view for showing, based on a curve graph, the accuracy rate corresponding to the multi-label vulnerability detection model under different thresholds, as well as the harmonic mean score of precision and recall rate; a model result sub-view for showing the classification results of different vulnerabilities; a batch loss sub-view for showing the loss change of each batch of samples in the current iteration round; a sample distribution sub-view for showing, based on a density scatter plot, the data distribution and classification results of samples in the multi-label vulnerability detection model; and a classification result sub-view for showing, based on a heat map, the classification results of each type of vulnerability of the samples.

[0011] According to an embodiment of the present disclosure, in the third dimension, a micro-code view is generated, where the micro-code view includes: a function call sub-view for showing, based on a node-link graph, the dependency relationships between contracts and between functions; a code structure sub-view for showing the function code structure; a function code sub-view for showing the function code; and a code weight sub-view for showing, based on a Sankey diagram, the relative importance of the current function code during the model training process.

[0012] Another aspect of the present disclosure provides a visual analysis device for blockchain smart contract code vulnerability detection, including: a data acquisition module for acquiring smart contract code vulnerability data and preprocessing the smart contract code vulnerability data to generate a dataset to be detected; a vulnerability detection module for classifying vulnerabilities according to the dataset to be detected by using a pre-trained multi-label vulnerability detection model to obtain classification results, where the multi-label vulnerability detection model is constructed based on pre-trained models of natural language and programming languages; and a visual analysis module for generating a visual analysis view according to the classification results, the visual analysis view being configured to be able to visually display the vulnerability detection of the smart contract from three dimensions; where the first dimension is used to show the code sequence distribution, the number of vulnerability types, and the vulnerability correlation, the second dimension is used to show the model performance, the sample distribution, and the classification results, and the third dimension is used to show the function call relationship, the code structure, and the change of code weight.

[0013] Another aspect of the present disclosure provides an electronic device, including: one or more processors; a memory for storing one or more programs; where when the one or more programs are executed by the one or more processors, the one or more processors implement the method as above.

[0014] Another aspect of the present disclosure provides a computer-readable storage medium storing computer-executable instructions, the instructions being used to implement the method as above when executed.

[0015] Another aspect of the present disclosure provides a computer program product, which includes computer-executable instructions that, when executed, are used to implement the method as described above.

[0016] Compared with the prior art, the visual analysis method and device for blockchain smart contract code vulnerability detection provided by the embodiments of the present disclosure have at least the following beneficial effects:

[0017] The visual analysis method and device for blockchain smart contract code vulnerability detection provided by the embodiments of the present disclosure construct a multi-label classification model for blockchain smart contract code vulnerability detection based on pre-trained models (CodeBERT) of natural language and programming languages to implement vulnerability detection. At the same time, a visual analysis interface with multi-view interaction is designed and implemented to visualize the vulnerability detection of smart contracts from three dimensions: macroscopic statistics, mesoscopic analysis, and microscopic code. By designing different sub-views to visually display the dataset, model, and code of smart contract vulnerability detection, the process of vulnerability detection of consortium blockchain smart contracts is made intuitive, the analysis ability of vulnerability detection is improved, and the interpretability of deep learning models is enhanced. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, the above and other objects, features, and advantages of the present disclosure will become clearer. In the drawings:

[0019] Figure 1 Schematically shows a flowchart of a visual analysis method for blockchain smart contract code vulnerability detection according to an embodiment of the present disclosure;

[0020] Figure 2 Schematically shows a display diagram of a visual analysis interface constructed in three dimensions according to an embodiment of the present disclosure;

[0021] Figure 3 Schematically shows a schematic diagram of a visual analysis method for blockchain smart contract code vulnerability detection according to an embodiment of the present disclosure;

[0022] Figure 4 Schematically shows a structural block diagram of a visual analysis device for blockchain smart contract code vulnerability detection according to an embodiment of the present disclosure;

[0023] Figure 5 Schematically shows a structural block diagram of an electronic device suitable for implementing a visual analysis method for blockchain smart contract code vulnerability detection according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, numerous specific details are set forth in order to provide a thorough understanding of the embodiments of the present disclosure. However, it is obvious that one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily obscuring the concepts of the present disclosure.

