COBRA: Interaction-Aware Bytecode-Level Vulnerability Detector for Smart Contracts
Wenkai Li, Xiaoqi Li, Zongwei Li, Yuqing Zhang
Abstract
The detection of vulnerabilities in smart contracts remains a significant challenge. While numerous tools are available for analyzing smart contracts in source code, only about 1.79% of smart contracts on Ethereum are open-source. For existing tools that target bytecodes, most of them only consider the semantic logic context and disregard function interface information in the bytecodes. In this paper, we propose COBRA, a novel framework that integrates semantic context and function interfaces to detect vulnerabilities in bytecodes of the smart contract. To our best knowledge, COBRA is the first framework that combines these two features. Moreover, to infer the function signatures that are not present in signature databases, we present SRIF (Signatures Reverse Inference from Functions), automatically learn the rules of function signatures from the smart contract bytecodes. The bytecodes associated with the function signatures are collected by constructing a control flow graph (CFG) for the SRIF training. We optimize the semantic context using the operation code in the static single assignment (SSA) format. Finally, we integrate the context and function interface representations in the latent space as the contract feature embedding. The contract features in the hidden space are decoded for vulnerability classifications with a decoder and attention module. Experimental results demonstrate that SRIF can achieve 94.76% F1-score for function signature inference. Furthermore, when the ground truth ABI exists, COBRA achieves 93.45% F1-score for vulnerability classification. In the absence of ABI, the inferred function feature fills the encoder, and the system accomplishes an 89.46% recall rate.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4003a0d9-c6b2-4f14-a1aa-6caf10d5b680Cited by top-tier papers3
- SCALM: Detecting Bad Practices in Smart Contracts Through LLMsZongwei Li, Xiaoqi Li, Wenkai Li, Xin WangAAAI 2025 · 40 citations
- Soleker: Uncovering Vulnerabilities in Solana Smart ContractsKunsong Zhao, Yunpeng Tian, Zuchao Ma, Xiapu LuoASE 2025
- Revealing the Dark Side of Smart Accounts: An Empirical Study of EIP-7702 Incurred Risks in Blockchain EcosystemMingyuan Huang, Han Liu, Shuo Yang, Daoyuan Wu et al.USENIX Security 2026
Builds on16
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 373 citations
- Sereum: Protecting Existing Smart Contracts Against Re-Entrancy AttacksMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviNDSS 2019 · 298 citations
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov et al.CCS 2019 · 288 citations
- Smart Contract Vulnerabilities: Vulnerable Does Not Imply ExploitedDaniel Perez, Benjamin LivshitsUSENIX Security 2021 · 150 citations
Related papers
- DeepInfer: Deep Type Inference from Smart Contract BytecodeKunsong Zhao, Zihao Li, Jianfeng Li, He Ye et al.FSE 2023 · 24 citations
- SmartDagger: a bytecode-based static analysis approach for detecting cross-contract vulnerabilityZeqin Liao, Zibin Zheng, Xiao Chen, Yuhong NanISSTA 2022 · 64 citations
- Smart Learning to Find Dumb ContractsTamer Abdelaziz, Aquinas HoborUSENIX Security 2023
- Cross-Modality Mutual Learning for Enhancing Smart Contract Vulnerability Detection on BytecodePeng Qian, Zhenguang Liu, Yifang Yin, Qinming HeWWW 2023 · 91 citations
- ReFun: Reconstructing Function Boundaries in EVM BytecodeYichuan Li, Wei Song, Jeff Huang, Hans-Arno JacobsenOOPSLA 2026 · 1 citation
