Intelligent contract multi-vulnerability detection method fusing vulnerability type correlation
Through the combination of multi-task learning architecture and vulnerability type embedded modules, the smart contract multi-vacancies detection model solves the problems of low vulnerability detection efficiency and insufficient accuracy in the existing technology, and achieves efficient and accurate multi-vacancies detection.
Patent Information
- Application Number
- CN202510541202.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-08-08
AI Technical Summary
The existing smart contract vulnerability detection methods are low in automation, low detection efficiency, high false alarm rate, and fail to fully utilize vulnerability type information, resulting in insufficient coverage of vulnerability detection.
Using a multi-task learning architecture, we extract shared features through the BERT model and combine BIGRU and vulnerability type embedding modules to build a smart contract multi-vulnerability detection model, and use vulnerability type information to improve detection accuracy and efficiency.
It realizes efficient and accurate detection of multiple vulnerabilities simultaneously, improves the coverage and accuracy of vulnerability detection, and reduces the risk of overfitting of a single task.
Smart Images

Figure CN120449164A_ABST
Abstract
Description
Technical Field
[0001] This paper is based on a multi-task learning framework and integrates vulnerability type information to realize multi-vulnerability detection of smart contracts, belonging to the field of blockchain smart contract security. Background Art
[0002] Blockchain is a chain-like structure based on blocks, essentially a distributed, shared transaction ledger. Its decentralized, tamper-proof, and traceable nature has led to its widespread application in digital cryptocurrencies and finance.
[0003] A smart contract is essentially a computer program that runs on a blockchain and can be automatically executed within the blockchain network. Due to code security issues that can easily arise during their development and design, smart contract security vulnerabilities frequently occur. Furthermore, smart contracts are often used to manage assets on the blockchain, and numerous attackers attempt to exploit potential vulnerabilities in smart contracts to steal assets. With the increasing number of smart contracts, the frequent occurrence of smart contract vulnerabilities has caused significant financial losses. Furthermore, the immutability of smart contracts makes vulnerability detection before deploying smart contracts crucial.
[0004] Traditional vulnerability detection methods primarily include formal verification, symbolic execution, and fuzz testing. Formal verification has a relatively low level of automation, hindering widespread application. Symbolic execution uses constraint solving to explore program execution paths, which can easily lead to problems such as state space explosion. Fuzz testing, due to its randomly generated test samples, can lead to insufficient code coverage, reduced efficiency, and a high false positive rate. Machine learning-based smart contract vulnerability detection methods are highly automated, overcoming the limitations of traditional methods. However, existing machine learning-based methods can detect a limited number of vulnerability types and fail to fully utilize the hidden information within vulnerability types.
[0005] This paper proposes a smart contract multi-vulnerability detection method that integrates vulnerability type correlation, and simultaneously implements vulnerability detection and type identification tasks with a multi-task learning architecture, shortening the vulnerability detection time and improving the classification accuracy of the model. Summary of the Invention
[0006] To solve the above problems, the present invention designs a smart contract multi-vulnerability detection method that integrates vulnerability type correlation. This method is based on a multi-task learning architecture. By learning multiple related tasks at the same time, it uses knowledge sharing between tasks to improve the generalization ability of all tasks and reduce the overfitting risk of a single task. Its basic idea is to use the similarity between tasks to improve the performance of the model on a single task. In recent years, multi-task learning has been widely used in many fields such as natural language processing, computer vision, and medical health. In order to make full use of vulnerability type information, the present invention introduces a vulnerability type embedding module into the multi-task learning framework to convert discrete vulnerability labels into continuous vector representations. The model can better capture vulnerability type information, thereby improving model performance. In addition, since it is difficult to obtain the source code of smart contracts, the bytecode is prone to lose semantic information during operation. Therefore, this article uses opcodes as the input of the model.