[0025] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0026] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0027] In the case of using expressions such as "at least one of A, B, and C, etc.", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).

[0028] In the embodiments of the present disclosure, in aspects such as the collection, update, analysis, processing, use, transmission, provision, disclosure, storage, etc. of the involved data (for example, including but not limited to user personal information), they all comply with the provisions of relevant laws and regulations, are used for legal purposes, and do not violate public order and good customs. In particular, necessary measures are taken for user personal information to prevent illegal access to user personal information data and to safeguard the security of user personal information, network security, and national security.

[0029] Blockchain is a distributed database that combines multiple technologies such as cryptography, consensus mechanisms, and smart contracts. It has characteristics such as decentralization, immutability, and security transparency, and has been widely used in fields such as finance, supply chain, healthcare, government affairs, and the Internet of Things. As one of the core technologies of blockchain, the security vulnerabilities of smart contracts are still a key issue that needs to be solved urgently. Due to problems such as imperfect programming languages and tools, and mistakes made by developers, it is easy to cause vulnerabilities in smart contract code. In addition, the immutability of blockchain also makes it difficult to stop losses and repair in a timely manner once there are vulnerabilities in the contract, which may lead to huge economic losses. Therefore, it is crucial to further explore and discover the security vulnerability patterns and detection methods of smart contracts.

[0030] In recent years, with the progress of deep learning technology, more and more researchers have begun to explore the method of detecting smart contract code vulnerabilities based on deep learning. By learning a large number of smart contracts, potential vulnerability patterns can be quickly identified, which can significantly improve the detection efficiency and accuracy, and has good generalization and scalability. Although there have been many studies on the method of detecting smart contract code vulnerabilities based on deep learning, the existing studies mainly focus on the research of code vector representation and detection models. These methods often lack intuitiveness, resulting in difficulties in analyzing smart contract vulnerabilities and insufficient interpretability, thus posing greater challenges for users to analyze and optimize the detection model and its results.

[0031] Therefore, there is an urgent need for a visual analysis technology for detecting vulnerabilities in blockchain smart contracts to achieve an intuitive display of smart contract code, vulnerabilities, models, and results.

[0032] Based on this, the embodiments of the present disclosure provide a visual analysis method and device for detecting smart contract code vulnerabilities in blockchain, aiming to achieve an intuitive display of smart contract code, vulnerabilities, models, and results.

[0033] To make the purpose, technical solution, and advantages of the present disclosure clearer and more understandable, the following further elaborates on the present disclosure in detail in combination with specific embodiments and with reference to the accompanying drawings.

[0034] Figure 1 The flowchart of the visual analysis method for detecting smart contract code vulnerabilities in blockchain according to the embodiments of the present disclosure is schematically shown.

[0035] As Figure 1 shown, the visual analysis method for detecting smart contract code vulnerabilities in blockchain of this embodiment may include operations S1 to S3, for example.

[0036] In operation S1, obtain smart contract code vulnerability data, and preprocess the smart contract code vulnerability data to generate a dataset to be detected.

[0037] In operation S2, according to the dataset to be detected, use the pre-trained multi-label vulnerability detection model to classify vulnerabilities and obtain the classification results. Among them, the multi-label vulnerability detection model is constructed based on the pre-trained models of natural language and programming languages.

[0038] In operation S3, according to the classification results, generate a visual analysis view, which is configured to be able to visually display the vulnerability detection of smart contracts from three dimensions.

[0039] Among them, the first dimension (macro statistics) is used to display the code sequence distribution, the number of vulnerability types, and the vulnerability correlation. The second dimension (meso analysis) is used to display the model performance, sample distribution, and classification results. The third dimension (micro code) is used to display the function call relationship, code structure, and code weight change.

[0040] The visual analysis method for blockchain smart contract code vulnerability detection provided by the embodiments of the present disclosure constructs a multi-label classification model for blockchain smart contract code vulnerability detection based on the pre-trained models of natural language and programming languages (CodeBERT) to achieve vulnerability detection. At the same time, it designs and implements a visual analysis interface with multi-view interaction, visualizes the vulnerability detection of smart contracts from three dimensions: macro statistics, meso analysis, and micro code, and visualizes the dataset, model, and code of smart contract vulnerability detection through different sub-views, realizing the visualization of the vulnerability detection process of consortium chain smart contracts, improving the analysis ability of vulnerability detection, and enhancing the interpretability of deep learning models.

