Identifying Solidity Smart Contract API Documentation Errors
Chenguang Zhu, Ye Liu, Xiuheng Wu, Yi Li
摘要
Smart contracts are gaining popularity as a means to support transparent, traceable, and self-executing decentralized applications, which enable the exchange of value in a trustless environment. Developers of smart contracts rely on various libraries, such as OpenZeppelin for Solidity contracts, to improve application quality and reduce development costs. The API documentations of these libraries are important sources of information for developers who are unfamiliar with the APIs. Yet, maintaining high-quality documentations is non-trivial, and errors in documentations may place barriers for developers to learn the correct usages of APIs. In this paper, we propose a technique, DocCon, to detect inconsistencies between documentations and the corresponding code for Solidity smart contract libraries. Our fact-based approach allows inconsistencies of different severity levels to be queried, from a database containing precomputed facts about the API code and documentations. DocCon successfully detected high-priority API documentation errors in popular smart contract libraries, including mismatching parameters, missing requirements, outdated descriptions, etc. Our experiment result shows that DocCon achieves good precision and is applicable to different libraries: 29 and 22 out of our reported 40 errors have been confirmed and fixed by library developers so far.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Understanding End-User Perception of Transfer Risks in Smart ContractsYustynn Panicker, Ezekiel O. Soremekun, Sudipta Chattopadhyay, Sumei SunCHI 2025 · 被引用 2 次
- EventSpec: Defining and Detecting Event-Semantic Issues in Blockchain EcosystemsYixuan Liu, Yuxin Dong, Ye Liu, Yin Wu 等ISSTA 2026
- TrapHunter: Exposing Covert Pathways in Trap Token ContractsYin Wu, Yixuan Liu, Yi Li, Chenyang Peng 等ISSTA 2026
- Identifying Multi-parameter Constraint Errors in Python Data Science Library API DocumentationXiufeng Xu, Fuman Xie, Chenguang Zhu, Guangdong Bai 等ISSTA 2025
- SymGPT: Auditing Smart Contracts via Combining Symbolic Execution with Large Language ModelsShihao Xia, Mengting He, Shuai Shao, Tingting Yu 等OOPSLA 2026
相关 Paper
- Using My Functions Should Follow My Checks: Understanding and Detecting Insecure OpenZeppelin Code in Smart ContractsHan Liu, Daoyuan Wu, Yuqiang Sun, Haijun Wang 等USENIX Security 2024 · 被引用 11 次
- Automating User Notice Generation for Smart Contract FunctionsXing Hu, Zhipeng Gao, Xin Xia, David Lo 等ASE 2021 · 被引用 23 次
- Demystifying OpenZeppelin's Own Vulnerabilities and Analyzing Their Propagation in Smart ContractsHan Liu, Daoyuan Wu, Yuqiang Sun, Shuai Wang 等ASE 2025 · 被引用 1 次
- DocTer: documentation-guided fuzzing for testing deep learning API functionsDanning Xie, Yitong Li, Mijung Kim, Hung Viet Pham 等ISSTA 2022 · 被引用 72 次
- Code Cloning in Solidity Smart Contracts: Prevalence, Evolution, and Impact on DevelopmentRan Mo, Haopeng Song, Wei Ding, Chaochao WuICSE 2025 · 被引用 1 次
