Skip to content
Conference

LLM-Driven Smart Contract Vulnerability Detection Based on Heterogeneous Graphs

Jul 2026 · Annual International Computer Software and Applications Conference · pp. 2970-2979 · 0 citations · 39 references
Computer Science

Abstract

As a core technology in blockchain-based systems, smart contracts are widely used in various fields. Meanwhile, their post-deployment immutability and financial nature render vulnerabilities attractive to attackers, as evidenced by significant economic losses, making smart contract vulnerability detection a critical task. Traditional detection tools mainly rely on vulnerability patterns derived from static program analysis, but are limited by expert experience and exhibit poor scalability. Recently, Large Language Models (LLMs) have emerged as a new solution for identifying smart contract vulnerabilities due to their remarkable capabilities in code understanding and reasoning. However, current prompting-based approaches are often restricted by high token overhead and the lack of domain-specific knowledge. To this end, this paper proposes an LLM-driven approach for detecting vulnerabilities in Ethereum smart contracts. First, we construct a heterogeneous graph that fuses control flow graphs (CFGs) and data flow graphs (DFGs) to capture the execution logic and transaction behavior of each smart contract with significantly reduced token consumption. Second, we leverage LLMs to extract key paths from each heterogeneous graph to filter out branches unrelated to vulnerabilities. Third, we build a knowledge repository based on the extracted key paths of both vulnerable and non-vulnerable smart contracts, together with a dual-metric retrieval mechanism. Finally, we design a Chain-of-Thought (CoT)-based prompt to guide vulnerability detection using the target smart contract's retrieved similar paths. Experiments on a public dataset of 1,093 smart contracts demonstrate the effectiveness of our approach, outperforming traditional tools by average improvements of 25.75% in accuracy and 31.44% in F1 score. Compared with LLM-based baselines, our approach achieves average improvements of 21.89% in accuracy and 26.91% in F1 score, along with a decrease of 52.88% in token consumption.

View source

Similar papers

Review Open access 2026

SVACS: Smart Contract Vulnerability Analysis via Control Flow Semantics

This paper proposes SVACS, a bytecode-based analysis framework to identify multiple co-existing vulnerabilities based on SWC registry to align with industry-standard security guidelines and assist security reviewers to ensure smart contract security.

Ankur Jain, Abhishar Anand, S. Tripathy · 0 citations
Sep 2026

Solidity Meets LLMs: A Transformer-Based Approach to Smart Contract Vulnerability Detection

The growing adoption of blockchain technologies, particularly the Ethereum platform, has amplified the critical role of smart contracts in decentralized applications. However, the increasing complexity and financial value of these contracts make them prime targets for cyber attacks. In this work, we present a transform...

Djamel Eddine Hakim Ghorab, Farid Mokhati, Mostafa Anouar Ghorab · 0 citations
#artificial intelligence Preprint Sep 2026

Automated Vulnerability Injection in Smart Contracts Using Large Language Models

Results show that LLM-based vulnerability injection is feasible, while exposing key limitations in scalability and diversity, and practical challenges including LLMs' non-determinism and the difficulty of preserving contract semantics are reported.

Luca Migliaccio, Roberto Natella, N. Ivaki et al. · 0 citations
Preprint Aug 2026

Enhancing Reliability of Symbolic Execution Tools for Smart Contract Analysis through Rule-Based False Positive Reduction

A blockchain is a decentralized, secure ledger system that enables transparent and immutable record-keeping, essential for trust and security in digital transactions. Smart contracts are self-executing agreements encoded on a blockchain, enabling different parties to fulfill the terms of the agreement automatically. Th...

M. Ahmad, M. Ali, M. Amer et al. · 0 citations
Sep 2026

SE4SC-LLM: an LLM-Augmented symbolic execution framework for smart contracts

SE4SC-LLM, an LLM-augmented symbolic execution framework for smart contracts that achieves 95.1% average CFG coverage, a 6.5 percentage point improvement over the strongest baseline, and detects 11.2% more vulnerabilities.

Tian-Huan Miao, Yang Liu · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.