Skip to content

A Unified Framework for Function-Level Vulnerability Detection and Explanation in Smart Contracts

Sep 2026 · ACM Transactions on Software Engineering and Methodology · 0 citations · 8 references

TL;DR

A unified framework combining a novel Hierarchical Cross-Attention Subgraph Neural Network for detection with Large Language Models for explanation form a comprehensive framework that significantly enhances both the technical accuracy and operational usability of smart contract analysis.

Abstract

Smart contracts enable decentralized applications, yet their immutability makes security vulnerabilities catastrophic, often leading to irrecoverable financial losses and systemic risks. Existing machine learning approaches typically operate at the coarse contract level, failing to localize issues to specific functions or provide interpretable remediation guidance for developers. To address these persistent limitations, we introduce a unified framework combining a novel Hierarchical Cross-Attention Subgraph Neural Network (HCA-SGNN) for detection with Large Language Models (LLMs) for explanation. For detection, HCA-SGNN processes functions as subgraphs, explicitly modeling control- and data-flow dependencies while capturing cross-function interactions to pinpoint localized risks. To enable robust training, we develop an AST-driven injection system that generates stealthy, context-aware vulnerabilities through template-based synthesis. Uniquely, this system ensures collision-free variable naming and version-specific compatibility, producing a comprehensive, function-level annotated dataset covering diverse classes such as reentrancy, integer overflows, and access control flaws. Complementing detection, we generate structured, human-readable justifications using synthetic data and chain-of-thought prompting. These explanations detail the vulnerability type, affected area, root cause, and actionable mitigation strategies, effectively bridging the gap between automated detection and practical insight. Together, these components form a comprehensive framework that significantly enhances both the technical accuracy and operational usability of smart contract analysis.

View source

Similar papers

Open access Sep 2026

TCRNet: Topology-Guided Contextual Representation Network for Smart Contract Vulnerability Detection

Smart contracts operate in decentralized environments where deployed code cannot be easily modified, making security vulnerabilities particularly critical. Even minor logical flaws may lead to severe financial and operational consequences. Although traditional static analysis and symbolic execution techniques have been...

R. S, Mahantesh Mathapati · 0 citations
Sep 2026

FiCoVuL: A Framework for Fine-grained and Cross-function Code Vulnerability Detection

Detecting vulnerabilities in software development is crucial yet challenging. Deep learning-based approaches have shown promise in automatically learning features for vulnerable function detection. In practice, human analysts need to correlate the behavioral logic of multiple functions to confirm the occurrence of vuln...

Hong-Jun Huang, Fu-Tai Zou, Jia-Ping Gui et al. · 0 citations
Sep 2026

Solidity Meets LLMs: A Transformer-Based Approach to Smart Contract Vulnerability Detection

The growing adoption of blockchain technologies, particularly the Ethereum platform, has amplified the critical role of smart contracts in decentralized applications. However, the increasing complexity and financial value of these contracts make them prime targets for cyber attacks. In this work, we present a transform...

Djamel Eddine Hakim Ghorab, Farid Mokhati, Mostafa Anouar Ghorab · 0 citations
Open access 2026

Benchmarking Prompt Engineering Against Fine-Tuning for Multi-Label Vulnerability Detection in Solidity Smart Contracts: An Empirical Study

Large Language Models (LLMs) are increasingly being deployed for smart contract security, yet a fundamental question remains unresolved for practitioners: when confronted with the realistic, multi-label setting where a single contract may harbor several concurrent vulnerabilities, which deployment strategy is more effe...

Badaruddin Chachar, J. Ferreira, M. Cavazza et al. · 0 citations
Preprint Aug 2026

Pre-Model Representation Failures in GNN-Based Smart Contract Vulnerability Detection

A failure analysis of the representation layer underlying GNN-based smart contract vulnerability detectors finds one confirmed case of misclassification caused directly by a representation-layer failure; the prevalence of such failures in real-world contract populations remains an open empirical question.

Birindwa Prisca Hondi, Chinoso Philip Nwishienyi, Charity Wanja Mwaura et al. · 0 citations
#artificial intelligence Preprint Sep 2026

Automated Vulnerability Injection in Smart Contracts Using Large Language Models

Results show that LLM-based vulnerability injection is feasible, while exposing key limitations in scalability and diversity, and practical challenges including LLMs' non-determinism and the difficulty of preserving contract semantics are reported.

Luca Migliaccio, Roberto Natella, N. Ivaki et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.