Skip to content
Review Open access

SVACS: Smart Contract Vulnerability Analysis via Control Flow Semantics

2026 · IEEE Access · Vol 14, pp. 123386-123397 · 0 citations · 28 references
Computer Science

TL;DR

This paper proposes SVACS, a bytecode-based analysis framework to identify multiple co-existing vulnerabilities based on SWC registry to align with industry-standard security guidelines and assist security reviewers to ensure smart contract security.

Abstract

Smart contracts play a key role in blockchain application development, but vulnerable smart contracts cause serious security risks to blockchain ecosystems. While most of the existing vulnerability detection techniques rely on analyzing Solidity source code, over 94% of deployed smart contracts are not open source. These smart contracts can only be accessible in bytecode form so these tools are not applicable. Existing bytecode based tools also have some limitations include improper handling of long opcode sequences and inability to detect multiple co-existing Smart Contract Weakness Classification (SWC) vulnerabilities. In this paper, we propose SVACS, a bytecode-based analysis framework to identify multiple co-existing vulnerabilities based on SWC registry to align with industry-standard security guidelines and assist security reviewers to ensure smart contract security. SVACS represents an Ethereum smart contract as control-flow graph (CFG), where each basic block is encoded using GraphCodeBERT. Block embeddings are refined using residual graph attention networks (RGAT) layer to capture inter-block control-flow dependencies. Contract-level vulnerability predictions are obtained by aggregating block-level logits. This enables SVACS to detect multiple co-existing SWC identifiers simultaneously. Performance is evaluated on a real-world dataset of 5,478 Ethereum contracts comprising 10 SWC vulnerability identifiers. The labels are obtained by combining a manually audited Consolidated Ground Truth corpus and additional smart contracts collected from Etherscan API and labelled using Slither-based analysis. To handle the multi-label and imbalanced nature of the dataset, iterative stratified splitting is used to maintain label distributions across splits, and label-wise thresholding is applied during prediction. It is found that SVACS outperforms state-of-the-art tools with 87.33% accuracy, 94.69% TPR, 15.67% FPR, 5.31% FNR, and 81.26% F1-score. SVACS achieved good performance across all 10 SWC vulnerability identifiers, with TPR ranging from 75.00% to 99.50%, FPR ranging from 1.87% to 88.81%, FNR ranging from 0.50% to 25.00%, and F1-score ranging from 54.04% to 92.89%. SVACS uses the GraphCodeBERT encoder and performs better than both CodeT5 and CodeT5p-220M in terms of higher accuracy by 8.19 and 7.89 percentage points, higher TPR by 1.37 and 2.86 percentage points, lower FPR by 10.54 and 9.76 percentage points, lower FNR by 1.37 and 2.86 percentage points, and improved F1-score by 10.21 and 9.65 percentage points, respectively. By performing directly on Ethereum Virtual Machine (EVM) bytecode and designing control-flow structure, SVACS offers a more effective solution for real-world smart contract security analysis.

Read PDF

Similar papers

Preprint Aug 2026

When Verified Source Becomes Attack Input: Defending Smart Contracts Against LLM-Based Vulnerability Scanning

Smart contracts are financial programs deployed on blockchains to manage digital assets. To build trust with users and investors, smart contract projects typically publish their source code on blockchain explorers and verify it against the deployed bytecode, making the on-chain program accessible through a human-readab...

Ming-Yuan Huang, Zimo Ji, Yifan Mo et al. · 0 citations
Aug 2026

Smart contract vulnerability detection using opcode sequences with variable length

A novel neural network model is proposed that accommodates variable-length input sequences and advances the state-of-the-art by enabling truncation-free processing of long sequences, demonstrating superior performance over baselines reliant on fixed inputs.

Peiqian Li, Guojun Wang, Xuelei Liu et al. · 0 citations
Preprint Aug 2026

Enhancing Reliability of Symbolic Execution Tools for Smart Contract Analysis through Rule-Based False Positive Reduction

A blockchain is a decentralized, secure ledger system that enables transparent and immutable record-keeping, essential for trust and security in digital transactions. Smart contracts are self-executing agreements encoded on a blockchain, enabling different parties to fulfill the terms of the agreement automatically. Th...

M. Ahmad, M. Ali, M. Amer et al. · 0 citations
Preprint Sep 2026

Function Name Is All You Need to Detect Blockchain Application Attacks

Blockchain application attacks, targeting business logic bugs in decentralized applications (dApps), have been an increasing concern to their developers and users, causing significant financial loss. Existing attack detectors either rely on handcrafted rules for detection, or need difficult-to-obtain smart contract sou...

Rui Xi, Ze-Hua Wang, Karthik Pattabiraman · 0 citations
#artificial intelligence Preprint Sep 2026

Automated Vulnerability Injection in Smart Contracts Using Large Language Models

Results show that LLM-based vulnerability injection is feasible, while exposing key limitations in scalability and diversity, and practical challenges including LLMs' non-determinism and the difficulty of preserving contract semantics are reported.

Luca Migliaccio, Roberto Natella, N. Ivaki et al. · 0 citations
Preprint Sep 2026

Detecting Logic Vulnerabilities Across the Contract and Device Layers of Blockchain-Enabled IoT With Multi-Agent Heterogeneous Graph Attention

MA-HGAT is extended into a cross-layer multi-agent heterogeneous graph attention framework that models contracts, firmware artifacts, device fleets, and transaction streams with a unified four-role, nine-relation schema and provides a unified and deployable framework for detecting logic vulnerabilities across the contr...

Min-Feng Qi, Jia-Lin Li, Tian-Qing Zhu et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.