[0041] According to the embodiments of the present disclosure, operation S1 preprocesses the smart contract code vulnerability data to generate a dataset to be detected, for example, may include:

[0042] Convert the smart contract code vulnerability data into an abstract syntax tree structure;

[0043] Extract the function sequence of the smart contract source code from the abstract syntax tree, and generate a dataset to be detected according to the function sequence.

[0044] In this embodiment, for example, first convert the Solidity (object-oriented programming language) source code into an abstract syntax tree, and then obtain the function sequence from the abstract syntax tree to generate a dataset to be detected.

[0045] According to the embodiments of the present disclosure, the structure of the multi-label vulnerability detection model may include, for example: the basic model CodeBERT and a fully connected layer connected to the output end of the CodeBERT model.

[0046] Then operation S2 classifies vulnerabilities using the pre-trained multi-label vulnerability detection model according to the dataset to be detected and obtains the classification results, which may include:

[0047] Use the CodeBERT model to convert the function sequence into feature vectors;

[0048] Based on the feature vectors, use a fully connected layer to map the feature vectors to the vulnerability classification space, generate corresponding probability values for each vulnerability category, and determine the vulnerability category according to a preset probability threshold to obtain the classification result.

[0049] In this embodiment, the CodeBERT model is used to convert the function sequence (dataset to be detected) into high-dimensional feature vectors, and these feature vectors will be passed to the fully connected layer.

[0050] The fully connected layer uses the sigmoid activation function to map these features to the probability values of each vulnerability category. Each vulnerability category corresponds to an output node, and the output is the predicted probability of that vulnerability category.

[0051] Finally, according to the set probability threshold, the model will judge which vulnerability categories may exist and finally give the corresponding vulnerability prediction results.

[0052] According to an embodiment of the present disclosure, operation S3 generates a visual analysis view according to the classification result, for example, may include:

[0053] Classify and organize the parameters, inputs, and outputs of the multi-label vulnerability detection model to generate JSON (lightweight data interchange format) data;

[0054] According to the JSON data, use visualization libraries to create visual analysis interfaces generated in the first dimension, second dimension, and third dimension respectively.

[0055] In this embodiment, for example, the call relationship and control flow graph of the function can be extracted through the Slither tool (a static analysis tool for blockchain smart contracts), the function sequence information obtained from the abstract syntax tree can be statistically analyzed, and the feature vectors, model parameters, inputs, outputs, and performance results generated by the CodeBERT model can be classified and organized to construct and standardize the JSON data available for the visual analysis view.

[0056] Then, use visualization libraries such as Echarts (a data visualization chart library based on JavaScript), AntV, and D3.js to create a visual analysis interface composed of a macro statistical view, a meso analysis view, and a micro code view from the generated JSON data.

[0057] Figure 2 Schematically shows a display diagram of the visual analysis interface constructed in three dimensions according to an embodiment of the present disclosure.

[0058] Such as Figure 2As shown, the visual analysis interface diagram constructed in three dimensions according to the embodiments of the present disclosure specifically includes a macro - statistics view, a meso - analysis view, and a micro - code view.

[0059] Among the three views, jumps are supported through interaction, and one or more views can be selected for analysis according to user needs.

[0060] According to an embodiment of the present disclosure, in the first dimension, a macro - statistics view is generated. The macro - statistics view focuses on the analysis at the dataset level and is used to display the code sequence distribution, the number of vulnerability types, and the vulnerability correlation.

[0061] Among them, the macro - statistics view includes: a function - length sub - view and a vulnerability - distribution sub - view.

[0062] The function - length sub - view is used to display the distribution of the smart - contract function code and sequence length. For example, the function - code length and the length after converting the function code into a Token sequence can be represented by blue and green respectively.

