Smart contract vulnerability detection method, device and equipment, medium and product

By combining RAG and Agent technologies and dynamically adjusting the detection strategy, the problems of poor generalization ability and insufficient real-time performance in existing smart contract vulnerability detection methods are solved, achieving highly accurate and efficient vulnerability detection.

CN120974508APending Publication Date: 2025-11-18BEIHANG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511120527.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-11
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Existing smart contract vulnerability detection methods based on large language models suffer from poor generalization ability, lack of domain-specific knowledge, inability to incorporate external knowledge in real time, and lack of customized detection strategies, resulting in poor accuracy and real-time performance of vulnerability detection.

Method used

This approach combines Retrieval Augmented Generation (RAG) with an intelligent agent to dynamically acquire vulnerability feature information from a real-time updated knowledge base. It also customizes detection strategies based on different vulnerability types and combines information retrieval and generation models to improve the accuracy and adaptability of vulnerability detection.

Benefits of technology

It significantly improves the accuracy, generalization ability, and real-time performance of smart contract vulnerability detection, and can automatically adjust the detection method according to contract characteristics to achieve accurate vulnerability identification and customized analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120974508A_ABST
    Figure CN120974508A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent contract vulnerability detection method and device, equipment, a medium and a product, and relates to the field of intelligent contract detection, and the method comprises the steps: obtaining an intelligent contract code needing to be detected by a user; determining a retrieval strategy according to the features of the smart contract code and the potential vulnerability type; according to the retrieval strategy, a retrieval model is utilized to retrieve a vulnerability knowledge base, and vulnerability information most related to the smart contract code is obtained; determining a vulnerability detection strategy by utilizing the vulnerability information most related to the intelligent contract code according to the characteristics of the intelligent contract code; according to the vulnerability detection strategy and the features of the intelligent contract code, vulnerability information most relevant to the intelligent contract code is used for detection, and a vulnerability detection result is obtained. According to the method, the accuracy, generalization ability and real-time performance of vulnerability detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of smart contract detection, and particularly relates to a smart contract vulnerability detection method and device, equipment, medium and product. BACKGROUND

[0002] With the rapid development of blockchain technology, smart contracts have become an indispensable core component in blockchain applications and are widely used in fields such as finance, insurance, and supply chain management. Smart contracts can automatically execute according to pre-set agreement terms, significantly improving operational efficiency. However, since a smart contract cannot be modified once it is deployed on a blockchain, the security of its code directly relates to the security of the entire system. Any potential vulnerabilities can pose serious security risks, thereby affecting the stability and credibility of the entire blockchain network. Therefore, the detection of smart contract vulnerabilities has become an important issue that needs to be addressed in blockchain technology. SUMMARY

[0003] The purpose of the present application is to provide a smart contract vulnerability detection method, device, equipment, medium and product, which can improve the accuracy, generalization ability and real-time performance of vulnerability detection.

[0004] To achieve the above-mentioned purpose, the present application provides the following solutions.

[0005] In a first aspect, the present application provides a smart contract vulnerability detection method, comprising:

[0006] obtaining a smart contract code that needs to be detected by a user;

[0007] determining a retrieval strategy according to the characteristics of the smart contract code and the types of potential vulnerabilities;

[0008] retrieving from a vulnerability knowledge base according to the retrieval strategy using a retrieval model to obtain vulnerability information most relevant to the smart contract code;

[0009] determining a vulnerability detection strategy according to the characteristics of the smart contract code using the vulnerability information most relevant to the smart contract code;

[0010] detecting according to the vulnerability detection strategy and the characteristics of the smart contract code using the vulnerability information most relevant to the smart contract code to obtain a vulnerability detection result.

[0011] In an embodiment, retrieving from a vulnerability knowledge base according to the retrieval strategy using a retrieval model to obtain vulnerability information most relevant to the smart contract code specifically comprises:

[0012] retrieving vulnerability knowledge entries in the vulnerability knowledge base based on similarity according to the retrieval strategy using a retrieval model to obtain a preliminary retrieval result;

[0013] optimizing the preliminary search result by using a reordering strategy to obtain a final search result; the final search result is the vulnerability information most relevant to the smart contract code.

[0014] In an embodiment, the construction process of the vulnerability knowledge base comprises:

[0015] obtaining various vulnerability data; the vulnerability data comprises smart contract code containing vulnerabilities and corresponding vulnerability information;

[0016] labeling the vulnerability data and storing it in the vulnerability knowledge base.

[0017] In an embodiment, the vulnerability detection strategy comprises a detection strategy and output content; the detection strategy is achieved by template selection, information filling and context reconstruction.

[0018] In an embodiment, according to the vulnerability detection strategy and the characteristics of the smart contract code, the vulnerability information most relevant to the smart contract code is used for detection to obtain a vulnerability detection result, specifically comprising:

[0019] According to the vulnerability detection strategy and the characteristics of the smart contract code, the vulnerability information most relevant to the smart contract code is used as the context, and a generation model is used for detection to obtain a vulnerability detection result.

[0020] In an embodiment, after the vulnerability information most relevant to the smart contract code is used for detection according to the vulnerability detection strategy and the characteristics of the smart contract code to obtain a vulnerability detection result, it further comprises:

[0021] The vulnerability detection result is displayed to the user and the vulnerability knowledge base is updated using the vulnerability detection result.

