引用本文:揭晚晴,邱望洁,黄鑫鹏,杨浩甫,赵冠球,张沁楠,夏清,郑宏威,郑志明.智能合约与DeFi协议漏洞检测技术综述.软件学报,2026,37(1):344-377
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 1465次   下载 1598 本文二维码信息
码上扫一扫!
分享到: 微信 更多
智能合约与DeFi协议漏洞检测技术综述
揭晚晴1,2,3, 邱望洁1,2,3, 黄鑫鹏1,2,3, 杨浩甫1,2,4, 赵冠球1,2, 张沁楠1,2, 夏清5, 郑宏威1,6, 郑志明1,2,3
1.未来区块链与隐私计算高精尖创新中心 (北京航空航天大学), 北京 100191;2.北京航空航天大学 人工智能学院, 北京 100191;3.中关村实验室, 北京 100191;4.南开大学 计算机学院, 天津 300071;5.中国科学院 软件研究所 并行软件与计算科学实验室, 北京 100190;6.北京微芯区块链与边缘计算研究院, 北京 100190
摘要:
智能合约作为区块链核心的可编程组件, 承担了资产管理和复杂业务逻辑处理的功能, 它们共同构成了去中心化金融(decentralized finance, DeFi)协议. 然而, 随着区块链的快速发展, 智能合约和DeFi协议的安全问题日益凸显, 吸引了大量攻击者利用其漏洞牟取利益. 近年来, 多起涉及智能合约和DeFi协议的重大安全事件强调了漏洞检测技术研究的必要性, 已成为安全防护的重中之重. 系统性地总结了现有工作, 提出了智能合约与DeFi协议漏洞检测技术研究框架, 分别从智能合约和DeFi协议两个层面对漏洞类型和检测技术进行梳理. 在智能合约方面, 重点分析了大语言模型(large language model, LLM)作为主要检测引擎和与传统方法结合的漏洞检测技术应用情况; 在DeFi协议方面, 系统性地分类并整理了DeFi协议层的漏洞及其检测方法, 并探讨了攻击发生前后检测方法的优势与局限性, 弥补了现有综述在DeFi协议漏洞检测方面的不足. 最后, 对现有检测方法面临的挑战进行总结, 并展望了未来的研究方向, 旨在为智能合约与DeFi协议的安全检测提供新的思路和理论支持.
关键词:  智能合约  DeFi协议  漏洞检测  大语言模型
DOI:10.13328/j.cnki.jos.007413
分类号:
基金项目:国家重点研发计划(2022ZD0116800); 国家自然科学基金(62141605, 62372493); 中国博士后科学基金(373500); 北京市自然科学基金(Z230001); 未来区块链与隐私计算高精尖创新中心建设项目(GJJ-23-001, GJJ-23-002); 北航敢为行动计划(KG16336101)
Survey on Vulnerability Detection Techniques for Smart Contract and DeFi Protocol
JIE Wan-Qing1,2,3, QIU Wang-Jie1,2,3, HUANG Xin-Peng1,2,3, YANG Hao-Fu1,2,4, ZHAO Guan-Qiu1,2, ZHANG Qin-Nan1,2, XIA Qing5, ZHENG Hong-Wei1,6, ZHENG Zhi-Ming1,2,3
1.Beijing Advanced Innovation Center for Future Blockchain and Privacy Computing (Beihang University), Beijing 100191, China;2.School of Artificial Intelligence, Beihang University, Beijing 100191, China;3.Zhongguancun Laboratory, Beijing 100191, China;4.College of Computer Science, Nankai University, Tianjin 300071, China;5.Joint Laboratory of Blockchain Technology and Application, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China;6.Beijing Academy of Blockchain and Edge Computing, Beijing 100190, China
Abstract:
As core programmable components of blockchain, smart contracts are responsible for asset management and the execution of complex business logic, forming the foundation of decentralized finance (DeFi) protocols. However, with the rapid advancement of blockchain technology, security issues related to smart contracts and DeFi protocols have become increasingly prominent, attracting numerous attackers seeking to exploit vulnerabilities for illicit gains. In recent years, several major security incidents involving smart contracts and DeFi protocols have highlighted the importance of vulnerability detection research, making it a critical area for security defense. This study systematically reviews existing literature and proposes a comprehensive framework for research on vulnerability detection in smart contracts and DeFi protocols. Specifically, vulnerabilities and detection techniques are categorized and analyzed for both domains. For smart contracts, the study focuses on the application of large language models (LLM) as primary detection engines and their integration with traditional methods. For DeFi protocols, it categorizes and details various protocol-level vulnerabilities and their detection methods, analyzing the strengths and limitations of detection strategies before and after attacks, addressing gaps in existing reviews on DeFi vulnerability detection. Finally, this study summarizes the challenges faced by current detection approaches and outlines future research directions, aiming to provide new insights and theoretical support for the security detection of smart contracts and DeFi protocols.
Key words:  smart contract  DeFi protocol  vulnerability detection  large language model (LLM)

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: