Intelligent contract vulnerability detection method based on event behavior analysis and related device

Through variational autoencoder and natural language processing technology, multi-dimensional feature analysis is carried out based on smart contract transaction event information, which solves the problem of insufficient dynamic behavior analysis of existing detection methods, and realizes efficient vulnerability detection and security guarantee for smart contracts.

CN120337229APending Publication Date: 2025-07-18西交网络空间安全研究院 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510416417.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing smart contract vulnerability detection methods rely on static code analysis, lack in-depth mining of on-chain transaction events and multi-dimensional feature utilization, resulting in insufficient dynamic behavior analysis capabilities and difficulty in capturing unknown vulnerabilities and new attack modes.

Method used

Using an event behavior analysis method, the transaction event information of the smart contract is transformed into multi-dimensional features using variational autoencoder and natural language processing technology, and the risk events are identified through training models to realize dynamic vulnerability detection.

Benefits of technology

Without relying on the contract source code, effectively identifying risk events in smart contracts, improving the detection ability of new vulnerabilities, enhancing the adaptability and accuracy of the detection system, and ensuring transaction security on the blockchain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337229A_ABST
    Figure CN120337229A_ABST
Patent Text Reader

Abstract

The invention discloses a smart contract vulnerability detection method based on event behavior analysis and a related device, and the method comprises the steps: coding Event information in a smart contract transaction history into a standardized multi-dimensional feature through a natural language processing technology, comparing the standardized multi-dimensional feature with a known risk event feature to obtain an Event event behavior feature group, and carrying out the detection of the vulnerability of a smart contract. And comparing the suspicious feature group with the security feature group through a variational auto-encoder, thereby effectively identifying and classifying the risk event features in the smart contract. According to the method, under the condition that the source code of the smart contract cannot be acquired, vulnerability identification and classification can be performed by fully utilizing the Event event behavior of the smart contract, so that the security of the smart contract on the block chain is effectively guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of blockchain security analysis, and particularly to an intelligent contract vulnerability detection method and related device based on event behavior analysis. Background Art

[0002] In recent years, blockchain technology has been widely applied in multiple fields due to its immutability, security, and decentralization characteristics. Among them, intelligent contracts based on blockchain protocols have become a key research direction. However, with the expansion of application scenarios, security issues such as reentrancy vulnerabilities and price manipulation attacks exposed by intelligent contracts have become increasingly prominent. Currently, the detection methods for intelligent contract security mainly include static analysis and dynamic analysis methods. These code-level detection technologies have achieved certain results through predefined rule pattern matching. It is worth noting that the transaction events generated during the on-chain execution of intelligent contracts completely record the runtime information such as the contract state change trajectory, event trigger sequence, and parameter passing. However, existing technologies generally regard transaction events as simple operation logs, and there is no systematic analysis framework for the structured data such as contract execution sequences, state migration characteristics, event signatures, and topics contained in them.

[0003] Technical problems existing in the prior art: 1. Single detection dimension: Existing methods overly rely on static rule matching of source code and lack in-depth mining of multi-dimensional features (such as state migration paths and event trigger timing relationships) in the transaction event data generated in real time on the chain, resulting in insufficient dynamic behavior analysis capabilities.

[0004] 2. Insufficient information utilization: The event signatures and topic data in transaction events cannot be effectively parsed, resulting in the lack of key analysis dimensions such as contract execution pattern recognition and cross-contract interaction behavior tracking, which limits the coverage of vulnerability detection.

[0005] 3. Adaptability limitations: The detection mechanism based on predefined rules is difficult to capture unknown vulnerability types not registered in the rule library, and the contract runtime behavior characteristics contained in transaction events have not been converted into extensible detection bases, resulting in insufficient adaptability of the detection system to new attack patterns. Summary of the Invention

[0006] The purpose of the present application is to solve the problems in the prior art and provide an intelligent contract vulnerability detection method and related device based on event behavior analysis.

[0007] To achieve the above purpose, the present application adopts the following technical solutions: In the first aspect, the present application provides an intelligent contract vulnerability detection method based on event behavior analysis, including the following steps: Obtain transaction event information on the blockchain; Input the transaction event information into a pre-trained transaction event classification model to obtain the classification result of the transaction event information and mark the transaction event; The pre-trained transaction event classification model is composed of a variational autoencoder and a decoder and is trained using the characteristics of secure transaction events.

[0008] In a second aspect, the present application provides an intelligent contract vulnerability detection system based on event behavior analysis, including: A data acquisition module for obtaining transaction event information on the blockchain; A classification and marking module for inputting the transaction event information into a pre-trained transaction event classification model to obtain the classification result of the transaction event information and mark the transaction event; The pre-trained transaction event classification model is composed of a variational autoencoder and a decoder and is trained using the characteristics of secure transaction events.

[0009] In a third aspect, the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above method are implemented.

[0010] In a fourth aspect, the present application provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1-6 are implemented.

[0011] In a fifth aspect, the present application provides a computer program product, which includes computer instructions. The processor of the computer device reads the computer instructions, and the processor of the computer device executes the computer instructions to implement the steps of the above method.

[0012] Compared with the prior art, the present application has the following beneficial effects: This application is based on the analysis and discovery that the contract throws an Event through a transaction, and the Events of risk events are very different from those of safe transactions in characteristics. It captures the transaction Events of known risk events and known safe transactions on the blockchain, uses natural language processing technology to organize the Event information of smart contracts into standardized multi-dimensional features, inputs the transaction Event features of risk events and the Event features of normal transactions into a variational autoencoder for training of a classification model, effectively filters normal event features, and at the same time screens out the risk event features in smart contracts, realizes smart contract vulnerability detection without code, effectively utilizes smart contract Event information, and ensures the security of smart contracts on the blockchain.

[0013] Furthermore, this application can obtain detailed information on contract execution through event logs when the contract code is inaccessible, ensuring effectiveness in the case where the source code is inaccessible. At the same time, the data acquisition difficulty is low, avoiding dependence on other high-cost analysis tools or complex debugging environments. It can be triggered immediately after the transaction execution is completed. The detection system can analyze potential vulnerabilities or abnormal behaviors by collecting Event data, which helps to detect security threats early. And this method can be combined with other external information, having a certain degree of scalability while further enhancing the accuracy of the detection model.

[0014] Furthermore, this application uses a variational autoencoder to train the risk Event transaction feature group and the safe Event transaction feature group. Since contract Events may exhibit dynamic characteristics as time and the execution environment change, the variational autoencoder is adopted to model the probability distribution of the data to adapt to the dynamic changes of Event features, thereby improving the detection ability for new or variant vulnerabilities. In the case where the Event feature distribution may be very complex, it learns the latent representation space of event features, thus more accurately capturing the differences between normal and abnormal features.

[0015] Furthermore, this application combines natural language processing technology with a variational autoencoder to analyze potential vulnerabilities in smart contracts through smart contract Events, integrating the advantages of semantic understanding, probability modeling, and dynamic adaptation. It not only improves the detection accuracy but also enhances the ability to handle complex, diverse, and new vulnerabilities.

[0016] Furthermore, this application conducts vulnerability detection based on natural language processing and variational autoencoders, in combination with smart contract transaction Events. By focusing on studying abnormal behaviors during the execution of smart contracts that may indicate potential vulnerabilities, monitoring smart contracts to collect event information, organizing this data into standardized multivariate features, and finally processing it using natural language processing and variational autoencoders, it is possible to utilize smart contract Event information for vulnerability identification and classification even when the source code of the smart contract is not available, effectively ensuring the security of smart contracts on the blockchain. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show certain embodiments of this application and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other relevant drawings can also be obtained based on these drawings.

[0018] Figure 1 It is a flowchart of the method of this application.

[0019] Figure 2 It is a schematic diagram of the system of this application.

[0020] Figure 3 It is an overall flowchart of the technology for vulnerability detection using natural language processing technology and variational autoencoders based on smart contract Event information in this application.

[0021] Figure 4 It is an overall flowchart of the variational autoencoder for processing classification tasks. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0022] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions in the embodiments of this application in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are some, but not all, of the embodiments of this application. Usually, the components of the embodiments of this application described and shown in the drawings here can be arranged and designed in various different configurations.

[0023] Therefore, the following detailed description of the embodiments of this application provided in the drawings is not intended to limit the scope of this application that is required to be protected, but merely represents the selected embodiments of this application. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this application.

[0024] It should be noted that like reference numerals and letters refer to like items in the following figures, and thus, once an item is defined in one figure, it is not necessary to further define and explain it in subsequent figures.

[0025] In the description of the embodiments of the present application, it should be noted that if terms such as "upper", "lower", "horizontal", "inner", etc. are used to indicate the orientation or positional relationship, it is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the inventive product is habitually placed during use. This is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to the present application. In addition, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0026] In addition, if the term "horizontal" appears, it does not mean that the component is required to be absolutely horizontal, but it can be slightly inclined. For example, "horizontal" only means that its direction is more horizontal relative to "vertical", and does not mean that the structure must be completely horizontal, but it can be slightly inclined.

[0027] In the description of the embodiments of the present application, it should also be noted that unless otherwise clearly specified and limited, if terms such as "set", "installed", "connected", "connected" are used, they should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific situations.

[0028] The following further describes the present application in detail with reference to the drawings: See Figure 1 , the embodiments of the present application disclose an intelligent contract vulnerability detection method based on event behavior analysis, including the following steps: S1 Obtain transaction event information on the blockchain; It should be noted that obtaining transaction event information on the blockchain includes: Use the eth_getTransactionReceipt method to obtain the log information of the transaction events on the blockchain, identify the function names and parameters of the log information, and the parameters include event signatures, index parameters, non-index parameters, contract addresses, transaction triggers, receiving addresses, numerical parameters, and timestamps.

[0029] S2 Input the transaction event information into a pre-trained transaction event classification model to obtain the classification result of the transaction event information and mark the transaction event; In practical applications, the pre-trained transaction event classification model consists of a variational autoencoder and a decoder, and is trained using the features of secure transaction events.

[0030] It should be noted that the construction method of the transaction event classification model is as follows: S201 Input the feature vector of the secure transaction event information into the variational autoencoder; S202 Construct a variational autoencoder and train the features of secure transaction events.

[0031] In practical applications, the feature vector of secure transaction event information is obtained through the following method: S2.1 Segment the text content of the log information of the transaction event, and use the TF-IDF method to extract keywords from the text content; S2.2 Construct an event library of transaction events according to the extracted keywords, and use the word2vec model to train the event library; S2.3 Perform feature encoding on each transaction event information through the trained word2vec model and convert it into a corresponding high-dimensional feature vector.

[0032] It should be noted that the cosine similarity is used to evaluate the high-dimensional feature vector to obtain the semantic relevance between transaction events. The method for evaluating the cosine similarity is as follows:

[0033] If is close to 1, the cosine similarity between semantically similar events is relatively high; if is close to 0, the cosine similarity between different types of events is relatively low. Among them, represents the function name, from address, to address of the known secure transaction event, represents the function name, from address, to address, value of the event to be detected, represents the value of the value of the known secure transaction event, represents the value of the value of the event to be detected.

[0034] In practical applications, constructing a variational autoencoder and training the features of secure transaction events includes: Input the feature vector of the secure transaction event information into the variational autoencoder in batches, map the input features to the latent space, and generate a mean vector and a variance vector; Use stochastic gradient descent to optimize the loss function and train until the loss converges.

[0035] Such as Figure 2As shown in the figure, an intelligent contract vulnerability detection system based on event behavior analysis is disclosed in an embodiment of the present application, including: A data acquisition module for obtaining transaction event information on the blockchain; A classification and marking module for inputting the transaction event information into a pre-trained transaction event classification model to obtain a classification result of the transaction event information and mark the transaction event; The pre-trained transaction event classification model is composed of a variational autoencoder and a decoder, and is trained using the characteristics of safe transaction events.

[0036] Embodiment Figure 3 This is the overall flowchart of the present application for intelligent contract vulnerability detection using natural language processing technology and variational autoencoders based on intelligent contract Event event information.

[0037] Step 1: Capture the transaction Events of known risk events and the transaction Events of safe events on the blockchain.

[0038] First, it is recognized that the Events in the contract usually include function names and parameters.

[0039] Secondly, the method for capturing transaction Events on the blockchain is as follows: By using the eth_getTransactionReceipt method, the logs for capturing these Events can be obtained. The receipt of the transaction is returned according to the transaction hash. The receipt is used as the output of the Event. For the topics in the receipt, the event signature, the actual sending address, and the receiving address in the contract transaction are retained, and redundant information is screened out to reduce interference from redundant information and token input, effectively improving the utilization efficiency of the large language model. The topics in these logs provide key details, such as the event signature, the actual sending address, and the transaction receiving address. Through this process, relevant information can be extracted and analyzed because these logs are the outputs recorded after the Event is triggered.

[0040] Once the Event content is captured, the next step is to decompose the result: Specifically, the complex data is decomposed into individual tokens and their corresponding hexadecimal content. This step is particularly important for log decoding because the hexadecimal content must match the ABI (Application Binary Interface) of the intelligent contract in order to translate it into readable function calls and parameters.

[0041] The Event thrown by the smart contract contains all transaction information, but not all information can be used for vulnerability detection. To ensure the effect of natural language processing and the accuracy of the autoencoder, while reducing the input of tokens, parameters with relatively large amounts of information are selected. The specific parameter selection is as follows: 1) Event signature: Identifies the type of Event and is used to distinguish functions. Since different Events often correspond to different behaviors of the smart contract, analyzing the event signature can help identify potential attack entry points.

[0042] 2) Indexed parameters: Can be used to quickly find Events for specific transactions or addresses, reducing unnecessary computational burdens.

[0043] 3) Non-indexed parameters: Contain the core data of the contract (such as transfer amounts, identifiers, etc.) and can be used to analyze changes in the contract state.

[0044] 4) Contract address: When analyzing multiple contracts, the contract address helps to locate the attack target, especially in cross-contract interactions.

[0045] 5) Transaction trigger: The behavior of the attacker is usually closely related to the trigger. Tracking the behavior of a specific address can reveal abnormal patterns.

[0046] 6) Receiving address: In a vulnerability attack, the target address may repeatedly receive abnormal calls or funds.

[0047] 7) Numerical parameters: Sudden large transactions or unexpected numerical changes may be signals of an attack.

[0048] 8) Timestamp: Some attacks (such as timestamp dependency vulnerabilities) may be related to specific time points or intervals.

[0049] Step 2: Use natural language processing techniques to convert the Event content into text entities. Text entities allow for semantic-level comparison with known vulnerability patterns, rather than just direct comparison of parameter values, improving the accuracy of risk event identification. At the same time, complex behavior patterns (such as frequent small transfers, abnormal transfer amounts, etc.) can be captured and converted into features that are easy to analyze.

[0050] Tokenize the text content of the Event log to separate the keywords in the Event. Apply the TF-IDF (Term Frequency-Inverse Document Frequency) method to extract keywords from the text to help identify the most representative words in the Event information that are helpful for classification. The TF-IDF formula is as follows:

[0051] Among them, represents the frequency of a certain word in a certain document; Represents the address transfer amount of a known secure transaction; Represents the inverse document frequency of a word, and the calculation formula is:

[0052] Among them, Represents the total number of documents; Represents the number of documents containing the word .

[0053] The specific method is as follows: S201: Clean the Event log data, including removing useless information, standardizing the format, etc., and then perform word segmentation on the Event text content to separate the keywords and phrases in the Event event; S202: Use TF-IDF (Term Frequency - Inverse Document Frequency) technology to analyze the text content of the Event log, evaluate the importance of each word in the Event event, and extract the most important text entities.