[0063] The vulnerability - distribution sub - view is used to display the relative frequency and potential connection of various vulnerabilities based on a three - layer sunburst chart. Different vulnerabilities are represented by different colors in the sunburst chart, and the size of each sector represents the proportion of the corresponding vulnerability. The first layer shows the number of each vulnerability, the second layer shows the number of the second vulnerability that exists simultaneously under the first - layer vulnerability, and the third layer shows the number of the third vulnerability when the first - and second - layer vulnerabilities co - exist. In addition, the user can click on the sector of interest to generate a new sunburst chart with the current vulnerability as the main one to further explore the relationship between vulnerabilities.

[0064] According to an embodiment of the present disclosure, in the second dimension, a meso - analysis view is generated. The meso - analysis view focuses on the analysis at the model level and is used to display the model performance, sample distribution, and classification results.

[0065] Among them, the meso - analysis view includes: a loss - change sub - view, a vulnerability - threshold sub - view, a model - result sub - view, a batch - loss sub - view, a sample - distribution sub - view, and a classification - result sub - view.

[0066] The loss - change sub - view is used to display the change trend of the loss function of the multi - label vulnerability detection model in different iteration rounds.

[0067] The vulnerability - threshold sub - view is used to display the corresponding accuracy rate and F1 - score (the harmonic - mean score of precision and recall) of the multi - label vulnerability detection model at different thresholds based on a curve graph. In the curve graph, for example, the abscissa represents the threshold, the left ordinate represents the accuracy rate, the right ordinate represents the F1 - score, the solid line represents the accuracy rate of different vulnerabilities at different thresholds, and the dashed line represents the F1 - score of different vulnerabilities at different thresholds.

[0068] The model result sub - view is used to display the classification results of different vulnerabilities. For example, the bar charts of accuracy, F1, precision, and recall can be represented by blank, right - slanted, square, and left - slanted bars respectively.

[0069] The batch loss sub - view is used to show the loss changes of each batch of samples in the current iteration round. For example, the average loss of the current round can be represented by a red dashed line.

[0070] The sample distribution sub - view is used to display the data distribution and classification results of samples in a multi - label vulnerability detection model based on a density scatter plot. For example, each data point is represented by a pie chart, and the color reflects the types of vulnerabilities existing in the current data point. A white circle and a gray border can indicate that the sample has no vulnerabilities, a single color can indicate that the sample has only one vulnerability, and multiple colors can indicate that there are multiple vulnerabilities. At the same time, a double - layer sunburst chart is used to represent the misclassified samples. For example, in the inner circle, white indicates that the current data point does not have the vulnerability of the color of the outer circle but is misreported as the vulnerability of the outer - circle color, and in the outer circle, red indicates that the vulnerability of the inner - circle color is missed.

[0071] The classification result sub - view is used to display the classification results of each vulnerability of the sample based on a heat map. For example, the depth of blue is proportional to the classification probability, 0 / 1 indicates whether the current sample has the vulnerability or not, and the color of the label text is used to represent the classification result, with red indicating a missed report and yellow indicating a false report.

[0072] The meso - analysis view supports multiple interactions. For example, by clicking on the iteration round in the loss change sub - view, the vulnerability threshold sub - view, model result sub - view, batch loss sub - view, and sample distribution sub - view will display the results of the corresponding iteration round. By clicking on the batch in the batch loss sub - view, the classification result sub - view will display the classification results of the samples in the corresponding batch. By selecting multiple samples in the sample distribution sub - view, the classification result sub - view will display the classification results of the selected samples.

[0073] According to an embodiment of the present disclosure, in the third dimension, a micro - code view is generated. The micro - code view focuses on the analysis at the function - code level and is used to display function call relationships, code structures, and code weight changes.

[0074] Among them, the micro - code view includes: a function call sub - view, a code structure sub - view, a function code sub - view, and a code weight sub - view.

[0075] The function call sub - view is used to display the dependency relationships between contracts and functions based on a node - link graph. For example, a triangle can be used to represent a file, a square to represent a contract, a gray circle to represent a function without vulnerabilities, a colored circle to represent a function with vulnerabilities, and a circle with a relatively large radius and a red border to represent the currently concerned function.

[0076] The code structure sub-view is used to display the function code structure. For example, a rectangle can be used to represent a statement, a gray border indicates no vulnerability, and a red border indicates a vulnerability. At the same time, small petals above can be used to represent the vulnerability situation of the statement, with gray representing no vulnerability.

