Hyperion: Unveiling DApp Inconsistencies Using LLM and Dataflow-Guided Symbolic Execution
Shuo Yang, Xingwei Lin, Jiachi Chen, Qingyuan Zhong, Lei Xiao, Renke Huang, Yanlin Wang, Zibin Zheng
Abstract
The rapid advancement of blockchain platforms has significantly accelerated the growth of decentralized applications (DApps). Similar to traditional applications, DApps integrate front-end descriptions that showcase their features to attract users, and back-end smart contracts for executing their business logic. However, inconsistencies between the features promoted in front-end descriptions and those actually implemented in the contract can confuse users and undermine DApps's trustworthiness. In this paper, we first conducted an empirical study to identify seven types of inconsistencies, each exemplified by a real-world DApp. Furthermore, we introduce Hyperion, an approach designed to automatically identify inconsistencies between front-end descriptions and back-end code implementation in DApps. This method leverages a fine-tuned large language model LLaMA2 to analyze DApp descriptions and employs dataflow-guided symbolic execution for contract bytecode analysis. Finally, Hyperion reports the inconsistency based on predefined detection patterns. The experiment on our ground truth dataset consisting of 54 DApps shows that Hyperion reaches 84.06% overall recall and 92.06 % overall precision in reporting DApp inconsistencies. We also implement Hyperion to analyze 835 real-world DApps. The experimental results show that Hyperion discovers 459 real-world DApps containing at least one inconsistency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 677f8c65-2401-4e98-bfec-2d31996b7ba9Cited by top-tier papers6
- RMCBench: Benchmarking Large Language Models' Resistance to Malicious CodeJiachi Chen, Qingyuan Zhong, Yanlin Wang, Kaiwen Ning et al.ASE 2024 · 6 citations
- DrainCode: Stealthy Energy Consumption Attacks on Retrieval-Augmented Code Generation via Context PoisoningYanli Wang, Jiadong Wu, Tianyue Jiang, Mingwei Liu et al.ASE 2025 · 3 citations
- AlignCoder: Aligning Retrieval with Target Intent for Repository-Level Code CompletionTianyue Jiang, Yanlin Wang, Yanli Wang, Daya Guo et al.ASE 2025 · 2 citations
- Precise Static Identification of Ethereum Storage VariablesSifis Lagouvardos, Yannis Bollanos, Michael Debono, Neville Grech et al.ICSE 2026 · 2 citations
- SSR: Safeguarding Staking Rewards by Defining and Detecting Logical Defects in DeFi StakingZewei Lin, Jiachi Chen, Jingwen Zhang, Zexu Wang et al.ASE 2025 · 1 citation
Builds on17
- Training language models to follow instructions with human feedbackLong Ouyang, Jeffrey Wu, Xu Jiang, Diogo Almeida et al.NeurIPS 2022 · 24,707 citations
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma et al.NeurIPS 2022 · 22,562 citations
- LoRA: Low-Rank Adaptation of Large Language ModelsEdward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu et al.ICLR 2022 · 18,833 citations
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
Related papers
- ÐArcher: detecting on-chain-off-chain synchronization bugs in decentralized applicationsWuqi Zhang, Lili Wei, Shuqing Li, Yepang Liu et al.FSE 2021 · 19 citations
- TracePilot: Self-Verifiable Framework for Decentralized Applications Fault Localization across TransactionsXuanyu Zhu, Zhiying Wu, Tao Wang, Ying Yan et al.ISSTA 2026
- Detecting Code-Comment Inconsistencies in Smart Contracts by Combining LLM and Program AnalysisJiashuo Zhang, Jiachi Chen, Ting Zhang, Yue Li et al.FSE 2026
- Identifying Solidity Smart Contract API Documentation ErrorsChenguang Zhu, Ye Liu, Xiuheng Wu, Yi LiASE 2022 · 16 citations
- Semantic Sleuth: Identifying Ponzi Contracts via Large Language ModelsCong Wu, Jing Chen, Ziwei Wang, Ruichao Liang et al.ASE 2024 · 29 citations
