Efficiently Detecting Reentrancy Vulnerabilities in Complex Smart Contracts
Zexu Wang, Jiachi Chen, Yanlin Wang, Yu Zhang, Weizhe Zhang, Zibin Zheng
摘要
Reentrancy vulnerability as one of the most notorious vulnerabilities, has been a prominent topic in smart contract security research. Research shows that existing vulnerability detection presents a range of challenges, especially as smart contracts continue to increase in complexity. Existing tools perform poorly in terms of efficiency and successful detection rates for vulnerabilities in complex contracts. To effectively detect reentrancy vulnerabilities in contracts with complex logic, we propose a tool named SliSE. SliSE's detection process consists of two stages: Warning Search and Symbolic Execution Verification. In Stage I, SliSE utilizes program slicing to analyze the Inter-contract Program Dependency Graph (I-PDG) of the contract, and collects suspicious vulnerability information as warnings. In Stage II, symbolic execution is employed to verify the reachability of these warnings, thereby enhancing vulnerability detection accuracy. SliSE obtained the best performance compared with eight state-of-the-art detection tools. It achieved an F1 score of 78.65%, surpassing the highest score recorded by an existing tool of 9.26%. Additionally, it attained a recall rate exceeding 90% for detection of contracts on Ethereum. Overall, SliSE provides a robust and efficient method for detection of Reentrancy vulnerabilities for complex contracts. CCS Concepts: • Software and its engineering → Software verification and validation; Software testing and debugging.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- One Signature, Multiple Payments: Demystifying and Detecting Signature Replay Vulnerabilities in Smart ContractsZexu Wang, Jiachi Chen, Zewei Lin, Wenqing Chen 等ICSE 2026
- BugSweeper: Function-Level Detection of Smart Contract Vulnerabilities Using Graph Neural NetworksUisang Lee, Changhoon Chung, Junmo Lee, Soo-Mook MoonAAAI 2026
- Copy-and-Paste? Identifying EVM-Inequivalent Code Smells in Multi-chain Reuse ContractsZexu Wang, Jiachi Chen, Tao Zhang, Yu Zhang 等ISSTA 2025
- Verifying Smart Contract Security against Re-entrancy Attacks through Relational Value AnalysisDivya Rathore, Kartik NagarFSE 2026
- HEMVM: A Heterogeneous Blockchain Framework for Interoperable Virtual MachinesVladyslav Nekriach, Sidi Mohamed Beillahi, Chenxing Li, Peilun Li 等OOPSLA 2025
它引用的顶会 Paper19
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 被引用 595 次
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 被引用 345 次
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov 等CCS 2019 · 被引用 288 次
相关 Paper
- Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker ContractsShuo Yang, Jiachi Chen, Mingyuan Huang, Zibin Zheng 等ICSE 2024 · 被引用 24 次
- Turn the Rudder: A Beacon of Reentrancy Detection for Smart Contracts on EthereumZibin Zheng, Neng Zhang, Jianzhong Su, Zhijie Zhong 等ICSE 2023 · 被引用 52 次
- Enhancing Smart Contract Security Analysis with Execution Property GraphsKaihua Qin, Zhe Ye, Zhun Wang, Weilin Li 等ISSTA 2025 · 被引用 1 次
- AdvSCanner: Generating Adversarial Smart Contracts to Exploit Reentrancy Vulnerabilities Using LLM and Static AnalysisYin Wu, Xiaofei Xie, Chenyang Peng, Dijun Liu 等ASE 2024 · 被引用 9 次
- Cross-Contract Static Analysis for Detecting Practical Reentrancy Vulnerabilities in Smart ContractsYinxing Xue, Mingliang Ma, Yun Lin, Yulei Sui 等ASE 2020 · 被引用 77 次