[0022] In a second aspect, the present application provides a smart contract vulnerability detection device, comprising:

[0023] an acquisition module for acquiring smart contract code to be detected by a user;

[0024] a search strategy determination module for determining a search strategy according to the characteristics of the smart contract code and potential vulnerability types;

[0025] a search module for searching in a vulnerability knowledge base according to the search strategy by using a search model to obtain vulnerability information most relevant to the smart contract code;

[0026] a vulnerability detection strategy determination module for determining a vulnerability detection strategy according to the characteristics of the smart contract code by using the vulnerability information most relevant to the smart contract code;

[0027] The detection module is configured to detect the vulnerability information most relevant to the smart contract code according to the detection strategy and the features of the smart contract code, and obtain a vulnerability detection result.

[0028] In a third aspect, the present application provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the smart contract vulnerability detection method.

[0029] In a fourth aspect, the present application provides a computer readable storage medium, which stores a computer program executable by a processor to implement the smart contract vulnerability detection method.

[0030] In a fifth aspect, the present application provides a computer program product, comprising a computer program executable by a processor to implement the smart contract vulnerability detection method.

[0031] According to the embodiments of the present application, the following technical effects are achieved:

[0032] The present application provides a smart contract vulnerability detection method, device, equipment, medium and product, determines a retrieval strategy according to the features of the smart contract code and potential vulnerability types; retrieves the vulnerability knowledge base according to the retrieval strategy using a retrieval model to obtain vulnerability information most relevant to the smart contract code; determines a vulnerability detection strategy according to the features of the smart contract code using the vulnerability information most relevant to the smart contract code; and detects according to the vulnerability detection strategy and the features of the smart contract code using the vulnerability information most relevant to the smart contract code to obtain a vulnerability detection result. By determining the retrieval strategy according to the features of the smart contract code and potential vulnerability types, and then determining the vulnerability detection strategy according to the vulnerability information most relevant to the smart contract code, the retrieval strategy and the vulnerability detection strategy are adjusted according to different smart contracts, which can improve the accuracy, generalization ability and real-time performance of vulnerability detection. BRIEF DESCRIPTION OF DRAWINGS

[0033] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the drawings needed in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0034] Figure 1 An application environment diagram of a smart contract vulnerability detection method in an embodiment of the present application;

[0035] Figure 2A flowchart of a smart contract vulnerability detection method provided by an embodiment of the present application is shown in FIG. 1.

[0036] Figure 3 A general framework diagram of the smart contract vulnerability detection is shown in FIG. 2.

[0037] Figure 4 A flowchart of the construction and update of the vulnerability knowledge base is shown in FIG. 3.

[0038] Figure 5 A flowchart of the vulnerability knowledge retrieval stage is shown in FIG. 4.

[0039] Figure 6 A flowchart of the vulnerability detection result generation stage is shown in FIG. 5.

[0040] Figure 7 A flowchart of the design and customized vulnerability detection of the Agent is shown in FIG. 6.

[0041] Figure 8 A functional module schematic diagram of a smart contract vulnerability detection device provided by another embodiment of the present application is shown in FIG. 7.

[0042] Figure 9 A structural schematic diagram of a computer device provided by an embodiment of the present application is shown in FIG. 8. DETAILED DESCRIPTION

[0043] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of the present application.

[0044] In recent years, with the rapid development of large language models (LLM) such as ChatGPT and DeepSeek, smart contract vulnerability detection methods based on LLM have gradually become a research hotspot. LLM can analyze smart contract code in depth through powerful natural language processing capabilities, helping to identify potential vulnerabilities. However, existing LLM-based smart contract vulnerability detection methods still face the following challenges.

[0045] Poor generalization ability: existing LLM models are usually trained on large-scale general datasets, lacking deep knowledge and specialized training for the smart contract field. Therefore, these models show poor generalization ability when facing different types of smart contract vulnerabilities, and the detection effect for some specific vulnerabilities is inconsistent, often failing to accurately capture the characteristics of all vulnerability types.

[0046] Lack of domain-specific knowledge: LLM models mainly rely on the knowledge in pre-training data, lacking a deep understanding of the unique characteristics and principles of each vulnerability type and the code structure specific to smart contracts. The types of vulnerabilities in smart contracts are diverse, and each has unique characteristics and principles. Existing models are difficult to effectively distinguish between different vulnerability types and conduct targeted detection in actual detection.

[0047] Cannot introduce external knowledge in real time: Current LLM methods mostly rely on static pre-training knowledge bases and cannot dynamically introduce real-time updated vulnerability knowledge bases during the vulnerability detection process. This makes the model unable to effectively identify vulnerabilities based on the latest vulnerability knowledge, resulting in poor accuracy and real-time performance of vulnerability detection.

[0048] Lack of customized detection strategies: Existing smart contract vulnerability detection methods are mostly general-purpose and difficult to customize detection strategies for different types of vulnerabilities. For different vulnerability types, the analysis method of smart contracts, the characteristics of vulnerabilities, and the means of attack may be different, and existing methods have great deficiencies in customizing vulnerability detection.

[0049] In summary, existing LLM-based smart contract vulnerability detection methods still need to be optimized in terms of generalization ability, integration of domain knowledge, real-time updating, and customized strategies.

[0050] To make the above purposes, features and advantages of the present application more obvious and easy to understand, the present application will be further described in detail below in conjunction with the drawings and specific embodiments.