[0054] Step 3: Input the text entities of the known risk Event transactions and the text entities of the secure Event transactions into the word2vec model for feature encoding, and the output is used as the input content of the variational autoencoder. Use the trained word2vec model to convert the key information in the Event transaction data into fixed-length vectors, and these vectors capture the context and semantic relationships of the Event transactions, which helps to understand complex Event event patterns.

[0055] Train the word2vec model using the historical dataset of Event events on the blockchain to learn the vector representation of Event text entities, and further perform feature encoding on the text entities in Step 2 through the trained word2vec model to obtain high-level semantic representations.

[0056] Specifically: Construct a large-scale Event event library of on-chain smart contract transactions, use it as a text corpus, train the corpus using the word2vec model, specify appropriate vector dimensions and window sizes, and through the trained word2vec model, perform feature encoding on each Event event information to convert it into corresponding high-dimensional feature vectors. Use standard evaluation methods, such as cosine similarity, to test the quality of the word vector encoding, that is, whether the word vectors obtained by word2vec training can reasonably reflect the semantics between different Event events. The formula for the cosine similarity evaluation method is as follows:

[0057] The cosine similarity between semantically similar Events (such as two Transfers) is relatively high (close to 1), while the cosine similarity between different types of Events (such as Transfer and Withdraw) is relatively low (close to 0).

[0058] Step 4: Construct a variational autoencoder to train the model on the features of Event events. Constructing a variational autoencoder to train the security features can extract low-dimensional latent variable representations from high-dimensional text data and capture their probability distributions, which helps with feature construction. At the same time, by comparing the differences between the input features and the reconstructed features or analyzing the deviations in the latent variable space, the variational autoencoder can effectively detect abnormal features, thereby efficiently identifying smart contract vulnerabilities.

[0059] Taking the known security features as input, load the data in small batches, initialize the model parameters with random initialization or pre-trained weights, and then use a suitable optimizer and set the learning rate. The input data passes through the encoder to generate and , and use the reparameterization trick to sample the latent variable , where the latent variable has the following formula:

[0060] where represents the mean vector, represents the noise sampled from the standard normal distribution (N(0,1).

[0061] Input the latent variable into the decoder to generate the reconstructed data , and calculate the reconstruction loss and the KL divergence loss. Combine the losses as the final training objective and train the data batch by batch until convergence.

[0062] The goal of using a variational autoencoder is to let the model learn the feature distribution of normal Events. The encoder can map the input features to the latent space to generate the mean vector and the variance vector , while the decoder reconstructs the input data from the latent space. The loss function of the variational autoencoder consists of two parts. The reconstruction loss measures the difference between the reconstructed data and the original input , which is commonly represented by binary cross-entropy (BCE), and the formula is as follows:

[0063] where represents the reconstruction loss.

[0064] The KL divergence loss measures the latent distribution and the standard normal distribution The difference encourages the latent space to have good structural characteristics. The KL divergence loss formula is as follows:

[0065] Among them, represents the KL divergence loss, represents the measure of information difference from distribution q to distribution p.

[0066] Then the total loss:

[0067] Among them, is the weight parameter that balances the two parts of the loss.

[0068] Specifically: S301: Input the collected known security features into the encoder in batches, map the input features to the latent space, and generate a mean vector and a variance vector; S302: Use stochastic gradient descent to optimize the loss function; S303: Train until the model converges, that is, the model can reconstruct normal event data.

[0069] Step 5: Deploy the trained autoencoder to process the classification task. The input content will be predicted in the model and a binary judgment will be made.

[0070] Specifically: Input the event to be detected into the trained variational autoencoder to obtain its reconstructed data. Calculate the reconstruction error of each event, determine the threshold through validation set tuning. When the reconstruction error exceeds the threshold, mark the event as abnormal.