[0077] The function code sub-view is used to display the function code.

[0078] The code weight sub-view is used to display the relative importance of the current function code during model training based on a Sankey diagram, that is, the weight changes of the current function code in 12 attention heads in different attention layers of the model. At the same time, it supports three granularities to display the Sankey diagram: code lines, words, and Tokens, enabling users to intuitively understand the weight distribution and changes of the code at different levels for each granularity. For example, when selecting the code line display granularity, the nodes of the Sankey diagram are code lines, the edges are the weights of the code lines in different attention heads, and the transparency of the edges is related to the attention score to highlight important data.

[0079] In this embodiment, by clicking on a single sample in the sample distribution sub-view or the classification result sub-view, the function call sub-view, the code structure sub-view, the function code sub-view, and the code weight sub-view will display the results of the corresponding sample.

[0080] The visual analysis method for blockchain smart contract code vulnerability detection provided by the embodiments of the present disclosure visualizes the vulnerability detection of smart contracts from three dimensions: macro statistics, meso analysis, and micro code. By designing different sub-views to visually display the dataset, model, and code of smart contract vulnerability detection, the vulnerability detection process of smart contracts is made intuitive, the analysis ability of vulnerability detection is improved, and the interpretability of deep learning models is enhanced.

[0081] Figure 3 Schematically shows the schematic diagram of the visual analysis method for blockchain smart contract code vulnerability detection according to the embodiments of the present disclosure.

[0082] As Figure 3 shown, the principle of the visual analysis method for blockchain smart contract code vulnerability detection in the embodiments of the present disclosure is as follows:

[0083] The source code of the smart contract is transformed into a function code sequence through an abstract syntax tree. After being processed by the vulnerability detection module, the model results and details are passed into the visual analysis module, and three-layer views of macro statistics, meso analysis, and micro code are generated after being processed by the visual analysis module.

[0084] The embodiments of the present disclosure also provide a training method for a multi-label vulnerability detection model, which is specifically as follows:

[0085] (1). Use a multi-tool confirmation mechanism to label the vulnerability data of smart contract code and generate a labeled dataset.

[0086] (2). Utilize the labeled dataset in step (1), extract and preprocess the functions of smart contract code using an abstract syntax tree, and construct a function sequence dataset.

[0087] (3). Use the function sequence dataset in step (2), select vulnerable functions and non-vulnerable functions of the same order of magnitude, and represent the vulnerability labels of each function in a one-hot encoding manner to construct a dataset; then divide the dataset into a training set, a validation set, and a test set.

[0088] (4). Use all the datasets in step (3), convert the code sequence into a feature vector using the CodeBERT model, and then train the model using a multi-label vulnerability detection model based on CodeBERT.

[0089] In this embodiment, the dataset Smartbugs Wild contains 47,398 smart contracts extracted from the Ethereum network, and the annotation results of these contracts are generated by multiple traditional tools. To further ensure the accuracy of the annotation, a multi-tool confirmation mechanism is adopted, that is, at least 2 tools need to confirm the existence of vulnerabilities in the contract simultaneously before annotation. Finally, 10,895 functions related to 8 types of vulnerabilities, namely access control (AC), arithmetic (AR), denial of service (DS), front running (FR), reentrancy (RE), time manipulation (TM), unchecked low level calls (UC), and other, are selected, and non-vulnerable data of the same order of magnitude is also added.

[0090] In the code preprocessing stage, an abstract syntax tree is used to preliminarily process the smart contract dataset, extract all functions from the smart contract source code, and remove comments and blank statements irrelevant to vulnerability detection, so that the functions can ensure as complete a semantic relationship as possible while reducing the data length. Remove redundant, unnecessary spaces, tabs, newlines, and some punctuation marks in the code, such as commas, quotation marks, and dots. Standardize the actual values of constants, and replace the actual values of data types such as integers, floating-point numbers, and strings with general identifiers to reduce the dependence on specific values.

[0091] Use the preprocessed normalized data to train the multi-label vulnerability detection model.

[0092] To better handle the multi-label vulnerability classification problem, the one-hot encoding method is used to represent the vulnerability labels of each function, that is, multiple vulnerability labels are encoded in binary form, where 1 indicates that the function has the current vulnerability and 0 indicates the absence.