[0007] The present invention adopts the following technical solutions:
[0008] A design of a smart contract multi-vulnerability detection method that integrates vulnerability type correlation is characterized by including the following steps:
[0009] (1) In the data preprocessing stage, the smart contract source code is compiled into contract bytecode, and the bytecode is cleaned to delete invalid bytecodes. The cleaned bytecode is then decompiled into a contract operation code sequence, and the operation code sequence is used as the input of the model;
[0010] (2) In the model design phase, first, a model framework based on multi-task learning hard parameter sharing is constructed to extract shared features between tasks and private features of different tasks. In the bottom shared layer of the framework, a feature extraction network based on the BERT model is constructed to learn the opcode sequence features; for vulnerability detection and type recognition tasks, a multi-task classification network based on BIGRU is constructed as the top-level specific task layer of the multi-task learning framework. Then, a vulnerability type embedding module is introduced to use vulnerability type information to alleviate the interference between private features of different tasks. Finally, the overall model is constructed by combining the bottom shared layer, the top-level specific task layer and the vulnerability type embedding module to obtain a smart contract multi-vulnerability detection model that integrates vulnerability type correlations.
[0011] (3) In the vulnerability detection stage, the operation code sequence of the smart contract to be detected is obtained according to the processing method of the data preprocessing stage, and the operation code sequence is input into the smart contract multi-vulnerability detection model that integrates the vulnerability type correlation to achieve vulnerability detection and type identification tasks.
[0012] In summary, the present invention mainly includes three stages: data preprocessing stage, model design stage and vulnerability detection stage.
[0013] (1) The data preprocessing stage includes:
[0014] ① Obtain smart contract dataset;
[0015] ② Select the vulnerability type to be detected and mark it as Y=[y0,y1,...,y m ], where m represents the number of vulnerability types that need to be detected, and y i =0 means that the smart contract sample does not have the i-th vulnerability, y i =1 means that the sample has the i-th vulnerability;
[0016] ③ Compile the smart contract source code into bytecode and clean it, then decompile the bytecode into the opcode sequence X=[x0,x1,...,x n ], where n represents the number of smart contract samples, x i Represents the smart contract operation code text;
[0017] (2) The model design phase includes:
[0018] 1. Build a model framework based on multi-task learning with hard parameter sharing. At the bottom shared layer, the framework uses the BERT model to learn opcode sequence features. At the top task-specific layer, a multi-task classification network based on BIGRU is constructed to perform vulnerability detection and type recognition. Then, a vulnerability type embedding module is introduced to fully utilize vulnerability type information.
[0019] ② Design of the underlying shared layer
[0020] The underlying shared layer builds a feature extraction network based on the BERT model, using token embedding, segment embedding, and position embedding to describe smart contract opcode sequences. Token embedding converts each word in the input into a fixed-dimensional vector; segment embedding distinguishes whether the input belongs to different sentences; and position embedding represents the position of a word in a sentence.
[0021] The opcode sequence is transformed through token embedding, segment embedding, and position embedding to obtain a vector representation. These three vectors are then superimposed and fed into the Transformer encoder for feature extraction. The Transformer encoder consists of a multi-head attention layer and a position feedforward network. The multi-head attention layer calculates the attention of each word in the sequence to other words, capturing global dependencies. The position feedforward network improves expressiveness through nonlinear transformations.
[0022] The specific calculation formula of the multi-head attention layer is as follows:
[0023] MHA(Q,K,V)=Concat[head1,...,head h ]W o (1)
[0024]
[0025] Among them, MHA stands for multi-head attention, Q, K, V represent query vector, key vector and value vector respectively, concat represents the concatenation operation, head i represents the output of the i-th head, h represents the number of heads, W o is the output transformation matrix, ATT is the attention calculation function, are the query, key, and value transformation matrices of the i-th head, softmax is the activation function, and d k is the dimension of the key vector.
[0026] The output result x of the multi-head attention layer is input into the position feedforward network PFFN, and then the result of the underlying shared layer is output.
