GenDetect: Generalizing Reactive Detection for Resilience Against Imitative DeFi Attack Cascade
Bowen Cai, Weiheng Bai, Youshui Lu, Haoran Xu, Yuannan Yang, Yajin Zhou, Kangjie Lu
Abstract
As blockchain ecosystems grow, financially motivated attackers have increasingly exploited vulnerabilities in decentralized finance (DeFi) protocols, resulting in frequent and severe losses. Unlike conventional cyberattacks, DeFi exploits propagate rapidly due to the transparent and composable nature of smart contracts. In this setting, we identify a critical behavioral pattern: Imitative Attack Cascade, where an initial successful exploit is quickly followed by a flurry of mimicking transactions that reuse attack logic with minor modifications or parameter changes. Our empirical analysis shows that over 69% of DeFi attacks exhibit strong behavioral similarity to earlier incidents, often occurring within hours or days of the initial attack.
This phenomenon highlights a fundamental limitation in current reactive detection workflows. While the initial attacks are often flagged through heuristic alerts, such as Tornado Cash traces, anomalous nonce usage, or known exploiter labels, these signals require manual validation and the construction of handcrafted detection rules through trace analysis. This process is labor-intensive and slow, resulting in unacceptable latency while follow-up attacks continue to spread. Motivated by this gap, our research goal is to ensure that once an attack has been observed, even a single instance, it can be rapidly abstracted into an actionable and generalizable detection rule, enabling scalable protection against imitative attacks.
We decompose the problem into two core challenges: (I) abstracting the semantics of diverse, obscure function signatures, and (II) matching transaction logic in noisy, evasive traces. To address these, we leverage two key insights: (i) the open-source nature of most DeFi protocols enables high-fidelity semantic classification of function signatures; (ii) contract labels allow us to isolate essential logic by filtering irrelevant calls and classifying attack intent. Based on these, we develop a reactive detection framework, GenDetect, which achieves strong benchmark performance (ACC: 98%, FPR: 1%, FNR: 3%) and, critically, discovers 56 previously unrevealed attacks from
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4c545969-2805-49ff-b7b6-8d08197751dbBuilds on6
- POMABuster: Detecting Price Oracle Manipulation Attacks in Decentralized FinanceRui Xi, Zehua Wang, Karthik PattabiramanS&P 2024 · 13 citations
- Towards Finding Accounting Errors in Smart ContractsBrian ZhangICSE 2024 · 8 citations
- Toward Automated Detecting Unanticipated Price Feed in Smart ContractYifan Mo, Jiachi Chen, Yanlin Wang, Zibin ZhengISSTA 2023 · 7 citations
- Your Exploit is Mine: Instantly Synthesizing Counterattack Smart ContractZhuo Zhang, Zhiqiang Lin, Marcelo Morales, Xiangyu Zhang et al.USENIX Security 2023
- The Blockchain Imitation GameKaihua Qin, Stefanos Chaliasos, Liyi Zhou, Benjamin Livshits et al.USENIX Security 2023
Related papers
- LookAhead: Preventing DeFi Attacks via Unveiling Adversarial ContractsShoupeng Ren, Lipeng He, Tianyu Tu, Di Wu et al.FSE 2025 · 3 citations
- HOUSTON: Real-Time Anomaly Detection of Attacks against Ethereum DeFi ProtocolsDongyu Meng, Fabio Gritti, Robert McLaughlin, Nicola Ruaro et al.NDSS 2026 · 2 citations
- Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?Stefanos Chaliasos, Marcos Antonios Charalambous, Liyi Zhou, Rafaila Galanopoulou et al.ICSE 2024 · 49 citations
- SoK: Decentralized Finance (DeFi) AttacksLiyi Zhou, Xihan Xiong, Jens Ernstberger, Stefanos Chaliasos et al.S&P 2023
- OctopusGuard: K-Line Enhanced Token Scam Detector Powered by Multimodal LLMsLitong Sun, YangTian Mi, Xiapu Luo, Weigang WuICSE 2026