[0051] The smart contract vulnerability detection method provided by the embodiments of the present application can be applied to, for example Figure 1The application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data required by the server 104 to process. The data storage system can be set up separately, or integrated on the server 104, or placed on the cloud or other servers. The terminal 102 can send the smart contract code to be processed to the server 104, and the server 104 receives the smart contract code to be processed. For the smart contract code to be processed, the server 104 determines the retrieval strategy according to the characteristics and potential vulnerability types of the smart contract code; according to the retrieval strategy, the retrieval model is used to retrieve the vulnerability knowledge base, and the most relevant vulnerability information of the smart contract code is obtained; the most relevant vulnerability information of the smart contract code is used to determine the vulnerability detection strategy according to the characteristics of the smart contract code; according to the vulnerability detection strategy and the characteristics of the smart contract code, the most relevant vulnerability information of the smart contract code is used for detection, and the vulnerability detection result is obtained. The server 104 can feed back the obtained vulnerability detection result to the terminal 102. In addition, in some embodiments, the smart contract vulnerability detection method can also be implemented by the server 104 or the terminal 102 alone, such as directly detecting the smart contract vulnerability of the terminal 102 for the smart contract code to be processed, or the server 104 can obtain the smart contract code to be processed from the data storage system and detect the smart contract vulnerability of the smart contract code to be processed.

[0052] Among them, the terminal 102 can be but not limited to various desktop computers, notebook computers, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things device can be a smart speaker, a smart TV, a smart air conditioner, a smart vehicle device, etc. The portable wearable device can be a smart watch, a smart bracelet, a head-mounted device, etc. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers, and can also be a cloud server.

[0053] In an exemplary embodiment, as Figure 2 shown, a smart contract vulnerability detection method is provided, which is executed by a computer device, specifically by a terminal or a server, etc. Computer device alone, or by a terminal and a server together, in the embodiment of the present application, take the server 104 in the Figure 1 application environment as an example for illustration, including the following steps 201 to 205. Among them:

[0054] Step 201: obtaining the smart contract code to be detected by the user.

[0055] Step 202: determining the retrieval strategy according to the characteristics and potential vulnerability types of the smart contract code.

[0056] Step 203: searching in the vulnerability knowledge base according to the search strategy and using a search model to obtain vulnerability information most relevant to the smart contract code.

[0057] Step 204: determining a vulnerability detection strategy according to the features of the smart contract code by using the vulnerability information most relevant to the smart contract code.

[0058] Step 205: detecting according to the vulnerability detection strategy and the features of the smart contract code by using the vulnerability information most relevant to the smart contract code to obtain a vulnerability detection result.

[0059] The steps 201 to 205 are implemented as described above. The search strategy is determined according to the features of the smart contract code and potential vulnerability types. The vulnerability detection strategy is determined according to the vulnerability information most relevant to the smart contract code. The search strategy and the vulnerability detection strategy are adjusted according to different smart contracts, which can improve the accuracy, generalization ability and real-time performance of vulnerability detection.

[0060] In an exemplary embodiment, searching in the vulnerability knowledge base according to the search strategy and using a search model to obtain vulnerability information most relevant to the smart contract code specifically includes:

[0061] Searching for vulnerability knowledge entries in the vulnerability knowledge base based on similarity according to the search strategy and using a search model to obtain a preliminary search result;

[0062] Optimizing the preliminary search result by using a reordering strategy to obtain a final search result; the final search result is the vulnerability information most relevant to the smart contract code.

[0063] In an exemplary embodiment, the construction process of the vulnerability knowledge base includes:

[0064] Obtaining various vulnerability data; the vulnerability data includes smart contract code containing vulnerabilities and corresponding vulnerability information;

[0065] Labeling the vulnerability data and storing it in the vulnerability knowledge base.

[0066] In an exemplary embodiment, the vulnerability detection strategy includes a detection strategy and output content; the detection strategy is implemented by template selection, information filling and context reconstruction.

[0067] In an exemplary embodiment, detecting according to the vulnerability detection strategy and the features of the smart contract code by using the vulnerability information most relevant to the smart contract code to obtain a vulnerability detection result specifically includes:

[0068] According to the vulnerability detection strategy and the characteristics of the smart contract code, the vulnerability information most relevant to the smart contract code is taken as the context, and a generation model is used for detection to obtain a vulnerability detection result.

[0069] In one exemplary embodiment, after the vulnerability detection result is obtained by using the vulnerability information most relevant to the smart contract code for detection according to the vulnerability detection strategy and the characteristics of the smart contract code, the method further comprises:

[0070] The vulnerability detection result is displayed to the user and the vulnerability knowledge base is updated using the vulnerability detection result.

[0071] To solve the above problems, the present application proposes a smart contract vulnerability detection method based on retrieval augmented generation (RAG) combined with an agent. By combining information retrieval with a generative model, the present application can dynamically obtain vulnerability feature information from a real-time updated knowledge base, and customize detection strategies according to different vulnerability types. Combined with Agent technology, the system can automatically adjust the detection method according to the specific characteristics of the contract, thereby improving the accuracy, generalization ability and real-time performance of vulnerability detection, and significantly improving the shortcomings of existing methods.

[0072] Specifically, the RAG model combines retrieval and generation mechanisms, enabling the model to reference a real-time updated knowledge base when generating vulnerability detection results. The knowledge base labels the code base, vulnerability features, and vulnerability principles of vulnerabilities. This compensates for the limitations of relying solely on LLM, enabling the model to not only reason based on pre-trained knowledge, but also to incorporate external knowledge in real time. At the same time, the Agent for smart contract vulnerability detection can customize its behavior according to specific vulnerability types, use information from the knowledge base to perform customized vulnerability analysis, and automatically adjust the detection strategy, thereby achieving more accurate vulnerability detection.

[0073] The present application proposes a smart contract vulnerability detection method based on RAG combined with Agent, aiming to improve the accuracy and adaptability of vulnerability detection by dynamically adjusting the detection strategy. This method combines the advantages of retrieval and generation models, and uses Agent to customize vulnerability detection strategies. As shown in Figure 3 , the method includes the following steps.

[0074] Step 1: The user submits the smart contract code to be detected to the agent.

[0075] Step two: After receiving the contract code, the agent first determines the retrieval strategy according to the characteristics of the code and the potential vulnerability types. The retrieval strategy here refers to how the agent selects to efficiently retrieve the vulnerability information related to the contract from the vulnerability knowledge base according to the specific characteristics of the contract (such as contract type, programming mode). The vulnerability information related to the contract includes retrieving vulnerability types (such as reentrant vulnerability, integer overflow vulnerability), vulnerability principles, specific vulnerability instances or security tips. Among them, the potential vulnerability types include reentrant vulnerability, integer overflow vulnerability, short address attack, denial of service and other smart contract field vulnerabilities. Determining the retrieval strategy according to the characteristics of the code and the potential vulnerability types specifically includes: after receiving the contract code, the agent first extracts the language version, syntax structure, function modifier, external call and other characteristic information of the code, and based on the given potential vulnerability types to be identified, builds a targeted retrieval strategy, only retrieves the most relevant vulnerability information of the current contract, thereby improving the detection efficiency and accuracy. For example, if it is detected whether there is a risk of reentrant vulnerability, at this time the agent will preferentially retrieve the principles, instances and repair suggestions of the reentrant vulnerability in the knowledge base to provide support for subsequent analysis. An example of building a targeted retrieval strategy is: given "detecting reentrant vulnerability", the agent will select the Detectagent corresponding to the reentrant vulnerability detection, and then retrieve the corresponding mechanism, definition, impact, etc. of the reentrant vulnerability

direct mapping, general reentrant knowledge

semantic similarity code retrieval

[0076] Step three: According to the determined retrieval strategy, the agent uses a vector-based retrieval model to extract relevant vulnerability information from the vulnerability knowledge base. The vulnerability knowledge base contains detailed vulnerability types, vulnerability definitions, vulnerability principles, vulnerability impacts, etc. The agent will find the most relevant vulnerability data of the current contract code and vulnerability type through retrieval in this stage.

[0077] Step four: After completing the search, the detection strategy begins to take effect. The detection strategy refers to the automatic adjustment and execution of the corresponding vulnerability detection strategy by the Agent based on the vulnerability information retrieved from the knowledge base, according to the type of contract and the specific characteristics of the vulnerability. The vulnerability detection strategy includes selecting the detection strategy, adjusting the output content of the generated model (such as ChatGPT or DeepSeek) to provide the most suitable detection method and analysis path for each type of vulnerability. Specifically, after completing the vulnerability information retrieval, the Agent further selects the most matching detection strategy from the pre-set detection strategy mapping table according to the function type of the contract (such as Token contract, DAO contract, NFT contract) and the identified vulnerability characteristics (such as reentrant vulnerability, integer overflow vulnerability); the detection strategy includes but is not limited to: selection of prompt word templates, adjustment of model output format, limitation of analysis focus, etc.; then, the Agent inputs the customized prompt words into the large language model to guide it to conduct in-depth analysis on specific types of vulnerabilities, and finally generates a structured vulnerability detection report, including vulnerability location, type, principle and repair suggestion.

[0078] Step five: Based on the detection strategy and the retrieved vulnerability knowledge, the generated model will generate customized vulnerability detection results. The Agent will feedback the detection results to the user, including the vulnerability type and whether the vulnerability exists, to help developers improve the security of the contract.

[0079] By combining the RAG model with the Agent, the present application can intelligently customize the detection strategy based on real-time retrieval of vulnerability characteristic information, thereby significantly improving the accuracy, efficiency and real-time performance of intelligent contract vulnerability detection.

[0080] The vulnerability knowledge base of the present application is the core component of the intelligent contract vulnerability detection system, which contains detailed definitions of different vulnerability types, vulnerability principles, vulnerability impacts, security tips, example codes and other information. The purpose of the knowledge base is to provide efficient and accurate vulnerability information support for the RAG+Agent architecture, so that the Agent can dynamically retrieve and utilize the latest vulnerability information for accurate analysis during the intelligent contract vulnerability detection process. The vulnerability knowledge base not only includes static vulnerability information, but also needs to have the ability of real-time updating and expansion, in order to timely cope with new emerging vulnerability types and attack means. The construction and updating process of the vulnerability knowledge base of the present application will be described below. Figure 4 The construction and updating process of the vulnerability knowledge base of the present application is described.

[0081] Step 1: Data Collection. In the process of building a vulnerability knowledge base, the first step is to collect data. The main task of this stage is to collect relevant vulnerability data from various channels. Through public data sets such as SWC Registry, EtherScan's vulnerability data set, SmartBugs, etc., collect smart contract code containing vulnerabilities and related information, and also need to obtain vulnerability types, repair methods, etc. from public vulnerability reports and vulnerability analysis reports published by blockchain security companies. In addition, developer communities and forums (such as GitHub and Stack Overflow) also provide a lot of sources of common vulnerabilities and vulnerability cases, which can help organize actual vulnerability events. At the same time, collect contract data samples that have been deployed on the blockchain and verified, which do not contain vulnerabilities, and can be used as control data to further verify the accuracy of the vulnerability detection system.

[0082] Step 2: Data Labeling. After data collection is complete, the next step is to organize and label the collected contract data. Each contract code will be clearly identified based on whether it contains vulnerabilities, so that subsequent retrieval and model generation can accurately classify and analyze based on these labels. Through the labeling of data, a clear vulnerability classification system can be established, which lays the foundation for the extraction and use of vulnerability information in the future.

[0083] Step 3: Build Retrieval Model. Next, an efficient retrieval model needs to be built to support the information retrieval function in the RAG architecture. The core of the retrieval model is to convert all vulnerability-related documents and code collected into vector representations. Through vectorization, each vulnerability entry (such as vulnerability type, definition, principle, etc.) can be efficiently represented, so that each piece of data in the vulnerability knowledge base can be stored in the form of a vector and support efficient retrieval and matching. The retrieval model will enable the RAG architecture to quickly find the most relevant vulnerability information based on the query for the current analysis task, thereby helping the generation model to provide accurate vulnerability detection results.

[0084] The core structure of the retrieval model is to vectorize vulnerability knowledge entries (such as vulnerability types, principles, example code, etc.) through pre-trained models (such as OpenAI's embedding algorithm, DeepSeek Embedding), and store them in a vector database to support semantic-level similarity retrieval. When the agent analyzes a piece of smart contract code, the agent will extract its key behavior features, encode them into vectors, query the vector library, and quickly recall the most relevant vulnerability information.

[0085] These retrieved vulnerability entries, such as the "reentrancy attack" related code examples, will be input as contextual cues into the generative model, which will determine whether the current code has similar vulnerabilities and generate detection conclusions and repair suggestions. This process combines the RAG architecture, enabling vulnerability detection to have knowledge support, precise recall, and the ability to dynamically respond to new vulnerabilities.

[0086] Step 4: Data storage and management. After building the retrieval model, data storage and management becomes the next key step. All vulnerability knowledge base data will be stored through an efficient database to facilitate fast queries. To ensure data persistence and consistency, ChromaDB vector database is used to store the vulnerability knowledge base, while providing API interfaces to allow agents to query related vulnerability information in real time. In addition, the vulnerability knowledge base needs to have version control management to regularly update and record changes in each update and repair strategy, ensuring its timeliness and accuracy. As new vulnerability types emerge, the knowledge base should have flexible scalability to support the dynamic addition of new vulnerability types and attack models.

[0087] Step 5: Integration with generative model. When the vulnerability knowledge base is completed, it needs to be integrated with the generative model. The purpose of integration is to enable generative models such as ChatGPT and DeepSeek to generate accurate vulnerability detection results based on information retrieved from the vulnerability knowledge base. In this process, each vulnerability type should have a customized DetectAgent that retrieves relevant information from the vulnerability knowledge base and generates specific vulnerability analysis and repair solutions. This customized behavior pattern can automatically adjust detection strategies according to different vulnerability types, thereby improving the accuracy and efficiency of vulnerability detection.

[0088] Step 6: Maintenance and update of vulnerability knowledge base. The maintenance and update of the vulnerability knowledge base is a continuous process. As new vulnerability types and attack methods emerge, the knowledge base needs to be updated regularly. Whenever a new vulnerability is discovered, it should be added to the vulnerability knowledge base and the corresponding repair method should be provided. To improve update efficiency, design automated tools to automatically obtain new vulnerability information from public vulnerability databases, project update logs, and other places for regular updates. In addition, security tips for vulnerabilities also need to be updated regularly to ensure that developers can respond to new security challenges.

[0089] By constructing and maintaining a systematic vulnerability knowledge base, and combining RAG and Agent technology, real-time support can be provided for smart contract vulnerability detection. The vulnerability knowledge base collects and organizes information from multiple data sources, builds an efficient retrieval model, and is closely integrated with the generation model to provide accurate vulnerability detection results. The dynamic updating mechanism ensures that the knowledge base can respond to new vulnerabilities and attack methods in a timely manner, thereby maintaining the accuracy and real-time nature of vulnerability detection.

[0090] The application of the RAG model in smart contract vulnerability detection combines the advantages of information retrieval and generation models, dynamically adjusts the retrieval strategy through Agent agents, and improves the accuracy and efficiency of vulnerability detection. The following will combine Figure 5 to explain the vulnerability knowledge retrieval phase flowchart of the present application in detail.

[0091] Step one: the user inputs the smart contract code that needs to be detected, and the agent receives the code and first converts it into a vector representation. The input contract code C in is converted into a vector representation V in by the embedding model (such as OpenAI's embedding algorithm) by the agent.

[0092] Step two: Agent formulates a retrieval strategy based on the vulnerability pattern of the input contract code C in (for example, reentrant vulnerability, integer overflow, access control problem, etc., which is given by the user, such as "whether the above code has a reentrant vulnerability"). Assuming that the vulnerability type is represented by L in , the Agent adjusts the query strategy according to L in , selects vulnerability instances related to the vulnerability type for retrieval (this and Figure 7 and its corresponding explanation are corresponding. The key method for Agent to determine the retrieval strategy is to detect the vulnerability type of the contract code, and call the corresponding DetectAgent.) In addition, Agent will also customize the retrieval strategy according to the semantic similarity of the contract code. The input code C in is converted into a vector V in , which is then compared with the vector representation of each vulnerability entry stored in the knowledge base. By calculating the semantic similarity, the most relevant vulnerability information is selected.

