GenDetect: Generalizing Reactive Detection for Resilience Against Imitative DeFi Attack Cascade
Bowen Cai, Weiheng Bai, Youshui Lu, Haoran Xu, Yuannan Yang, Yajin Zhou, Kangjie Lu
摘要
As blockchain ecosystems grow, financially motivated attackers have increasingly exploited vulnerabilities in decentralized finance (DeFi) protocols, resulting in frequent and severe losses. Unlike conventional cyberattacks, DeFi exploits propagate rapidly due to the transparent and composable nature of smart contracts. In this setting, we identify a critical behavioral pattern: Imitative Attack Cascade, where an initial successful exploit is quickly followed by a flurry of mimicking transactions that reuse attack logic with minor modifications or parameter changes. Our empirical analysis shows that over 69% of DeFi attacks exhibit strong behavioral similarity to earlier incidents, often occurring within hours or days of the initial attack.
This phenomenon highlights a fundamental limitation in current reactive detection workflows. While the initial attacks are often flagged through heuristic alerts, such as Tornado Cash traces, anomalous nonce usage, or known exploiter labels, these signals require manual validation and the construction of handcrafted detection rules through trace analysis. This process is labor-intensive and slow, resulting in unacceptable latency while follow-up attacks continue to spread. Motivated by this gap, our research goal is to ensure that once an attack has been observed, even a single instance, it can be rapidly abstracted into an actionable and generalizable detection rule, enabling scalable protection against imitative attacks.
We decompose the problem into two core challenges: (I) abstracting the semantics of diverse, obscure function signatures, and (II) matching transaction logic in noisy, evasive traces. To address these, we leverage two key insights: (i) the open-source nature of most DeFi protocols enables high-fidelity semantic classification of function signatures; (ii) contract labels allow us to isolate essential logic by filtering irrelevant calls and classifying attack intent. Based on these, we develop a reactive detection framework, GenDetect, which achieves strong benchmark performance (ACC: 98%, FPR: 1%, FNR: 3%) and, critically, discovers 56 previously unrevealed attacks from
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper6
- POMABuster: Detecting Price Oracle Manipulation Attacks in Decentralized FinanceRui Xi, Zehua Wang, Karthik PattabiramanS&P 2024 · 被引用 13 次
- Towards Finding Accounting Errors in Smart ContractsBrian ZhangICSE 2024 · 被引用 8 次
- Toward Automated Detecting Unanticipated Price Feed in Smart ContractYifan Mo, Jiachi Chen, Yanlin Wang, Zibin ZhengISSTA 2023 · 被引用 7 次
- Your Exploit is Mine: Instantly Synthesizing Counterattack Smart ContractZhuo Zhang, Zhiqiang Lin, Marcelo Morales, Xiangyu Zhang 等USENIX Security 2023
- The Blockchain Imitation GameKaihua Qin, Stefanos Chaliasos, Liyi Zhou, Benjamin Livshits 等USENIX Security 2023
相关 Paper
- LookAhead: Preventing DeFi Attacks via Unveiling Adversarial ContractsShoupeng Ren, Lipeng He, Tianyu Tu, Di Wu 等FSE 2025 · 被引用 3 次
- HOUSTON: Real-Time Anomaly Detection of Attacks against Ethereum DeFi ProtocolsDongyu Meng, Fabio Gritti, Robert McLaughlin, Nicola Ruaro 等NDSS 2026 · 被引用 2 次
- Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?Stefanos Chaliasos, Marcos Antonios Charalambous, Liyi Zhou, Rafaila Galanopoulou 等ICSE 2024 · 被引用 49 次
- SoK: Decentralized Finance (DeFi) AttacksLiyi Zhou, Xihan Xiong, Jens Ernstberger, Stefanos Chaliasos 等S&P 2023
- OctopusGuard: K-Line Enhanced Token Scam Detector Powered by Multimodal LLMsLitong Sun, YangTian Mi, Xiapu Luo, Weigang WuICSE 2026