[0093] In this embodiment, CodeBERT is used as the base model, its output is connected to a fully connected layer, the sigmoid activation function is used to convert the model output into a probability value, and the multi-label cross-entropy loss function is used to calculate the difference between the predicted probability and the true label. Suppose there are N samples, and each sample has K vulnerabilities, then the multi-label cross-entropy loss function is:

[0094]

[0095] where, represents whether the th sample has the th vulnerability, represents the probability that the th sample has the th vulnerability.

[0096] In this embodiment, accuracy, recall, precision, and F1 score are used as the evaluation metrics for the vulnerability detection model. For each vulnerability :

[0097] Accuracy( ): Accuracy represents the proportion of all correctly classified samples in the total number of samples.

[0098]

[0099] Recall( ): Recall represents the proportion of samples that actually exist and are correctly predicted as .

[0100]

[0101] Precision( ): Precision represents the proportion of samples predicted as that actually exist .

[0102]

[0103] F1 score( ): It is the harmonic mean of precision and recall, used to balance the two.

[0104]

[0105] where, (True Positive) represents the number of samples correctly predicted as , that is, the number of samples that actually exist and are also predicted as . (True Negative) represents the number of samples incorrectly predicted as , that is, the number of samples that actually do not exist but are predicted as . It can be called the number of samples misreported as . (False Positive) represents the number of samples that fail to be predicted as , that is, the number of samples that actually exist but are predicted as non - existent . It can be called the number of samples with missed reports. (False Negative) represents the number of samples correctly predicted as non - existent , that is, the number of samples that actually do not exist and are also predicted as non - existent .

[0106] Figure 4 Schematically shows a structural block diagram of a visual analysis device for blockchain smart contract code vulnerability detection according to an embodiment of the present disclosure.

[0107] As Figure 4 shown, the visual analysis device 400 for blockchain smart contract code vulnerability detection according to an embodiment of the present disclosure includes: a data acquisition module 410, a vulnerability detection module 420, and a visual analysis module 430.

[0108] The data acquisition module 410 is configured to acquire smart contract code vulnerability data and pre - process the smart contract code vulnerability data to generate a dataset to be detected.

[0109] The vulnerability detection module 420 is configured to classify vulnerabilities according to the dataset to be detected by using a pre - trained multi - label vulnerability detection model, and obtain a classification result, wherein the multi - label vulnerability detection model is constructed based on pre - trained models of natural language and programming languages.

[0110] The visual analysis module 430 is configured to generate a visual analysis view according to the classification result, and the visual analysis view is configured to be able to visually display the vulnerability detection of smart contracts from three dimensions.

[0111] Among them, the first dimension is used to display the code sequence distribution, the number of vulnerability types, and the vulnerability correlation, the second dimension is used to display the model performance, the sample distribution, and the classification result, and the third dimension is used to display the function call relationship, the code structure, and the code weight change.

[0112] According to embodiments of the present disclosure, any plurality of modules, sub-modules, units, sub-units, or at least part of the functions of any of them can be implemented in one module. Any one or more of the modules, sub-modules, units, sub-units according to embodiments of the present disclosure can be split into multiple modules for implementation. Any one or more of the modules, sub-modules, units, sub-units according to embodiments of the present disclosure can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or can be implemented by any other reasonable way of integrating or packaging circuits, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in any appropriate combination of several of them. Alternatively, one or more of the modules, sub-modules, units, sub-units according to embodiments of the present disclosure can be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding functions can be executed.

[0113] For example, any plurality of the data acquisition module 410, the vulnerability detection module 420, and the visual analysis module 430 can be combined and implemented in one module / unit / sub-unit, or any one of the module / unit / sub-unit can be split into multiple modules / units / sub-units. Alternatively, at least part of the functions of one or more of these modules / units / sub-units can be combined with at least part of the functions of other modules / units / sub-units and implemented in one module / unit / sub-unit. According to embodiments of the present disclosure, at least one of the data acquisition module 410, the vulnerability detection module 420, and the visual analysis module 430 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or can be implemented by any other reasonable way of integrating or packaging circuits, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in any appropriate combination of several of them. Alternatively, at least one of the data acquisition module 410, the vulnerability detection module 420, and the visual analysis module 430 can be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding functions can be executed.