[0093] Step three: in the retrieval phase, the agent queries by calculating the similarity between the vector representation V in of the input code fragment and the vector representation V KB of the vulnerability knowledge entry stored in the ChromaDB vector database. The calculation process uses cosine similarity where V in · V KB is the dot product of the vectors, and ||Vin || and ||V KB || are the Euclidean norms (i.e., the modulus of the vectors) of the input vector and the knowledge base vector, respectively. A high cosine similarity value indicates that the input code has a high semantic similarity to the vulnerability entry, indicating that the entry is related to potential vulnerabilities. (After retrieval, multiple entries are obtained, and similar entry recall, i.e., Top-K retrieval, K value can be customized).

[0094] Step four: After the initial retrieval, the agent will use a re-ranking (Rerank) strategy to optimize the retrieval results twice. By re-ranking the retrieval results according to additional criteria such as vulnerability severity, code context, attack path, etc., the most relevant vulnerability entries are placed in the front row. The criteria are determined according to the characteristics of the vulnerabilities. The first layer of sorting is based on semantic similarity, and the second layer of re-ranking is based on vulnerability characteristics on the basis of the first layer.

[0095] Step five: After completing the Rerank strategy, the agent finally returns the most relevant vulnerability information for the input contract code. The vulnerability information includes: example code, whether there is a vulnerability, definition, cause, impact, and repair suggestion.

[0096] By combining the RAG model and the Agent's vulnerability customization retrieval strategy, the present application can achieve accurate retrieval of smart contract vulnerabilities.

[0097] In the generation phase, the Agent adjusts the output strategy of the generation model according to the retrieved vulnerability information, so that it generates accurate detection results for different vulnerability types. The generation model combines input code and retrieval information to generate vulnerability detection results, ensuring the context relevance and accuracy of the detection results. The following will combine Figure 6 The vulnerability detection result generation phase flowchart of the RAG model of the present application is described in detail.

[0098] Step one: After the retrieval phase is completed, the agent enters the adjustment phase of the detection strategy. At this time, the Agent combines the specific type of contract with the characteristics of the vulnerability according to the relevant information retrieved from the vulnerability knowledge base, and customizes the vulnerability detection strategy. The core of this stage is to ensure that the generation model (such as ChatGPT or DeepSeek) can adjust the output content and detection method according to different vulnerability types and characteristics. "Customization" means that the Agent dynamically adjusts the analysis process and generation method of vulnerability detection according to different vulnerability types and contract characteristics, to achieve "specialized" processing for each type of vulnerability, ensuring that the detection results are accurate and have context adaptability.

[0099] Customized prompt templates and generation strategies: Each vulnerability detection agent, DetectAgent, uses a specialized prompt template for the type of vulnerability it is responsible for (e.g., reentrancy, integer overflow, etc.). The input content of the generation model is adjusted to focus on the key risk points of that type of vulnerability, guiding the model to generate more targeted detection conclusions and repair suggestions.

[0100] Step two: Based on the retrieved vulnerability information and the type of contract, the Agent dynamically adjusts the detection strategy of the generation model. This means that for different types of vulnerabilities (such as reentrancy attacks, integer overflow, etc.), the output of the generation model will be different to ensure that the generated answers or classification results are more targeted and accurate. For example, if the contract involves a fund transfer operation, the Agent will select a detection strategy related to reentrancy vulnerabilities to guide the generation model to focus on this type of vulnerability. Conversely, for contracts related to state updates or permission control, the generation model may focus on other types of vulnerabilities.

[0101] The "Agent dynamically adjusts the detection strategy of the generation model" is achieved through three methods: preset prompt template selection, information retrieval and filling, and context structure reconstruction. The goal is to make the generation model (such as ChatGPT, DeepSeek) generate more accurate detection results based on different vulnerability types and contract semantics. First, the smart contract code is analyzed to extract its function type and behavior characteristics. Then, combined with the retrieval results of the vulnerability knowledge base, the corresponding prompt template is selected according to the preset strategy mapping table. Next, the retrieved vulnerability definitions, example codes, and repair suggestions are filled into the template fields, and the prompt content is reconstructed in the context of the current contract's sensitive code fragments to guide the generation model to focus on the key risk points of specific vulnerabilities. Finally, the customized prompt words are input into the large language model to obtain highly targeted vulnerability detection results.

[0102] 1. Template selection (Template Selection)

[0103] The Agent predefines a specialized Prompt template for each type of vulnerability (such as reentrancy, integer overflow, and permission control). For example, the reentrancy vulnerability template guides the model to focus on "whether external calls are made before state updates," and the integer overflow template focuses on "whether there are boundary checks for arithmetic operations."

[0104] 2. Information injection (Information Injection)

[0105] The Agent inserts the relevant vulnerability information (definitions, example codes, and repair suggestions) retrieved from the vulnerability knowledge base into specific positions in the Prompt template, serving as the model's contextual knowledge, allowing the model to have "current vulnerability background."

[0106] 3. Context Rewriting

[0107] For specific code structures of input contracts (such as whether to include call.value() and other sensitive operations), the Agent rewrites or strengthens the instruction part of the Prompt, guiding the generation model to focus on analyzing these high-risk areas.