[0071] As Figure 4 shown, when processing the classification task, input the feature to be detected into the trained variational autoencoder to obtain its reconstructed data. Calculate the reconstruction error of each event, determine the threshold through validation set tuning. When the reconstruction error exceeds the threshold, mark the event as abnormal. This not only improves the detection ability of abnormal features but also ensures the generalization effect for complex feature distributions, effectively targets the vulnerabilities of code-free smart contracts, can identify potential risks while the contract is being traded, realizes early warning of risky transactions, and effectively guarantees the transaction security on the blockchain.

[0072] The computer device provided by an embodiment of the present application. The computer device of this embodiment includes: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps in the above-mentioned method embodiments are implemented. Or, when the processor executes the computer program, the functions of each module / unit in the above-mentioned device embodiments are implemented.

[0073] A computer program can be divided into one or more modules / units, and one or more modules / units are stored in a memory and executed by a processor to complete the present application.

[0074] The computer device can be a computing device such as a desktop computer, a notebook, a handheld computer, and a cloud server. The computer device may include, but is not limited to, a processor and a memory.

[0075] The processor can be a Central Processing Unit (CPU), or can also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0076] The memory can be used to store the computer program and / or modules. The processor realizes various functions of the computer device by running or executing the computer program and / or modules stored in the memory, and by invoking the data stored in the memory.

[0077] If the integrated module / unit of the computer device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present application, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of the above-mentioned various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, Read-Only Memory (ROM), Random Access Memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0078] The above are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. An intelligent contract vulnerability detection method based on event behavior analysis, characterized in that, It includes the following steps: Obtain the transaction event information on the blockchain; Input the transaction event information into a pre-trained transaction event classification model to obtain the classification result of the transaction event information and mark the transaction event; The pre-trained transaction event classification model is composed of a variational autoencoder and a decoder and is trained using the features of secure transaction events.

2. The intelligent contract vulnerability detection method based on transaction event behavior analysis according to claim 1, characterized in that The obtaining of the transaction event information on the blockchain includes: Use the eth_getTransactionReceipt method to obtain the log information of the transaction event on the blockchain, identify the function name and parameters of the log information, and the parameters include event signature, index parameter, non-index parameter, contract address, transaction trigger, receiving address, numerical parameter, and timestamp.

3. The intelligent contract vulnerability detection method based on transaction event behavior analysis according to claim 1, wherein, The construction method of the transaction event classification model is as follows: Input the feature vector of the secure transaction event information into the variational autoencoder; Construct a variational autoencoder to train the features of secure transaction events.

4. The intelligent contract vulnerability detection method based on transaction event behavior analysis according to claim 3, characterized in that The feature vector of the secure transaction event information is obtained through the following method: Segment the text content of the log information of the transaction event, and use the TF-IDF method to extract keywords from the text content; Construct an event library of the transaction event according to the extracted keywords, and use the word2vec model to train the event library; Perform feature encoding on each transaction event information through the trained word2vec model to convert it into a corresponding high-dimensional feature vector.

5. The intelligent contract vulnerability detection method based on transaction event behavior analysis according to claim 4, characterized in that Evaluate the high-dimensional feature vectors through cosine similarity to obtain the semantic relevance between transaction events.

6. The method for detecting vulnerabilities in smart contracts based on transaction event behavior analysis according to claim 3, wherein The constructing of the variational autoencoder to train the features of secure transaction events includes: Input the feature vectors of the secure transaction event information into the variational autoencoder in batches, map the input features to the latent space, and generate a mean vector and a variance vector; Use stochastic gradient descent to optimize the loss function and train until the loss converges.

7. An intelligent contract vulnerability detection system based on event behavior analysis, characterized in that, It includes: A data acquisition module for obtaining the transaction event information on the blockchain; A classification and marking module for inputting the transaction event information into a pre-trained transaction event classification model to obtain the classification result of the transaction event information and mark the transaction event; The pre-trained transaction event classification model is composed of a variational autoencoder and a decoder and is trained using the features of secure transaction events.

8. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1-6.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1-6.

10. A computer program product, characterized in that, The computer program product includes computer instructions. The processor of the computer device reads the computer instructions, and the processor of the computer device executes the computer instructions to implement the steps of the method according to any one of claims 1 to 6.