Mind the Gap: Detecting Description-Execution Mismatch Attacks in DAO Governance
Bowen Cai, Nanzi Yang, Weiheng Bai, Youshui Lu, Yajin Zhou, Kangjie Lu
Abstract
Decentralized autonomous organizations (DAOs) make protocol changes through the proposal-based process: (1) Initiators submit a proposal; (2) DAO members vote for it based on the proposal description, and if it passes, (3) the project executes the code behind the proposal. Such a process is inherently vulnerable to deceptive proposals: the description intent and the actual code execution may mismatch. A malicious proposer could submit a proposal with a benign-looking description to pass voting, while the executed code performs harmful actions, such as transferring funds or taking control of the protocol, which we call Description-Execution Mismatch (DEMI) attack.
In this paper, we present the first systematic framework for DEMI detection in real DAO governance. First, the diversity of DAO deployments makes it difficult to design a unified analysis that can apply and scale to different proposals. To address this challenge, we propose a DAO-agnostic simulation framework; its core first builds a per-DAO governance profile from historical on-chain transactions, then performs live proposal simulation by driving each new proposal through the full governance lifecycle to obtain its execution behaviors. Second, the incompatibility between free-form descriptions and structured execution traces makes consistency checking non-trivial. We address this via an evidence-mapping paradigm that requires an LLM to locate explicit per-action textual justifications, rather than issuing a holistic consistency judgment, substantially improving precision and recall over direct querying.
We evaluate our system on a large-scale dataset of real-world Ethereum DAO governance activity. Our lifecycle simulation successfully derives execution results for 92.7% of active DAOs and 89.3% of executed proposals, substantially exceeding the coverage of existing governance platforms. Our DEMI detector achieves a mean precision of 81.7% and a mean recall of 98.3% under stratified crossvalidation, and its underlying evidence-mapping design generalizes across LLM vendors rather than depending on any single model. Under a systematic red-team/blue-team evaluation, the Robustness Guard defends the large majority of adaptive attacks even against an adversary that knows the detector, and this robustness appears largely structural: it generalizes to held-out proposals, and in our
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e3a1752c-56df-4fb9-8b5d-584815608e35Builds on1
Related papers
- Quantitative Runtime Monitoring of Ethereum Transaction AttacksXinyao Xu, Ziyu Mao, Jianzhong Su, Xingwei Lin et al.WWW 2025 · 1 citation
- EOSAFE: Security Analysis of EOSIO Smart ContractsNingyu He, Ruiyi Zhang, Haoyu Wang, Lei Wu et al.USENIX Security 2021 · 69 citations
- LookAhead: Preventing DeFi Attacks via Unveiling Adversarial ContractsShoupeng Ren, Lipeng He, Tianyu Tu, Di Wu et al.FSE 2025 · 3 citations
- GenDetect: Generalizing Reactive Detection for Resilience Against Imitative DeFi Attack CascadeBowen Cai, Weiheng Bai, Youshui Lu, Haoran Xu et al.ICSE 2026
- Phishing in Wonderland: Evaluating Learning-Based Ethereum Phishing Transaction Detection and PitfallsAhod Alghuried, David MohaisenNDSS 2026 · 4 citations