[0027] The specific calculation formula is as follows:
[0028] PFFN(x)=GELU(xW1+b1)W2+b2 (4)
[0029] Output=LayerNorm(x+PFFN(x)) (5)
[0030] Among them, GELU is the activation function, W1, W2, b1, and b2 represent the weights and biases of the two fully connected layers respectively, and LayerNorm represents layer normalization.
[0031] ③Top-level specific task layer design
[0032] The specific task layer includes two tasks: vulnerability detection and type recognition. The present invention uses BIGRU to extract specific task features. Recurrent neural networks (RNNs) are suitable for learning the features of sequence data. However, traditional RNNs have the problem of gradient vanishing or exploding when processing long sequences. In order to solve this problem, the long short-term memory network (LSTM) was proposed. It selectively retains or discards information through a gate mechanism that controls information retention and omission. In addition, the gated recurrent unit (GRU) simplifies the LSTM, has fewer parameters, and reduces computational complexity. Therefore, the specific task layer of the present invention uses BIGRU to extract features of different tasks. The parameter update process is as follows:
[0033] Compute the reset gate:
[0034] r t =σ(W r [h t-1 , x t ]) (6)
[0035] Compute the update gate:
[0036] z t =σ(W z [h t-1 , x t ]) (7)
[0037] Compute candidate states:
[0038]
[0039] Calculate the hidden layer output:
[0040]
[0041] Among them, σ represents the sigmoid function, W r 、W z 、W h are all weight matrices, the symbol [] indicates matrix connection, x t is the input at the current moment, h t-1 is the hidden state of the previous moment, tanh represents the hyperbolic tangent function, and ⊙ represents the Hadamard product.
[0042] ④ Vulnerability type embedding module design
[0043] The vulnerability type information is converted into a vector representation through the embedding layer. The cosine similarity is calculated to obtain the similarity matrix S between the opcode text X and the vulnerability type Y. The attention coefficient α is used to make the model focus on the opcode text related to the vulnerability type. Then, classification networks are constructed according to different tasks.
[0044] The specific calculation formula is as follows:
[0045]
[0046] α=softmax(max_pooling(S)) (11)
[0047] Among them, T represents transpose, ||||2 represents L2 norm, max_pooling is the maximum pooling operation, and softmax is the activation function.
[0048] The vulnerability detection task branch uses binary cross entropy loss:
[0049] Loss1=-[ylog(p)+(1-y)log(1-p)] (12)
[0050] The type recognition task branch uses cross entropy loss:
[0051]
[0052] Where n is the number of samples, m is the number of vulnerability categories, y is the true label value, and p is the predicted probability. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 is a flow chart of the present invention;
[0054] Figure 2 It is a model structure diagram of the present invention;
[0055] Figure 3 It is a feature extraction network based on the BERT model;
[0056] Figure 4 It is the BIGRU structure diagram in the model. DETAILED DESCRIPTION
[0057] This paper designs a smart contract multi-vulnerability detection method that integrates vulnerability type correlation. The model is based on a multi-task learning hard parameter sharing architecture, which improves the scalability of the model. By measuring the correlation of vulnerability types, the model fully utilizes vulnerability type information and improves vulnerability detection accuracy.
[0058] The present invention includes three stages: data preprocessing, model design, and vulnerability detection. The implementation steps are as follows:
[0059] (1) Data preprocessing stage
[0060] ① The dataset used in this paper contains 148,384 contract data items, including 27 vulnerability types. Based on the needs, this paper selects 10 common vulnerabilities.
[0061] ② Obtain the smart contract source code from the dataset, compile it into bytecode, and then decompile it into contract opcode. The processed dataset is shown in Table 1. The dataset is then divided into training set, validation set, and test set in a ratio of 7:1:2.
[0062] Table 1 Smart contract dataset
[0063]
[0064] (2) Model design stage
[0065] Based on the above, we designed a smart contract multi-vulnerability detection method that integrates vulnerability type correlation and determined the model parameters to achieve optimal model performance. The parameter settings are as follows:
[0066] ①Epoch: training round
[0067] The number of training rounds determines the degree of model fit. As the number of training rounds increases, the model may overfit. The present invention gradually increases the number of training rounds from [20, 40, 60, 80, 100].
