POMABuster: Detecting Price Oracle Manipulation Attacks in Decentralized Finance
Rui Xi, Zehua Wang, Karthik Pattabiraman
摘要
Price Oracle Manipulation Attacks (POMAs) are increasingly occurring in blockchain systems, and result in significant financial loss. Prior work on detecting POMAs only considers single-transaction attacks, in which the entire attack is contained within a single transaction. We systematically study POMAs in blockchain systems (Ethereum). We find that POMAs that span multiple transactions have become much more frequent than single-transaction POMAs. Thus, there is a compelling need for a framework that can detect POMAs spanning multiple transactions. Moreover, there is a need to come up with generic rules for detecting POMAs rather than rely on past attack patterns like prior work has done.We first devise first-principle rules for detecting POMAs based on traditional stock market manipulation attacks. We then propose POMABuster, which leverages these rules to detect POMAs spanning both single and multiple transactions. POMABuster leverages common characteristics of POMA attackers’ behavior to optimize its detection. We evaluate POMABuster on 2.5 years’ worth of transactions from the blockchain, as well as a dataset compiled from the Code4rena audit reports. Our results demonstrate that POMABuster detects nearly 6.5X more POMAs than prior work. Further, POMABuster has a 1% worst-case false positive rate, and zero false negative rate, both of which significantly outperform prior work.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper2
- GenDetect: Generalizing Reactive Detection for Resilience Against Imitative DeFi Attack CascadeBowen Cai, Weiheng Bai, Youshui Lu, Haoran Xu 等ICSE 2026
- Automated and Accurate Token Transfer Identification and Its Applications in Cryptocurrency SecurityShuwei Song, Ting Chen, Ao Qiao, Xiapu Luo 等FSE 2025
相关 Paper
- DeFort: Automatic Detection and Analysis of Price Manipulation Attacks in DeFi ApplicationsMaoyi Xie, Ming Hu, Ziqiao Kong, Cen Zhang 等ISSTA 2024 · 被引用 9 次
- On Identifying Sound Conditions for Frontrunning ResistanceSebastian Holler, Anna Piscitelli, Jannik Albrecht, Stephan Dübler 等CCS 2026
- A Large Scale Study of the Ethereum Arbitrage EcosystemRobert McLaughlin, Christopher Kruegel, Giovanni VignaUSENIX Security 2023
- The Blockchain Imitation GameKaihua Qin, Stefanos Chaliasos, Liyi Zhou, Benjamin Livshits 等USENIX Security 2023
- Phishing in Wonderland: Evaluating Learning-Based Ethereum Phishing Transaction Detection and PitfallsAhod Alghuried, David MohaisenNDSS 2026 · 被引用 4 次