[0114] It should be noted that the visual analysis device part for blockchain smart contract code vulnerability detection in the embodiments of the present disclosure corresponds to the visual analysis method part for blockchain smart contract code vulnerability detection in the embodiments of the present disclosure. For the description of the visual analysis device part for blockchain smart contract code vulnerability detection, please refer to the visual analysis method part for blockchain smart contract code vulnerability detection for details, and will not be elaborated here.

[0115] Figure 5 Schematically shows a structural block diagram of an electronic device suitable for implementing a visual analysis method for blockchain smart contract code vulnerability detection according to an embodiment of the present disclosure. Figure 5 The shown electronic device is only an example and should not bring any restrictions to the functions and usage scope of the embodiments of the present disclosure.

[0116] As Figure 5 shown, the electronic device 500 according to an embodiment of the present disclosure includes a processor 501, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 502 or the program loaded from the storage part 508 into the random access memory (RAM) 503. The processor 501 can include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), and so on. The processor 501 can also include on-board memory for caching purposes. The processor 501 can include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiments of the present disclosure.

[0117] In the RAM 503, various programs and data required for the operation of the electronic device 500 are stored. The processor 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. The processor 501 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 502 and / or the RAM 503. It should be noted that the program can also be stored in one or more memories other than the ROM 502 and the RAM 503. The processor 501 can also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.

[0118] According to an embodiment of the present disclosure, the electronic device 500 may further include an input / output (I / O) interface 505, and the input / output (I / O) interface 505 is also connected to the bus 504. The electronic device 500 may further include one or more of the following components connected to the input / output (I / O) interface 505: an input part 506 including a keyboard, a mouse, etc.; an output part 507 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage part 508 including a hard disk, etc.; and a communication part 509 including a network interface card such as a LAN card, a modem, etc. The communication part 509 performs communication processing via a network such as the Internet. The drive 510 is also connected to the input / output (I / O) interface 505 as needed. A removable medium 511, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 510 as needed, so that a computer program read from it can be installed into the storage part 508 as needed.

[0119] According to an embodiment of the present disclosure, the method flow according to the embodiment of the present disclosure may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program includes program codes for executing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from the network through the communication part 509, and / or installed from the removable medium 511. When the computer program is executed by the processor 501, the above functions defined in the system of the embodiment of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described system, device, apparatus, module, unit, etc. may be implemented by computer program modules.

[0120] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiment of the present disclosure is implemented.

[0121] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium. For example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, device, or apparatus.

[0122] For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include one or more memories other than the above-described ROM 502 and / or RAM 503 and / or ROM 502 and RAM 503.

[0123] Embodiments of the present disclosure also include a computer program product, which includes a computer program that contains program code for executing the methods provided by the embodiments of the present disclosure. When the computer program product runs on an electronic device, the program code is used to cause the electronic device to implement the methods provided by the embodiments of the present disclosure.

[0124] When the computer program is executed by the processor 501, the above functions defined in the system / apparatus of the embodiments of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.

[0125] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices, magnetic storage devices, etc. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium, and is downloaded and installed through the communication part 509, and / or installed from the removable medium 511. The program code contained in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0126] In accordance with embodiments of the present disclosure, program code for executing the computer programs provided by the embodiments of the present disclosure may be written in any combination of one or more programming languages. Specifically, these computing programs may be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. The programming languages include, but are not limited to, programming languages such as Java, C++, Python, the "C" language, or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0127] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions. Those skilled in the art can understand that the features described in the various embodiments of the present disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features described in the various embodiments of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.

[0128] The above describes the embodiments of the present disclosure. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments are described separately above, this does not mean that the measures in the respective embodiments cannot be used advantageously in combination. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.