[0108] Step Three: The generation model (such as ChatGPT or DeepSeek) generates specific detection results based on the adjusted detection strategy and the input contract code segment, combined with the retrieved vulnerability information as context. The generated content includes the type of vulnerability and whether the vulnerability exists. In this step, the generation model not only considers the input code segment itself, but also makes full use of the retrieved related vulnerability information, so that the generated detection results are more accurate. For example, if the retrieved vulnerability information points to a specific attack path, the generation model will consider this path to determine whether the current contract code is vulnerable.

[0109] Step Four: After the results generated by the generation model are sorted out, the Agent finally presents the vulnerability detection results to the user. These results include whether the vulnerability exists, the detailed information of the type of vulnerability, helping developers quickly identify and fix potential vulnerabilities in the contract.

[0110] Through the above design, the generation stage not only clearly shows how the RAG model combines retrieval information and generation model output results, but also highlights how the Agent adjusts the detection strategy according to the contract and vulnerability characteristics, ensuring that the final generated detection results have accuracy and context relevance.

[0111] In this application, the core function of the Agent designed for smart contract vulnerability detection is to automatically adjust the detection strategy according to different vulnerability types and perform customized vulnerability analysis. Each vulnerability type is corresponded to a DetectAgent, and each DetectAgent is responsible for handling a specific type of vulnerability, using information retrieved from the vulnerability knowledge base for analysis and detection. The following will be combined with Figure 5 The design of the Agent in this application and the customized vulnerability detection process are described in detail.

[0112] Step One: Receive the user-submitted smart contract code to be detected.

[0113] Step Two: The Agent determines the retrieval strategy based on the characteristics of the contract (such as contract type, programming mode) and potential vulnerability types, that is, how to efficiently retrieve relevant information from the vulnerability knowledge base.

[0114] Step three: According to the retrieval strategy, the agent extracts relevant vulnerability information from the vulnerability knowledge base using a vector-based retrieval model. The vulnerability knowledge base contains detailed vulnerability types, definitions, principles, etc. The agent finds relevant vulnerability data related to the current contract code and vulnerability type through vector retrieval.

[0115] Step four: After completing the retrieval, the Agent starts applying the detection strategy. This includes automatically adjusting the detection method according to the retrieved vulnerability information, selecting the detection strategy and output content of the generated model (such as ChatGPT, DeepSeek). The Agent customizes the behavior of the generated model according to the contract type and vulnerability characteristics, ensuring that the generated vulnerability detection results are most suitable for the current contract and vulnerability type.

[0116] Step five: Based on the detection strategy and retrieved vulnerability information, the generated model (such as ChatGPT, DeepSeek) generates customized vulnerability detection results, outputting vulnerability types, whether the vulnerability exists, etc. The generated detection results are customized according to specific vulnerability types to ensure that each vulnerability detection path is optimized.

[0117] Step six: The agent outputs the final vulnerability detection results to the user, including vulnerability information.

[0118] The present application improves the accuracy and efficiency of smart contract vulnerability detection by combining RAG and Agent technology. The agent can retrieve relevant information from the updated vulnerability knowledge base in real time and customize the detection strategy according to the contract characteristics, enhancing the generalization ability and real-time performance. At the same time, the Agent can automatically adjust the detection method according to different vulnerability types, improving the relevance and flexibility of vulnerability identification, and significantly improving the shortcomings of existing methods.

[0119] Based on the same inventive concept, the embodiments of the present application also provide an intelligent contract vulnerability detection device for implementing the intelligent contract vulnerability detection method described above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, so the specific limitations in one or more intelligent contract vulnerability detection device embodiments provided below can refer to the limitations of the intelligent contract vulnerability detection method described above, which will not be repeated here.

[0120] In one exemplary embodiment, as shown in Figure 8 , an intelligent contract vulnerability detection device is provided, comprising:

[0121] The acquisition module 801 is configured to acquire the smart contract code that needs to be detected by the user.

[0122] The retrieval strategy determination module 802 is configured to determine a retrieval strategy according to the characteristics of the smart contract code and the potential vulnerability types.

[0123] The retrieval module 803 is configured to retrieve, according to the retrieval strategy, the vulnerability information most relevant to the smart contract code from the vulnerability knowledge base by using a retrieval model.

[0124] The vulnerability detection strategy determination module 804 is configured to determine a vulnerability detection strategy according to the features of the smart contract code by using the vulnerability information most relevant to the smart contract code.

[0125] The detection module 805 is configured to detect, according to the vulnerability detection strategy and the features of the smart contract code, by using the vulnerability information most relevant to the smart contract code, to obtain a vulnerability detection result.

[0126] In an exemplary embodiment, a computer device is provided, which can be a server or a terminal. An internal structure diagram of the computer device can be as shown in Figure 9 The computer device includes a processor, a memory, an input / output interface (I / O), and a communication interface. The processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium to run. The database of the computer device is configured to store smart contract vulnerability detection data. The input / output interface of the computer device is configured to exchange information between the processor and external devices. The communication interface of the computer device is configured to communicate with external terminals through a network connection. The computer program is executed by the processor to implement a smart contract vulnerability detection method.

[0127] Those skilled in the art can understand that Figure 9 the structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components. In an exemplary embodiment, a computer device is provided, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-mentioned method embodiments.