[0068] ②Batch size: batch size
[0069] The batch size affects the optimization speed of the model. A larger batch size occupies more memory. The present invention gradually increases the batch size from [16, 32, 64, 128].
[0070] ③Learning rate: learning rate
[0071] The learning rate controls the update of model weights. A higher learning rate can easily lead to model instability. The present invention gradually increases the learning rate from 0.0001 to 0.1.
[0072] ④Dropout rate: random dropout rate
[0073] The function of the random dropout rate is to prevent overfitting. In the present invention, the initial value of the random dropout rate is set to 0.1, and the value is gradually increased until the best effect is achieved.
[0074] ⑤Optimizer: Optimizer
[0075] After defining the loss function, the gradient is optimized using an optimizer. The present invention uses the Adam optimizer.
[0076] Set the model's hyperparameters according to the above content and train the model until the model achieves optimal performance.
[0077] (3) Vulnerability detection phase
[0078] Based on the above content, the hyperparameters of the smart contract multi-vulnerability detection model that integrates vulnerability type correlations are trained using the training set, verified using the validation set, and continuously optimized through feedback until the model reaches optimal performance.
[0079] Experimental verification shows that the model performance is optimal when the smart contract multi-vulnerability detection method that integrates vulnerability type correlation adopts the hyperparameters shown in Table 2.
[0080] Table 2 Hyperparameter settings
[0081] Hyperparameters value Epoch 80 Batch size 64 Learning rate 0.001 Dropout rate 0.5 Optimizer Adam
[0082] The experimental results of the smart contract multi-vulnerability detection method that integrates vulnerability type correlation are shown in Table 3.
[0083] Table 3 Experimental results
[0084]
[0085]
[0086] In summary, the vulnerability detection method proposed in this paper uses a deep learning algorithm to fully extract features and accurately and efficiently detect 10 types of smart contract vulnerabilities. This method is applicable to a large number of smart contract vulnerability detection scenarios.
[0087] The above description is only an example of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent changes and improvements made based on the principles and design ideas of the present invention should fall within the scope of protection of the present invention.
Claims
1. A design of a smart contract multi-vulnerability detection method that integrates vulnerability type correlation, characterized by: The following steps are involved: (1) In the data preprocessing stage, the smart contract source code is compiled into contract bytecode, and the bytecode is cleaned to delete invalid bytecodes. The cleaned bytecode is then decompiled into a contract operation code sequence, and the operation code sequence is used as the input of the model; (2) In the model design phase, first, a model framework based on multi-task learning hard parameter sharing is constructed to extract shared features between tasks and private features of different tasks. In the bottom shared layer of the framework, a feature extraction network based on the BERT model is constructed to learn the opcode sequence features. For vulnerability detection and type recognition tasks, a multi-task classification network based on BIGRU is constructed as the top-level specific task layer of the multi-task learning framework. Then, a vulnerability type embedding module is introduced to use vulnerability type information to alleviate the interference between private features of different tasks. Finally, the overall model is constructed by combining the bottom shared layer, the top-level specific task layer and the vulnerability type embedding module to obtain a smart contract multi-vulnerability detection model that integrates vulnerability type correlation. (3) In the vulnerability detection stage, the operation code sequence of the smart contract to be detected is obtained according to the processing method of the data preprocessing stage, and the operation code sequence is input into the smart contract multi-vulnerability detection model that integrates the vulnerability type correlation to achieve vulnerability detection and type identification tasks.
2. The method according to claim 1, wherein: (1) The data preprocessing stage includes: ① Obtain smart contract dataset; ② Select the vulnerability type to be detected and mark it as Y=[y0,y1,...,y m ], where m represents the number of vulnerability types that need to be detected, and y i =0 means that the smart contract sample does not have the i-th vulnerability, y i =1 means that the sample has the i-th vulnerability; ③ Compile the smart contract source code into bytecode and clean it, then decompile the bytecode into the opcode sequence X=[x0,x1,...,x n ], where n represents the number of smart contract samples, x i Represents the smart contract opcode text.