Claims

1. A visual analysis method for detecting vulnerabilities in blockchain smart contract code, characterized in that: The method comprises: Obtain smart contract code vulnerability data, and preprocess the smart contract code vulnerability data to generate a data set to be detected; According to the data set to be detected, vulnerability classification is performed using a pre-trained multi-label vulnerability detection model to obtain a classification result, wherein the multi-label vulnerability detection model is constructed based on a pre-trained model of a natural language and a programming language; Generate a visual analysis view according to the classification result, wherein the visual analysis view is configured to be able to visually display the vulnerability detection of the smart contract from three dimensions; Among them, the first dimension is used to display the distribution of code sequences, the number of vulnerability types and vulnerability correlation; the second dimension is used to display the model performance, sample distribution and classification results; the third dimension is used to display the function call relationship, code structure and code weight changes.

2. The method according to claim 1, characterized in that The preprocessing of the smart contract code vulnerability data to generate a data set to be detected includes: Convert the smart contract code vulnerability data into an abstract syntax tree structure; A function sequence of the smart contract source code is extracted from the abstract syntax tree, and a data set to be tested is generated according to the function sequence.

3. The method according to claim 2, characterized in that The structure of the multi-label vulnerability detection model includes: a CodeBERT model and a fully connected layer connected to the output end of the CodeBERT model; Wherein, the vulnerability classification is performed using a pre-trained multi-label vulnerability detection model according to the data set to be detected, and the classification results obtained include: Converting the function sequence into a feature vector using the CodeBERT model; Based on the feature vector, using the fully connected layer to map the feature vector to a vulnerability classification space, and generate a corresponding probability value for each vulnerability category; and According to the preset probability threshold, the vulnerability category is determined and the classification result is obtained.

4. The method according to claim 1, characterized in that Generating a visual analysis view according to the classification result includes: Classify and organize the parameters, inputs, and outputs of the multi-label vulnerability detection model to generate JSON data; According to the JSON data, a visualization library is used to create visual analysis interfaces generated in the first dimension, the second dimension, and the third dimension respectively.

5. The method according to claim 4, characterized in that Under the first dimension, a macro statistical view is generated, wherein the macro statistical view includes: Function length subview, which is used to show the distribution of smart contract function code and sequence length; The vulnerability distribution subview is used to display the relative frequency and potential connections of various vulnerability types based on a three-layer sunburst chart.

6. The method according to claim 4, characterized in that Under the second dimension, a meso-level analysis view is generated, wherein the meso-level analysis view includes: The loss change subview is used to show the change trend of the loss function of different iteration rounds of the multi-label vulnerability detection model; The vulnerability threshold subview is used to display the accuracy of the multi-label vulnerability detection model at different thresholds based on a curve chart, as well as the harmonic mean score of precision and recall; Model result subview, used to display the classification results of different vulnerabilities; The batch loss subview is used to show the loss changes of each batch of samples in the current iteration round; The sample distribution subview is used to display the data distribution and classification results of the samples in the multi-label vulnerability detection model based on the density scatter plot; The classification result subview is used to display the classification results of each vulnerability of the sample based on the heat map.

7. The method according to claim 4, characterized in that In the third dimension, a micro code view is generated, wherein the micro code view includes: The function call subview is used to display the dependencies between contracts and functions based on the node link graph; The code structure subview is used to display the function code structure; Function code subview, used to display function code; The code weight subview is used to display the relative importance of the current function code in the model training process based on the Sankey diagram.

8. A visual analysis device for detecting vulnerabilities in blockchain smart contract codes, characterized in that: The device comprises: A data acquisition module is used to acquire smart contract code vulnerability data and pre-process the smart contract code vulnerability data to generate a data set to be detected; A vulnerability detection module is used to classify vulnerabilities according to the data set to be detected using a pre-trained multi-label vulnerability detection model to obtain a classification result, wherein the multi-label vulnerability detection model is constructed based on a pre-trained model of a natural language and a programming language; A visual analysis module, used to generate a visual analysis view according to the classification result, wherein the visual analysis view is configured to be able to visually display the vulnerability detection of the smart contract from three dimensions; Among them, the first dimension is used to display the distribution of code sequences, the number of vulnerability types and vulnerability correlation; the second dimension is used to display the model performance, sample distribution and classification results; the third dimension is used to display the function call relationship, code structure and code weight changes.

9. An electronic device, characterized in that: include: one or more processors; A storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors execute the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having executable instructions stored thereon, characterized in that: When the instruction is executed by a processor, the processor executes the method according to any one of claims 1 to 7.