[0128] In an exemplary embodiment, a computer readable storage medium is provided, which stores a computer program. The computer program is executed by a processor to implement the above-mentioned method embodiments.

[0129] In an example embodiment, a computer program product is provided, including a computer program which, when executed by a processor, implements the above-mentioned method embodiments.

[0130] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant regulations.

[0131] In the present application, all actions of obtaining signals, information or data are carried out in compliance with the corresponding data protection regulations and policies of the country where the device is located, and with the authorization given by the owner of the corresponding device.

[0132] It can be understood by those skilled in the art that all or part of the processes in the above-mentioned embodiment methods can be completed by a computer program instructing related hardware, and the computer program can be stored in a non-volatile computer readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiment methods. In the embodiments provided by the present application, any reference to the memory, database or other medium can include at least one of non-volatile and volatile memories. The non-volatile memory can include read-only memory (Read-Only Memory, ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive memory (Magnetoresistive Random Access Memory, MRAM), ferroelectric memory (Ferroelectric Random Access Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. The volatile memory can include random access memory (Random Access Memory, RAM) or external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as static random access memory (Static Random Access Memory, SRAM) or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc.

[0133] The database involved in each of the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a blockchain, and the like, without being limited thereto. The processor involved in each of the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, and the like, without being limited thereto.

[0134] The technical features of the above embodiments can be combined in any manner. To make the description concise, all possible combinations of the technical features in the above embodiments are not described, but it should be considered that any combination of the technical features is within the scope of the present disclosure, as long as there is no contradiction.

[0135] The principles and implementation manners of the present application are described by using specific examples herein, and the above embodiments are only used to help understand the method of the present application and its core idea. Meanwhile, for those skilled in the art, the specific implementation manners and application ranges can be changed according to the idea of the present application. In summary, the content of the present description should not be understood as a limitation of the present application.

Claims

1. A method for detecting smart contract vulnerabilities, characterized in that, The smart contract vulnerability detection method includes: Obtain the smart contract code that the user needs to test; Determine the retrieval strategy based on the characteristics of smart contract code and the types of potential vulnerabilities; Based on the retrieval strategy, the retrieval model is used to search the vulnerability knowledge base to obtain the vulnerability information most relevant to the smart contract code. Based on the characteristics of the smart contract code, a vulnerability detection strategy is determined using the vulnerability information most relevant to the smart contract code. Based on the vulnerability detection strategy and the characteristics of the smart contract code, the vulnerability information most relevant to the smart contract code is used for detection to obtain the vulnerability detection results.

2. The smart contract vulnerability detection method according to claim 1, characterized in that, Based on the aforementioned retrieval strategy, a retrieval model is used to search the vulnerability knowledge base to obtain vulnerability information most relevant to the smart contract code, specifically including: Based on the aforementioned retrieval strategy, the retrieval model is used to retrieve vulnerability knowledge entries in the vulnerability knowledge base based on similarity, and preliminary retrieval results are obtained. The preliminary search results are optimized using a reordering strategy to obtain the final search results; the final search results are the vulnerability information most relevant to the smart contract code.

3. The smart contract vulnerability detection method according to claim 1, characterized in that, The process of building the vulnerability knowledge base includes: Acquire various vulnerability data; the vulnerability data includes smart contract code containing vulnerabilities and corresponding vulnerability information; The vulnerability data is tagged and stored in a vulnerability knowledge base.

4. The smart contract vulnerability detection method according to claim 1, characterized in that, The vulnerability detection strategy includes a detection strategy and output content; the detection strategy is implemented through template selection, information filling, and context reconstruction.

5. The smart contract vulnerability detection method according to claim 1, characterized in that, Based on the aforementioned vulnerability detection strategy and the characteristics of the smart contract code, vulnerability detection is performed using the vulnerability information most relevant to the smart contract code to obtain vulnerability detection results, specifically including: Based on the vulnerability detection strategy and the characteristics of the smart contract code, the vulnerability information most relevant to the smart contract code is used as context, and a generative model is used for detection to obtain the vulnerability detection results.

6. The smart contract vulnerability detection method according to claim 1, characterized in that, After obtaining the vulnerability detection results by performing vulnerability detection using the vulnerability information most relevant to the smart contract code based on the aforementioned vulnerability detection strategy and the characteristics of the smart contract code, the process further includes: The vulnerability detection results are displayed to the user, and the vulnerability knowledge base is updated using the vulnerability detection results.

7. A smart contract vulnerability detection device, characterized in that, The smart contract vulnerability detection device includes: The acquisition module is used to acquire the smart contract code that the user needs to inspect; The retrieval strategy determination module is used to determine the retrieval strategy based on the characteristics of the smart contract code and the types of potential vulnerabilities. The retrieval module is used to search the vulnerability knowledge base according to the retrieval strategy and the retrieval model to obtain the vulnerability information most relevant to the smart contract code. The vulnerability detection strategy determination module is used to determine the vulnerability detection strategy based on the characteristics of the smart contract code by utilizing the vulnerability information most relevant to the smart contract code. The detection module is used to perform detection based on the vulnerability detection strategy and the characteristics of the smart contract code, using the vulnerability information most relevant to the smart contract code, and to obtain vulnerability detection results.

8. A computer device, comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that the processor executes the computer program to implement the smart contract vulnerability detection method according to any one of claims 1-6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the smart contract vulnerability detection method according to any one of claims 1-6.

10. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the smart contract vulnerability detection method according to any one of claims 1-6.