3. The method according to claim 1, characterized in that The model design phase includes: ① Build a model framework based on multi-task learning hard parameter sharing. In the bottom shared layer of the framework, the BERT model is used to learn the opcode sequence features. In the top task-specific layer, a multi-task classification network based on BIGRU is constructed to implement vulnerability detection and type recognition tasks. Then, a vulnerability type embedding module is introduced to fully utilize the vulnerability type information. ②Model framework design The underlying shared layer builds a feature extraction network based on the BERT model, using token embedding, segment embedding, and position embedding to describe the sequence of smart contract operation codes. Token embedding converts each word in the input into a vector of fixed dimension; segment embedding is used to distinguish whether the input belongs to different sentences; and position embedding is used to represent the position of a word in a sentence. The opcode sequence is transformed into a vector representation through token embedding, segment embedding, and position embedding. These three vectors are then superimposed and fed into a Transformer encoder for feature extraction. The Transformer encoder consists of a multi-head attention layer and a position feedforward network. The multi-head attention layer calculates the attention of each word in the sequence to other words, capturing global dependencies. The position feedforward network improves expressiveness through nonlinear transformations. The specific calculation formula of the multi-head attention layer is as follows: MHA(Q,K,V)=Concat[head1,...,head h ]W o (1) Among them, MHA stands for multi-head attention, Q, K, V represent query vector, key vector and value vector respectively, concat represents the concatenation operation, head i represents the output of the i-th head, h represents the number of heads, W o is the output transformation matrix, ATT is the attention calculation function, W i Q 、W i K 、W i V are the query, key, and value transformation matrices of the i-th head, softmax is the activation function, and d k is the dimension of the key vector; Input the output result x of the multi-head attention layer into the position feedforward network PFFN, and then output the result of the underlying shared layer; The specific calculation formula is as follows: PFFN(x)=GELU(xW1+b1)W2+b2 (4) Output=LayerNorm(x+PFFN(x)) (5) Among them, GELU is the activation function, W1, W2, b1, b2 represent the weights and biases of the two fully connected layers respectively, and LayerNorm represents layer normalization; The specific task layer includes two tasks: vulnerability detection and type recognition. This paper uses BIGRU to extract specific task features. A long short-term memory network (LSTM) is proposed to selectively retain or discard information through a gate mechanism that controls information retention and omission. In addition, the gated recurrent unit (GRU) simplifies the LSTM. The parameter update process is as follows: Compute the reset gate: r t =σ(W r [h t-1 ,x t ]) (6) Compute the update gate: z t =σ(W z [h t-1 ,x t ]) (7) Compute candidate states: Calculate the hidden layer output: Among them, σ represents the sigmoid function, W r 、W z 、W h are all weight matrices, the symbol [] indicates matrix connection, x t is the input at the current moment, h t-1 is the hidden state of the previous moment, tanh represents the hyperbolic tangent function, and ⊙ represents the Hadamard product; ③ Vulnerability type embedding module design The vulnerability type information is converted into a vector representation through the embedding layer. The cosine similarity is calculated to obtain the similarity matrix S between the opcode text X and the vulnerability type Y. The attention coefficient α is used to make the model focus on the opcode text related to the vulnerability type. Then, classification networks are constructed according to different tasks to complete the vulnerability detection and type identification tasks. The specific calculation formula is as follows: α=softmax(max_pooling(S)) (11) Among them, T represents transpose, ||||2 represents L2 norm, max_pooling is the maximum pooling operation, and softmax is the activation function; The vulnerability detection task branch uses binary cross entropy loss: Loss1=-[ylog(p)+(1-y)log(1-p)] (12) The type recognition task branch uses cross entropy loss: Where n is the number of samples, m is the number of vulnerability categories, y is the true label value, and p is the predicted probability.